CVE-2026-20515: Use After Free
In gpu, there is a possible system crash due to use after free. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS11122991; Issue ID: MSV-8132.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ALPS11122991 - Compensating control
Because exploitation requires user interaction, reduce exposure by ensuring users are not tricked into performing the triggering action (e.g., restrict/monitor untrusted user activities that could lead to the vulnerable GPU code path).
Event History
Frequently Asked Questions
What access would an attacker need to exploit this issue?
Exploitation requires local user execution privileges and user interaction. The stated impact is local information disclosure and a possible system crash.
What identifiers can be used to track remediation?
The vendor patch identifier is ALPS11122991, and the associated issue identifier is MSV-8132.