What is CVE-2026-21067?
This vulnerability is caused by improper input validation in the libsmsd.so library, allowing local attackers to write out-of-bounds memory on versions prior to SMR Aug-2026 Release 1. Affected devices must apply the security patch.
Azərbaycanca: Bu boşluq libsmsd.so kitabxanasında düzgün giriş doğrulamasının olmaması səbəbindən yaranır. Lokal təcavüzkarlara SMR Aug-2026 Release 1 öncəsi versiyalarda hədəf sistemdə yaddaş sərhədlərini aşaraq məlumat yazmağa imkan verir. Təsirə məruz qalan cihazlar üçün təhlükəsizlik yaması tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-787
FAQ2
What level of access does an attacker need to exploit CVE-2026-21067?
An attacker requires local access to the target system to exploit this vulnerability.
Which component contains the CVE-2026-21067 vulnerability?
This vulnerability exists in the libsmsd.so library due to improper input validation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.