CVE-2026-40031: Ufrisk Memprocfs

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

MemProcFS before 5.17 contains multiple unsafe library-loading patterns that enable DLL and shared-library hijacking across six attack surfaces, including bare-name LoadLibraryU and dlopen calls without path qualification for vmmpyc, libMSCompression, and plugin DLLs. An attacker who places a malicious DLL or shared library in the working directory or manipulates LD_LIBRARY_PATH can achieve arbitrary code execution when MemProcFS loads.

Affected products

  • Ufrisk Memprocfs: before 5.17 (fixed in 5.17)

Published 2026-04-08. Last modified 2026-07-24.