Impact
Wind River VxWorks 7 versions earlier than 26.09 contain a flaw where certain system call arguments can cause the IPNET subsystem to fail to release kernel memory and system file descriptors during application termination. The leak can accumulate over time, exhausting available memory and descriptor resources, which may ultimately lead to application or system crashes and denial of service.
Affected Systems
Wind River’s VxWorks 7 operating system, specifically all versions preceding 26.09. No additional vendor or product variants are cited in the CVE record.
Risk and Exploitability
The CVSS score of 5.5 classifies the flaw as moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating limited publicly known exploitation. Based on the description, the likely attack vector involves sending crafted system call arguments to the vulnerable IPNET subsystem, which may be reachable locally or remotely depending on the deployment context of VxWorks 7.
OpenCVE Enrichment