VxWorks 7 Memory Resource leak
Summary
| CVE | CVE-2026-97686 |
|---|---|
| State | PUBLISHED |
| Assigner | WindRiver |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-28 19:16:50 UTC |
| Updated | 2026-09-28 20:47:20 UTC |
| Description | Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminating the calling application. Fixed in Version 26.09. Security Researcher: Zhi Yang Bingren Wu Finding |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from 0bf9931a-6ebf-4f48-bd14-39ee5e1d61f8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Problem Types: CWE-772 | CWE-772 CWE-772 Missing release of resource after effective lifetime
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 0bf9931a-6ebf-4f48-bd14-39ee5e1d61f8 | Secondary | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | CNA | CVSS | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Wind River | VxWorks 7 | affected VxWorks 7 | RTOS |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| support2.windriver.com/index.php | 0bf9931a-6ebf-4f48-bd14-39ee5e1d61f8 | support2.windriver.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.