AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-21399

MEDIUM · CVSS 6.9 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Intel Open Volume Kernel Library prior to version 2.0.2 is susceptible to a heap-based buffer overflow, which could be exploited by an authenticated user to cause a denial of service. This vulnerability poses a high risk to system availability, particularly in environments where local access is possible, and attackers may leverage low-complexity methods without requiring user interaction. Organizations utilizing this library should prioritize patching to mitigate potential service disruptions.

CVE
CVE-2026-21399
Severity
MEDIUM
CVSS
6.9
EPSS
0.11%

Original NVD Description

Heap-based buffer overflow for the Intel(R) Open Volume Kernel Library (Intel(R) Open VKL) library maintained by intel(R) before version 2.0.2 within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.