VYPR
High severityNVD Advisory· Published Jun 2, 2026· Updated Jun 2, 2026

CVE-2026-10047

CVE-2026-10047

Description

Bitdefender Napoca hypervisor has an out-of-bounds write in its real-mode hook handler, allowing guest code to corrupt the hypervisor heap.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Bitdefender Napoca hypervisor has an out-of-bounds write in its real-mode hook handler, allowing guest code to corrupt the hypervisor heap.

Vulnerability

The Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the real-mode hook handler, implemented in napoca/kernel/handler.c. The handler uses a guest-controlled SS:SP-derived offset as an index into the 1MB RealModeMemory buffer without bounds validation. With SS=0xFFFF and ESP=0xFFFF, the computed offset can reach 0x10FFEF, exceeding the RealModeMemory buffer by 65,519 bytes. The IRET frame push can therefore write past the end of the buffer into the hypervisor heap. The product is end-of-life and unsupported when assigned [1].

Exploitation

An attacker with guest access can trigger this vulnerability by manipulating the SS:SP registers to values such as 0xFFFF:0xFFFF. This crafted offset is then used to write past the end of the RealModeMemory buffer during an IRET frame push, corrupting the hypervisor heap [1].

Impact

Successful exploitation allows an attacker to write past the end of the RealModeMemory buffer into the hypervisor heap, potentially leading to arbitrary code execution within the hypervisor context or a denial-of-service condition. The scope of the compromise is the hypervisor itself [1].

Mitigation

The Bitdefender Napoca bare-metal hypervisor is end-of-life and unsupported. No patches are available for this vulnerability. Users should migrate to a supported hypervisor solution [1].

AI Insight generated on Jun 2, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.