CVE-2026-0027
published 2026-03-02CVE-2026-0027: In smmu_detach_dev of arm-smmu-v3.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with…
PriorityP432medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.15%
4.4th percentile
In smmu_detach_dev of arm-smmu-v3.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wqj9-34jq-h8rm: In smmu_detach_dev of arm-smmu-v3
ghsa_unreviewed·2026-03-02
CVE-2026-0027 [MEDIUM] CWE-416 GHSA-wqj9-34jq-h8rm: In smmu_detach_dev of arm-smmu-v3
In smmu_detach_dev of arm-smmu-v3.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2026-0027: In smmu_detach_dev of arm-smmu-v3
osv·2026-03-01
CVE-2026-0027 CVE-2026-0027: In smmu_detach_dev of arm-smmu-v3
In smmu_detach_dev of arm-smmu-v3.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-58346 moodle: Blind SSRF risk in MNet peers function [fedora-all]
bugzilla·2026-07-28
CVE-2026-58346 [MEDIUM] CVE-2026-58346 moodle: Blind SSRF risk in MNet peers function [fedora-all]
CVE-2026-58346 moodle: Blind SSRF risk in MNet peers function [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
MSA-26-0027: Blind SSRF risk in MNet peers function
Description: A blind SSRF risk was identified in the MNet peers
management functionality, due to missing validation of peer
hostnames against the cURL blocked hosts configuration.
Note: This feature is only available to site
administrators.
Issue summary: Blind SSRF risk in MNet peers function
Severity/Risk: Minor
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier
unsupported versions
Versions fixed: 5.2.1, 5.1.5, 5
Bugzilla
CVE-2026-58346 moodle: Blind SSRF risk in MNet peers function
bugzilla·2026-06-30
CVE-2026-58346 [MEDIUM] CVE-2026-58346 moodle: Blind SSRF risk in MNet peers function
CVE-2026-58346 moodle: Blind SSRF risk in MNet peers function
MSA-26-0027: Blind SSRF risk in MNet peers function
Description: A blind SSRF risk was identified in the MNet peers
management functionality, due to missing validation of peer
hostnames against the cURL blocked hosts configuration.
Note: This feature is only available to site
administrators.
Issue summary: Blind SSRF risk in MNet peers function
Severity/Risk: Minor
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier
unsupported versions
Versions fixed: 5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by: DangKhai (VPBank Security Team)
Issue no.: MDL-87911
https://android.googlesource.com/kernel/common/+/3af14d2057f2f3df97472cef6b293113b020d1e6https://android.googlesource.com/kernel/common/+/5161b3e75fb025bb4ebb11fbf1ac037021e56719https://android.googlesource.com/kernel/common/+/a47e0e78ad5b4e153b40fc1c9def11991aa6ca0chttps://source.android.com/docs/security/bulletin/2026/2026-03-01
2026-03-02
Published