CVE-2026-15419
Received Received - Intake

Silicon Labs CP210x Driver Kernel Pool Memory Corruption

Vulnerability report for CVE-2026-15419, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: Silicon Graphics (SGI)

Description

In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to corrupt kernel pool memory, resulting in arbitrary code execution with escalated privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-10
AI Q&A
2026-09-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
silicon_labs cp210x_driver to 11.5.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in the silabser.sys driver for CP210x devices version 11.5.0 and earlier. A local unprivileged user can exploit a malicious device to send malformed packets, corrupting kernel pool memory. This allows arbitrary code execution with elevated privileges.

Impact Analysis

An attacker with physical or local access could exploit this to gain full control over the system, install malware, steal data, or disrupt operations. It requires a malicious device connected to the system.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR (data protection) and HIPAA (health data privacy). Compliance may be compromised if systems are not patched, risking legal penalties and reputational damage.

Mitigation Strategies

Update the CP210x driver to a version newer than v11.5.0 to address the kernel pool memory corruption issue. Restrict physical access to systems using these devices to prevent malicious device insertion.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15419. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart