Report Name: Linux Patch Wednesday September 2026Generated: 2026-10-02 13:20:20
| Product Name | Prevalence | U | C | H | M | L | A | Comment |
|---|---|---|---|---|---|---|---|---|
| Angular | 0.95 | 4 | 1 | 5 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |||
| Vim | 0.95 | 1 | 1 | 2 | Highly configurable command-line text editor used in development and system administration. | |||
| Active Directory | 0.9 | 1 | 1 | Active Directory is a directory service developed by Microsoft for Windows domain networks | ||||
| GLib | 0.9 | 1 | 1 | GLib is a widely used low-level core library for the GNOME ecosystem and many Linux applications, providing data structures, utility APIs, event loops, IPC facilities, and GDBus for D-Bus communication. | ||||
| Linux Kernel | 0.9 | 1 | 45 | 495 | 271 | 812 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| Polkit | 0.9 | 1 | 1 | polkit is a toolkit for defining and handling authorizations. It is used for allowing unprivileged processes to speak to privileged processes | ||||
| Rust | 0.9 | 2 | 2 | Rust is a modern, high-performance systems programming language focused on safety, concurrency, and memory management. | ||||
| Sudo | 0.9 | 1 | 1 | 2 | Sudo is a widely used Unix/Linux utility that allows permitted users to execute commands with elevated (typically root) privileges while providing extensive logging and fine-grained security controls. It is a foundational component in most Linux and BSD distributions. | |||
| Windows Kernel | 0.9 | 1 | 1 | 2 | Windows Kernel | |||
| WordPress | 0.9 | 1 | 1 | WordPress is a widely-used open source content management system (CMS) for building websites and blogs. It provides a plugin and theme architecture and is written in PHP, typically paired with MySQL/MariaDB for storage. | ||||
| nghttp2 | 0.9 | 1 | 1 | nghttp2 is an implementation of HTTP/2 and its header compression algorithm HPACK in C | ||||
| util-linux | 0.9 | 1 | 1 | 2 | Linux utility suite providing core system tools including mount. Vulnerability affects SUID mount binary due to TOCTOU race condition. | |||
| Dovecot | 0.85 | 1 | 2 | 3 | Open-source IMAP and POP3 email server with authentication and indexing features. | |||
| Grafana | 0.85 | 1 | 1 | Grafana is an open-source analytics and monitoring platform that provides dashboards and visualization tools for metrics collected from various data sources. | ||||
| Ruby on Rails | 0.85 | 1 | 1 | Full-stack Ruby web framework with MVC architecture and built-in view helpers and storage system. | ||||
| .NET Framework | 0.8 | 1 | 1 | .NET Framework | ||||
| Binutils | 0.8 | 3 | 9 | 12 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |||
| CUPS | 0.8 | 2 | 2 | CUPS is a modular printing system for Unix-like computer operating systems which allows a computer to act as a print server | ||||
| Chromium | 0.8 | 2 | 15 | 283 | 301 | 43 | 644 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google |
| Expat | 0.8 | 1 | 1 | Expat is a lightweight stream-oriented XML parser library written in C, widely embedded in applications and other software that needs to parse XML documents. | ||||
| FreeIPA | 0.8 | 1 | 2 | 3 | 6 | FreeIPA is a free and open source identity management system | ||
| GNOME desktop | 0.8 | 1 | 4 | 5 | GNOME originally an acronym for GNU Network Object Model Environment, is a free and open-source desktop environment for Linux and other Unix-like operating systems | |||
| GNU C Library | 0.8 | 6 | 6 | The GNU C Library, commonly known as glibc, is the GNU Project's implementation of the C standard library | ||||
| Keycloak | 0.8 | 1 | 4 | 16 | 3 | 24 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| Mozilla Firefox | 0.8 | 21 | 100 | 3 | 124 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | ||
| Netty | 0.8 | 1 | 1 | 6 | 8 | Netty is a non-blocking I/O client-server framework for the development of Java network applications such as protocol servers and clients | ||
| Node.js | 0.8 | 1 | 5 | 6 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |||
| OpenSSL | 0.8 | 8 | 4 | 1 | 13 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | ||
| PHP | 0.8 | 4 | 7 | 4 | 15 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | ||
| RPC | 0.8 | 1 | 1 | 3 | 5 | Remote Procedure Call Runtime | ||
| Safari | 0.8 | 2 | 5 | 7 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |||
| The Qt Company Qt | 0.8 | 1 | 1 | Qt is a cross-platform application development framework used to build graphical user interfaces and applications for desktop, mobile, and embedded systems. It provides a comprehensive set of libraries, tools, and APIs, including Qt Quick for declarative UI development using QML. The vulnerability affects the Qt Quick Text component, where improper validation of width and height attributes in the | ||||
| Windows Resilient File System (ReFS) | 0.8 | 1 | 1 | Windows component | ||||
| Zabbix | 0.8 | 3 | 3 | Zabbix is an open-source software tool to monitor IT infrastructure such as networks, servers, virtual machines, and cloud services | ||||
| jackson-databind | 0.8 | 1 | 2 | 2 | 5 | Jackson Databind is a widely used Java library for converting JSON data to and from Java objects, providing data-binding functionality within the Jackson JSON processing ecosystem. | ||
| BusyBox | 0.75 | 1 | 1 | BusyBox combines many common Unix utilities into a small executable and is widely used in embedded Linux systems, appliances, containers, and recovery environments. | ||||
| Gitea | 0.75 | 2 | 3 | 6 | 1 | 12 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| xmldom | 0.75 | 6 | 6 | 3 | 15 | JavaScript XML parser and serializer implementing W3C DOM standards. | ||
| Apache Tomcat | 0.7 | 3 | 4 | 1 | 8 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | ||
| Asterisk | 0.7 | 1 | 1 | Asterisk is a free and open source framework for building communications applications and is sponsored by Sangoma | ||||
| BIND | 0.7 | 1 | 3 | 4 | BIND is a suite of software for interacting with the Domain Name System | |||
| Envoy | 0.7 | 8 | 3 | 11 | Envoy is a cloud-native, open-source edge and service proxy | |||
| FFmpeg | 0.7 | 1 | 7 | 8 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |||
| MinIO | 0.7 | 3 | 1 | 4 | MinIO is a high-performance, S3-compatible object storage system designed for large-scale data infrastructure. It supports cloud-native workloads and provides APIs for storing, retrieving, and managing unstructured data such as photos, videos, log files, and backups, with a focus on scalability, speed, and simplicity. | |||
| Open Asset Import Library Assimp | 0.7 | 1 | 1 | Open Asset Import Library is a library that loads various 3D file formats into a shared, in-memory format | ||||
| Oracle MySQL | 0.7 | 2 | 2 | MySQL is an open-source relational database management system | ||||
| Oracle VM VirtualBox | 0.7 | 3 | 18 | 21 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |||
| RPM | 0.7 | 2 | 2 | 4 | RPM is a package management system and software packaging format widely used by Linux distributions in the Red Hat ecosystem and related systems, including tools for building RPM packages. | |||
| SQLite | 0.7 | 1 | 1 | 2 | SQLite is a database engine written in the C programming language | |||
| cpp-httplib | 0.7 | 1 | 1 | 2 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library | |||
| qs | 0.7 | 2 | 1 | 3 | qs is a popular JavaScript library for parsing and serializing URL query strings. It supports nested objects, arrays, custom parsing options, and is widely used in Node.js frameworks and middleware to handle HTTP query parameters and form-encoded data. | |||
| alsa-lib | 0.65 | 1 | 1 | alsa-lib is the user-space library for the Advanced Linux Sound Architecture (ALSA), providing APIs for audio and MIDI device access and configuration on Linux systems. | ||||
| idna | 0.65 | 1 | 1 | idna is a Python library implementing Internationalized Domain Names in Applications (IDNA), providing support for Unicode domain name encoding and decoding according to the IDNA standard. It is widely used by Python networking, HTTP, and DNS-related software. | ||||
| Bouncy Castle | 0.6 | 1 | 1 | Bouncy Castle is a collection of APIs used in cryptography | ||||
| FreeRDP | 0.6 | 1 | 6 | 15 | 22 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | ||
