CVE-2026-97686: VxWorks 7 Memory Resource leak
Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminating the calling application. Fixed in Version 26.09.
Security Researcher: Zhi Yang Bingren Wu Finding
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wind River VxWorks 7to a version that resolves this vulnerability.Fixed in 26.09
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs local access and low-privileged access to a VxWorks 7 system, as indicated by the AV:L and PR:L vector. No user interaction is required.
What is the practical impact?
Repeated use of specific system call arguments can cause the IPNET subsystem to retain kernel memory and system file descriptors after the calling application exits. This can lead to resource exhaustion and availability impact.
Which versions are affected and how is it fixed?
VxWorks 7 versions prior to 26.09 are affected. Wind River fixed the issue in version 26.09.