CVE-2026-21102
A critical flaw in DualDAR software allows a local user with elevated privileges to run arbitrary code as the system’s root user. The vulnerability is a use‑after‑free bug that can be triggered by a privileged attacker on the same machine. It is not publicly exploitable yet, but it could let an attacker take full control of the affected system.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
DualDAR software versions prior to the SMR Sep‑2026 Release 1.
Real-world impact
An attacker who can run programs on the affected machine could exploit the flaw to execute any code they choose with root privileges, effectively taking over the entire system.
Why this severity
The CVSS score of 9.3 reflects that the flaw is local, requires high privileges to exploit, and grants the attacker full control over the system. The vector shows that the attacker needs local access and can achieve high impact on confidentiality, integrity, and availability.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
How it’s attacked
References & advisories
- security.samsungmobile.com/securityUpdate.smsbvendor advisory