# CVE-2026-20971: Eight-Year-Old Samsung Knox PROCA/FIVE Kernel Use-After-Free in /proc/pid/integrity Handlers

> A use-after-free in Samsung's proprietary PROCA/FIVE kernel integrity subsystem (CVE-2026-20971, CVSS 7.8) lets a local untrusted Android app race execve() against the procfs handlers under /proc/pid/integrity/, which fetch a raw pointer to a task_integrity object without holding a reference. LucidBit Labs demonstrated a crash-free KASLR-bypass leak and a spinlock-driven constrained kernel write; Samsung patched it in the January 2026 SMR (patch level 2026-01-01).

- **Published:** 2026-06-24T00:00:00Z
- **Last reviewed:** 2026-06-24T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0925
- **ID:** TL-2026-0925
- **Severity:** HIGH (CVSS 7.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-20971

## Description

CVE-2026-20971 is a race-condition use-after-free vulnerability in Samsung's PROCA (Process Authenticator) and FIVE (File-based Integrity Verification Engine) kernel integrity subsystem, a proprietary Samsung extension of the Linux Integrity Measurement Architecture (IMA) bundled into the Samsung Knox security stack. The flaw was introduced around 2017 and lay dormant for roughly eight years, affecting essentially every Samsung Galaxy device from the Galaxy S9 through the S25 and the A-series (validated on the Galaxy A54), across both Exynos and Qualcomm chipset variants and Android 13, 14, 15 and 16.

FIVE tracks the trust state of every running process via a per-task `task_integrity` object. When a process forks and the child calls `execve()`, FIVE allocates a fresh integrity object and drops the old one through `task_integrity_put(old_tint)`, freeing the original struct. The bug is that the procfs handlers exposed under `/proc/<pid>/integrity/` (`proc_integrity_value_read()`, `proc_integrity_reset_file()`, `proc_integrity_label_read()`) read a raw pointer to the target task's `task_integrity` object without taking a reference. In a fully preemptive kernel a reader thread can be suspended between fetching the pointer and dereferencing it. If the victim task executes `execve()` in that window, `task_integrity_put()` frees the object and the handler resumes operating on freed memory — for example `proc_integrity_value_read()` resuming into `task_integrity_user_read()` with a dangling pointer.

LucidBit Labs built three distinct primitives on top of the UAF. (1) A memory-disclosure / KASLR-bypass oracle: `task_integrity_user_read()` reads the `user_value` field at offset 0 of the freed object, returning a DWORD from reclaimed kernel memory with no crash risk, usable to defeat kernel address-space layout randomization. (2) An arbitrary-call attempt: `proc_integrity_reset_file()` drives a `d_dname()` function-pointer call through a freed `struct file`; the researchers forced the `reset_file` refcount to 1 by loading a non-ELF system binary (`/system/bin/monkey`) to win controlled reallocation, but Android's kernel Control-Flow Integrity (KCFI) blocked arbitrary redirection, constraining call targets to type-compatible functions. (3) A constrained write: `proc_integrity_label_read()` acquires a `spinlock_t` on the freed object, and once that memory is reclaimed the queued-spinlock atomic operations produce a constrained write at offset 0x0c, capable of overlapping adjacent pointers, refcounts or length fields. The chain is reachable from an untrusted, unprivileged app and yields kernel memory corruption with a plausible path toward deeper device control. No public weaponized exploit or in-the-wild abuse has been reported; the work is defensive security research. Samsung remediated the flaw in the January 2026 Security Maintenance Release (SMR Jan-2026 Release 1, patch level 2026-01-01 or later) by holding a proper reference to the integrity object across the procfs handlers.

## MITRE ATT&CK

- T1106 Native API
- T1203 Exploitation for Client Execution
- T1068 Exploitation for Privilege Escalation
- T1404 Exploitation for Privilege Escalation
- T1407 Download New Code at Runtime
- T1553 Subvert Trust Controls
- T1685 Disable or Modify Tools
- T1082 System Information Discovery
- T1426 System Information Discovery
- T1212 Exploitation for Credential Access
- T1424 Process Discovery
- T1577 Compromise Application Executable
- T1611 Escape to Host
- T1548 Abuse Elevation Control Mechanism
- T1057 Process Discovery
- T1083 File and Directory Discovery
- T1620 Reflective Code Loading

## Sources

- [Samsung Mobile Security Update January 2026 (SMR Jan-2026 Release 1)](https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=01)
- [NVD - CVE-2026-20971](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-20971)
- [Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks](https://www.securityweek.com/eight-year-old-samsung-knox-flaw-exposed-millions-of-galaxy-devices-to-kernel-attacks/)
- [8-Year-Old Samsung KNOX Vulnerability Exposes Galaxy Devices to Kernel Attacks](https://cybersecuritynews.com/8-year-old-samsung-knox-vulnerability/)
- [Samsung KNOX Kernel UAF Exposes Millions of Galaxy Devices](https://securityaffairs.com/194090/security/samsung-knox-kernel-uaf-exposes-millions-of-galaxy-devices.html)
- [Eight-Year-Old Samsung KNOX Kernel Vulnerability Exposed Millions of Galaxy Devices (QPulse)](https://qpulse.quasarcybertech.com/news/4276/eight-year-old-samsung-knox-kernel-vulnerability-exposed-millions-of-galaxy-devices)
- [Samsung Knox - Real-time Kernel Protection (RKP) whitepaper](https://docs.samsungknox.com/admin/fundamentals/whitepaper/samsung-knox-for-android/core-platform-security/real-time-kernel-protection/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0925
