Home

Description

VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and earlier, respectively), as well as VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a vulnerability in their virtual audio drivers (vbvoicemeetervaio64*.sys, vbmatrixvaio64*.sys, vbaudio_vmauxvaio*.sys, vbaudio_vmvaio*.sys, and vbaudio_vmvaio3*.sys). The drivers allocate non-paged pool and map it into user space, where a length value associated with the allocation is exposed and can be modified by an unprivileged local attacker. On subsequent IOCTL handling, the corrupted length is used directly as the IoAllocateMdl length argument without adequate integrity checks before building and mapping the MDL, which can cause a kernel crash (BSoD), typically PAGE_FAULT_IN_NONPAGED_AREA. This flaw allows a local user to trigger a denial-of-service on affected Windows systems.

PUBLISHED Reserved 2026-01-15 | Published 2026-01-22 | Updated 2026-01-22 | Assigner VulnCheck




MEDIUM: 6.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-823: Use of Out-of-range Pointer Offset

Product status

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Credits

Klaus Hahnenkamp finder

References

github.com/emkaix/security-research/tree/main/CVE-2026-23764 technical-description exploit

forum.vb-audio.com/viewtopic.php?p=7574 release-notes patch

forum.vb-audio.com/viewtopic.php?p=7527 release-notes patch

vb-audio.com/ product

www.vulncheck.com/...-dos-via-corrupted-ioallocatemdl-length third-party-advisory

cve.org (CVE-2026-23764)

nvd.nist.gov (CVE-2026-23764)

Download JSON