Junglewise Threat Intelligence

CVE-2026-21399: Intel Open VKL heap-based buffer overflow

CVE-2026-21399 · Severity: info · CVSS 6.9 · Published 2026-08-11

Vendors: Intel.

Executive brief

Intel Open VKL is a software library used for volume rendering in graphics applications. A heap-based buffer overflow vulnerability in versions before 2.0.2 can allow an authenticated attacker with local access to crash the application or potentially corrupt system memory, causing denial of service and data integrity issues.

Technical details

A heap-based buffer overflow vulnerability exists in Intel Open VKL before version 2.0.2 within Ring 3 user-mode applications. The vulnerability requires local access and an authenticated user with low-complexity attack execution and no user interaction needed. The attack vector is local, and while confidentiality impact is none, the vulnerability results in low integrity impact and high availability impact. Patches are available in version 2.0.2 or later, downloadable from the official GitHub releases page.

Affected products

  • Intel Open VKL before 2.0.2

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: patched: Version 2.0.2 or later available on GitHub

References