CVE-2026-19380
A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to improper update of reference count. Local access is required to approach this attack. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.6
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.12%
- CWE
- CWE-911, CWE-664
- Published
- 2026-08-10
- Last modified
- 2026-08-10
Affected products
- Mullvad wireguard.sys
Weakness type
Related vulnerabilities
- CVE-2026-77587 — Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object...
- CVE-2026-49419 — Jail reference count underflow
- CVE-2024-45783 — Grub2: fs/hfs+: refcount can be decremented twice
- CVE-2024-46972 — GPU DDK - Security: Reference count overflow in pvr_sync_rollback_export_fence
- CVE-2024-43102 — umtx Kernel panic or Use-After-Free
- CVE-2023-6270 — Kernel: aoe: improper reference count leads to use-after-free vulnerability
- CVE-2023-5633 — Kernel: vmwgfx: reference count issue leads to use-after-free in surface handling
- CVE-2023-2019 — A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events....