PatchSiren

ASRock CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ASRock CVE published 2026-09-14

CVE-2026-90891

A vulnerability in ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. allows authenticated local attackers to send a specially crafted IOCTL request, causing the driver to write to improperly restricted I/O ports, resulting in a forced operating system reboot. The vulnerability has a medium severity and requires system administrators and security teams to assess exposure and prioritize p [truncated]

MEDIUM ASRock CVE published 2026-09-14

CVE-2026-90890

A vulnerability in ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. allows authenticated local attackers to send a specially crafted IOCTL request, causing the driver to dereference an unvalidated pointer and resulting in an operating system crash. The vulnerability has a medium severity and is classified as an Untrusted Pointer Dereference. Local system defenders and administrators sh [truncated]