CVE-2026-58731
Received Received - Intake

Out-of-Bounds Read in Linux Physical Memory Management

Vulnerability report for CVE-2026-58731, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-18

Assigner: Google Devices

Description

In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-18
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
google android *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.
CWE-457 The code uses a variable that has not been initialized, leading to unpredictable or unintended results.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds read issue in the physmem_extmem_linux.c file. It occurs because some functions in the file do not properly initialize data before using it, leading to potential memory access beyond allocated bounds. This flaw can be exploited locally to disclose sensitive information without requiring additional privileges or user interaction.

Impact Analysis

This vulnerability could allow an attacker with local access to read sensitive data from memory that they should not be able to access. Since no extra privileges or user interaction are needed, it lowers the barrier for exploitation. The impact includes potential exposure of confidential or personal information stored in memory.

Compliance Impact

This vulnerability could lead to local information disclosure, which may result in unauthorized access to sensitive data. For GDPR, this could violate principles of data protection and user privacy, potentially leading to compliance issues if personal data is exposed. For HIPAA, unauthorized disclosure of protected health information could breach regulatory requirements.

Mitigation Strategies

Apply vendor patches or updates for the affected software. Monitor official security advisories for fixes. Restrict access to vulnerable systems if possible. Ensure no unnecessary privileges are granted to users.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-58731. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart