Description
In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

An out-of-bounds memory read/write flaw in the Android kernel’s iommu.c driver allows a local attacker to read or overwrite memory beyond intended bounds due to improper input validation. The vulnerability is a classic input validation failure (CWE-20) that gives the attacker the ability to gain kernel level privileges without needing any additional execution privileges.

Affected Systems

Google Android devices that utilize the Android kernel common repository containing the vulnerable iommu.c code are affected. Any build prior to the latest patched release, meaning current and older devices that have not applied the fix, are susceptible. No specific device model or OS version is listed, so all Android installations using the affected kernel component are potentially vulnerable.

Risk and Exploitability

The flaw scores 7.8 on CVSS, categorizing it as high severity. It requires only local access and no user interaction, meaning a legitimate user or an attacker with local privileges can trigger it with minimal effort. The EPSS is <1%, indicating a low probability of exploitation in the wild, and it is not listed in CISA KEV. Nonetheless, the risk is significant because the vulnerability permits full kernel privilege escalation, which can be leveraged for a range of destructive actions if a local attacker is present.

Generated by OpenCVE AI on September 9, 2026 at 17:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android OS and kernel patch that fixes the iommu.c input validation flaw.
  • If a patch is not available, enforce strict SELinux or device‑policy restrictions to limit untrusted local applications from accessing low‑level kernel interfaces, reducing the attack surface.
  • Continuously monitor kernel and iommu logs for anomalous memory access patterns and, if possible, disable unused IOMMU interfaces or enable additional mitigations such as kernel address space randomization.

Generated by OpenCVE AI on September 9, 2026 at 17:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 09 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title Android Kernel iommu.c Out-of-Bounds Memory Access Leading to Local Privilege Escalation

Tue, 08 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-09-08T21:02:06.884Z

Reserved: 2026-07-02T06:14:16.313Z

Link: CVE-2026-58941

cve-icon Vulnrichment

Updated: 2026-09-08T21:01:55.727Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:18:03.363

Modified: 2026-09-24T18:48:09.083

Link: CVE-2026-58941

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T20:00:03Z

Weaknesses
  • CWE-20

    Improper Input Validation