{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-102005","assignerOrgId":"0bf9931a-6ebf-4f48-bd14-39ee5e1d61f8","state":"PUBLISHED","assignerShortName":"WindRiver","dateReserved":"2026-09-28T17:08:32.052Z","datePublished":"2026-09-28T20:15:52.709Z","dateUpdated":"2026-09-28T20:43:19.687Z"},"containers":{"cna":{"providerMetadata":{"orgId":"0bf9931a-6ebf-4f48-bd14-39ee5e1d61f8","shortName":"WindRiver","dateUpdated":"2026-09-28T20:15:52.709Z"},"title":"VxWorks Memory Allocation","datePublic":"2026-09-28T20:01:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-401","description":"CWE-401 Missing release of memory after effective lifetime","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-130","descriptions":[{"lang":"en","value":"CAPEC-130 Excessive Allocation"}]}],"affected":[{"vendor":"Wind River Inc","product":"VxWorks 7","platforms":["RTOS"],"versions":[{"status":"affected","version":"VxWorks 7"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"Wind River VxWorks 7 24.03 through 26.03, a memory leak occurs under specific, non-default configuration states when processing specific service routines, causing the system to terminate operations before releasing allocated memory pools. Fixed in VxWorks 7 26.09","supportingMedia":[{"type":"text/html","base64":false,"value":"Wind River VxWorks 7 24.03 through 26.03, a memory leak occurs under specific, non-default configuration states when processing specific service routines, causing the system to terminate operations before releasing allocated memory pools. Fixed in VxWorks 7 26.09"}]}],"references":[{"url":"https://support2.windriver.com/index.php?page=cve"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseSeverity":"MEDIUM","baseScore":5.5,"vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.5"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-28T20:43:09.369982Z","id":"CVE-2026-102005","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-28T20:43:19.687Z"}}]}}