CVE-2026-0029 Details
Description
In __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
A memory corruption vulnerability has been identified in the Android kernel's pKVM implementation for arm64 architecture. This issue arises from a logic error in the 'pkvm_init_vm' function, which can lead to a local escalation of privileges. The vulnerability does not require any additional execution privileges or user interaction for exploitation.
Users can apply the latest patches available in the Android Common Kernels repository to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| google android | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Mar 6, 2026 | CVE Modified | [email protected] |
| Mar 3, 2026 | Initial Analysis | [email protected] |
| Mar 3, 2026 | CVE Modified | CISA-ADP |
| Mar 3, 2026 | CVE Modified | CISA-ADP |
| Mar 2, 2026 | New CVE Received | [email protected] |