{"id":"CVE-2026-93689","summary":"WinFsp through 2.2.26215 NULL Pointer Dereference via Fast I/O","details":"WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the volume context before use. An unprivileged local user can trigger a denial of service by opening the WinFsp control device and issuing FSP_IOCTL_TRANSACT requests, causing a system crash.","modified":"2026-09-24T08:22:23.620651Z","published":"2026-09-18T15:06:04.237Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-476"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93689.json","unresolved_ranges":[{"extracted_events":[{"last_affected":"2.2.26215"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"fixed":"2.2.26215"}],"source":"DESCRIPTION"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93689.json"},{"type":"ADVISORY","url":"https://github.com/winfsp/winfsp/releases/tag/v2.2B4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93689"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/winfsp-through-2.2.26215-null-pointer-dereference-via-fast-i-o"},{"type":"FIX","url":"https://github.com/winfsp/winfsp/commit/b8103265ec63fa87ac264c62bb796dbc38376652"},{"type":"PACKAGE","url":"https://github.com/winfsp/winfsp"},{"type":"ARTICLE","url":"https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.c#L105-L114"},{"type":"ARTICLE","url":"https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.c#L146-L152"},{"type":"ARTICLE","url":"https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.c#L68-L73"},{"type":"ARTICLE","url":"https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/volume.c#L1059-L1060"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/winfsp/winfsp","events":[{"introduced":"0"},{"fixed":"b8103265ec63fa87ac264c62bb796dbc38376652"},{"fixed":"fde790d8ea41283606d1c56b557608a17e455f59"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v2.2B4","v2.2B3","v2.2B2","v2.2B1","v2.1","v2.1B2","v2.1B1","v2.0","v2.0RC1","v2.0B2","v2.0B1","v1.11","v1.11RC1","v1.11B3","v1.11B2","v1.11B1","v1.10","v1.10B5","v1.10B4","v1.10B3","v1.10B2","v1.10B1","before-rebrand-support","v1.9","v1.9B2","v1.9B1","v1.8B3","v1.8B2","v1.8B1","v1.7","v1.7B2","v1.7B1","v1.6","v1.5","v1.5B5","v1.5B4","v1.5B3","v1.5B2","v1.5B1","v1.4B3","v1.4B2","v1.4B1","v1.3B3","v1.3B2","v1.3B1","v1.2","v1.2B3","v1.2B2","v1.2B1","v1.1.17192","v1.1","v1.1B3","v1.1B2","v1.1B1","v1.0","v1.0RC3","v1.0RC2","v1.0RC1","v0.17","GPLv3","v0.16","v0.14","v0.13","v0.12","v0.11","v0.10","v0.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93689.json","vanir_signatures_modified":"2026-09-24T08:22:23Z","vanir_signatures":[{"source":"https://github.com/winfsp/winfsp/commit/b8103265ec63fa87ac264c62bb796dbc38376652","target":{"file":"src/sys/devctl.c"},"deprecated":false,"digest":{"line_hashes":["310144547497755340342771537126062955353","282066152080186285032257451810471237714","53418514655879279331891009504780534234","281403502953302829344506469835815627295"],"threshold":0.9},"id":"CVE-2026-93689-1f747092","signature_type":"Line","signature_version":"v1"},{"id":"CVE-2026-93689-77c30428","signature_type":"Function","signature_version":"v1","source":"https://github.com/winfsp/winfsp/commit/b8103265ec63fa87ac264c62bb796dbc38376652","target":{"file":"src/sys/devctl.c","function":"FspFastIoDeviceControl"},"deprecated":false,"digest":{"function_hash":"141545644312169895745879558420568320476","length":1456}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}