Use-After-Free in Samsung Knox PROCA driver
CVE-2026-20971 is a high-severity use-after-free vulnerability in Samsung’s Knox PROCA (Process Authenticator) kernel driver, fixed in SMR Jan-2026 Release 1. The flaw arises from a race condition in the interaction between the PROCA and FIVE integrity subsystems, specifically around the lifetime of the kernel task_integrity object that stores integrity state for a running process. In the vulnerable condition, one kernel path can continue using a task_integrity pointer after another path has freed and potentially reallocated the underlying object, creating a dangling-pointer condition in kernel memory. Reported reachable paths include procfs-backed integrity handlers such as proc_integrity_value_read(), proc_integrity_reset_file(), and proc_integrity_label_read(). Researchers reported multiple exploitation primitives from this bug, including a kernel memory disclosure, a function-pointer-related path through a freed struct file, and a constrained kernel write when the freed task_integrity object is reclaimed as another kernel object. Samsung described the issue as allowing a local attacker to potentially execute arbitrary code prior to the January 2026 release.
Are you exposed to this one?
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
Impact, mitigation & remediation
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
Impact
What an attacker gets, and what they’ve been doing with it.
Mitigation
If you can’t patch tonight, do this now.
Remediation
Patch, then assume compromise.
Exploits
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Affected products & vendors
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
Recent activity
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A use-after-free vulnerability in Samsung's PROCA driver within the Knox security framework that could allow local kernel memory corruption and potentially arbitrary code execution on affected Galaxy devices.
A high-severity use-after-free race condition vulnerability in Samsung’s KNOX kernel security framework involving PROCA and FIVE that could be triggered from an untrusted app, leading to kernel memory corruption and potentially deeper control of the device.
The version that knows your environment.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.