CVE-2026-56906
android :unknown:: Sicherheitsluecke
highEPSS 0.1%
Description
In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
android:unknown:
:0KernelMetrics
Show all metrics
Severity
high
65.00
no public PoC known
7.0
Published
2026-10-06 19:18 UTC
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-10-07 04:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-56906","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- SSVC: {"id":"CVE-2026-56906","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-10-06 19:18 UTC· dsap-vuln-management@google.com
- Description: In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/56xxx/CVE-2026-56906.json">CVE-2026-56906</a>
- Reference: https://source.android.com/docs/security/bulletin/pixel/2026/2026-10-01
- CVE Modified2026-10-06 19:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CVSS V3.1: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- CWE: CWE-362
- SSVC: {"id":"CVE-2026-56906","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…