SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-7639

HIGH · CVSS 7.8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

A vulnerability exists in software that runs as a non-privileged user, allowing improper GPU system calls that can lead to a use-after-free condition. This flaw may enable unprivileged memory access through shader code, potentially exposing sensitive data in physical memory. Organizations utilizing affected software should prioritize patching this vulnerability to mitigate the risk of unauthorized data access.

CVE
CVE-2026-7639
Severity
HIGH
CVSS
7.8
EPSS
0.12%

Original NVD Description

Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilitating unprivileged memory access from a shader code. Triggering failure path in the MMU mapping logic by a malicious code could lead to incomplete cleanup of an internal driver state, allowing for future unauthorized access to the contents of the physical memory.