PT-2026-33549 · Novumos · Novumos
Minecanton209
·
Published
2026-04-18
·
Updated
2026-04-20
·
CVE-2026-40572
CVSS v3.1
9.0
Critical
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
NovumOS versions prior to 0.24
Description
Syscall 15 ('MemoryMapRange') allows Ring 3 user-mode processes to map arbitrary virtual address ranges into their address space without validating against forbidden regions. This includes critical kernel structures such as the IDT (Interrupt Descriptor Table), GDT (Global Descriptor Table), TSS (Task State Segment), and page tables. A local attacker can exploit this to modify kernel interrupt handlers, resulting in privilege escalation from user mode to kernel context.
Recommendations
Update to version 0.24.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Novumos