CVE-2026-19569: Product identification pending
- Severity
- 8.8 (HIGH)
- Vendor
- ZEPHYRPROJECT
- Patch status
- Unknown
- Published
- 2026-10-09T08:16:54.563
- Modified
- 2026-10-09T08:16:54.563
Why it matters
This matters because the affected product may allow code execution. Prioritize systems that are internet-facing or have privileged access to other infrastructure.
Recommended admin actions
- Review and patch based on exposure, asset criticality, and business impact.
- Compare installed versions against the affected version range in the advisory.
- Review logs for suspicious activity related to the affected application or component.
Technical summary
dynamic_object_create() in kernel/userspace/userspace.c computed the backing allocation for a dynamically allocated kernel object as obj_size_get(otype) + size, and for thread stack elements as STACK_ELEMENT_DATA_SIZE(size) (a round-up plus fixed overhead), without checking either expression for unsigned wrap-around. A size close to SIZE_MAX makes the computed total wrap to a very small value, so the heap chunk handed out is a few bytes while the object descriptor is still tagged with the full requested type and registered in the kernel object table. The size argument reaches that arithmetic directly from user mode. k_object_alloc_size() is declared __syscall in include/zephyr/sys/kobject.h, its verifier z_vrfy_k_object_alloc_size() in kernel/userspace/userspace_handler.c is a bare pass-through, and z_object_alloc() only range-checks otype — nothing bounds size. The stack-element branch is additionally reachable through the k_thread_stack_alloc() syscall via kernel/dynamic.c. Because subsequent kernel-object validation checks only the object's type and initialization state, the undersized handle passes K_SYSCALL_OBJ_INIT()/K_SYSCALL_OBJ_NEVER_INIT(), and the matching init syscall (for example k_mutex_init(), k_sem_init(), or k_thread_create()) then writes a complete object over the truncated allocation. An unprivileged user-mode thread can therefore trigger a supervisor-mode out-of-bounds write into the kernel resource-pool heap, of a size and content it substantially controls, corrupting sys_heap chunk metadata and adjacent kernel objects. Under CONFIG_GEN_PRIV_STACKS the thread-stack branch additionally stores an attacker-influenced wild pointer as a user thread's privileged stack base. The practical result is escape from the CONFIG_USERSPACE sandbox — kernel-level code execution or at minimum kernel memory corruption and system compromise. Exploitation requires CONFIG_USERSPACE together with CONFIG_DYNAMIC_OBJECTS (also selected by CONFIG_DYNAMIC_THREAD under userspace), and a calling thread with an assigned resource pool. The fix rejects both overflowing computations and frees the partially built descriptor.
View the official NVD record for CVE-2026-19569
CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.
VULNERABILITY PULSE
| AFFECTED PRODUCT | ACTION | ||
|---|---|---|---|
| CVE-2026-96207 |
Microsoft Partner Center
Reporter: SECURE
|
10
CRITICAL
|
VIEW RECORD |
| CVE-2026-94503 |
Zombify
Reporter: AUDIT
|
10
CRITICAL
|
VIEW RECORD |
| CVE-2026-94510 |
Microsoft Bookings
Reporter: SECURE
|
9.9
CRITICAL
|
VIEW RECORD |
| CVE-2026-92555 |
Product identification pending PATCH
Reporter: ILETISIM
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-16340 |
Product identification pending
Reporter: PSIRT
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-14991 |
Product identification pending
Reporter: PSIRT
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-15762 |
Product identification pending
Reporter: PSIRT
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-14269 |
Product identification pending
Reporter: PSIRT
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-14502 |
DataPower Gateway 10.6CD
Reporter: PSIRT
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-14992 |
Product identification pending
Reporter: PSIRT
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-93034 |
SGLang
Reporter: CRET
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-84272 |
Guardium Data Protection
Reporter: PSIRT
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-78401 |
Product identification pending
Reporter: PSIRT
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-78406 |
Product identification pending
Reporter: PSIRT
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-107722 |
fast-jwt PATCH
Reporter: SECURITY-ADVISORIES
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-75875 |
Guardium Data Protection
Reporter: PSIRT
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-80381 |
Guardium Data Protection
Reporter: PSIRT
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-84249 |
Guardium Data Protection
Reporter: PSIRT
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-77900 |
Azure App Service for Linux
Reporter: SECURE
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-88131 |
Microsoft Dataverse
Reporter: SECURE
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-69435 |
Azure SRE Agent
Reporter: SECURE
|
9.6
CRITICAL
|
VIEW RECORD |
| CVE-2026-107406 |
ADC PATCH
Reporter: 50A63C94-1EA7-4568-8C11-EB79E7C5A2B5
|
9.5
CRITICAL
|
VIEW RECORD |
| CVE-2026-103663 |
Ollama PATCH
Reporter: CVD
|
9.4
CRITICAL
|
VIEW RECORD |
| CVE-2026-106126 |
Tenable Identity Exposure (SaaS)
Reporter: VULNREPORT
|
9.4
CRITICAL
|
VIEW RECORD |
| CVE-2026-14990 |
Product identification pending
Reporter: PSIRT
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-107640 |
Product identification pending
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-9209 |
mJobTime
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-107699 |
Product identification pending
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-107700 |
Product identification pending
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-107703 |
@enmaso/node-convert
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-107704 |
image_optimizer
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-104075 |
TVU Receiver / Transceiver PATCH
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-104076 |
TVU Receiver / Transceiver PATCH
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-84244 |
Guardium Data Protection
Reporter: PSIRT
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-107779 |
skyeye
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-107780 |
skyeye
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-107726 |
hazelcast PATCH
Reporter: SECURITY-ADVISORIES
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-5759 |
FalkorDB PATCH
Reporter: 33C584B5-0579-4C06-B2A0-8D8329FCAB9C
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-107908 |
FalkorDB PATCH
Reporter: 33C584B5-0579-4C06-B2A0-8D8329FCAB9C
