What is CVE-2026-49743?
CVE-2026-49743 allows non-privileged user software to issue improper GPU system calls, manipulating the lifetimes of kernel synchronization objects and leading to read/write Use-After-Free vulnerabilities. This occurs during workload submission involving a fence exported by the GPU driver. Affected systems should apply security updates immediately and restrict non-privileged user GPU access.
Azərbaycanca: CVE-2026-49743 qeyri-imtiyazlı istifadəçi kimi işləyən proqram təminatının GPU sistem çağırışları vasitəsilə kernel səviyyəsində sinxronizasiya obyektlərinin ömrünü manipulyasiya etməsinə şərait yaradır. Bu, read/write Use-After-Free (UAF) zəifliyinə səbəb ola bilər, xüsusilə GPU driver tərəfindən ixrac edilən fence ilə əlaqəli iş yükü təqdimatı zamanı. Təsirə məruz qalan sistemlərdə dərhal təhlükəsizlik yeniləmələri tətbiq edilməli və qeyri-imtiyazlı istifadəçi fəaliyyətləri məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
What type of software can exploit the CVE-2026-49743 vulnerability?
This vulnerability can be exploited by non-privileged user software.
Which object exported by the GPU driver is involved when the CVE-2026-49743 issue occurs?
The issue occurs during workload submission involving a fence exported by the GPU driver.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.