CVE-2026-8050
Received Received - Intake
NULL Pointer Dereference in SignalRGB Prior to 1.3.7.0

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: CERT/CC

Description
In SignalRGB versions prior to 1.3.7.0, seven of the thirteen IOCTL handlers dereference the SystemBuffer pointer without first verifying that it is non-NULL. Sending an IOCTL with an empty input buffer causes a NULL pointer dereference, resulting in a kernel crash.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-18
AI Q&A
2026-06-18
EPSS Evaluated
N/A
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
signalrgb signalrgb to 1.3.7.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

In SignalRGB versions prior to 1.3.7.0, seven out of thirteen IOCTL handlers access the SystemBuffer pointer without checking if it is NULL. If an IOCTL call is made with an empty input buffer, this leads to a NULL pointer dereference.

This causes the kernel to crash due to the invalid memory access.

Impact Analysis

Exploiting this vulnerability can cause the system kernel to crash, resulting in a denial of service condition.

This can lead to system instability and potential downtime until the system is restarted.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8050. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart