{"api_version":"1","generated_at":"2026-09-28T21:53:46+00:00","cve":"CVE-2026-97686","urls":{"html":"https://cve.report/CVE-2026-97686","api":"https://cve.report/api/cve/CVE-2026-97686.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-97686","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-97686"},"summary":{"title":"VxWorks 7 Memory Resource leak","description":"Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminating the calling application. Fixed in Version 26.09. \n\n\nSecurity Researcher: Zhi Yang Bingren Wu Finding","state":"PUBLISHED","assigner":"WindRiver","published_at":"2026-09-28 19:16:50","updated_at":"2026-09-28 20:47:20"},"problem_types":["CWE-772","CWE-772 CWE-772 Missing release of resource after effective lifetime"],"metrics":[{"version":"3.1","source":"0bf9931a-6ebf-4f48-bd14-39ee5e1d61f8","type":"Secondary","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://support2.windriver.com/index.php?page=cve&order_by=cve_modified_date&order_way=asc#list","name":"https://support2.windriver.com/index.php?page=cve&order_by=cve_modified_date&order_way=asc#list","refsource":"0bf9931a-6ebf-4f48-bd14-39ee5e1d61f8","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-97686","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97686","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Wind River","product":"VxWorks 7","version":"affected VxWorks 7","platforms":["RTOS"]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-97686","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-28T19:25:35.769605Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-28T19:25:43.054Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["RTOS"],"product":"VxWorks 7","vendor":"Wind River","versions":[{"status":"affected","version":"VxWorks 7"}]}],"datePublic":"2026-09-28T18:39:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminating the calling application. Fixed in Version 26.09.&nbsp;<div><br></div><div>Security Researcher:&nbsp;<span>Zhi Yang Bingren</span><span>&nbsp;Wu Finding&nbsp;</span></div>\n\n<div>\n\n\n\n</div>"}],"value":"Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminating the calling application. Fixed in Version 26.09. \n\n\nSecurity Researcher: Zhi Yang Bingren Wu Finding"}],"impacts":[{"capecId":"CAPEC-469","descriptions":[{"lang":"en","value":"CAPEC-469 HTTP DoS"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-772","description":"CWE-772 Missing release of resource after effective lifetime","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-28T18:48:23.773Z","orgId":"0bf9931a-6ebf-4f48-bd14-39ee5e1d61f8","shortName":"WindRiver"},"references":[{"url":"https://support2.windriver.com/index.php?page=cve&order_by=cve_modified_date&order_way=asc#list"}],"source":{"discovery":"UNKNOWN"},"title":"VxWorks 7 Memory Resource leak","x_generator":{"engine":"Vulnogram 1.0.5"}}},"cveMetadata":{"assignerOrgId":"0bf9931a-6ebf-4f48-bd14-39ee5e1d61f8","assignerShortName":"WindRiver","cveId":"CVE-2026-97686","datePublished":"2026-09-28T18:48:23.773Z","dateReserved":"2026-09-24T21:12:17.354Z","dateUpdated":"2026-09-28T19:25:43.054Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-28 19:16:50","lastModifiedDate":"2026-09-28 20:47:20","problem_types":["CWE-772","CWE-772 CWE-772 Missing release of resource after effective lifetime"],"metrics":{"cvssMetricV31":[{"source":"0bf9931a-6ebf-4f48-bd14-39ee5e1d61f8","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-28T19:25:35.769605Z","id":"CVE-2026-97686","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"97686","Ordinal":"1","Title":"VxWorks 7 Memory Resource leak","CVE":"CVE-2026-97686","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"97686","Ordinal":"1","NoteData":"Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminating the calling application. Fixed in Version 26.09. \n\n\nSecurity Researcher: Zhi Yang Bingren Wu Finding","Type":"Description","Title":"VxWorks 7 Memory Resource leak"}]}}}