Executive brief
A flaw in the Android kernel's IOMMU (input/output memory management unit) component allows a local attacker to read or write memory outside of allocated bounds due to improper input validation. This could enable privilege escalation on affected Android devices without requiring additional permissions or user interaction.
Technical details
The vulnerability exists in multiple functions of iommu.c (specifically arch/arm64/kvm/hyp/nvhe/iommu/iommu.c) in the Android Linux kernel, where input validation is insufficient when handling IOVA (Input/Output Virtual Address) and physical address alignment. An attacker with local access can supply misaligned addresses to iommu map/unmap operations, bypassing page-size alignment checks and triggering out-of-bounds read or write operations. The vulnerability requires no additional execution privileges and does not require user interaction. Patches addressing this issue involve hardening the alignment checks in the iommu code to ensure IOVA and physical addresses are properly aligned to page size boundaries.
Affected products
- Google Android kernel Linux kernel (Android common kernel)
Timeline
- 2026-09-08: disclosed
- 2026-06-02: patched: Patches merged to Android kernel common branches