| GNU Screen | 0.6 | 1 | 1 | GNU Screen is a terminal multiplexer that allows multiple virtual terminal sessions to be accessed and controlled from a single physical terminal. It supports session detaching/reattaching, multiple windows, logging, and scripting — and historically is distributed as part of the GNU Project for use on Unix-like systems. When run with setuid-root privileges (as in CVE-2025-23395), Screen may perform privileged file operations on user-supplied paths without dropping elevated privileges, enabling unprivileged users to create root-owned files and potentially escalate to root. | ||||
| ImageMagick | 0.6 | 4 | 3 | 7 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |||
| Jetty | 0.6 | 3 | 3 | Jetty is a Java based web server and servlet engine | ||||
| Libsoup | 0.6 | 1 | 1 | 2 | libsoup is an HTTP client/server library for GNOME. It uses GObjects and the glib main loop to integrate well with GNOME applications and also has a synchronous API for use in CLI tools. | |||
| MongoDB | 0.6 | 41 | 7 | 48 | MongoDB is a source-available, cross-platform, document-oriented database program | |||
| Nokogiri | 0.6 | 1 | 1 | Nokogiri is an open source XML and HTML library for the Ruby programming language | ||||
| PHP Secure Communications Library | 0.6 | 1 | 1 | phpseclib provides pure-PHP implementations of SSH2, SFTP, RSA, DSA, Elliptic Curves, AES, ChaCha20, X. 509, CSR, CRL, SPKAC | ||||
| Perl | 0.6 | 2 | 14 | 1 | 17 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | ||
| Puma | 0.6 | 1 | 1 | Puma is a Ruby/Rack web server built for parallelism | ||||
| Python | 0.6 | 2 | 4 | 3 | 9 | Python is a high-level, general-purpose programming language | ||
| Rclone | 0.6 | 1 | 8 | 6 | 15 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers, supporting over 40 cloud storage products including S3, Google Drive, Dropbox, OneDrive, and many more. | ||
| Redis | 0.6 | 3 | 3 | Redis is an open-source in-memory storage, used as a distributed, in-memory key–value database, cache and message broker, with optional durability | ||||
| TuneD | 0.6 | 1 | 1 | Tuned is a daemon that uses udev to monitor connected devices and statically and dynamically tunes system settings according to a selected profile | ||||
| Vault | 0.6 | 1 | 1 | Vault secures, stores, and tightly controls access to tokens, passwords, certificates, API keys, and other secrets critical in modern computing | ||||
| ajv | 0.6 | 2 | 2 | ajv (Another JSON Schema Validator) is a high-performance JavaScript library for validating JSON data against JSON Schema specifications, widely used in Node.js applications and APIs. | ||||
| gdk-pixbuf | 0.6 | 2 | 2 | gdk-pixbuf is an open source image loading and manipulation library used primarily in GNOME-based applications for handling various image formats, including JPEG, PNG, and GIF. | ||||
| libheif | 0.6 | 1 | 2 | 3 | libheif is an open source HEIF and AVIF image file format decoder and encoder library, supporting modern image codecs and container features. | |||
| libxml2 | 0.6 | 2 | 7 | 9 | libxml2 is an XML toolkit implemented in C, originally developed for the GNOME Project | |||
| pgAdmin | 0.6 | 1 | 1 | pgAdmin is the most popular and feature rich Open Source administration and development platform for PostgreSQL, the most advanced Open Source database in the world | ||||
| strongSwan | 0.6 | 7 | 2 | 9 | strongSwan is an open source IPsec-based VPN solution that provides secure network connectivity using IKEv1 and IKEv2 protocols, widely used on Linux systems for site-to-site and remote access VPN deployments. | |||
| wpa_supplicant | 0.6 | 1 | 1 | wpa_supplicant is a free software implementation of an IEEE 802.11i supplicant for Linux, FreeBSD, NetBSD, QNX, AROS, Microsoft Windows, Solaris, OS/2 (including ArcaOS and eComStation) and Haiku | ||||
| .NET | 0.5 | 1 | 3 | 4 | Product detected by a:microsoft:.net (exists in CPE dict) | |||
| 389 Directory Server | 0.5 | 1 | 3 | 2 | 6 | 389 Directory Server is a highly usable, fully featured, reliable and secure LDAP server implementation | ||
| Ant | 0.5 | 1 | 1 | Product detected by a:apache:ant (exists in CPE dict) | ||||
| Cockpit | 0.5 | 1 | 1 | Cockpit is a web-based server administration tool for Linux systems that allows users to manage servers, containers, storage, and network configurations through a browser interface. | ||||
| CommonMark | 0.5 | 1 | 3 | 4 | Product detected by a:thephpleague:commonmark (exists in CPE dict) | |||
| Crypto | 0.5 | 2 | 2 | Product detected by a:golang:crypto (exists in CPE dict) | ||||
| Curl | 0.5 | 5 | 2 | 7 | Product detected by a:haxx:curl (exists in CPE dict) | |||
| DOMPurify | 0.5 | 1 | 1 | DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG | ||||
| Elasticsearch | 0.5 | 2 | 2 | Product detected by a:elastic:elasticsearch (exists in CPE dict) | ||||
| FRRouting | 0.5 | 1 | 1 | FRRouting (FRR) is an IP routing protocol suite for Linux and Unix platforms, supporting BGP, OSPF, RIP, IS-IS, and other routing protocols for network infrastructure. | ||||
| FreeMarker | 0.5 | 1 | 1 | Product detected by a:apache:freemarker (exists in CPE dict) | ||||
| GIMP | 0.5 | 1 | 2 | 7 | 10 | GIMP is an open-source image manipulation program used for photo editing, graphic design, and digital art creation. | ||
| GPU Display Driver | 0.5 | 11 | 11 | Product detected by a:nvidia:gpu_display_driver (exists in CPE dict) | ||||
| GitPython | 0.5 | 4 | 9 | 13 | Product detected by a:gitpython_project:gitpython (exists in CPE dict) | |||
| Hostapd | 0.5 | 1 | 1 | 2 | Product detected by a:w1.fi:hostapd (exists in CPE dict) | |||
| IMAP | 0.5 | 2 | 3 | 5 | Product detected by a:cyrus:imap (exists in CPE dict) | |||
| Kamailio | 0.5 | 2 | 1 | 3 | Kamailio is an open-source SIP server used for building scalable VoIP, instant messaging, and real-time communications systems. | |||
| KeePass | 0.5 | 1 | 1 | KeePass is a free open source password manager, which helps you to manage your passwords in a secure way | ||||
| LXD | 0.5 | 1 | 1 | Product detected by a:canonical:lxd (exists in CPE dict) | ||||
| Libraw | 0.5 | 1 | 1 | Product detected by a:libraw:libraw (exists in CPE dict) | ||||
| Morgan | 0.5 | 2 | 2 | Product detected by a:morgan_project:morgan (exists in CPE dict) | ||||
| NGINX | 0.5 | 1 | 3 | 4 | Nginx is an open-source web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache | |||
| NVIDIA GPU Display Driver | 0.5 | 1 | 1 | A NVIDIA driver is a software program that enables communication between your computer and the NVIDIA graphics processor installed in your system | ||||
| Nodemailer | 0.5 | 3 | 3 | 2 | 8 | Nodemailer is a Node.js module for sending email, supporting SMTP, message composition, attachments, and multiple transport mechanisms. | ||
| NumPy | 0.5 | 1 | 1 | NumPy is a library for the Python programming language, adding support for large, multi-dimensional arrays and matrices, along with a large collection of high-level mathematical functions | ||||
| OpenEXR | 0.5 | 5 | 13 | 18 | OpenEXR is an open source high-dynamic-range image file format and reference implementation widely used in computer graphics, visual effects, animation, and motion picture production. | |||
| OpenNLP | 0.5 | 1 | 1 | Product detected by a:apache:opennlp (exists in CPE dict) | ||||
| OpenTelemetry | 0.5 | 4 | 4 | OpenTelemetry is a collection of APIs, SDKs, and tools. Use it to instrument, generate, collect, and export telemetry data (metrics, logs and traces) to help you analyze your software's performance and behavior | ||||
| Pcre2 | 0.5 | 4 | 1 | 1 | 6 | Product detected by a:pcre:pcre2 (exists in CPE dict) | ||
| Pypdf | 0.5 | 3 | 1 | 4 | PyPDF is a Python library for reading, manipulating, and writing PDF files, including extraction, splitting, merging, and encryption features. | |||
| RDF4J | 0.5 | 1 | 1 | Product detected by a:eclipse:rdf4j (exists in CPE dict) | ||||
| SPIP | 0.5 | 1 | 1 | 2 | 4 | SPIP is an open-source software content management system designed for web site publishing, oriented towards online collaborative editing | ||
| Suricata | 0.5 | 6 | 2 | 8 | Suricata is an open-source intrusion detection and prevention system (IDS/IPS) and network security monitoring engine that supports deep packet inspection and threat detection. | |||
| TLS | 0.5 | 1 | 8 | 1 | 10 | TLS | ||
| Thunderbird | 0.5 | 5 | 5 | Product detected by a:mozilla:thunderbird (exists in CPE dict) | ||||
