CVE-2026-8050 Details
Description
In SignalRGB versions prior to 1.3.7.0, seven of the thirteen IOCTL handlers dereference the SystemBuffer pointer without first verifying that it is non-NULL. Sending an IOCTL with an empty input buffer causes a NULL pointer dereference, resulting in a kernel crash.
A NULL pointer dereference vulnerability has been identified in the SignalRGB kernel driver, 'SignalIo.sys', in versions prior to 1.3.7.0. This vulnerability arises because seven of the thirteen IOCTL handlers dereference the 'SystemBuffer' pointer without verifying that it is non-NULL. Sending an IOCTL with an empty input buffer causes a NULL pointer dereference, leading to a kernel crash. The vulnerability allows authenticated local users to trigger repeated kernel crashes, causing a denial-of-service condition.
Users are advised to update to SignalRGB version 1.3.7.0 or later, where this vulnerability has been addressed. Organizations should also implement mitigations to reduce exposure to 'Bring Your Own Vulnerable Driver' attacks, such as restricting administrative privileges and enabling protections like Windows Defender Application Control or an equivalent endpoint detection and response solution.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 17, 2026CISA-ADP
Assessed Jun 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.cert.org/vuls/id/380058 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| SignalRGB | < 1.3.7.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 18, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | New CVE Received | [email protected] |
Volerion