CVE-2026-20971Disclosure(samsung / android)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch samsung android systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android

Threat summary

  • Patch or workaround signal is available
  • 21 mentions across 10 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 17 signals
  • Disclosure: 12 classified signals
  • General: 3 classified signals
  • Peaked 9d ago at 6 mentions (2026-06-23); latest day: 1
  • 21 total mentions across 10 days

Affected systems

Vendors
Products
android

4 versions affected across 1 product

Deep dive

Activity timeline21 mentions / 10d
02356Mentions · 2026-06-23: 6Mentions · 2026-06-24: 3Mentions · 2026-06-25: 3Mentions · 2026-06-26: 2Mentions · 2026-06-29: 1Mentions · 2026-07-05: 1Mentions · 2026-07-08: 1Mentions · 2026-07-18: 1Mentions · 2026-08-21: 2Mentions · 2026-08-22: 1Patch / Workaround · 2026-06-23: 5Patch / Workaround · 2026-06-24: 1Patch / Workaround · 2026-06-25: 2Patch / Workaround · 2026-06-26: 1Patch / Workaround · 2026-07-08: 1Patch / Workaround · 2026-08-22: 1Technical Details · 2026-06-23: 6Technical Details · 2026-06-24: 3Technical Details · 2026-06-25: 1Technical Details · 2026-06-26: 1Technical Details · 2026-06-29: 1Technical Details · 2026-07-05: 1Technical Details · 2026-07-08: 1Technical Details · 2026-08-21: 2Technical Details · 2026-08-22: 106-2306-2406-2506-2606-2907-0507-0807-1808-2108-22
Signal classification3 categories
Disclosure
1257.1%
Patch
628.6%
General
314.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-06-236
Disclosure1Patch5
2026-06-243
Disclosure3
2026-06-253
Disclosure2Patch1
2026-06-262
Disclosure1General1
2026-06-291
Disclosure1
2026-07-051
General1
2026-07-081
Disclosure1
2026-07-181
General1
2026-08-212
Disclosure2
2026-08-221
Disclosure1
Full discourse20 posts
  • Lior Keshet@LiorKesh
    Disclosure

    We published a technical write-up on CVE-2026-20971: a Samsung Android kernel use-after-free found by our team at LucidBit Labs. The interesting part: the bug lived inside a defense mechanism.

    Post summary

    The text announces the discovery of a Samsung Android kernel use‑after‑free (CVE‑2026‑20971) and references a technical write‑up, but no PoC, exploit code, patch, or evidence of active exploitation is mentioned.

    295101.2K762.4M
    347 followersView on X
  • 0xor0ne@0xor0ne
    General

    Samsung Kernel UAF (CVE-2026-20971) https://lucidbitlabs.com/blog/when-defenses-become-attack-surface/ #infosec https://t.co/2Nc0TMstDD

    Post summary

    The tweet references a CVE and a blog link but offers no concrete information about the vulnerability, potential PoC, exploitation status, or remediation.

    150030015516.9K
    93.6K followersView on X
  • 0xor0ne@0xor0ne
    Disclosure

    App to Kernel UAF memory corruption in Samsung devices (CVE-2026-20971) https://lucidbitlabs.com/blog/when-defenses-become-attack-surface/ #infosec https://t.co/QBuGWmN6xk

    Post summary

    The blog announces CVE-2026-20971, describing it as an app-to-kernel use‑after‑free memory corruption affecting Samsung devices.

    2321169747.7K
    93.9K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2026-20971: Samsung Android kernel UAF affecting Galaxy S9-S25 https://lucidbitlabs.com/blog/when-defenses-become-attack-surface/

    Post summary

    The tweet announces CVE‑2026‑20971, a user‑after‑free flaw in Samsung’s Android kernel that impacts Galaxy S9‑S25 phones, linking to a blog for more details.

    17118113.5K
    159.6K followersView on X
  • Mr. OS@ksg93rd
    Disclosure

    #Kernel_Security When Defenses Become Attack Surface: CVE-2026-20971, a Samsung Kernel UAF https://lucidbitlabs.com/blog/when-defenses-become-attack-surface // Target: Samsung Android Kernel. Affected Devices: Galaxy S9 through Galaxy S25, A-series, Exynos, and Qualcomm devices. Impact: App to Kernel memory corruption. Status: Reported by LucidBit, fixed on Samsung's January 2026 Android security update CyberPocket makes cybersecurity alerts easy to understand. Paste an alert, upload a screenshot, or submit a security message, and CyberPocket turns confusing technical details into a clear summary, risk level, next steps, and client-ready ticket notes. Built for individuals, students, IT teams, MSPs, MSSPs, and SOC analysts, CyberPocket helps you triage faster, learn smarter, and respond with confidence. Visit http://cyberpocket.org and turn confusing alerts into clear action.

    Post summary

    The post announces the Samsung Kernel UAF CVE‑2026‑20971, details its scope and impact, and notes that it will be patched in the January 2026 security update.