| TimescaleDB | 0.5 | 3 | 3 | Product detected by a:timescale:timescaledb (exists in CPE dict) | ||||
| Traefik | 0.5 | 1 | 2 | 4 | 7 | Product detected by a:traefik:traefik (exists in CPE dict) | ||
| Visual Studio 2022 | 0.5 | 4 | 4 | Product detected by a:microsoft:visual_studio_2022 (exists in CPE dict) | ||||
| Xeon Bronze 3408U | 0.5 | 3 | 3 | Product detected by h:intel:xeon_bronze_3408u (exists in CPE dict) | ||||
| Znuny | 0.5 | 1 | 1 | Znuny/Znuny LTS is a fork of the ((OTRS)) Community Edition, one of the most flexible web-based ticketing systems used for Customer Service, Help Desk, IT Service Management | ||||
| authelia | 0.5 | 1 | 1 | Product detected by a:authelia:authelia (exists in CPE dict) | ||||
| canvg | 0.5 | 1 | 1 | Product detected by a:canvg:canvg (does NOT exist in CPE dict) | ||||
| dart_software_development_kit | 0.5 | 1 | 1 | Product detected by a:dart:dart_software_development_kit (exists in CPE dict) | ||||
| fast-uri | 0.5 | 4 | 2 | 6 | Product detected by a:openjsf:fast-uri (does NOT exist in CPE dict) | |||
| gobgp | 0.5 | 1 | 1 | Product detected by a:osrg:gobgp (does NOT exist in CPE dict) | ||||
| haproxy | 0.5 | 1 | 1 | Product detected by a:haproxy:haproxy (exists in CPE dict) | ||||
| helm | 0.5 | 1 | 1 | Product detected by a:helm:helm (exists in CPE dict) | ||||
| libevent | 0.5 | 1 | 6 | 1 | 8 | libevent is a portable event notification library that provides an asynchronous event loop and networking primitives for applications using sockets, timers, signals, DNS, and HTTP. | ||
| libexpat | 0.5 | 2 | 2 | Product detected by a:libexpat_project:libexpat (exists in CPE dict) | ||||
| libmongocrypt | 0.5 | 1 | 1 | Product detected by a:mongodb:libmongocrypt (exists in CPE dict) | ||||
| n8n | 0.5 | 1 | 1 | Product detected by a:n8n:n8n (exists in CPE dict) | ||||
| nltk | 0.5 | 1 | 22 | 1 | 24 | Product detected by a:nltk:nltk (exists in CPE dict) | ||
| nokogiri | 0.5 | 2 | 1 | 3 | Product detected by a:nokogiri:nokogiri (exists in CPE dict) | |||
| nsd | 0.5 | 1 | 2 | 3 | Product detected by a:nlnetlabs:nsd (exists in CPE dict) | |||
| onnx | 0.5 | 1 | 1 | Product detected by a:linuxfoundation:onnx (exists in CPE dict) | ||||
| openCryptoki | 0.5 | 1 | 1 | Product detected by a:opencryptoki_project:opencryptoki (exists in CPE dict) | ||||
| openssl | 0.5 | 1 | 1 | Product detected by a:openssl:openssl (exists in CPE dict) | ||||
| tesseract_ocr | 0.5 | 7 | 1 | 8 | Product detected by a:tesseract-ocr:tesseract_ocr (does NOT exist in CPE dict) | |||
| trivy | 0.5 | 1 | 1 | Product detected by a:aquasec:trivy (does NOT exist in CPE dict) | ||||
| undici | 0.5 | 9 | 2 | 11 | Product detected by a:nodejs:undici (exists in CPE dict) | |||
| wolfSSL | 0.5 | 1 | 1 | wolfSSL is a small, portable, embedded SSL/TLS library targeted for use by embedded systems developers | ||||
| xeon_6315p | 0.5 | 1 | 1 | Product detected by h:intel:xeon_6315p (does NOT exist in CPE dict) | ||||
| Apache Tika | 0.4 | 1 | 1 | Apache Tika is an open source content analysis toolkit that detects and extracts metadata and structured text content from a wide range of file formats such as PDF, Microsoft Office, and multimedia files. | ||||
| Azure | 0.4 | 1 | 1 | Azure | ||||
| Erlang/OTP | 0.4 | 6 | 3 | 9 | Erlang/OTP is a set of libraries for the Erlang programming language | |||
| Flatpak | 0.4 | 1 | 1 | Flatpak is a utility for software deployment and package management for Linux | ||||
| GPAC | 0.4 | 1 | 4 | 5 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |||
| GVfs | 0.4 | 4 | 1 | 5 | GVfs (GNOME Virtual File System) is userspace virtual filesystem software for GNOME that provides backends (including FTP) to access different remote and local file systems transparently. | |||
| Git | 0.4 | 1 | 1 | Git | ||||
| Horde IMP | 0.4 | 1 | 1 | IMP is the Internet Messaging Program. It is written in PHP and provides webmail access to IMAP and POP3 accounts. It uses the best-of-class Horde/Imap_Client library to provide fast, robust connections to the remote IMAP/POP3 server. | ||||
| Net-SNMP | 0.4 | 1 | 1 | Net-SNMP is a suite of applications and libraries implementing the Simple Network Management Protocol (SNMP), used for monitoring and managing networked systems and devices. | ||||
| Spring Framework | 0.4 | 1 | 10 | 2 | 13 | The Spring Framework is an application framework and inversion of control container for the Java platform | ||
| U-Boot | 0.4 | 2 | 2 | Das U-Boot (U-Boot) is an open-source universal boot loader used on many embedded boards and SoCs to initialize hardware, provide low-level diagnostics, and load an operating system kernel. It is implemented primarily in C with board-specific assembly. | ||||
| Oj | 0.35 | 1 | 1 | Oj (Optimized JSON) is a high-performance JSON parser and object serialization library packaged as a Ruby gem, designed to provide fast JSON encoding and decoding for Ruby applications. | ||||
| JOSE | 0.3 | 3 | 1 | 4 | JavaScript module for JSON Object Signing and Encryption (JOSE) | |||
| WeasyPrint | 0.3 | 1 | 1 | Python library to generate PDF documents from HTML/CSS | ||||
| gitoxide | 0.3 | 1 | 4 | 3 | 8 | gitoxide is an idiomatic, lean, fast & safe pure Rust implementation of Git, designed for correctness and performance, available both as a Rust library (gix crate) and command-line interface tools. | ||
| zstd-jni | 0.25 | 4 | 5 | 9 | zstd-jni provides Java Native Interface bindings for the Zstandard lossless compression library, enabling high-performance compression and decompression from Java, Android, and other JVM languages. | |||
| GitHub | 0.2 | 1 | 1 | GitHub, Inc. is an Internet hosting service for software development and version control using Git | ||||
| Incus | 0.2 | 3 | 3 | Incus is an open source system container and virtual machine manager used to create, manage, and operate Linux containers and virtual machines. | ||||
| libtiff | 0.2 | 1 | 2 | 1 | 4 | libtiff is a widely used library for reading and writing TIFF (Tagged Image File Format) files, offering tools like tiff2ps. | ||
| Fast DDS | 0.15 | 2 | 2 | eProsima Fast DDS is a C++ implementation of the OMG Data Distribution Service (DDS) and RTPS protocols, providing high-performance publish-subscribe middleware for distributed and real-time systems. | ||||
| kin-openapi | 0.12 | 2 | 1 | 1 | 4 | kin-openapi is a Go library for parsing, converting, validating, and working with OpenAPI and Swagger specifications and for validating HTTP requests and responses against OpenAPI schemas. | ||
| WebOb | 0.1 | 1 | 1 | WebOb is a Python library that provides objects for HTTP requests and responses, commonly used by Python web frameworks and applications. | ||||
| libtpms | 0.08 | 1 | 1 | libtpms is a software library implementing a TPM 1.2 and TPM 2.0 emulator, commonly used by virtualization and software TPM components such as swtpm. | ||||
| Unknown Product | 0 | 137 | 199 | 336 | Unknown Product |
| Vulnerability Type | Criticality | U | C | H | M | L | A |
|---|---|---|---|---|---|---|---|
| Remote Code Execution | 1.0 | 4 | 21 | 255 | 45 | 325 | |
| Authentication Bypass | 0.98 | 2 | 5 | 28 | 37 | 72 | |
| Code Injection | 0.97 | 3 | 6 | 7 | 16 | ||
| Command Injection | 0.97 | 3 | 3 | 7 | 13 | ||
| XXE Injection | 0.97 | 1 | 2 | 3 | |||
| Arbitrary File Writing | 0.95 | 2 | 1 | 3 | |||
| Security Feature Bypass | 0.9 | 15 | 53 | 146 | 1 | 215 | |
| Server-Side Request Forgery | 0.87 | 1 | 6 | 11 | 1 | 19 | |
| Elevation of Privilege | 0.85 | 1 | 5 | 8 | 1 | 15 | |
| Arbitrary File Reading | 0.83 | 8 | 2 | 10 | |||
| Information Disclosure | 0.83 | 33 | 106 | 2 | 141 | ||
| Cross Site Scripting | 0.8 | 3 | 6 | 12 | 21 | ||
| Open Redirect | 0.75 | 1 | 3 | 1 | 5 | ||
| Denial of Service | 0.7 | 2 | 52 | 184 | 19 | 257 | |
| Path Traversal | 0.7 | 13 | 17 | 30 | |||
| Incorrect Calculation | 0.5 | 3 | 24 | 4 | 31 | ||
| Memory Corruption | 0.5 | 1 | 68 | 316 | 36 | 421 | |
| Spoofing | 0.4 | 6 | 21 | 1 | 28 | ||
| Unknown Vulnerability Type | 0 | 501 | 527 | 1028 |
| Source | U | C | H | M | L | A |
|---|---|---|---|---|---|---|
| almalinux | 1 | 15 | 8 | 1 | 25 | |
| altlinux | 5 | 31 | 359 | 559 | 104 | 1058 |
| debian | 3 | 49 | 495 | 1215 | 531 | 2293 |
| oraclelinux | 2 | 27 | 123 | 39 | 191 | |
| redhat | 14 | 8 | 1 | 23 | ||
| redos | 5 | 23 | 55 | 21 | 104 | |
| ubuntu | 1 | 17 | 32 | 11 | 61 |
1.
