{"id":"CVE-2026-21101","title":"Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege.","summary":"Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege.","severity":"high","cvss":8.4,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cvssSource":"cna","cwe":["CWE-20"],"vendor":"Samsung Mobile","product":"Samsung Mobile Devices","affected":["devices (all versions)"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-11T03:56:37.893104Z"},"published":"2026-09-09","updated":"2026-09-11","sourceUpdated":"2026-09-11T12:59:09.674Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-21101","references":[{"url":"https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09"}],"tags":["cve.org"],"epss":0.00118,"epssPercentile":0.01972,"ingestedAt":"2026-09-11T16:45:47.911Z","slug":"CVE-2026-21101","body":"## Overview\n\nImproper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege.\n\n## Affected\n\n- `devices (all versions)`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":46.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":85402,"id":"CVE-2026-21101","ts":1789134092333,"field":"cvss","old":"8.4","new":"6.7"},{"seq":85401,"id":"CVE-2026-21101","ts":1789134092333,"field":"severity","old":"high","new":"medium"},{"seq":56240,"id":"CVE-2026-21101","ts":1789074388703,"field":"cvss","old":"8.4","new":"6.7"},{"seq":56239,"id":"CVE-2026-21101","ts":1789074388703,"field":"severity","old":"high","new":"medium"}]}