Android Kernel pKVM Memory Corruption Vulnerability Leading to Privilege Escalation

Vulnerability

A memory corruption vulnerability has been identified in the Android kernel's pKVM implementation for arm64 architecture. This issue arises from a logic error in the 'pkvm_init_vm' function, which can lead to a local escalation of privileges. The vulnerability does not require any additional execution privileges or user interaction for exploitation.

Impact

Exploitation of this vulnerability could result in unauthorized privilege escalation within the affected system.

Remediation

Users can apply the latest patches available in the Android Common Kernels repository to address this vulnerability.

Added: Mar 2, 2026, 7:28 PM
Updated: Mar 2, 2026, 8:49 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.4
remediation
0.0
relevance
3.4
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.