CVE-2026-93689
MEDIUM
6,8
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
5,5
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
Description
AI Translation Available
WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the volume context before use. An unprivileged local user can trigger a denial of service by opening the WinFsp control device and issuing FSP_IOCTL_TRANSACT requests, causing a system crash.
476
NULL Pointer Dereference
StableCommon Consequences
Security Scopes Affected:
Availability
Integrity
Confidentiality
Potential Impacts:
Dos: Crash, Exit, Or Restart
Execute Unauthorized Code Or Commands
Read Memory
Modify Memory
Applicable Platforms
Languages:
C, C++, Java, C#, Go
https://github.com/winfsp/winfsp
https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.c#L105-L114
https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.c#L146-L152
https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.c#L68-L73
https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/volume.c#L1059-L1060
https://github.com/winfsp/winfsp/commit/b8103265ec63fa87ac264c62bb796dbc38376652
https://github.com/winfsp/winfsp/releases/tag/v2.2B4
https://www.vulncheck.com/advisories/winfsp-through-2.2.26215-null-pointer-dere…