Remote Code Execution - Gitea (CVE-2026-60004) - Urgent [958]
Description:
altlinux: CVE-2026-60004 was patched at 2026-08-27, 2026-08-29, 2026-09-04
2.
Authentication Bypass - Gitea (CVE-2026-20896) - Urgent [942]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (vulncheck_kev object) website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:ETHAN-ANDREWS:EXPLOITARIUM-DETECTIONS, Vulners:PublicExploit:GitHub:RZ1027:CVE-2026-20896, Vulners:PublicExploit:GitHub:XAOCZENON:CVE-2026-20896, Vulners:PublicExploit:GitHub:JUDGEDBYKIRA:CVE-2026-20896-GITEA-AUTHENTICATION-BYPASS, Vulners:PublicExploit:GitHub:YYM8538:CVE-2026-20896, Vulners:PublicExploit:GitHub:KALETH4:CVE-2026-20896, Vulners:PublicExploit:GitHub:SZYBNEV:CVE-2026-20896-GITEA-POC, BDU:PublicExploit websites | |
| 0.98 | 15 | Authentication Bypass | |
| 0.75 | 14 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.9 | 10 | EPSS Probability is 0.02755, EPSS Percentile is 0.85496 |
altlinux: CVE-2026-20896 was patched at 2026-08-27, 2026-08-29, 2026-09-04
3.
Authentication Bypass - Keycloak (CVE-2026-18963) - Urgent [939]
Description: A flaw was found in the reset-credentials flow of the
altlinux: CVE-2026-18963 was patched at 2026-08-20, 2026-08-26, 2026-08-28
4.
Remote Code Execution - Chromium (CVE-2026-85046) - Urgent [919]
Description: Type confusion in V8 in Google Chrome prior to 152.0.7977.82
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (chrome object, cisa_kev object, vulncheck_kev object), NVD:CISAKEV websites | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:serotav.github.io, Vulners:PublicExploit:GitHub:SNEAKYNACHOS:CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-AND-CVE-2026-85046.-ESCAPE-THE-V8-CARCASS., Vulners:PublicExploit:GitHub:SNEAKYNACHOS:CVE-2026-85046-WHO-PUT-THE-SILVERBACK-GUERILLA-IN-THE-WASM, Vulners:PublicExploit:GitHub:SNEAKYNACHOS:CVE-2026-87491-AND-CVE-2026-85046-THE-BAGEL-FELL-OFF-THE-COUNTER, Vulners:PublicExploit:GitHub:HORKIMHAB:CVE-2026-85046, BDU:PublicExploit websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.7 | 10 | EPSS Probability is 0.01462, EPSS Percentile is 0.72273 |
altlinux: CVE-2026-85046 was patched at 2026-09-05
debian: CVE-2026-85046 was patched at 2026-09-05, 2026-09-16
5.
Remote Code Execution - Chromium (CVE-2026-87491) - Urgent [907]
Description: Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (cisa_kev object, vulncheck_kev object), NVD:CISAKEV websites | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:SNEAKYNACHOS:CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-AND-CVE-2026-85046.-ESCAPE-THE-V8-CARCASS., Vulners:PublicExploit:GitHub:SNEAKYNACHOS:CVE-2026-87491-AND-CVE-2026-85046-THE-BAGEL-FELL-OFF-THE-COUNTER websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.00997, EPSS Percentile is 0.60979 |
altlinux: CVE-2026-87491 was patched at 2026-09-17
debian: CVE-2026-87491 was patched at 2026-09-16
6.
Remote Code Execution - SPIP (CVE-2026-77806) - Urgent [904]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (vulncheck_kev object) website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | SPIP is an open-source software content management system designed for web site publishing, oriented towards online collaborative editing | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.9 | 10 | EPSS Probability is 0.04201, EPSS Percentile is 0.90444 |
debian: CVE-2026-77806 was patched at 2026-08-21, 2026-08-25
7.
Authentication Bypass - PHP (CVE-2026-55584) - Critical [701]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:EDB-ID:52648, Vulners:PublicExploit:PACKETSTORM:224403 websites | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.8 | 10 | EPSS Probability is 0.02417, EPSS Percentile is 0.83318 |
debian: CVE-2026-55584 was patched at 2026-09-16
8.
Remote Code Execution - Chromium (CVE-2026-78904) - Critical [680]
Description: Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:VXSSROOTT:CVE-2026-78904-DIGITAL-DINAR-DRAIN website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00475, EPSS Percentile is 0.39938 |
altlinux: CVE-2026-78904 was patched at 2026-08-28
debian: CVE-2026-78904 was patched at 2026-09-03, 2026-09-16
9.
Remote Code Execution - PHP (CVE-2026-56705) - Critical [680]
Description: Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:CHIEFYORU:EXPLOIT-CVE-2026-56705, Vulners:PublicExploit:GitHub:BOREAS37:CVE-2026-56705, BDU:PublicExploit websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00497, EPSS Percentile is 0.41436 |
debian: CVE-2026-56705 was patched at 2026-09-16
10.
Authentication Bypass - FreeIPA (CVE-2026-76578) - Critical [677]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:BRAINBOB:CVE-2026-76578 website | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | FreeIPA is a free and open source identity management system | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00453, EPSS Percentile is 0.38472 |
altlinux: CVE-2026-76578 was patched at 2026-09-07
debian: CVE-2026-76578 was patched at 2026-09-16
11.
Remote Code Execution - Chromium (CVE-2026-78905) - Critical [669]
Description: Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:VXSSROOTT:CVE-2026-78905-FACEBOOK-ACCOUNT-TAKEOVER website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00475, EPSS Percentile is 0.39938 |
altlinux: CVE-2026-78905 was patched at 2026-08-28
debian: CVE-2026-78905 was patched at 2026-09-03, 2026-09-16
12.
Remote Code Execution - Chromium (CVE-2026-87528) - Critical [669]
Description: Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00349, EPSS Percentile is 0.28392 |
altlinux: CVE-2026-87528 was patched at 2026-09-17
debian: CVE-2026-87528 was patched at 2026-09-16
13.
Remote Code Execution - NumPy (CVE-2026-79657) - Critical [666]
Description: NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like ReppTokenizer._execute and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | NumPy is a library for the Python programming language, adding support for large, multi-dimensional arrays and matrices, along with a large collection of high-level mathematical functions | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.7 | 10 | EPSS Probability is 0.01214, EPSS Percentile is 0.66999 |
debian: CVE-2026-79657 was patched at 2026-09-16
14.
Authentication Bypass - Curl (CVE-2026-19931) - Critical [663]
Description: A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.7 | 10 | EPSS Probability is 0.01162, EPSS Percentile is 0.65603 |
altlinux: CVE-2026-19931 was patched at 2026-09-02, 2026-09-07
debian: CVE-2026-19931 was patched at 2026-09-16
15.
Remote Code Execution - Chromium (CVE-2026-78938) - Critical [657]
Description: Type confusion in V8 in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:EDDINOS2:CVE-2026-78938 website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00406, EPSS Percentile is 0.34435 |
altlinux: CVE-2026-78938 was patched at 2026-08-28
debian: CVE-2026-78938 was patched at 2026-09-03, 2026-09-16
16.
Remote Code Execution - PHP (CVE-2026-56702) - Critical [657]
Description: Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00343, EPSS Percentile is 0.27635 |
debian: CVE-2026-56702 was patched at 2026-09-16
17.
Remote Code Execution - SQLite (CVE-2026-56703) - Critical [652]
Description: Adminer before 5.4.3 contains a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | SQLite is a database engine written in the C programming language | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.01134, EPSS Percentile is 0.64861 |
debian: CVE-2026-56703 was patched at 2026-09-16
18.
Server-Side Request Forgery - Gitea (CVE-2026-22874) - Critical [649]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:ELIOT-CODE:CVE-2026-22874-POC, BDU:PublicExploit websites | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.75 | 14 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00464, EPSS Percentile is 0.39169 |
altlinux: CVE-2026-22874 was patched at 2026-08-27, 2026-08-29, 2026-09-04
19.
