CVE-2026-21085: Keymaster trustlet vulnerability
Published Sep 9, 2026
·Updated
Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.
Affected Software
1 affected component
Keymaster trustlet<SMR Sep-2026 Release 1
Event History
Sep 9, 2026
CVE Published
via MITRE·04:47 AM
Data Sourced
via MITRE·04:47 AM
DescriptionWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs local privileged access to the affected device.
2
Which releases are affected?
The issue affects the Keymaster trustlet before the SMR Sep-2026 Release 1 update.
3
What should organizations do to remediate the issue?
Apply SMR Sep-2026 Release 1 or a later update that includes the fix.