Threat reportVulnerabilityTL-2026-0925
CVE-2026-20971: Eight-Year-Old Samsung Knox PROCA/FIVE Kernel Use-After-Free in /proc/pid/integrity Handlers
CVE-2026-20971 (TL-2026-0925), also tracked as 8-Year-Old Samsung Knox Vulnerability, is a high-severity software vulnerability scored CVSS 7.8, first published 2026-06-24. It has no confirmed attribution, affects Samsung Galaxy S-series (PROCA/FIVE kernel integrity driver), references 1 CVE (CVE-2026-20971), maps to 17 MITRE ATT&CK techniques (T1057, T1068, T1082), and is covered by 9 detection rules and 18 indicators of compromise.
- CVSS
- 7.8/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 17MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 18Indicators of compromise
Key facts for TL-2026-0925
- Threat ID
- TL-2026-0925
- Also known as
- 8-Year-Old Samsung Knox Vulnerability, Samsung Knox PROCA/FIVE UAF
- Severity
- HIGH
- CVSS
- 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- consumer, government, enterprise, telecommunications
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 18
How CVE-2026-20971 works
A use-after-free in Samsung's proprietary PROCA/FIVE kernel integrity subsystem (CVE-2026-20971, CVSS 7.8) lets a local untrusted Android app race execve() against the procfs handlers under /proc/pid/integrity/, which fetch a raw pointer to a task_integrity object without holding a reference. LucidBit Labs demonstrated a crash-free KASLR-bypass leak and a spinlock-driven constrained kernel write; Samsung patched it in the January 2026 SMR (patch level 2026-01-01).
CVE-2026-20971 is a race-condition use-after-free vulnerability in Samsung's PROCA (Process Authenticator) and FIVE (File-based Integrity Verification Engine) kernel integrity subsystem, a proprietary Samsung extension of the Linux Integrity Measurement Architecture (IMA) bundled into the Samsung Knox security stack. The flaw was introduced around 2017 and lay dormant for roughly eight years, affecting essentially every Samsung Galaxy device from the Galaxy S9 through the S25 and the A-series (validated on the Galaxy A54), across both Exynos and Qualcomm chipset variants and Android 13, 14, 15 and 16.
FIVE tracks the trust state of every running process via a per-task `task_integrity` object. When a process forks and the child calls `execve()`, FIVE allocates a fresh integrity object and drops the old one through `task_integrity_put(old_tint)`, freeing the original struct. The bug is that the procfs handlers exposed under `/proc/<pid>/integrity/` (`proc_integrity_value_read()`, `proc_integrity_reset_file()`, `proc_integrity_label_read()`) read a raw pointer to the target task's `task_integrity` object without taking a reference. In a fully preemptive kernel a reader thread can be suspended between fetching the pointer and dereferencing it. If the victim task executes `execve()` in that window, `task_integrity_put()` frees the object and the handler resumes operating on freed memory — for example `proc_integrity_value_read()` resuming into `task_integrity_user_read()` with a dangling pointer.
LucidBit Labs built three distinct primitives on top of the UAF. (1) A memory-disclosure / KASLR-bypass oracle: `task_integrity_user_read()` reads the `user_value` field at offset 0 of the freed object, returning a DWORD from reclaimed kernel memory with no crash risk, usable to defeat kernel address-space layout randomization. (2) An arbitrary-call attempt: `proc_integrity_reset_file()` drives a `d_dname()` function-pointer call through a freed `struct file`; the researchers forced the `reset_file` refcount to 1 by loading a non-ELF system binary (`/system/bin/monkey`) to win controlled reallocation, but Android's kernel Control-Flow Integrity (KCFI) blocked arbitrary redirection, constraining call targets to type-compatible functions. (3) A constrained write: `proc_integrity_label_read()` acquires a `spinlock_t` on the freed object, and once that memory is reclaimed the queued-spinlock atomic operations produce a constrained write at offset 0x0c, capable of overlapping adjacent pointers, refcounts or length fields. The chain is reachable from an untrusted, unprivileged app and yields kernel memory corruption with a plausible path toward deeper device control. No public weaponized exploit or in-the-wild abuse has been reported; the work is defensive security research. Samsung remediated the flaw in the January 2026 Security Maintenance Release (SMR Jan-2026 Release 1, patch level 2026-01-01 or later) by holding a proper reference to the integrity object across the procfs handlers.
