CVE-2026-97686

Summary

Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminating the calling application. Fixed in Version 26.09.

Affected Software

VendorProductVersion RangeStatus
Wind RiverVxWorks 7VxWorks 7affected

Weaknesses

  • CWE-772: CWE-772 Missing release of resource after effective lifetime

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References