Remote Code Execution - FreeRDP (CVE-2026-63633) - Critical [647]
Description: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00459, EPSS Percentile is 0.38841 |
almalinux: CVE-2026-63633 was patched at 2026-08-31
debian: CVE-2026-63633 was patched at 2026-08-25
oraclelinux: CVE-2026-63633 was patched at 2026-09-01
20.
Remote Code Execution - Chromium (CVE-2026-79266) - Critical [645]
Description: Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:VIROLOGI-INFO:CHROME-VULN-SCANNER website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00279, EPSS Percentile is 0.20478 |
altlinux: CVE-2026-79266 was patched at 2026-08-28
debian: CVE-2026-79266 was patched at 2026-09-03, 2026-09-16
21.
Code Injection - xmldom (CVE-2026-83609) - Critical [643]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.97 | 15 | Code Injection | |
| 0.75 | 14 | JavaScript XML parser and serializer implementing W3C DOM standards. | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00326, EPSS Percentile is 0.25727 |
debian: CVE-2026-83609 was patched at 2026-09-16
22.
Code Injection - xmldom (CVE-2026-83616) - Critical [643]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.97 | 15 | Code Injection | |
| 0.75 | 14 | JavaScript XML parser and serializer implementing W3C DOM standards. | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00348, EPSS Percentile is 0.28194 |
debian: CVE-2026-83616 was patched at 2026-09-16
23.
Code Injection - xmldom (CVE-2026-83618) - Critical [643]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.97 | 15 | Code Injection | |
| 0.75 | 14 | JavaScript XML parser and serializer implementing W3C DOM standards. | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00328, EPSS Percentile is 0.25902 |
debian: CVE-2026-83618 was patched at 2026-09-16
24.
Remote Code Execution - LXD (CVE-2026-66897) - Critical [642]
Description: A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using os.Create with an unconfined string path. This discrepancy between path resolution checks and file creation allows an attacker to escape directory confinement, overwrite root-owned host files, and achieve host root
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:canonical:lxd (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.9. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00668, EPSS Percentile is 0.50208 |
debian: CVE-2026-66897 was patched at 2026-09-16
25.
Remote Code Execution - canvg (CVE-2025-25977) - Critical [642]
Description: An issue in canvg v.4.0.2 allows an attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:canvg:canvg (does NOT exist in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00707, EPSS Percentile is 0.51731 |
debian: CVE-2025-25977 was patched at 2026-08-25
26.
Command Injection - PHP (CVE-2026-84361) - Critical [639]
Description: Composer is a dependency Manager for the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:SAKU0512:CVE-2026-84361-POC, BDU:PublicExploit websites | |
| 0.97 | 15 | Command Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00409, EPSS Percentile is 0.34695 |
debian: CVE-2026-84361 was patched at 2026-09-16
27.
Remote Code Execution - GitPython (CVE-2026-76218) - Critical [630]
Description: GitPython before 3.1.58 contains a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:gitpython_project:gitpython (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.0072, EPSS Percentile is 0.52181 |
altlinux: CVE-2026-76218 was patched at 2026-09-01
debian: CVE-2026-76218 was patched at 2026-08-20
redos: CVE-2026-76218 was patched at 2026-09-02
28.
Remote Code Execution - GitPython (CVE-2026-76220) - Critical [630]
Description: GitPython before 3.1.58 contains a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:gitpython_project:gitpython (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.0057, EPSS Percentile is 0.45691 |
altlinux: CVE-2026-76220 was patched at 2026-09-01
debian: CVE-2026-76220 was patched at 2026-08-20
redos: CVE-2026-76220 was patched at 2026-09-01
29.
Remote Code Execution - GitPython (CVE-2026-78676) - Critical [630]
Description: GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:gitpython_project:gitpython (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00426, EPSS Percentile is 0.36261 |
altlinux: CVE-2026-78676 was patched at 2026-09-01
debian: CVE-2026-78676 was patched at 2026-08-25
redos: CVE-2026-78676 was patched at 2026-09-08
30.
Remote Code Execution - nltk (CVE-2026-79675) - Critical [630]
Description: NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfile to Stanford wrapper classes to achieve arbitrary
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00426, EPSS Percentile is 0.36261 |
debian: CVE-2026-79675 was patched at 2026-09-16
31.
Security Feature Bypass - Gitea (CVE-2026-58424) - Critical [630]
Description: Permanent Fork PR Workflow Approval Gate Bypass
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:BRIDGERALDERSON:CVE-2026-58424 website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.75 | 14 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| 0.9 | 10 | CVSS Base Score is 8.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0037, EPSS Percentile is 0.30678 |
altlinux: CVE-2026-58424 was patched at 2026-08-27, 2026-08-29, 2026-09-04
32.
Authentication Bypass - Traefik (CVE-2026-53622) - Critical [627]
Description: Traefik is an HTTP reverse proxy and load balancer. Versions prior to 3.7.3, 3.6.18, and 2.11.51 have a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthenticated clients to bypass router-specific mTLS enforcement. When HTTP/3 is enabled on an entrypoint, the TLS handshake selects the applicable TLS configuration through an exact, case-sensitive lookup on the SNI value, which fails to match wildcard host patterns (e.g., *.example.com) or case variants of the configured hostname. Because the handshake falls back to the default TLS configuration — which may not require client certificates — a client can complete the QUIC handshake without presenting a certificate, while the subsequent HTTP routing layer still dispatches the request to a backend protected by a router-specific mTLS policy. The issue affects deployments where HTTP/3 is enabled, a router uses a wildcard Host rule or case-insensitive hostname matching, a router-specific TLSOptions enforces client certificate authentication, and UDP access to the entrypoint is reachable by an attacker. This vulnerability is fixed in versions 3.7.3, 3.6.18, and 2.11.51.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:traefik:traefik (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00629, EPSS Percentile is 0.48481 |
altlinux: CVE-2026-53622 was patched at 2026-09-15, 2026-09-16
33.
Remote Code Execution - Windows Kernel (CVE-2026-78680) - Critical [626]
Description: NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygraph.dot2img and AlignedSent._repr_svg_, allowing attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows Kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.0213 |
debian: CVE-2026-78680 was patched at 2026-08-25
34.
Remote Code Execution - Chromium (CVE-2026-85045) - Critical [621]
Description: Race condition in V8 in Google Chrome prior to 152.0.7977.82
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:SNEAKYNACHOS:CVE-2026-85045 website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00219, EPSS Percentile is 0.12516 |
altlinux: CVE-2026-85045 was patched at 2026-09-05
debian: CVE-2026-85045 was patched at 2026-09-05, 2026-09-16
35.
Remote Code Execution - GitPython (CVE-2026-76221) - Critical [619]
Description: GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #' to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:gitpython_project:gitpython (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00485, EPSS Percentile is 0.40613 |
altlinux: CVE-2026-76221 was patched at 2026-09-01
debian: CVE-2026-76221 was patched at 2026-08-20
redos: CVE-2026-76221 was patched at 2026-09-01
36.
Security Feature Bypass - Gitea (CVE-2026-58433) - Critical [619]
Description: Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.75 | 14 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00284, EPSS Percentile is 0.20988 |
altlinux: CVE-2026-58433 was patched at 2026-08-27, 2026-08-29, 2026-09-04
redos: CVE-2026-58433 was patched at 2026-08-20
37.
Command Injection - Netty (CVE-2026-89044) - Critical [616]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.97 | 15 | Command Injection | |
| 0.8 | 14 | Netty is a non-blocking I/O client-server framework for the development of Java network applications such as protocol servers and clients | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16198 |
debian: CVE-2026-89044 was patched at 2026-09-16
38.
Denial of Service - Expat (CVE-2026-66046) - Critical [615]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Expat is a lightweight stream-oriented XML parser library written in C, widely embedded in applications and other software that needs to parse XML documents. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00586, EPSS Percentile is 0.46451 |
debian: CVE-2026-66046 was patched at 2026-08-20
39.
Denial of Service - RPC (CVE-2026-84304) - Critical [615]
Description: g
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Remote Procedure Call Runtime | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00415, EPSS Percentile is 0.35224 |
debian: CVE-2026-84304 was patched at 2026-09-16
40.
Security Feature Bypass - Chromium (CVE-2026-87606) - Critical [615]
Description: Missing authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:SNEAKYNACHOS:CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-AND-CVE-2026-85046.-ESCAPE-THE-V8-CARCASS. website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0024, EPSS Percentile is 0.15284 |
altlinux: CVE-2026-87606 was patched at 2026-09-17
debian: CVE-2026-87606 was patched at 2026-09-16
41.
Cross Site Scripting - xmldom (CVE-2026-83605) - Critical [613]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.75 | 14 | JavaScript XML parser and serializer implementing W3C DOM standards. | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00348, EPSS Percentile is 0.28242 |
debian: CVE-2026-83605 was patched at 2026-09-16
42.
Cross Site Scripting - xmldom (CVE-2026-83607) - Critical [613]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.75 | 14 | JavaScript XML parser and serializer implementing W3C DOM standards. | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00348, EPSS Percentile is 0.28194 |
debian: CVE-2026-83607 was patched at 2026-09-16
43.
