{"id":"ASB-A-508703529", "published":"2026-09-01T00:00:00Z", "modified":"2026-09-17T16:10:43.690857626Z", "aliases":["CVE-2026-58846", "A-508703529"], "details":"In kvm_iommu_map_sg of iommu.c, there is a possible use after free due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "affected":[{"package":{"name":":linux_kernel:", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":":0"}, {"fixed":":2026-09-05"}]}], "versions":["Kernel"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/kernel/common/+/ad34d15396568919a8ddd306ce2120e76d111b7c"], "severity":"Critical", "spl":"2026-09-05", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"168954781745444072032503680114273002111", "length":1066}, "id":"ASB-A-508703529-044effee", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/kernel/common/+/ad34d15396568919a8ddd306ce2120e76d111b7c", "target":{"file":"arch/arm64/kvm/hyp/nvhe/iommu/iommu.c", "function":"kvm_iommu_map_sg"}}, {"deprecated":false, "digest":{"line_hashes":["14531556049287530510865264223986290014", "113222022963745869985270281040455277746", "2315668818763018126251938254453642398"], "threshold":0.9}, "id":"ASB-A-508703529-c56cc12d", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/kernel/common/+/ad34d15396568919a8ddd306ce2120e76d111b7c", "target":{"file":"arch/arm64/kvm/hyp/nvhe/iommu/iommu.c"}}]}}], "references":[{"type":"ADVISORY", "url":"https://source.android.com/security/bulletin/2026-09-01"}, {"type":"FIX", "url":"https://android.googlesource.com/kernel/common/+/ad34d15396568919a8ddd306ce2120e76d111b7c"}]}