    03012111.2K
    3.4K followersView on X
  • ɐpnH@AlAssaf_H
    Disclosure

    When Defenses Become Attack Surface: CVE-2026-20971, a Samsung Kernel UAF https://lucidbitlabs.com/blog/when-defenses-become-attack-surface/ https://t.co/15yPwxmBcu

    Post summary

    The brief reference announces a Samsung kernel use‑after‑free vulnerability (CVE‑2026‑20971) but provides no proof‑of‑concept, exploit details, or patch information.

    0501077.9K
    844 followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    CVE-2026-20971: Samsung Android kernel UAF affecting Galaxy S9-S25 https://lucidbitlabs.com/blog/when-defenses-become-attack-surface/

    Post summary

    The post announces CVE-2026-20971, a use‑after‑free flaw in the Samsung Android kernel that affects Galaxy S9 through S25, and provides a blog link for more details.

    030711.1K
    33.6K followersView on X
  • LucidBitLabs@LucidBitLabs
    Disclosure

    Last week we disclosed CVE-2026-20971: a Samsung KNOX kernel UAF affecting Galaxy S9-S25 devices. It was later covered by SecurityWeek and Security Affairs. Technical writeup: https://lucidbitlabs.com/blog/when-defenses-become-attack-surface/

    Post summary

    The text announces the disclosure of CVE‑2026‑20971, describing it as a Samsung KNOX kernel UAF on selected Galaxy devices.

    01010139
    191 followersView on X
  • Schmidtis Blog@SchmidtisBlog
    Patch

    Ein Kernel-Bug gefährdet Millionen Samsung Galaxy-Geräte seit 8 Jahren. Lucid Bit Labs entdeckte CVE-2026-20971. Prüft euren Januar-Patch! https://www.schmidtisblog.de/acht-jahre-ungepatcht-speicherfehler-gefaehrdet-millionen-samsung-galaxy-smartphones-1809996/

    Post summary

    A kernel bug (CVE‑2026‑20971) discovered by Lucid Bit Labs has been affecting millions of Samsung Galaxy devices for eight years; users are urged to apply the January patch to mitigate the risk.

    01010123
    1.2K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Disclosure

    An eight-year-old Samsung KNOX vulnerability, CVE-2026-20971, let an untrusted app corrupt kernel memory on Galaxy phones from the S9 to the S25. #Samsung #KNOX #AndroidSecurity #UseAfterFree #Galaxy https://securityexpress.info/samsung-knox-vulnerability https://t.co/xAy9QbuVPC

    Post summary

    The tweet announces an eight‑year‑old Samsung KNOX vulnerability (CVE‑2026‑20971) that enables kernel memory corruption via a use‑after‑free, but no PoC, exploit code, patch or active exploitation is mentioned.

    00020546
    12.8K followersView on X
  • Israel@f1tym1
    Patch

    CVE-2026-20971, a use-after-free in Samsung's PROCA kernel component, affected Galaxy S9 through S25 devices for years before patching in January 2026. https://ift.tt/F1AXV72

    Post summary

    CVE‑2026‑20971 is a use‑after‑free bug in Samsung’s PROCA kernel component affecting Galaxy S9‑S25 devices; it was addressed with a patch released in January 2026.

    0101085
    1.0K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    A use-after-free vulnerability in Samsung KNOX affecting hundreds of millions of Galaxy devices and tracked as CVE-2026-20971 was disclosed by LucidBit, with Samsung releasing a fix in January 2026. https://t.co/eLOw7KNkxX

    Post summary

    The tweet announces a use-after-free flaw in Samsung KNOX (CVE-2026-20971) impacting many Galaxy devices and notes that Samsung has already released a patch in January 2026.

    10000111
    396 followersView on X
  • Xavier Rivera@XavierRiveraX
    Patch

    CVE-2026-20971 (CVSS 7.8) in Samsung KNOX affected Galaxy S9-S25 and A-series phones on Android 13-16. A race condition in the PROCA process authenticator lets an untrusted app read freed memory before the FIVE integrity subsystem clears it, enabling kernel corruption. Fixed in Samsung's January 2026 SMR update; verify managed Android devices in your MDM inventory have applied the patch.

    Post summary

    The post reports a race‑condition CVE affecting Samsung KNOX on Android devices and alerts that a patch is released in January 2026, recommending verification of device updates.

