Impact
The vulnerability resides in multiple functions within alloc.c of the Android kernel and is caused by a race condition that can be exploited by an unauthenticated local user. The race condition permits unauthorized read and write access to kernel memory, enabling a local attacker to elevate privileges without requiring additional execution privileges or any user interaction. There is no mention of remote or network-based attack vectors, so the impact is confined to local privilege escalation if the race condition can be consistently triggered.
Affected Systems
This issue affects devices running the Google Android operating system that include the vulnerable kernel code. The exact kernel revision is not specified in the available data, and no particular Android OS version is listed here. The security bulletin linked in the references indicates that the fix is included in the latest security update released by Google for Android as of September 2026.
Risk and Exploitability
The CVSS score of 7.0 marks this as a high severity vulnerability. The EPSS score of 0.00062 (less than 0.1%) indicates a very low probability of exploitation, yet the lack of a user‑interaction requirement makes local exploitation attainable. Because the vulnerability is not listed in CISA’s KEV catalog, there is no evidence of active exploitation, but the high CVSS score and the capability for local privilege escalation warrant immediate attention.
OpenCVE Enrichment