CVE-2026-0029

HIGH EPSS 1.4%
Published Mar 2, 20263mo ago · Modified Jun 17, 20261w ago
8.4 CVSS 3.1
High
Find Similar
Published Mar 2, 2026 3mo ago
Last Modified Jun 17, 2026 1w ago

Description

In __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS Details

Base Score
8.4
Exploitability
2.5
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
1.4% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-269 Improper Privilege Management Authorization

Affected Products 1

VendorProductVersionRange
googleandroid*any

References 4

  • android.googlesource.com https://android.googlesource.com/kernel/common/+/42eff3b2fd3a906ac8cdb6284d3265bc0856b56b
    PatchProduct
  • android.googlesource.com https://android.googlesource.com/kernel/common/+/749cf1743eb22eff1851c68a533147e1af97a9bf
    PatchProduct
  • android.googlesource.com https://android.googlesource.com/kernel/common/+/ae242b26371808a221578b89c937568781719d2c
    PatchProduct
  • source.android.com https://source.android.com/docs/security/bulletin/2026/2026-03-01

Remediation

  • android.googlesource.com https://android.googlesource.com/kernel/common/+/42eff3b2fd3a906ac8cdb6284d3265bc0856b56b
    PatchProduct
  • android.googlesource.com https://android.googlesource.com/kernel/common/+/749cf1743eb22eff1851c68a533147e1af97a9bf
    PatchProduct
  • android.googlesource.com https://android.googlesource.com/kernel/common/+/ae242b26371808a221578b89c937568781719d2c
    PatchProduct