Impact
The flaw is a logic error in the arm‑smmu‑v3.c driver that leads to a use‑after‑free condition. Because the driver does not properly verify the state of a freed object, an attacker with local access can trigger the flaw to run code with system privileges. No special user interaction is required, allowing the exploit to be performed by any local component or malicious application that can communicate with the driver. The weakness is classified as CWE‑416.
Affected Systems
Android devices that use the arm‑smmu‑v3 driver before the 2026‑09‑01 security bulletin are affected. The advisory does not list specific Android release numbers, so all Android versions containing the vulnerable driver in the kernel prior to the bulletin are at risk.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity. The EPSS score is less than 1%, suggesting a low likelihood of exploitation. The vulnerability is not present in the CISA KEV catalog. Exploitation requires local presence on the device; an attacker could use a malicious application or privileged component to trigger the use‑after‑free and elevate privileges without further user interaction.
OpenCVE Enrichment