Wind River VxWorks 7 < 26.09 Multiple Vulnerabilities

high Nessus Plugin ID 358456

Synopsis

The remote VxWorks device is potentially affected by multiple vulnerabilities.

Description

According to its self-reported version, the remote device is running Wind River VxWorks 7 prior to release 26.09. It is, therefore, affected by multiple vulnerabilities:

- In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in memory corruption within the memory management subsystem. (CVE-2026-102004)

- In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the process management subsystem failing to properly release allocated kernel memory before terminating the calling application.
(CVE-2026-102006)

- In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminating the calling application.
(CVE-2026-97686)

Note that Nessus cannot determine the VxWorks 7 release designation (for example 26.09) from the detected operating system version, so an affected release cannot be distinguished from one that already includes the fix. This finding is therefore reported as a potential vulnerability.

Note that Nessus has not tested for this issue but has instead relied only on the OS version.

Solution

Upgrade to Wind River VxWorks 7 release 26.09 or later, or contact the device vendor to obtain the appropriate update.

See Also

http://www.nessus.org/u?56829c79

http://www.nessus.org/u?6361c599

http://www.nessus.org/u?929bb04f

Plugin Details

Severity: High

ID: 358456

File Name: vxworks_7_26_09.nasl

Version: 1.1

Type: Remote

Family: Misc.

Published: 10/1/2026

Updated: 10/1/2026

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.36

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-102004

CVSS v3

Risk Factor: High

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/o:windriver:vxworks

Required KB Items: Settings/ParanoidReport, Host/VxWorks

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 9/28/2026

Reference Information

CVE: CVE-2026-102004, CVE-2026-102006, CVE-2026-97686