Description
VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a vulnerability in their virtual audio drivers (vbvoicemeetervaio64*.sys, vbmatrixvaio64*.sys, vbaudio_vmauxvaio*.sys, vbaudio_vmvaio*.sys, and vbaudio_vmvaio3*.sys). The drivers map non-paged pool memory into user space via MmMapLockedPagesSpecifyCache using UserMode access without proper exception handling. If the mapping fails, such as when a process has exhausted available virtual address space, MmMapLockedPagesSpecifyCache raises an exception that is not caught, causing a kernel crash (BSoD), typically SYSTEM_SERVICE_EXCEPTION with STATUS_NO_MEMORY. This flaw allows a local unprivileged user to trigger a denial-of-service on affected Windows systems.
Published: 2026-01-22
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

The vulnerability exists in the virtual audio drivers for VB‑Audio’s Voicemeeter, Voicemeeter Banana, Voicemeeter Potato, Matrix, and Matrix Coconut. The drivers mistakenly expose non‑paged pool memory to user space through MmMapLockedPagesSpecifyCache with UserMode access, and they lack proper exception handling. When the mapping fails—such as when a process has exhausted virtual address space—an uncaught exception triggers a kernel crash, producing a blue‑screen loss of service. The flaw is limited to a local unprivileged user and results in a SYSTEM_SERVICE_EXCEPTION with STATUS_NO_MEMORY. The impact is a complete denial of service on the affected Windows system. The flaw is not exploitable for privilege escalation or data exfiltration; it simply forces a reboot or crash, so confidentiality and integrity are not directly affected. The affected code resides in the driver files vbvoicemeetervaio64*.sys, vbmatrixvaio64*.sys, vbaudio_vmauxvaio*.sys, vbaudio_vmvaio*.sys, and vbaudio_vmvaio3*.sys.

Affected Systems

VB‑Audio Software markets several products that are impacted: Voicemeeter (Standard), Voicemeeter Banana, and Voicemeeter Potato, each of which has a vulnerable release ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 respectively, and older versions. The Matrix and Matrix Coconut audio drivers are also vulnerable in builds ending in 1.0.2.2 and 2.0.2.2, respectively.

Risk and Exploitability

The CVSS score for this issue is 6.9, indicating moderate severity. The EPSS score is below 1 %, meaning that at the time of analysis the estimated exploitation probability is very low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local user with an unprivileged account running a process that can intentionally or inadvertently consume all available virtual address space to cause the mapping to fail. Once triggered, the kernel crashes, leading to a system reboot. The attack is straightforward: any user with the ability to run a custom process can exhaust address space and trigger the fault. No network interaction or elevated privileges are required. Because the flaw results only in a denial of service, the risk to confidentiality or integrity is negligible; the concern is operational availability.

Generated by OpenCVE AI on April 16, 2026 at 17:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest releases of Voicemeeter Standard, Voicemeeter Banana, Voicemeeter Potato, Matrix, and Matrix Coconut, which remove the driver flaw.
  • If an update is not yet available, uninstall or disable the affected virtual audio drivers so they cannot be loaded by user applications.
  • Monitor Windows event logs for SYSTEM_SERVICE_EXCEPTION entries to detect accidental crashes and verify that no pending drivers remain installed.

Generated by OpenCVE AI on April 16, 2026 at 17:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 05 Mar 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Twistedmatrix
Twistedmatrix twistedweb
CPEs cpe:2.3:a:twistedmatrix:twistedweb:*:*:*:*:*:*:*:*
Vendors & Products Twistedmatrix
Twistedmatrix twistedweb

Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Vb-audio Software
Vb-audio Software matrix
Vb-audio Software matrix Coconut
Vb-audio Software voicemeeter
Vb-audio Software voicemeeter Banana
Vb-audio Software voicemeeter Potato
Vendors & Products Vb-audio Software
Vb-audio Software matrix
Vb-audio Software matrix Coconut
Vb-audio Software voicemeeter
Vb-audio Software voicemeeter Banana
Vb-audio Software voicemeeter Potato

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 22 Jan 2026 16:30:00 +0000

Type Values Removed Values Added
Description VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a vulnerability in their virtual audio drivers (vbvoicemeetervaio64*.sys, vbmatrixvaio64*.sys, vbaudio_vmauxvaio*.sys, vbaudio_vmvaio*.sys, and vbaudio_vmvaio3*.sys). The drivers map non-paged pool memory into user space via MmMapLockedPagesSpecifyCache using UserMode access without proper exception handling. If the mapping fails, such as when a process has exhausted available virtual address space, MmMapLockedPagesSpecifyCache raises an exception that is not caught, causing a kernel crash (BSoD), typically SYSTEM_SERVICE_EXCEPTION with STATUS_NO_MEMORY. This flaw allows a local unprivileged user to trigger a denial-of-service on affected Windows systems.
Title VB-Audio Voicemeeter & Matrix Drivers DoS via MmMapLockedPagesSpecifyCache
Weaknesses CWE-755
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Twistedmatrix Twistedweb
Vb-audio Software Matrix Matrix Coconut Voicemeeter Voicemeeter Banana Voicemeeter Potato
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-03-05T01:30:25.083Z

Reserved: 2026-01-15T18:42:20.939Z

Link: CVE-2026-23762

cve-icon Vulnrichment

Updated: 2026-01-22T18:24:48.989Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:16:37.480

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-23762

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T18:00:11Z

Weaknesses