SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-41154

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

The vulnerability allows software running as a non-privileged user to perform out-of-bounds (OOB) memory reads or writes via GPU API calls, potentially leading to unauthorized access to sensitive kernel memory. This flaw arises from improper buffer indexing during the page freeing process in the sparse memory implementation, affecting systems that utilize this memory management technique. Organizations using affected software should prioritize remediation to mitigate the risk of exploitation and potential system compromise.

CVE
CVE-2026-41154
Severity
HIGH
CVSS
7.8
EPSS
0.13%

Original NVD Description

Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls. When indexing pages larger than 4kB in the page freeing logic of the sparse memory implementation, incorrect buffer indexing leads to OOB access.