SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-49428

HIGH · CVSS 8.4 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Certain system calls, such as open(2) with the O_TRUNC flag and fspacectl(2), improperly free memory in largepage objects, which should not be allowed. This vulnerability allows unprivileged local users to access freed kernel memory, potentially leading to privilege escalation. Organizations utilizing systems that implement these calls should prioritize addressing this issue to mitigate the risk of unauthorized access and privilege escalation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-49428
Severity
HIGH
CVSS
8.4
EPSS
0.29%

Original NVD Description

Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage objects. These operations are not permitted on largepage objects, but the implementation did not verify this. An unprivileged local user can abuse the bug to access freed kernel memory. This can be exploited to escalate privileges.

Related CVEs

Other vulnerabilities affecting the same vendor(s)