PT-2026-6005 · Unknown · Vpu Driver
Published
2026-02-04
·
Updated
2026-03-10
·
CVE-2026-0106
CVSS v3.1
9.3
Critical
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Android VPU driver versions prior to the February 2026 security patch
Description
The issue resides within the
vpu ioctl function, specifically in the vpu mmap component. A missing bounds check allows for a potential arbitrary address mapping. Successful exploitation could lead to local privilege escalation without requiring additional execution privileges or user interaction. Reports indicate that devices running Android are at risk, with a potential impact on a significant number of devices. The vulnerability allows for arbitrary read/write access to the kernel from a low-privileged userland context through a media parsing process. The vpu ioctl function and its vpu mmap component are central to the issue.Recommendations
Install the February 2026 security patch for Android.
Fix
LPE
Memory Corruption
Out of bounds Read
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vpu Driver