Threats Tagged 'cve-2026-13216'
View all threats tagged with 'cve-2026-13216'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-13216'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-13216 is a vulnerability in the Zephyr project's virtio PCI driver where an unvalidated device-supplied capability length can cause out-of-bounds stack writes during device initialization. This occurs because a length value read from the PCI config space is only checked by an assert that is disabled in production builds, allowing attacker-controlled data to overflow a fixed-size buffer. The flaw can lead to kernel stack corruption and potential code execution or crashes when an untrusted virtio PCIe device is present. The vulnerability primarily affects bare-metal systems with untrusted devices or confidential computing scenarios where the guest must defend against the host. A fix replaces the disabled assert with a runtime range check to validate the length before copying data. Join the discussion | CVE Database V5 | 08/25/2026, 16:05:36 UTC Added: 08/25/2026, 16:22:53 UTC |
Showing 1 to 1 of 1 result