Medium severity5.5NVD Advisory· Published Sep 18, 2026
CVE-2026-93689
CVE-2026-93689
Description
WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the volume context before use. An unprivileged local user can trigger a denial of service by opening the WinFsp control device and issuing FSP_IOCTL_TRANSACT requests, causing a system crash.
Patches
Vulnerability mechanics
References
7- github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.cnvd
- github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.cnvd
- github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.cnvd
- github.com/winfsp/winfsp/blob/v2.2B4/src/sys/volume.cnvd
- github.com/winfsp/winfsp/commit/b8103265ec63fa87ac264c62bb796dbc38376652nvd
- github.com/winfsp/winfsp/releases/tag/v2.2B4nvd
- www.vulncheck.com/advisories/winfsp-through-2.2.26215-null-pointer-dereference-via-fast-i-onvd
News mentions
0No linked articles in our index yet.