CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-49743

highCVSS 7.8covered by 1 sourcefirst seen 2026-07-24
Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs. During workload submission involving a fence exported by the GPU driver, the reference count of the underlying synchronisation primitive is not properly incremented. This can be exploited, by destroying the exported fence and prematurely release the underlying primitive, resulting in a potential use-after-free condition.

⚡ Watch CVE-2026-49743

Get an email if CVE-2026-49743 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-49743

CVE.org record

Embed the live status

CVE-2026-49743 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-49743 status](https://www.csirts.com/badge/CVE-2026-49743)](https://www.csirts.com/cve/CVE-2026-49743)