Threats Tagged 'cve-2026-19574'
View all threats tagged with 'cve-2026-19574'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-19574'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-19574 is a high-severity vulnerability in the Zephyr project affecting ARM64 memory domain management. The ARM64 MMU back-end uses a simple round-robin counter to allocate ASIDs (address space identifiers) for memory domains, but with only 255 ASIDs available, the counter can wrap and assign the same ASID to multiple live domains. This causes TLB entries from one domain to remain accessible when another domain with the same ASID is active, breaking memory domain isolation. Exploitation requires a CONFIG_USERSPACE application on ARM64 creating more than 255 memory domains, but domain creation APIs are supervisor-only, limiting direct user control. The vulnerability allows a user-mode thread in one domain to read and write memory of another domain, violating memory isolation boundaries. A fix is implemented that scans live domains to avoid ASID reuse and fails domain creation if no ASIDs are free. Join the discussion | CVE Database V5 | 10/09/2026, 07:16:43 UTC Added: 10/09/2026, 07:34:00 UTC |
Showing 1 to 1 of 1 result