MITRE ATT&CK techniques used in TL-2026-0925
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1426 System Information Discovery
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1404 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism; T1611 Escape to Host
Execution
T1106 Native API; T1203 Exploitation for Client Execution
Credential Access
T1212 Exploitation for Credential Access
Defense Evasion
T1407 Download New Code at Runtime; T1620 Reflective Code Loading
discovery
defense-impairment
T1553 Subvert Trust Controls; T1685 Disable or Modify Tools
Persistence
Affected products and versions in CVE-2026-20971
- Samsung — Galaxy S-series (PROCA/FIVE kernel integrity driver)
Vulnerable versions: Galaxy S9; S10; S20; S21; S22; S23; S24; S25
Fixed in: SMR Jan-2026 Release 1 (patch level 2026-01-01+) - Samsung — Galaxy A-series (validated on A54)
Vulnerable versions: Galaxy A54; A-series Exynos and Qualcomm variants
Fixed in: SMR Jan-2026 Release 1 (patch level 2026-01-01+) - Samsung — Android OS on Samsung Mobile (Knox PROCA driver)
Vulnerable versions: Android 13; Android 14; Android 15; Android 16 (SMR Feb-2022 through Dec-2025)
Fixed in: SMR Jan-2026 Release 1
Remediation for CVE-2026-20971
Patches
- Samsung SMR Jan-2026 Release 1 (SVE/Knox PROCA driver fix for CVE-2026-20971); applies to Android 13, 14, 15, 16
Immediate actions
- Install the Samsung January 2026 Security Maintenance Release (verify Settings > About phone > Android security update shows 2026-01-01 or later)
- Restrict installation of untrusted/sideloaded apps that could host a local exploit
Workarounds
- No vendor workaround other than patching; integrity-tracking procfs entries are not user-disableable
- Limit exposure by vetting and minimizing third-party app installs until patched
Longer-term hardening
- Enforce MDM policy requiring devices to be at the latest Samsung SMR patch level before granting access to corporate resources
- Deploy mobile threat defense (MTD) / EDR capable of flagging local privilege-escalation behavior on Android
CVEs associated with CVE-2026-20971
Weaknesses (CWE) in CVE-2026-20971
Timeline of CVE-2026-20971
- Use-after-free introduced in Samsung's PROCA/FIVE kernel integrity subsystem when the /proc/pid/integrity handlers were added without holding a reference to the task_integrity object (~8 years before disclosure).
- Vulnerable code present across Samsung Security Maintenance Releases from February 2022 onward (per NVD affected-configuration range), spanning Android 13 through 16.
- LucidBit Labs analyzes the PROCA/FIVE procfs handlers, identifies the execve()/task_integrity_put() race, and develops the KASLR-bypass leak, d_dname arbitrary-call attempt, and spinlock constrained-write primitives.
- LucidBit Labs responsibly discloses CVE-2026-20971 to Samsung ahead of the January 2026 Security Maintenance Release.
- Samsung publishes the January 2026 Mobile Security bulletin (SMR Jan-2026) listing the PROCA/FIVE integrity-driver fix among the month's SVE items.
- Samsung publishes the January 2026 SMR (Release 1) fixing the PROCA driver UAF; patch level 2026-01-01 or later. CVE-2026-20971 published on NVD.
- NVD record for CVE-2026-20971 last modified, finalizing CVSS v3.1 (7.8) and CWE-416 mapping.
- Public technical write-ups (SecurityWeek, CyberSecurityNews, Security Affairs) detail the eight-year-old Knox flaw and LucidBit's exploitation primitives.
- Threat ingested and analyzed by the Threadlinqs intelligence pipeline; KCFI confirmed as the control that downgraded the arbitrary-call primitive to a constrained write, keeping the chain short of full code execution.
Sources cited for CVE-2026-20971
- Samsung Mobile Security Update January 2026 (SMR Jan-2026 Release 1)
- NVD - CVE-2026-20971
- Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks
- 8-Year-Old Samsung KNOX Vulnerability Exposes Galaxy Devices to Kernel Attacks
- Samsung KNOX Kernel UAF Exposes Millions of Galaxy Devices
- Eight-Year-Old Samsung KNOX Kernel Vulnerability Exposed Millions of Galaxy Devices (QPulse)
- Samsung Knox - Real-time Kernel Protection (RKP) whitepaper
Detection coverage for TL-2026-0925
As of 2026-06-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0925 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.