HIGHCVSS 7.8Vulnerability

CVE-2026-7639

Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilitating unprivileged memory access from a shader code. Triggering failure path in the MMU mapping logic by a malicious code could lead to incomplete cleanup of an internal driver state, allowing for future unauthorized access to the contents of the physical memory.

Properties

severity
HIGH
cvss_score
7.8
cvss_severity
HIGH
epss_score
0.00179
retrieved_at
2026-09-26T23:52:08+00:00
last_source
FIRST EPSS
score
7.8
cve_id
CVE-2026-7639
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
signal_observed_at
2026-09-11T17:55:57+00:00
vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
published_at
2026-07-10T21:17:00.637
last_modified
2026-08-12T17:20:01.957
epss_percentile
0.06728

Related Entities (7)

ENRICHED_BY (1)

→[Source]FIRST EPSS

HAS_WEAKNESS (1)

→[Weakness]Incomplete Cleanup

DESCRIBED_BY (1)

→[Source]NVD

AFFECTS_PRODUCT (4)

→[Product]
→[Product]
→[Product]
→[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-7639 (CVSS 7.8) — Ninja Signal Threat Intelligence | Ninja Signal