CRITICAL 9.3 NVD
CVE-2026-21102
Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.
Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.
Affected Products
- samsung/android
References
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-09 via NVD. Affected: samsung/android.
Risk Timeline
CVE Disclosed2026-09-09 · 1 day ago
Remediation Resources
Official Advisory
security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-21095 | Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR | CRITICAL | 9.2 |
| CVE-2026-21096 | Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SM | CRITICAL | 9.2 |
| CVE-2026-21092 | Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attac | HIGH | 8.8 |
| CVE-2026-21087 | Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local | HIGH | 8.6 |
| CVE-2026-21085 | Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows | HIGH | 8.4 |
| CVE-2026-21101 | Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allo | HIGH | 8.4 |
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.