Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119)
A write-what-where condition exists in the IOCTL Handler of BioStar VALKYRIE AURORA 2.10.2411.0800. The vulnerability is located in function sub_1105C of the file BS_RVSIO64.sys and can be exploited through manipulation of the PhysicalAddress argument. A public proof-of-concept exploit is available.
A local user with low-level privileges can write arbitrary data to arbitrary memory locations, potentially enabling code execution and complete system compromise including reading sensitive data, modifying system files, and disrupting service availability.
One proof-of-concept exploit is available on github.com. There is no evidence of proof of exploitation at the moment.
Patch information is available via GitHub Advisory (GHSA-9qw7-9w2r-xc4v).
Prioritize patching this vulnerability immediately given the public availability of exploit code. Restrict local access and user privileges to the minimum necessary. Monitor for suspicious IOCTL calls to BS_RVSIO64.sys. Consider disabling or isolating BioStar VALKYRIE AURORA if patching cannot be applied urgently.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Feedly found the first article mentioning CVE-2026-94129 . See article
NVD published the first details for CVE-2026-94129
A CVSS base score of 8.8 has been assigned.
GitHub Advisories released a security advisory .
A proof of concept exploit has been released
Be the first to know critical vulnerabilities
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
