CVE-2026-15418

Summary

In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to leak up to 145 bytes of uninitialized kernel pool memory. This vulnerability affects Windows 10 and earlier.

Affected Software

VendorProductVersion RangeStatus
Silicon Labssilabser.sys driver0 <= 11.5.0affected

Weaknesses

  • CWE-130: CWE-130: Improper Handling of Length Parameter Inconsistency

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References