← Back to search

CVE-2026-0163

9.8 CRITICAL

Published 2026-08-04 · Updated 2026-08-05

AI risk analysis

Summary
The flaw involves a use after free vulnerability in vpu_ioctl.c, allowing remote escalation of privilege without additional execution privileges. This is critical as it can be exploited by attackers to gain full control over the system.
Exploitability
Exploitation is relatively straightforward with no user interaction required. The attacker must have network access to the affected system.
Blast radius
If exploited, the impact is severe as it allows remote attackers to gain full control over the system, potentially leading to data theft, system compromise, and further attacks.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the fixed version 2.590 or later.
rceprivilege-escalationnetwork

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-416

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.