CVE-2026-8050: Signalrgb Kernel Driver
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
In SignalRGB versions prior to 1.3.7.0, seven of the thirteen IOCTL handlers dereference the SystemBuffer pointer without first verifying that it is non-NULL. Sending an IOCTL with an empty input buffer causes a NULL pointer dereference, resulting in a kernel crash.
Affected products
- Signalrgb Signalrgb Kernel Driver: before 1.3.7.0 (fixed in 1.3.7.0)
Published 2026-06-17. Last modified 2026-06-22.