ZeroHour

CVE-2026-21101

large

Local privilege escalation to root in Samsung Knox DualDAR driver

CVSS 4.0
8.4 high
EPSS
<1%p2
Published
()
Modified
AI analysis

CVE-2026-21101 is an improper input validation flaw in the Samsung Knox DualDAR driver, the component behind Samsung's dual-layer data-at-rest encryption on eligible Galaxy devices. It is triggered when a local attacker who already holds high (but not root) privileges on the device sends malformed input to the driver. If exploited, the attacker gains arbitrary code execution with root privileges, giving full control over the device's software context including the encrypted-storage environment. Affected devices are Samsung Galaxy devices carrying the DualDAR driver in releases prior to Samsung's SMR Sep-2026 Release 1 security maintenance update. There is currently no known exploitation in the wild: the flaw is not on the CISA KEV list and no public proof-of-concept has been published.

What to do: Update all DualDAR-capable Galaxy devices to SMR Sep-2026 Release 1 or later and verify the installed security patch level in the device's software-update settings. Until patched, restrict which apps, device administrators or MDM profiles hold high privileges on DualDAR-enabled devices, since exploitation requires an attacker who already has local privileged access. Confirm model-level applicability against Samsung's security advisories before prioritizing fleet-wide remediation.

Affected
Samsung Knox DualDAR driver (Galaxy devices supporting Knox DualDAR, Android)prior to SMR Sep-2026 Release 1
Estimated exposure
largelikely on the order of hundreds of thousands of devices (Knox DualDAR is limited to select Galaxy enterprise/government models) — DualDAR ships only on select Samsung Knox Galaxy models sold primarily into government, defense and regulated enterprise deployments, whose combined installed base is plausibly in the hundreds of thousands, though Samsung does not publish…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege.

Vendors
samsung
Products
android
Weakness
CWE-20
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.