Back to vendor advisories
SonicWall PSIRT AdvisoriesSNWLID-2026-0010

SonicWall Global VPN Client (GVC) Out-of-bounds kernel memory read vulnerability

SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.

5.5CVSS out of 10Medium severity
Scope

What the vendor says is affected

  • SonicWall Global VPN Client (GVC): 4.10.8.1108 and earlier versions

Versions the vendor lists as fixed

  • SonicWall Global VPN Client (GVC): 5.0.0.2008 and higher versions
Next step

What the vendor recommends

Install the applicable fixed SonicWall release for your product and branch. SonicWall Global VPN Client (GVC): 5.0.0.2008 and higher versions

Review the complete instructions on the vendor's site
Timeline

When this advisory changed

  1. Published by SonicWall

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.

Vulnerabilities

CVEs named in this advisory