CVE-2026-56906

android :unknown:: Sicherheitsluecke

Description

In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

android:unknown:
:0Kernel

Metrics

7.0
Source: cna-v3
0.0 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
high
no public PoC known
0.1 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-10-06 19:18 UTC

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-10-07 04:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-56906","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
    • SSVC: {"id":"CVE-2026-56906","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  2. New CVE Received2026-10-06 19:18 UTC· dsap-vuln-management@google.com
    • Description: In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/56xxx/CVE-2026-56906.json">CVE-2026-56906</a>
    • Reference: https://source.android.com/docs/security/bulletin/pixel/2026/2026-10-01
  3. CVE Modified2026-10-06 19:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • CVSS V3.1: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
    • CWE: CWE-362
    • SSVC: {"id":"CVE-2026-56906","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…