CVE-2026-21087: Google libmdnie.so vulnerability
Published Sep 9, 2026
·Updated
Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege.
Affected Software
1 affected component
Google libmdnie.so<SMR Sep-2026 Release 1
Event History
Sep 9, 2026
CVE Published
via MITRE·04:47 AM
Data Sourced
via MITRE·04:47 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A local attacker can exploit it. The provided information does not indicate that remote access alone is sufficient.
2
What level of access could successful exploitation provide?
Successful exploitation can allow arbitrary code execution with system server privilege.
3
Which releases are affected?
libmdnie.so versions prior to SMR Sep-2026 Release 1 are affected.