{"id":"CVE-2026-84290","title":"IBM Guardium Data Protection 12.0, 12.1, 12.2 is affected by an improper validation of user-supplied pointers in the WfpMonitor kernel driver","summary":"IBM Guardium Data Protection 12.0, 12.1, 12.2 is affected by an improper validation of user-supplied pointers in the WfpMonitor kernel driver. Certain METHOD_NEITHER IOCTL handlers dereference user-controlled pointers without adequate pr…","severity":"medium","cvss":5.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H","cwe":["CWE-119"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T20:49:50.083","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84290","references":[{"url":"https://www.ibm.com/support/pages/node/7291676","label":"psirt@us.ibm.com"}],"tags":["nvd"],"ingestedAt":"2026-10-08T20:06:22.191Z","slug":"CVE-2026-84290","body":"## Overview\n\nIBM Guardium Data Protection 12.0, 12.1, 12.2 is affected by an improper validation of user-supplied pointers in the WfpMonitor kernel driver. Certain METHOD_NEITHER IOCTL handlers dereference user-controlled pointers without adequate probing and exception handling, potentially allowing a privileged local attacker to cause a system crash or perform limited kernel-memory reads.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":28.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}