Security Advisory

CVE-2026-90890

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-14 10:35:49
Last updated 2026-09-14 11:19:45
Assigner twcert
CVSS score 6.8
State PUBLISHED

Description

ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating system crash.