CVE-2026-90890

Summary

ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating system crash.

Affected Software

VendorProductVersion RangeStatus
ASRockASRock Polychrome SYNC/RGB for MB0 <= 1.0.118affected
ASRockASRock Polychrome SYNC/RGB for VGA0 <= 2.0.219affected

Weaknesses

  • CWE-822: CWE-822 Untrusted Pointer Dereference

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References