Threats Tagged 'cve-2026-19575'
View all threats tagged with 'cve-2026-19575'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-19575'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-19575 is a memory safety vulnerability in the Zephyr RTOS affecting the device_deinit() system call handler when both CONFIG_USERSPACE and CONFIG_DEVICE_DEINIT_SUPPORT are enabled. The vulnerability allows a local unprivileged user thread to pass a kernel object pointer that bypasses proper type validation, leading to an indirect call to an arbitrary address in supervisor mode, enabling full kernel code execution. This flaw affects Zephyr versions from 4.2.0 through 4.4.2 inclusive. The issue is fixed by restricting the object type check to driver objects only, preventing misuse of arbitrary kernel objects. Join the discussion | CVE Database V5 | 10/09/2026, 07:16:47 UTC Added: 10/09/2026, 07:34:00 UTC |
Showing 1 to 1 of 1 result