CVE Vulnerabilities

CVE-2026-102710

Improper Privilege Management

Published: Sep 29, 2026 | Modified: Sep 29, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Attacker model / Preconditions: a loaded TXM_MODULE_USER_MODE | TXM_MODULE_MEMORY_PROTECTION module issuing kernel dispatch calls, on a build with TX_ENABLE_EVENT_TRACE.

A user-mode, memory-protected module can register an arbitrary function pointer as the global trace-full callback. The kernel calls it directly — no validation, no trampoline — from privileged kernel code when the trace buffer wraps.

An invalid pointer faults the kernel (DoS). A pointer into the modules own code was observed running with kernel privilege (CONTROL.nPRIV = 0), confirmed at runtime with a register capture inside that code.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Potential Mitigations

References