← Back to the live CVE advisory feed

CVE-2026-17052: Product identification pending

Severity
7.8 (HIGH)
Vendor
ZEPHYRPROJECT
Patch status
Unknown
Published
2026-09-21T19:17:04.080
Modified
2026-09-21T19:17:04.080

Why it matters

High-severity vulnerability requiring prioritized review.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Compare installed versions against the affected version range in the advisory.

Technical summary

The Time-aware GPIO syscall verification handler z_vrfy_tgpio_pin_read_ts_ec() in drivers/timeaware_gpio/timeaware_gpio_handlers.c validated only the port device object and passed the caller-supplied timestamp and event_count output pointers to the driver without a K_SYSCALL_MEMORY_WRITE() check. The other handlers in the same file (z_vrfy_tgpio_port_get_time(), z_vrfy_tgpio_port_get_cycles_per_second()) already performed that check, so the omission left one syscall unguarded. tgpio_pin_read_ts_ec() is declared __syscall, so with CONFIG_USERSPACE=y an unprivileged user-mode thread that has been granted access to the TGPIO device object can invoke it with arbitrary pointer values. tgpio_intel_read_ts_ec() in drivers/timeaware_gpio/timeaware_gpio_intel.c bounds-checks only the pin index and then unconditionally performs timestamp = … and event_count = …, executing two 8-byte stores in supervisor mode at addresses chosen by the user-mode caller. The result is a write-what-where primitive that crosses the userspace/kernel boundary: the target address is fully attacker-chosen and the stored values are the hardware time-capture and event-counter register contents. Corrupting kernel data structures this way can escalate the calling thread to supervisor privilege or crash the system; the device-object permission required is a narrow capability that is not intended to confer any kernel-memory access. The fix adds the two missing K_SYSCALL_MEMORY_WRITE() validations before the driver call. Exposure is narrow in practice. Only builds with CONFIG_USERSPACE=y and CONFIG_TIMEAWARE_GPIO=y compile the affected file, and from v3.6.0 onward the file additionally referenced a relocated header () and removed Z_SYSCALL_* macros, so such a configuration failed to build until those were repaired after v4.4.0. Downstream trees that locally corrected that breakage, and v3.5.0 builds where it did not exist, are the exposed population.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 22, 2026 08:00 AM UTC
281 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-77521
MaxKB PATCH
Reporter: SECURITY-ADVISORIES
10
CRITICAL
VIEW RECORD
CVE-2026-79920
ajenti PATCH
Reporter: SECURITY-ADVISORIES
9.9
CRITICAL
VIEW RECORD
CVE-2026-94301
Apache MINA
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-85751
Mailu PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-13355
Meta Box Frontend Submission
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-19658
Give Tributes
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-94571
Product identification pending PATCH
Reporter: CVE
9.4
CRITICAL
VIEW RECORD
CVE-2026-94572
Product identification pending PATCH
Reporter: CVE
9.4
CRITICAL
VIEW RECORD
CVE-2026-58491
warpgate PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-94424
MTT S80 Driver Package
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-94425
MTT S80 Driver Package
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-94493
PDV5701
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-61674
fluent-bit PATCH
Reporter: SECURITY-ADVISORIES
9.2
CRITICAL
VIEW RECORD
CVE-2025-12999
Eclipse Open VSX
Reporter: EMO
9.1
CRITICAL
VIEW RECORD
CVE-2026-86473
Apache Airflow PATCH
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-46649
joplin PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-79916
MaxKB PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-88807
Product identification pending PATCH
Reporter: MEISSNER
8.9
HIGH
VIEW RECORD
CVE-2026-55563
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.9
HIGH
VIEW RECORD
CVE-2026-92574
Confidential Compute Attestation
Reporter: SECALERT
8.8
HIGH
VIEW RECORD
CVE-2026-84285
Product identification pending
Reporter: 3DS.INFORMATION-SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-53940
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-82412
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-62371
kubeedge PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-63116
deepstream.io PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-84990
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-62182
kubeedge PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-55159
luci-app-adblock-fast PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-55897
luci PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-88409
Product identification pending
Reporter: CVE
8.8
HIGH
VIEW RECORD
CVE-2026-92438
Ninja Forms
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-16651
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-65651
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-65652
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-65653
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-65654
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-89139
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-94381
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
8.7
HIGH
VIEW RECORD
CVE-2026-94411
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94412
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94496
jshERP
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94497
jshERP
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94501
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-61652
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-94622
vllm
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94623
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94624
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94626
vllm
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94627
vllm
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94383
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
8.6
HIGH
VIEW RECORD
CVE-2025-71421
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-94403
iGameCenter
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-55071
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.4
HIGH
VIEW RECORD
CVE-2026-49811
Product identification pending PATCH
Reporter: SECURITY_ALERT
8.4
HIGH
VIEW RECORD
CVE-2026-94374
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
8.3
HIGH
VIEW RECORD
CVE-2026-94401
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
8.3
HIGH
VIEW RECORD
CVE-2026-94488
Product identification pending PATCH
Reporter: CVE
8.3
HIGH
VIEW RECORD
CVE-2026-55074
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-61628
nginx-ignition PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-80110
Product identification pending
Reporter: SECALERT
8.1
HIGH
VIEW RECORD
CVE-2026-94184
Product identification pending
Reporter: SECALERT
8.1
HIGH
VIEW RECORD
CVE-2026-77560
tinyauth PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-83621
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-48826
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-48975
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-48976
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-62369
kubeedge PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-58269
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-15801
Red Hat OpenShift Container Platform 4
Reporter: SECALERT
8
HIGH
VIEW RECORD
CVE-2026-65980
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.9
HIGH
VIEW RECORD
CVE-2026-55567
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.8
HIGH
VIEW RECORD
CVE-2026-17052
Product identification pending
Reporter: VULNERABILITIES
7.8
HIGH
VIEW RECORD
CVE-2026-49810
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.8
HIGH
VIEW RECORD
CVE-2026-81469
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.8
HIGH
VIEW RECORD
CVE-2026-76898
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.7
HIGH
VIEW RECORD
CVE-2026-63330
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.7
HIGH
VIEW RECORD
CVE-2026-55105
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.7
HIGH
VIEW RECORD
CVE-2026-59814
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.6
HIGH
VIEW RECORD
CVE-2026-47321
Apache MINA
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-91863
Product identification pending PATCH
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-91864
Product identification pending PATCH
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-91865
Product identification pending PATCH
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-91866
Product identification pending PATCH
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-88806
Product identification pending PATCH
Reporter: MEISSNER
7.5
HIGH
VIEW RECORD
CVE-2026-52741
gocd PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-61629
nginx-ignition PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-71543
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-94449
Product identification pending
Reporter: SECALERT
7.5
HIGH
VIEW RECORD
CVE-2026-73512
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-73513
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-73547
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-73548
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-73550
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-73552
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-73553
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-88406
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-88407
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-88411
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-91827
Ninja Forms
Reporter: CONTACT
7.5
HIGH
VIEW RECORD
CVE-2026-75939
Product identification pending
Reporter: SECALERT
7.4
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.