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-107935 |
Red Hat Build of Podman Desktop
Reporter: SECALERT
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-93947 |
Traveler PATCH
Reporter: AUDIT
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-96327 |
WPLMS PATCH
Reporter: AUDIT
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-96328 |
JNews – Pay Writer PATCH
Reporter: AUDIT
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-96330 |
tagDiv Opt-In Builder PATCH
Reporter: AUDIT
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-96331 |
Ajax Search Pro PATCH
Reporter: AUDIT
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-96809 |
EduAdmin Booking PATCH
Reporter: AUDIT
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-7827 |
FalkorDB PATCH
Reporter: 33C584B5-0579-4C06-B2A0-8D8329FCAB9C
|
9.2
CRITICAL
|
VIEW RECORD |
| CVE-2026-107910 |
FalkorDB PATCH
Reporter: 33C584B5-0579-4C06-B2A0-8D8329FCAB9C
|
9.2
CRITICAL
|
VIEW RECORD |
| CVE-2026-19218 |
Product identification pending PATCH
Reporter: ILETISIM
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-95210 |
Product identification pending
Reporter: CVE
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-107781 |
skyeye
Reporter: DISCLOSURE
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-16823 |
Product identification pending
Reporter: PSIRT
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-16916 |
Product identification pending
Reporter: PSIRT
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-19491 |
Product identification pending
Reporter: PSIRT
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-79842 |
HPE Intelligent Management Center (iMC)
Reporter: SECURITY-ALERT
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-106155 |
Product identification pending PATCH
Reporter: SECURITY
|
8.9
HIGH
|
VIEW RECORD |
| CVE-2026-19083 |
Product identification pending PATCH
Reporter: ILETISIM
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-62142 |
WP 2FA PATCH
Reporter: AUDIT
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-105436 |
MainWP Child PATCH
Reporter: AUDIT
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-107375 |
generator-jhipster PATCH
Reporter: SECURITY-ADVISORIES
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-107701 |
Product identification pending
Reporter: DISCLOSURE
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-18740 |
Product identification pending
Reporter: PSIRT
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-19482 |
Product identification pending
Reporter: PSIRT
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-89091 |
Product identification pending
Reporter: SECALERT
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-7826 |
Product identification pending PATCH
Reporter: 33C584B5-0579-4C06-B2A0-8D8329FCAB9C
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-107909 |
Product identification pending PATCH
Reporter: 33C584B5-0579-4C06-B2A0-8D8329FCAB9C
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-19569 |
Product identification pending
Reporter: VULNERABILITIES
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-19570 |
Product identification pending
Reporter: VULNERABILITIES
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-96671 |
Featured Image from URL PATCH
Reporter: AUDIT
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-102784 |
Gridbox extension for Joomla
Reporter: SECURITY
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-44031 |
DCMTK PATCH
Reporter: 33C584B5-0579-4C06-B2A0-8D8329FCAB9C
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-105830 |
commonmark PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-107639 |
ILIAS PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-107378 |
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-93858 |
Product identification pending
Reporter: CVE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-106433 |
Product identification pending
Reporter: CNA
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-101024 |
Product identification pending
Reporter: ICS-CERT
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-107725 |
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-105672 |
Tapo C325WB v2
Reporter: F23511DB-6C3E-4E32-A477-6AA17D310630
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-105674 |
Tapo C325WB v2
Reporter: F23511DB-6C3E-4E32-A477-6AA17D310630
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-83943 |
Product identification pending
Reporter: SECURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-16159 |
Product identification pending
Reporter: PSIRT
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-16163 |
Product identification pending
Reporter: PSIRT
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-81932 |
Product identification pending
Reporter: PSIRT
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-104077 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-107322 |
Product identification pending PATCH
Reporter: FF89BA41-3AA1-4D27-914A-91399E9639E5
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-107707 |
Intego Antivirus
Reporter: DISCLOSURE
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-107782 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-11318 |
Product identification pending
Reporter: DISCLOSURE
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-105269 |
Product identification pending
Reporter: ICS-CERT
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-94663 |
ProfileGrid PATCH
Reporter: AUDIT
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-95599 |
Product identification pending
Reporter: AUDIT
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-95607 |
Product identification pending
Reporter: AUDIT
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-95610 |
Product identification pending
Reporter: AUDIT
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-96329 |
Product identification pending
Reporter: AUDIT
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-104078 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-84250 |
Product identification pending
Reporter: PSIRT
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-107732 |
sumatrapdf
Reporter: SECURITY-ADVISORIES
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-105833 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.3
HIGH
|
VIEW RECORD |
| CVE-2026-107705 |
Product identification pending
Reporter: DISCLOSURE
|
8.3
HIGH
|
VIEW RECORD |
About the Vulnerability Pulse CVE Feed
The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.
How to Use the CVE Advisory Tracker
Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.
What Is a CVE Advisory?
A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.
CVE Analysis & Writeups
For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.