Cross Site Scripting - xmldom (CVE-2026-83617) - Critical [613]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.75 | 14 | JavaScript XML parser and serializer implementing W3C DOM standards. | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00328, EPSS Percentile is 0.25902 |
debian: CVE-2026-83617 was patched at 2026-09-16
44.
Security Feature Bypass - Curl (CVE-2026-80231) - Critical [613]
Description: A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.00937, EPSS Percentile is 0.59103 |
altlinux: CVE-2026-80231 was patched at 2026-09-02, 2026-09-07
45.
Security Feature Bypass - libevent (CVE-2026-63382) - Critical [613]
Description: Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | libevent is a portable event notification library that provides an asynchronous event loop and networking primitives for applications using sockets, timers, signals, DNS, and HTTP. | |
| 0.9 | 10 | CVSS Base Score is 9.2. According to Vulners data source | |
| 0.5 | 10 | EPSS Probability is 0.00587, EPSS Percentile is 0.46511 |
debian: CVE-2026-63382 was patched at 2026-08-25, 2026-09-11
ubuntu: CVE-2026-63382 was patched at 2026-09-01, 2026-09-16
46.
Elevation of Privilege - util-linux (CVE-2026-76642) - Critical [611]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | Linux utility suite providing core system tools including mount. Vulnerability affects SUID mount binary due to TOCTOU race condition. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07381 |
debian: CVE-2026-76642 was patched at 2026-09-16
47.
Remote Code Execution - Chromium (CVE-2026-87533) - Critical [609]
Description: Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0011, EPSS Percentile is 0.01426 |
altlinux: CVE-2026-87533 was patched at 2026-09-17
debian: CVE-2026-87533 was patched at 2026-09-16
48.
Memory Corruption - Linux Kernel (CVE-2026-74586) - Critical [608]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:TARPEG007:CVE-2026-74586, BDU:PublicExploit websites | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.005, EPSS Percentile is 0.4159 |
debian: CVE-2026-74586 was patched at 2026-08-25
oraclelinux: CVE-2026-74586 was patched at 2026-09-04
49.
Remote Code Execution - GIMP (CVE-2026-59087) - Critical [607]
Description: A flaw was found in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:gitlab.gnome.org, BDU:PublicExploit websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | GIMP is an open-source image manipulation program used for photo editing, graphic design, and digital art creation. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00478, EPSS Percentile is 0.40147 |
altlinux: CVE-2026-59087 was patched at 2026-09-14
50.
Authentication Bypass - Curl (CVE-2026-13608) - Critical [603]
Description: A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00644, EPSS Percentile is 0.49213 |
altlinux: CVE-2026-13608 was patched at 2026-09-02, 2026-09-07
debian: CVE-2026-13608 was patched at 2026-09-16
51.
Security Feature Bypass - Chromium (CVE-2026-87441) - Critical [603]
Description: Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.18364 |
altlinux: CVE-2026-87441 was patched at 2026-09-17
debian: CVE-2026-87441 was patched at 2026-09-16
52.
Security Feature Bypass - Chromium (CVE-2026-87447) - Critical [603]
Description: Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00278, EPSS Percentile is 0.20359 |
altlinux: CVE-2026-87447 was patched at 2026-09-17
debian: CVE-2026-87447 was patched at 2026-09-16
53.
Security Feature Bypass - Chromium (CVE-2026-87483) - Critical [603]
Description: Incorrect authorization in Browser in Google Chrome on on Android prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00249, EPSS Percentile is 0.16429 |
altlinux: CVE-2026-87483 was patched at 2026-09-17
debian: CVE-2026-87483 was patched at 2026-09-16
54.
Security Feature Bypass - Chromium (CVE-2026-87503) - Critical [603]
Description: Inappropriate implementation in Downloads in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00254, EPSS Percentile is 0.1706 |
altlinux: CVE-2026-87503 was patched at 2026-09-17
debian: CVE-2026-87503 was patched at 2026-09-16
55.
Security Feature Bypass - Chromium (CVE-2026-87505) - Critical [603]
Description: Incorrect authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00206, EPSS Percentile is 0.1094 |
altlinux: CVE-2026-87505 was patched at 2026-09-17
debian: CVE-2026-87505 was patched at 2026-09-16
56.
Security Feature Bypass - Chromium (CVE-2026-87513) - Critical [603]
Description: Missing authorization in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00285, EPSS Percentile is 0.2112 |
altlinux: CVE-2026-87513 was patched at 2026-09-17
debian: CVE-2026-87513 was patched at 2026-09-16
57.
Security Feature Bypass - Chromium (CVE-2026-87535) - Critical [603]
Description: Information loss or omission in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00258, EPSS Percentile is 0.17607 |
altlinux: CVE-2026-87535 was patched at 2026-09-17
debian: CVE-2026-87535 was patched at 2026-09-16
58.
Security Feature Bypass - jackson-databind (CVE-2026-19032) - Critical [603]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Jackson Databind is a widely used Java library for converting JSON data to and from Java objects, providing data-binding functionality within the Jackson JSON processing ecosystem. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00463, EPSS Percentile is 0.39108 |
debian: CVE-2026-19032 was patched at 2026-09-16
59.
Command Injection - 389 Directory Server (CVE-2026-19843) - Critical [601]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:GDUMA-PHDATA:PATCH-CVE-2026-19843 website | |
| 0.97 | 15 | Command Injection | |
| 0.5 | 14 | 389 Directory Server is a highly usable, fully featured, reliable and secure LDAP server implementation | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0048, EPSS Percentile is 0.40288 |
altlinux: CVE-2026-19843 was patched at 2026-09-08, 2026-09-11
debian: CVE-2026-19843 was patched at 2026-09-16
60.
Security Feature Bypass - Curl (CVE-2026-80230) - Critical [601]
Description: When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00566, EPSS Percentile is 0.4548 |
altlinux: CVE-2026-80230 was patched at 2026-09-02, 2026-09-07
debian: CVE-2026-80230 was patched at 2026-09-16
61.
Security Feature Bypass - Curl (CVE-2026-80255) - Critical [601]
Description: A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00684, EPSS Percentile is 0.50866 |
altlinux: CVE-2026-80255 was patched at 2026-09-02, 2026-09-07
debian: CVE-2026-80255 was patched at 2026-09-16
62.
Memory Corruption - Linux Kernel (CVE-2026-74581) - High [596]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00399, EPSS Percentile is 0.33699 |
almalinux: CVE-2026-74581 was patched at 2026-08-26, 2026-09-03
debian: CVE-2026-74581 was patched at 2026-08-25
oraclelinux: CVE-2026-74581 was patched at 2026-08-26, 2026-09-04, 2026-09-07
redhat: CVE-2026-74581 was patched at 2026-08-26, 2026-08-27, 2026-09-01, 2026-09-03
63.
Memory Corruption - Linux Kernel (CVE-2026-80714) - High [596]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00404, EPSS Percentile is 0.34213 |
debian: CVE-2026-80714 was patched at 2026-09-16
oraclelinux: CVE-2026-80714 was patched at 2026-09-04
64.
Denial of Service - xmldom (CVE-2026-83613) - High [595]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.75 | 14 | JavaScript XML parser and serializer implementing W3C DOM standards. | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00344, EPSS Percentile is 0.27739 |
debian: CVE-2026-83613 was patched at 2026-09-16
65.
Denial of Service - xmldom (CVE-2026-83614) - High [595]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.75 | 14 | JavaScript XML parser and serializer implementing W3C DOM standards. | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00351, EPSS Percentile is 0.28534 |
debian: CVE-2026-83614 was patched at 2026-09-16
66.
Denial of Service - xmldom (CVE-2026-83615) - High [595]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.75 | 14 | JavaScript XML parser and serializer implementing W3C DOM standards. | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00351, EPSS Percentile is 0.28534 |
debian: CVE-2026-83615 was patched at 2026-09-16
67.
Remote Code Execution - GitPython (CVE-2026-87817) - High [595]
Description: GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:gitpython_project:gitpython (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00309, EPSS Percentile is 0.23744 |
debian: CVE-2026-87817 was patched at 2026-09-16
68.
Authentication Bypass - 389 Directory Server (CVE-2026-76560) - High [591]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:BRAINBOB:CVE-2026-76578 website | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | 389 Directory Server is a highly usable, fully featured, reliable and secure LDAP server implementation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00367, EPSS Percentile is 0.30271 |
almalinux: CVE-2026-76560 was patched at 2026-09-08
altlinux: CVE-2026-76560 was patched at 2026-09-08, 2026-09-11
debian: CVE-2026-76560 was patched at 2026-09-16
oraclelinux: CVE-2026-76560 was patched at 2026-09-08, 2026-09-10
redhat: CVE-2026-76560 was patched at 2026-09-08
69.
