Junglewise Threat Intelligence

CVE-2026-58767: ARM SMMU v3 privilege escalation in arm-smmu-v3.c

CVE-2026-58767 · Severity: medium · CVSS 6.7 · Published 2026-09-15

Executive brief

The ARM System Memory Management Unit (SMMU) v3 is a core security component in mobile processors that controls memory access and device isolation. A logic error in the kernel driver code allows a local attacker with system-level execution privileges to escalate their access further, potentially compromising the integrity of the operating system.

Technical details

The vulnerability is a privilege escalation (EoP) arising from a logic error in multiple functions within arm-smmu-v3.c, a Linux kernel driver for ARM's SMMU v3 hardware. The flaw permits local escalation of privilege when an attacker already has system execution context. Attack vector is local; user interaction is not required for exploitation. The vulnerability has been patched in Android security updates with patch level 2026-09-05 or later.

Affected products

  • Google Android prior to 2026-09-05 patch level
  • Google Pixel prior to 2026-09-05 patch level

Timeline

  • 2026-09-15: disclosed: Published in Pixel Update Bulletin
  • 2026-09-05: patched: Addressed in 2026-09-05 security patch level

References

Related threats