CVE-2026-15418
Received Received - Intake

Silicon Labs CP210x Driver Kernel Memory Leak

Vulnerability report for CVE-2026-15418, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: Silicon Graphics (SGI)

Description

In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to leak up to 145 bytes of uninitialized kernel pool memory. This vulnerability affects Windows 10 and earlier.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-10
AI Q&A
2026-09-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
silicon_labs cp210x_driver to 11.5.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-130 The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the silabser.sys driver for CP210x devices version 11.5.0 and earlier. A local unprivileged user with a malicious device can send malformed packets to leak up to 145 bytes of uninitialized kernel pool memory. It affects Windows 10 and earlier versions.

Detection Guidance

Detection involves monitoring for unusual kernel memory access or malformed packets from CP210x devices. Check for driver version 11.5.0 or earlier using system tools like 'driverquery' or 'wmic driver'. Inspect device logs for suspicious activity related to silabser.sys.

Impact Analysis

An attacker could exploit this to access sensitive kernel memory data, potentially leading to information disclosure. This could include passwords, encryption keys, or other sensitive system information.

Mitigation Strategies

Update the CP210x driver to the latest version. Restrict physical access to systems using these devices. Monitor network traffic for malformed packets targeting the driver. Disable the driver if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15418. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart