Impact
A missing permission check in the function that maps I/O memory in the kernel’s KVM subsystem can cause a use‑after‑free error. The flaw allows a local user process to read or manipulate memory that has already been released, giving the attacker the ability to gain elevated privileges on the device without any additional code execution or user interaction.
Affected Systems
The vulnerability is present in the Android kernel code maintained by Google, specifically affecting devices that ship with the widely used Android kernel repository. No specific kernel version range is listed in the data, so any device that has not applied the upstream patch will likely be impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and while a precise EPSS score is not available, the flaw is not listed in the CISA KEV catalog, suggesting it may not yet be actively exploited. The attack can be carried out from a local user context; an attacker who can run code on the device, such as through a malicious app, can trigger the use‑after‑free by allocating and freeing resources in a way that the kernel accepts. No remote network access is required.
OpenCVE Enrichment