CVE-2026-56129 Details
Description
Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A logged-in user with no administrative privilege may access physical memory.
A vulnerability exists in the Generic IO & Memory Access driver for Toshiba and Dynabook PCs, all versions, installed on models released between 2009 and 2016. This vulnerability allows a logged-in user without administrative privileges to access physical memory, due to exposed IOCTL commands with inadequate access control. The issue was reported by Akshit Yadav (valium) and is not remotely exploitable.
Users are advised to uninstall the affected driver. After removal, BIOS passwords can be managed through the BIOS Setup Utility. For guidance on accessing the BIOS Setup, refer to the instructions available on the Dynabook support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 25, 2026CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://corporate.jp.sharp/info/product-security/advisory-list/2026-003/ | [email protected] | AdvisoryRemedyVendor |
| https://global.sharp/corporate/info/product-security/advisory-list/2026-003/ | [email protected] | AdvisoryRemedyVendor |
| https://jvn.jp/en/vu/JVNVU91051826/ | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-782 | Exposed IOCTL with Insufficient Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Toshiba Generic IO & Memory Access | All versions |
CPE
Remediation
| |
| Dynabook Generic IO & Memory Access | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | [email protected] |
Volerion