CVE-2026-40031
ufrisk MemProcFS, memprocfs
MemProcFS before 5.17 contains multiple unsafe library-loading patterns that enable DLL and shared-library hijacking across six attack surfaces, including bare-name LoadLibraryU and dlopen calls without path qualification for vmmpyc, libMSCompression, and plugin DLLs. An attacker who places a malicious DLL or shared library in the working directory or manipulates LD_LIBRARY_PATH can achieve arbitrary code execution when MemProcFS loads.
- CVSS
- 8.5
- EPSS
- 0.14% 4.01% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.09