CVE-2026-0029
published 2026-03-02CVE-2026-0029: In __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no…
PriorityP344high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
EPSS
0.11%
1.4th percentile
In __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — |
CVSS provenance
nvdv3.18.4HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cisa7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cfhx-3vr6-pxq9: In __pkvm_init_vm of pkvm
ghsa_unreviewed·2026-03-02
CVE-2026-0029 [CRITICAL] CWE-269 GHSA-cfhx-3vr6-pxq9: In __pkvm_init_vm of pkvm
In __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2026-0029: In __pkvm_init_vm of pkvm
osv·2026-03-01
CVE-2026-0029 CVE-2026-0029: In __pkvm_init_vm of pkvm
In __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CISA
Omnissa Workspace ONE Server-Side Request Forgery
cisa·2026-03-09·CVSS 7.5
CVE-2021-22054 [HIGH] CWE-918 Omnissa Workspace ONE Server-Side Request Forgery
Vulnerability: Omnissa Workspace ONE Server-Side Request Forgery
Affected: Omnissa Workspace One UEM
Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://web.archive.org/web/20211222154335/https://www.vmware.com/security/advisories/VMSA-2021-0029.html ; https://nvd.nist.gov/vuln/detail/CVE-2021-22054
Remediation Due Date: 2026-03-23
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://android.googlesource.com/kernel/common/+/42eff3b2fd3a906ac8cdb6284d3265bc0856b56bhttps://android.googlesource.com/kernel/common/+/749cf1743eb22eff1851c68a533147e1af97a9bfhttps://android.googlesource.com/kernel/common/+/ae242b26371808a221578b89c937568781719d2chttps://source.android.com/docs/security/bulletin/2026/2026-03-01
2026-03-02
Published