Junglewise Threat Intelligence

CVE-2026-90890: ASRock Polychrome SYNC untrusted pointer dereference

CVE-2026-90890 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Executive brief

ASRock Polychrome SYNC/RGB is a software utility that controls RGB lighting and system features on ASRock motherboards and graphics cards. A vulnerability in this software allows an authenticated local attacker to crash the operating system by sending a specially crafted request to the driver, disrupting user experience and system availability.

Technical details

This vulnerability is an untrusted pointer dereference in the ASRock Polychrome SYNC/RGB driver. An authenticated local attacker can send a specially crafted IOCTL request that causes the driver to dereference an unvalidated pointer, leading to a kernel-level crash (denial of service). The attack requires local access and authentication, but no user interaction is needed. The impact is availability loss through operating system crashes. Patches are available; users should update to version later than 1.0.118 for MB or 2.0.219 for VGA.

Affected products

  • ASRock Polychrome SYNC/RGB for MB 1.0.118 and earlier
  • ASRock Polychrome SYNC/RGB for VGA 2.0.219 and earlier

Timeline

  • 2026-09-14: disclosed

References

Related threats