    0000190
    578 followersView on X
  • Štefan Engi@stefan_engi
    Patch

    Vedeli ste o o osem rokov starej vysoko závažnej zraniteľnosti typu use-after-free v Samsungovom rámci KNOX? Ide o CVE-2026-20971 s hodnotením CVSS 7.8, ktorá umožňuje útoky na kernel na miliónoch zariadení Galaxy. Chyba vzniká z race condition (pretekov) medzi autentifikáciou procesu PROCA a kontrolami integrity jadra FIVE počas volania execve(). Zraniteľnosť je zneužiteľná lokálne z nedôveryhodnej aplikácie, pričom vyžaduje interakciu používateľa. Postihnuté sú všetky Android zariadenia Galaxy od rady S9 až po S25 (verzie Android 13 – 16). Samsung chybu opravil v bezpečnostnej aktualizácii z januára 2026. #samsung #knox #exploit

    Post summary

    The post describes a use‑after‑free vulnerability (CVE-2026-20971) in Samsung Knox that affects Galaxy devices and was resolved in a January 2026 security update.

    10000100
    83 followersView on X
  • Kyssta@kysstalol
    Disclosure

    App to Kernel UAF memory corruption in Samsung devices (CVE-2026-20971) demonstrates how security defenses can become attack surfaces. Critical reminder that firmware patches must address kernel vulnerabilities directly.

    Post summary

    The text announces a new Samsung kernel UAF vulnerability and stresses the need for firmware patches, but it does not provide a PoC, exploit, or evidence of ongoing attacks.

    0000032
    22 followersView on X
  • BT Haberler@BTHaberler
    Disclosure

    Samsung Knox'ta 8 yıllık açık: Galaxy S9'dan S25'e kadar tüm cihazlar etkileniyor! LucidBit Labs, Samsung Knox'un PROCA ve FIVE bileşenlerinde bir use-after-free açığı keşfetti. CVE-2026-20971 (CVSS 7.8), Exynos ve Qualcomm çipli geniş bir cihaz yelpazesini etkiliyor. • Bir iş parçacığı belleğe işaretçi alırken askıya alınıyor, başka bir iş parçacığı belleği serbest bırakıyor — sonra ilk iş parçacığı boş belleğe erişmeye devam ediyor. • KCFI korumasını atlatmak için çalıştırılamayan dosyalar yüklemeye zorlanan işlemler kullanıldı. • Android 13, 14, 15 ve 16'yı etkiliyor; yama Ocak 2026 güvenlik güncellemesiyle geldi. Fiziksel erişim gerektirse de başka zararlı yazılımlarla birleşince kurumsal ağlara sızma riski taşıyor! #SiberGüvenlik #Samsung #GüvenlikAçığı

    Post summary

    The text announces the discovery of a use‑after‑free vulnerability in Samsung Knox, provides technical details and a planned patch, but offers no PoC or evidence of active exploitation.

    0000091
    36 followersView on X
  • Israel@f1tym1
    General

    Update: dailysecurityreview assigns a specific CVSS score of 7.8 to CVE-2026-20971, providing quantified severity metric not included in the original post. https://ift.tt/tNySbCR

    Post summary

    The update assigns a CVSS score of 7.8 to CVE-2026-20971, adding quantified severity information without reporting exploits, patches, or active attacks.

    0000045
    1.0K followersView on X
  • Global Macro Signals@GlobalMacroSigs
    General

    @LiorKesh The uncomfortable signal in CVE-2026-20971 is that hardening code can expand attack surface. “Defense mechanism” bugs are the ones teams tend to trust longest.

    Post summary

    The tweet points out that hardening code may enlarge the attack surface and that defense‑mechanism bugs are often overtrusted, but it does not provide any technical, PoC, exploit, or patch information.

    0000065
    5.5K followersView on X
  • 상식과정의@cheolsoo8
    Disclosure

    보안업체 루시드비트 랩스(LucidBit Labs)는 2026년 6월 22일 CVE-2026-20971 취약점의 분석 결과를 공개했다. 삼성전자는 이에 앞서 2026년 1월 보안 업데이트를 통해 문제를 수정했다. 출처 : 데일리시큐(https://www.dailysecu.com)

    Post summary

    LucidBit Labs published an analysis of CVE-2026-20971 on June 22, 2026, noting that Samsung had already remedied the flaw with a January security update.

    0000036
    3.1K followersView on X
  • Shah Sheikh@shah_sheikh
    Patch

    Samsung KNOX Kernel UAF Exposes Millions of Galaxy Devices: Samsung’s KNOX flaw (CVE-2026-20971) is a kernel UAF in PROCA/FIVE that can enable corruption via a race; Samsung patched it in Jan 2026. Experts found a nasty kernel flaw in Samsung’s KNOX… https://securityaffairs.com/194090/security/samsung-knox-kernel-uaf-exposes-millions-of-galaxy-devices.html?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The article announces a kernel use-after-free flaw in Samsung KNOX (CVE-2026-20971) affecting millions of Galaxy devices, and notes that Samsung released a patch in January 2026.

    0000054
    2.3K followersView on X
CPE platform detail116 entries

116 of 116 entries

PartVendorProductVersionTarget SWTarget HW
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid13.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid14.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid15.0--
OSsamsungandroid16.0--
OSsamsungandroid16.0--
OSsamsungandroid16.0--
OSsamsungandroid16.0--
OSsamsungandroid16.0--

Explore more