What the vulnerability does

01Description

In imgsys, there is a possible memory corruption due to improper locking. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10363254; Issue ID: MSV-5617.

Key dates

02Disclosure timeline

February 2, 2026 CVE published
March 30, 2026 Record updated