{
  "id": 9121554,
  "title": "Gigabyte admits an oopsie with Gigabyte Control Center software leaving kernel exposed to attackers",
  "url": "https://urgent.news/2026/09/22/gigabyte-admits-an-oopsie-with-gigabyte-control-center-software",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-22T09:17:21.000Z",
  "source": {
    "name": "PC Gamer",
    "slug": "pc-gamer",
    "url": "https://www.pcgamer.com/hardware/motherboards/gigabyte-admits-an-oopsie-with-gigabyte-control-center-software-leaving-kernel-exposed-to-attackers/"
  },
  "original_language": "en",
  "account": "Gigabyte has released an update for its Control Center software that addresses a vulnerability affecting two kernel drivers, GVCIDrv64.sys and gdrv3.sys. The issue stems from insufficient access control and improper validation of input parameters, allowing authenticated local attackers to perform unauthorized operations such as arbitrary physical memory mapping and direct hardware access. By sending a crafted IOCTL request, an attacker could bypass memory protections and elevate themselves to the kernel level.\n\nThe company acknowledges the discovery of the flaw by Mohamed Alzhrani (0xMaz) and Subhan Sultanov (me1n) and thanks them for their assistance in the patching process. Gigabyte warns that this is a period when Intel is rumored to be discontinuing its bug bounty program. Users with GCC versions 26.08.28.01, GBT_VGA_26.08.24.01, or later already have the necessary fix implemented. The current version is 26.09.10.01. Gigabyte has introduced several measures to address the issue, including enhanced access control, interface hardening, privilege validation, and input validation. To protect systems, users are advised to update their software, as the latest version is 26.09.10.01. For more information, visit Gigabyte's dedicated security disclosure page.",
  "summary": "Mitigated version is already available.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}