CVE-2026-21101
largeLocal privilege escalation to root in Samsung Knox DualDAR driver
CVE-2026-21101 is an improper input validation flaw in the Samsung Knox DualDAR driver, the component behind Samsung's dual-layer data-at-rest encryption on eligible Galaxy devices. It is triggered when a local attacker who already holds high (but not root) privileges on the device sends malformed input to the driver. If exploited, the attacker gains arbitrary code execution with root privileges, giving full control over the device's software context including the encrypted-storage environment. Affected devices are Samsung Galaxy devices carrying the DualDAR driver in releases prior to Samsung's SMR Sep-2026 Release 1 security maintenance update. There is currently no known exploitation in the wild: the flaw is not on the CISA KEV list and no public proof-of-concept has been published.
What to do: Update all DualDAR-capable Galaxy devices to SMR Sep-2026 Release 1 or later and verify the installed security patch level in the device's software-update settings. Until patched, restrict which apps, device administrators or MDM profiles hold high privileges on DualDAR-enabled devices, since exploitation requires an attacker who already has local privileged access. Confirm model-level applicability against Samsung's security advisories before prioritizing fleet-wide remediation.
| Samsung Knox DualDAR driver (Galaxy devices supporting Knox DualDAR, Android) | prior to SMR Sep-2026 Release 1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege.
- Vendors
- samsung
- Products
- android
- Weakness
- CWE-20
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.