CVE-2026-0106

All FrameworksAndroidCWE-125CVE-2026-0106

CVE-2026-0106

State: PUBLISHED · Published: 2026-02-05 · Updated: 2026-02-26 · Assigner: Google_Devices
Description
In vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2026/0xxx/CVE-2026-0106.json