CVE-2026-102005

Summary

Wind River VxWorks 7 24.03 through 26.03, a memory leak occurs under specific, non-default configuration states when processing specific service routines, causing the system to terminate operations before releasing allocated memory pools. Fixed in VxWorks 7 26.09

Affected Software

VendorProductVersion RangeStatus
Wind River IncVxWorks 7VxWorks 7affected

Weaknesses

  • CWE-401: CWE-401 Missing release of memory after effective lifetime

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References