Threat intelligence dashboard
CVE-2026-97686medium

VxWorks 7 Memory Resource leak

Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminating the calling application. Fixed in Version 26.09.  Security Researcher: Zhi Yang Bingren Wu Finding

Risk score

5.5

CVSS 3.1

Vendor
Wind River
Product
VxWorks 7
CWE
CWE-772
Published
Sep 28, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

VxWorks 7

Wind River

Platforms: RTOS

Version / rangeStatusType
VxWorks 7affected—

Technical metrics

5.5

CVSS 3.1

Severity
medium
Source
WindRiver
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H