CVE-2026-84290 — IBM Guardium Data Protection 12.0, 12.1, 12.2 is affected by an improper validation of user-supplied pointers in the WfpMonitor kernel driver.
Description
IBM Guardium Data Protection 12.0, 12.1, 12.2 is affected by an improper validation of user-supplied pointers in the WfpMonitor kernel driver. Certain METHOD_NEITHER IOCTL handlers dereference user-controlled pointers without adequate probing and exception handling, potentially allowing a privileged local attacker to cause a system crash or perform limited kernel-memory reads.
CVSS v3.1 base metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:HMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Local
Attack Vector
AC
Low
Attack Complexity
PR
High
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
Low
Confidentiality
I
None
Integrity
A
High
Availability
Related threats
same CWE or vendorCVE-2026-82344 — IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality.
CVE-2026-82344 · 2h ago
CVE-2026-82335 — IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based buffer overflow in the MongoDB protocol parser.
CVE-2026-82335 · 2h ago
CVE-2026-106067 — A heap-based buffer overflow was found in GIMP’s Hot color filter plug-in.
CVE-2026-106067 · 1d ago
CVE-2026-106066 — A heap-based buffer overflow was found in GIMP’s raw data export plug-in.
CVE-2026-106066 · 1d ago
CVE-2026-76464 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensiv…
CVE-2026-76464 · 1d ago
CVE-2026-106065 — A heap-based buffer overflow was found in GIMP’s PCX export plug-in.
CVE-2026-106065 · 1d ago