Information Disclosure - Chromium (CVE-2026-87629) - High [591]
Description: Incorrect authorization in Sources in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00248, EPSS Percentile is 0.16348 |
altlinux: CVE-2026-87629 was patched at 2026-09-17
debian: CVE-2026-87629 was patched at 2026-09-16
70.
Memory Corruption - OpenSSL (CVE-2026-80229) - High [591]
Description: When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.00899, EPSS Percentile is 0.57884 |
altlinux: CVE-2026-80229 was patched at 2026-09-02, 2026-09-07
debian: CVE-2026-80229 was patched at 2026-09-16
71.
Security Feature Bypass - Chromium (CVE-2026-87468) - High [591]
Description: Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00202, EPSS Percentile is 0.10297 |
altlinux: CVE-2026-87468 was patched at 2026-09-17
debian: CVE-2026-87468 was patched at 2026-09-16
72.
Security Feature Bypass - Chromium (CVE-2026-87475) - High [591]
Description: Missing authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00236, EPSS Percentile is 0.14714 |
altlinux: CVE-2026-87475 was patched at 2026-09-17
debian: CVE-2026-87475 was patched at 2026-09-16
73.
Security Feature Bypass - Chromium (CVE-2026-87493) - High [591]
Description: Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00202, EPSS Percentile is 0.10296 |
altlinux: CVE-2026-87493 was patched at 2026-09-17
debian: CVE-2026-87493 was patched at 2026-09-16
74.
Security Feature Bypass - Chromium (CVE-2026-87515) - High [591]
Description: Incorrect authorization in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00236, EPSS Percentile is 0.14714 |
altlinux: CVE-2026-87515 was patched at 2026-09-17
debian: CVE-2026-87515 was patched at 2026-09-16
75.
Security Feature Bypass - Chromium (CVE-2026-87532) - High [591]
Description: Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11341 |
altlinux: CVE-2026-87532 was patched at 2026-09-17
debian: CVE-2026-87532 was patched at 2026-09-16
76.
Security Feature Bypass - Chromium (CVE-2026-87580) - High [591]
Description: Incorrect authorization in WebAppInstalls in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00213, EPSS Percentile is 0.11815 |
altlinux: CVE-2026-87580 was patched at 2026-09-17
debian: CVE-2026-87580 was patched at 2026-09-16
77.
Security Feature Bypass - Chromium (CVE-2026-87584) - High [591]
Description: Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00213, EPSS Percentile is 0.11815 |
altlinux: CVE-2026-87584 was patched at 2026-09-17
debian: CVE-2026-87584 was patched at 2026-09-16
78.
Security Feature Bypass - Chromium (CVE-2026-87589) - High [591]
Description: Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00202, EPSS Percentile is 0.10296 |
altlinux: CVE-2026-87589 was patched at 2026-09-17
debian: CVE-2026-87589 was patched at 2026-09-16
79.
Security Feature Bypass - Curl (CVE-2026-82209) - High [589]
Description: When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`). Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`).
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0054, EPSS Percentile is 0.44098 |
altlinux: CVE-2026-82209 was patched at 2026-09-02, 2026-09-07
debian: CVE-2026-82209 was patched at 2026-09-16
80.
Security Feature Bypass - Traefik (CVE-2026-88008) - High [589]
Description: Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backend. If the backend accepts h2c and returns 101 Switching Protocols, Traefik enters a raw tunnel and no longer applies routers, BasicAuth, ForwardAuth, IPAllowList, RateLimit, access logging, metrics, or tracing to later HTTP/2 requests, allowing an unauthenticated request through an unprotected route to reach protected paths on the same backend. This issue is fixed in 2.11.57 and 3.7.13.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:BOREAS37:CVE-2026-88008-POC website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:traefik:traefik (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00341, EPSS Percentile is 0.27515 |
altlinux: CVE-2026-88008 was patched at 2026-09-15, 2026-09-16
81.
Security Feature Bypass - libevent (CVE-2026-63385) - High [589]
Description: Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | libevent is a portable event notification library that provides an asynchronous event loop and networking primitives for applications using sockets, timers, signals, DNS, and HTTP. | |
| 0.9 | 10 | CVSS Base Score is 9.2. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00403, EPSS Percentile is 0.34158 |
debian: CVE-2026-63385 was patched at 2026-08-25, 2026-09-11
ubuntu: CVE-2026-63385 was patched at 2026-09-01, 2026-09-16
82.
Security Feature Bypass - nltk (CVE-2026-78683) - High [589]
Description: NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=False, routing deserialization through WarningUnpickler, which does not override find_class() and therefore permits arbitrary class resolution. When an application loads an attacker-crafted model file, embedded pickle gadget chains execute arbitrary Python code with the privileges of the user running the application. NLTK provides a RestrictedUnpickler for safe deserialization, but it is not used by production code paths. Fixed in 3.10.0.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, Vulners:PublicExploit:GitHub:KINRYULABS:RESEARCH-POCS websites | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00292, EPSS Percentile is 0.21783 |
debian: CVE-2026-78683 was patched at 2026-08-25
83.
Security Feature Bypass - wolfSSL (CVE-2026-82208) - High [589]
Description: With the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | wolfSSL is a small, portable, embedded SSL/TLS library targeted for use by embedded systems developers | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00425, EPSS Percentile is 0.36157 |
altlinux: CVE-2026-82208 was patched at 2026-09-02, 2026-09-07
debian: CVE-2026-82208 was patched at 2026-09-16
84.
Elevation of Privilege - Polkit (CVE-2026-19816) - High [587]
Description: A flaw was found in PackageKit. PackageKit skips the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | polkit is a toolkit for defining and handling authorizations. It is used for allowing unprivileged processes to speak to privileged processes | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00143, EPSS Percentile is 0.04013 |
debian: CVE-2026-19816 was patched at 2026-09-16
85.
Authentication Bypass - Gitea (CVE-2026-55986) - High [585]
Description: Email Management API Bypasses ManageCredentials Feature Restrictions
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.98 | 15 | Authentication Bypass | |
| 0.75 | 14 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00253, EPSS Percentile is 0.16981 |
altlinux: CVE-2026-55986 was patched at 2026-08-27, 2026-08-29, 2026-09-04
redos: CVE-2026-55986 was patched at 2026-08-20
86.
Denial of Service - xmldom (CVE-2026-83606) - High [583]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.75 | 14 | JavaScript XML parser and serializer implementing W3C DOM standards. | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00301, EPSS Percentile is 0.22821 |
debian: CVE-2026-83606 was patched at 2026-09-16
87.
Denial of Service - xmldom (CVE-2026-83612) - High [583]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.75 | 14 | JavaScript XML parser and serializer implementing W3C DOM standards. | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00301, EPSS Percentile is 0.22819 |
debian: CVE-2026-83612 was patched at 2026-09-16
88.
Denial of Service - xmldom (CVE-2026-83619) - High [583]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.75 | 14 | JavaScript XML parser and serializer implementing W3C DOM standards. | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00301, EPSS Percentile is 0.22822 |
debian: CVE-2026-83619 was patched at 2026-09-16
89.
Information Disclosure - FreeRDP (CVE-2026-85089) - High [581]
Description: FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in lib
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00416, EPSS Percentile is 0.35345 |
altlinux: CVE-2026-85089 was patched at 2026-09-10, 2026-09-11
debian: CVE-2026-85089 was patched at 2026-09-16
90.
Remote Code Execution - RPM (CVE-2026-78367) - High [580]
Description: A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand()
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | RPM is a package management system and software packaging format widely used by Linux distributions in the Red Hat ecosystem and related systems, including tools for building RPM packages. | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00141, EPSS Percentile is 0.03826 |
debian: CVE-2026-78367 was patched at 2026-08-25
91.
Authentication Bypass - nltk (CVE-2026-65915) - High [579]
Description: NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to nltk.data.load() to read arbitrary files accessible to the process user, including credentials and configuration files.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00359, EPSS Percentile is 0.29439 |
debian: CVE-2026-65915 was patched at 2026-08-25
92.
Path Traversal - SQLite (CVE-2026-34968) - High [575]
Description: Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Path Traversal | |
| 0.7 | 14 | SQLite is a database engine written in the C programming language | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00331, EPSS Percentile is 0.26199 |
debian: CVE-2026-34968 was patched at 2026-09-16
93.
Arbitrary File Writing - GitPython (CVE-2026-76219) - High [574]
Description: GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0.5 | 14 | Product detected by a:gitpython_project:gitpython (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00299, EPSS Percentile is 0.22583 |
altlinux: CVE-2026-76219 was patched at 2026-09-01
debian: CVE-2026-76219 was patched at 2026-08-20
redos: CVE-2026-76219 was patched at 2026-09-01
94.
Remote Code Execution - libtiff (CVE-2026-52490) - High [569]
Description: An issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.2 | 14 | libtiff is a widely used library for reading and writing TIFF (Tagged Image File Format) files, offering tools like tiff2ps. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00403, EPSS Percentile is 0.34165 |
debian: CVE-2026-52490 was patched at 2026-09-16
95.
