---
id: CVE-2026-93689
title: >-
  WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in
  the kernel driver's Fast I/O device control handler that fails to validate the
  volume context before use
summary: >-
  WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in
  the kernel driver's Fast I/O device control handler that fails to validate the
  volume context before use. An unprivileged local user can trigger a denial of
  se…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-476
vendor: winfsp
product: winfsp
affected:
  - winfsp <= 2.2.26215
published: '2026-09-18'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:25:55.870'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93689'
references:
  - url: 'https://github.com/winfsp/winfsp'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.c#L105-L114'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.c#L146-L152'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/devctl.c#L68-L73'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/winfsp/winfsp/blob/v2.2B4/src/sys/volume.c#L1059-L1060'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/winfsp/winfsp/commit/b8103265ec63fa87ac264c62bb796dbc38376652
    label: disclosure@vulncheck.com
  - url: 'https://github.com/winfsp/winfsp/releases/tag/v2.2B4'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/winfsp-through-2.2.26215-null-pointer-dereference-via-fast-i-o
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00116
epssPercentile: 0.01848
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T16:18:34.054641Z'
ingestedAt: '2026-09-18T15:44:31.587Z'
---

## Overview

WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the volume context before use. An unprivileged local user can trigger a denial of service by opening the WinFsp control device and issuing FSP_IOCTL_TRANSACT requests, causing a system crash.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
