CVE-2026-56972
In multiple locations, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to local escalation of priv
CVSS
6.7
Medio
EPSS
0.1%
p0
KEV
—
Exploit Today
0
0-100
Publicado: 15 sept 2026 · Última mod.: 18 sept 2026 · CWE-787
0.1%EPSS · 30 días0.1%
2026-09-162026-09-18
In multiple locations, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-930156.3 MED15.9%
——5BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream endpoint discovery. A bonded peer can send an AVDTP DISCOVER response with more endpoints than the fixed table holds, causing out-of-bounds writes that corrupt adjacent static objects and crash the process or sever event delivery.1dCVE-2026-928806.3 MED16.4%
——5A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the component EA SCHl parser. This manipulation of the argument entry/entries causes out-of-bounds write. Remote exploitation of the attack is possible. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is suggested to install a patch to address this issue.1dCVE-2026-252807.8 ALT1.5%
——0Memory corruption when processing escape handling flow with insufficient user buffer sizes.4hCVE-2026-240747.8 ALT5.8%
——2Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.4hCVE-2026-240737.8 ALT5.8%
——2Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.4hCVE-2026-927867.8 ALT2.8%
——1LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP prediction. Attackers can craft malicious model files with invalid node references that trigger out-of-bounds writes at attacker-chosen offsets in the leaf_depth_ buffer during feature contribution computation.2d