CVE-2026-102005: VxWorks Memory Allocation
Wind River VxWorks 7 24.03 through 26.03, a memory leak occurs under specific, non-default configuration states when processing specific service routines, causing the system to terminate operations before releasing allocated memory pools. Fixed in VxWorks 7 26.09
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wind River VxWorks 7to a version that resolves this vulnerability.Fixed in 26.09
Event History
Frequently Asked Questions
Are default VxWorks 7 deployments affected?
The issue occurs only under specific non-default configuration states. The provided information does not identify which configuration options enable the affected service routines.
What access does an attacker need to trigger the condition?
The vector requires local access and low privileges, with no user interaction required. The described impact is availability loss through memory-pool exhaustion and termination of operations.
What version resolves the issue?
The issue is fixed in VxWorks 7 26.09. The affected range is VxWorks 7 24.03 through 26.03.