windows_subsystem_for_linux_wsl2 vulnerabilities
CVEs whose affected-version data names the windows_subsystem_for_linux_wsl2 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-57973Medium· 6.3Windows Subsystem for Linux (WSL2) Kernel Tampering Vulnerability
Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally.
▾ SunlitMicrosoft · Windows Subsystem for Linux (WSL2)EPSS 0.22%via CVEORG
CVE-2026-57968High· 7.8Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability
Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
▾ TwilightMicrosoft · Windows Subsystem for Linux (WSL2)EPSS 0.33%via CVEORG