Description
In kvm_iommu_map_sg of iommu.c, there is a possible use after free due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch Urgently
AI Analysis

Impact

A missing permission check in the function that maps I/O memory in the kernel’s KVM subsystem can cause a use‑after‑free error. The flaw allows a local user process to read or manipulate memory that has already been released, giving the attacker the ability to gain elevated privileges on the device without any additional code execution or user interaction.

Affected Systems

The vulnerability is present in the Android kernel code maintained by Google, specifically affecting devices that ship with the widely used Android kernel repository. No specific kernel version range is listed in the data, so any device that has not applied the upstream patch will likely be impacted.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, and while a precise EPSS score is not available, the flaw is not listed in the CISA KEV catalog, suggesting it may not yet be actively exploited. The attack can be carried out from a local user context; an attacker who can run code on the device, such as through a malicious app, can trigger the use‑after‑free by allocating and freeing resources in a way that the kernel accepts. No remote network access is required.

Generated by OpenCVE AI on September 9, 2026 at 14:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android kernel update that includes the upstream patch for the KVM IOMMU mapping bug
  • If an update is not yet available, disable the KVM subsystem or remove the device from the trusted device list by setting the appropriate driver configuration parameters
  • Enforce stricter permission checks on the iommu_iova_to_host function and verify that untrusted users cannot map I/O memory using privileged calls
  • Consider implementing mandatory access controls such as SELinux policies that restrict local users from accessing the KVM runtime APIs

Generated by OpenCVE AI on September 9, 2026 at 14:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Title Possible Use After Free in KVM IOMMU Mapping Enables Local Privilege Escalation

Tue, 08 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In kvm_iommu_map_sg of iommu.c, there is a possible use after free due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-08T20:53:31.165Z

Reserved: 2026-07-02T06:00:06.365Z

Link: CVE-2026-58846

cve-icon Vulnrichment

Updated: 2026-09-08T20:53:23.626Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:18:03.077

Modified: 2026-09-24T16:26:56.140

Link: CVE-2026-58846

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T20:00:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management