WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the volume context before use. An unprivileged local user can trigger a denial of service by opening the WinFsp control device and issuing FSP_IOCTL_TRANSACT requests, causing a system crash.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-476"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93689.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "2.2.26215"
}
],
"source": "AFFECTED_FIELD"
},
{
"extracted_events": [
{
"fixed": "2.2.26215"
}
],
"source": "DESCRIPTION"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93689.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"310144547497755340342771537126062955353",
"282066152080186285032257451810471237714",
"53418514655879279331891009504780534234",
"281403502953302829344506469835815627295"
],
"threshold": 0.9
},
"id": "CVE-2026-93689-1f747092",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/winfsp/winfsp/commit/b8103265ec63fa87ac264c62bb796dbc38376652",
"target": {
"file": "src/sys/devctl.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "141545644312169895745879558420568320476",
"length": 1456
},
"id": "CVE-2026-93689-77c30428",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/winfsp/winfsp/commit/b8103265ec63fa87ac264c62bb796dbc38376652",
"target": {
"file": "src/sys/devctl.c",
"function": "FspFastIoDeviceControl"
}
}
]
"2026-09-24T08:22:23Z"