Toaruos is a niche operating system project with a narrowly scoped vulnerability footprint concentrated in its single eponymous product, where the observed weakness classes center on resource-exposure issues and memory-safety flaws including out-of-bounds reads and writes. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Toaruos over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-36710HIGH ToaruOS 1.99.2 is affected by incorrect access control via the kernel. Improper MMU management and having a low GDT address allows it to be mapped in userland. A call gate can then | Jun 8, 2022 | 8.8 | 26 | NO | NO |
CVE-2022-38932HIGH readelf in ToaruOS 2.0.1 has a global overflow allowing RCE when parsing a crafted ELF file. | Sep 27, 2022 | 7.8 | 25 | NO | NO |
CVE-2019-13049HIGH An integer wrap in kernel/sys/syscall.c in ToaruOS 1.10.10 allows users to map arbitrary kernel pages into userland process space via TOARU_SYS_FUNC_MMAP, leading to escalation of | Jun 29, 2019 | 7.8 | 25 | NO | NO |
CVE-2019-13047HIGH kernel/sys/syscall.c in ToaruOS through 1.10.9 has incorrect access control in sys_sysfunc case 9 for TOARU_SYS_FUNC_SETHEAP, allowing arbitrary kernel pages to be mapped into user | Jun 29, 2019 | 7.8 | 25 | NO | NO |
CVE-2019-13046HIGH linker/linker.c in ToaruOS through 1.10.9 has insecure LD_LIBRARY_PATH handling in setuid applications. | Jun 29, 2019 | 7.8 | 25 | NO | NO |
CVE-2019-12937HIGH apps/gsudo.c in gsudo in ToaruOS through 1.10.9 has a buffer overflow allowing local privilege escalation to the root user via the DISPLAY environment variable. | Jun 23, 2019 | 7.8 | 25 | NO | NO |
CVE-2019-13048MEDIUM kernel/sys/syscall.c in ToaruOS through 1.10.9 allows a denial of service upon a critical error in certain sys_sbrk allocation patterns (involving PAGE_SIZE, and a value less than | Jun 29, 2019 | 5.5 | 20 | NO | NO |
readelf in ToaruOS 2.0.1 has some arbitrary address read vulnerabilities when parsing a crafted ELF file. | Sep 28, 2022 | 3.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Toaruos.
Media articles that mention a CVE ID that affects a product developed by Toaruos — matched by CVE ID, not by vendor name.