CVE-2026-8050
Last modified
CVE-2026-8050 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In SignalRGB versions prior to 1.3.7.0, seven of the thirteen IOCTL handlers dereference the SystemBuffer pointer without first verifying that it is non-NULL. Sending an IOCTL with an empty input buffer causes a NULL pointer dereference, resulting in a kernel crash.. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
In SignalRGB versions prior to 1.3.7.0, seven of the thirteen IOCTL handlers dereference the SystemBuffer pointer without first verifying that it is non-NULL. Sending an IOCTL with an empty input buffer causes a NULL pointer dereference, resulting in a kernel crash.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-8050?
How severe is CVE-2026-8050?
How do I fix CVE-2026-8050?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8043External control of a file name in Ivanti Xtraction before v…9.6
- CVE-2026-8045CWE-611 Improper Restriction of XML External Entity Referenc…6.5
- CVE-2026-8046The affected products insufficiently verify authorization wh…8.1
- CVE-2026-8047The affected products perform improper length checking when …8.7
- CVE-2026-8048The My Email Shortcode plugin for WordPress is vulnerable to…6.4
- CVE-2026-8049In SignalRGB versions prior to 1.3.7.0, the \\.\SignalIo dev…5.3
- CVE-2026-8051OS command injection in Ivanti Virtual Traffic Manager befor…7.2
- CVE-2026-8052HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulner…6
- CVE-2026-8053An issue in MongoDB Server's time-series collection implemen…8.8
- CVE-2026-8054Improper Neutralization of Special Elements used in an SQL C…10
- CVE-2026-8055Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-8056IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated u…8.8
Are you affected by CVE-2026-8050?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