Information Disclosure - Chromium (CVE-2026-87482) - High [567]
Description: Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via crafted network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07532 |
altlinux: CVE-2026-87482 was patched at 2026-09-17
debian: CVE-2026-87482 was patched at 2026-09-16
96.
Security Feature Bypass - Chromium (CVE-2026-87599) - High [567]
Description: Improper input validation in Interstitials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00184, EPSS Percentile is 0.08252 |
altlinux: CVE-2026-87599 was patched at 2026-09-17
debian: CVE-2026-87599 was patched at 2026-09-16
97.
Path Traversal - nltk (CVE-2026-62384) - High [565]
Description: NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass the path validation guard and are resolved to files outside the intended corpus root when accessed via frame_by_name(), _lu_file(), or doc() methods.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00563, EPSS Percentile is 0.45339 |
debian: CVE-2026-62384 was patched at 2026-08-25
98.
Path Traversal - nltk (CVE-2026-63312) - High [565]
Description: NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00563, EPSS Percentile is 0.45339 |
debian: CVE-2026-63312 was patched at 2026-08-25
99.
Memory Corruption - FFmpeg (CVE-2026-75143) - High [563]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:PACKETSTORM:229150 website | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00405, EPSS Percentile is 0.34338 |
debian: CVE-2026-75143 was patched at 2026-08-20
ubuntu: CVE-2026-75143 was patched at 2026-09-03, 2026-09-16
100.
Server-Side Request Forgery - nltk (CVE-2026-78682) - High [560]
Description: NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, nltk.downloader.Downloader.index/download) when an HTTP proxy is configured. pathsec.urlopen validates the requested hostname locally, but proxy-handler inheritance disables the safe HTTP/HTTPS handlers so the actual fetch is performed by the proxy against a destination that is never re-validated. An attacker can supply a validated public URL that the proxy forwards to an internal loopback-only service, allowing disclosure of internal HTTP resources, loading of forged downloader indexes, and installation of attacker-chosen package content.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00253, EPSS Percentile is 0.17026 |
debian: CVE-2026-78682 was patched at 2026-08-25
101.
Remote Code Execution - GIMP (CVE-2026-78465) - High [559]
Description: A flaw was found in the file-pcx plugin in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:gitlab.gnome.org, BDU:PublicExploit websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | GIMP is an open-source image manipulation program used for photo editing, graphic design, and digital art creation. | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.14572 |
altlinux: CVE-2026-78465 was patched at 2026-09-14
debian: CVE-2026-78465 was patched at 2026-08-25
102.
Security Feature Bypass - Chromium (CVE-2026-78903) - High [555]
Description: Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:VXSSROOTT:CVE-2026-78903-SWIFT-KICK-TO-THE-CREDS website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00268, EPSS Percentile is 0.19028 |
altlinux: CVE-2026-78903 was patched at 2026-08-28
debian: CVE-2026-78903 was patched at 2026-09-03, 2026-09-16
103.
Security Feature Bypass - Chromium (CVE-2026-87575) - High [555]
Description: Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:SNEAKYNACHOS:CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-AND-CVE-2026-85046.-ESCAPE-THE-V8-CARCASS. website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.0404 |
altlinux: CVE-2026-87575 was patched at 2026-09-17
debian: CVE-2026-87575 was patched at 2026-09-16
104.
Security Feature Bypass - Chromium (CVE-2026-87577) - High [555]
Description: Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00197, EPSS Percentile is 0.09646 |
altlinux: CVE-2026-87577 was patched at 2026-09-17
debian: CVE-2026-87577 was patched at 2026-09-16
105.
Denial of Service - Nodemailer (CVE-2026-90776) - High [553]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Nodemailer is a Node.js module for sending email, supporting SMTP, message composition, attachments, and multiple transport mechanisms. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00479, EPSS Percentile is 0.40225 |
debian: CVE-2026-90776 was patched at 2026-09-16
106.
Denial of Service - gobgp (CVE-2026-41642) - High [553]
Description: GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a remote Denial of Service (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:osrg:gobgp (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00503, EPSS Percentile is 0.41788 |
redos: CVE-2026-41642 was patched at 2026-09-07
107.
Denial of Service - libevent (CVE-2026-63383) - High [553]
Description: Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | libevent is a portable event notification library that provides an asynchronous event loop and networking primitives for applications using sockets, timers, signals, DNS, and HTTP. | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00384, EPSS Percentile is 0.32108 |
debian: CVE-2026-63383 was patched at 2026-08-25, 2026-09-11
ubuntu: CVE-2026-63383 was patched at 2026-09-01, 2026-09-16
108.
Denial of Service - libevent (CVE-2026-63384) - High [553]
Description: Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | libevent is a portable event notification library that provides an asynchronous event loop and networking primitives for applications using sockets, timers, signals, DNS, and HTTP. | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00384, EPSS Percentile is 0.32108 |
debian: CVE-2026-63384 was patched at 2026-08-25, 2026-09-11
ubuntu: CVE-2026-63384 was patched at 2026-09-01, 2026-09-16
109.
Denial of Service - nltk (CVE-2026-80205) - High [553]
Description: NLTK versions before 3.10.0 contain a regular expression
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00489, EPSS Percentile is 0.40922 |
debian: CVE-2026-80205 was patched at 2026-09-16
110.
Memory Corruption - Curl (CVE-2026-18924) - High [553]
Description: A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.00897, EPSS Percentile is 0.57822 |
altlinux: CVE-2026-18924 was patched at 2026-09-02, 2026-09-07
debian: CVE-2026-18924 was patched at 2026-09-16
111.
Path Traversal - GitPython (CVE-2026-78677) - High [553]
Description: GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Product detected by a:gitpython_project:gitpython (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0043, EPSS Percentile is 0.3655 |
altlinux: CVE-2026-78677 was patched at 2026-09-01
debian: CVE-2026-78677 was patched at 2026-08-25
redos: CVE-2026-78677 was patched at 2026-09-08
112.
Path Traversal - nltk (CVE-2026-62388) - High [553]
Description: NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00457, EPSS Percentile is 0.38743 |
debian: CVE-2026-62388 was patched at 2026-08-25
113.
Arbitrary File Reading - GitPython (CVE-2026-76217) - High [552]
Description: GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0.5 | 14 | Product detected by a:gitpython_project:gitpython (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0036, EPSS Percentile is 0.29581 |
altlinux: CVE-2026-76217 was patched at 2026-09-01
debian: CVE-2026-76217 was patched at 2026-08-20
redos: CVE-2026-76217 was patched at 2026-09-01
114.
Memory Corruption - Linux Kernel (CVE-2026-81000) - High [548]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:0XBLACKASH:CVE-2026-81000, BDU:PublicExploit websites | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.05991 |
debian: CVE-2026-81000 was patched at 2026-09-16
115.
Server-Side Request Forgery - Nodemailer (CVE-2026-82659) - High [548]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.5 | 14 | Nodemailer is a Node.js module for sending email, supporting SMTP, message composition, attachments, and multiple transport mechanisms. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00254, EPSS Percentile is 0.17073 |
debian: CVE-2026-82659 was patched at 2026-09-16
116.
Denial of Service - Redis (CVE-2026-68553) - High [546]
Description: Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can place printf-style format specifiers in the STUN USERNAME or REALM attribute, which passes is_secure_string() validation and is embedded into Redis keys at nine call sites in src/apps/relay/ns_ioalib_engine_impl.c. send_message_to_
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Redis is an open-source in-memory storage, used as a distributed, in-memory key–value database, cache and message broker, with optional durability | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00345, EPSS Percentile is 0.27892 |
debian: CVE-2026-68553 was patched at 2026-08-25
117.
Information Disclosure - Chromium (CVE-2026-87497) - High [543]
Description: Uninitialized resource in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00204, EPSS Percentile is 0.10648 |
altlinux: CVE-2026-87497 was patched at 2026-09-17
debian: CVE-2026-87497 was patched at 2026-09-16
118.
Information Disclosure - Mozilla Firefox (CVE-2026-84127) - High [543]
Description: Information disclosure in the WebExtensions component in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:bugzilla.mozilla.org website | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.05 |
altlinux: CVE-2026-84127 was patched at 2026-09-01, 2026-09-05
119.
Arbitrary File Reading - GitPython (CVE-2026-78678) - High [541]
Description: GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0.5 | 14 | Product detected by a:gitpython_project:gitpython (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0024, EPSS Percentile is 0.15293 |
altlinux: CVE-2026-78678 was patched at 2026-09-01
debian: CVE-2026-78678 was patched at 2026-08-25
redos: CVE-2026-78678 was patched at 2026-09-08
120.
Arbitrary File Reading - nltk (CVE-2026-79674) - High [541]
Description: NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attackers to read files outside the intended data root. Attackers can supply arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCorpusReader constructors to access filesystem content and SQLite databases outside the pathsec sandbox boundary.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00226, EPSS Percentile is 0.13406 |
debian: CVE-2026-79674 was patched at 2026-09-16
121.
Denial of Service - Kamailio (CVE-2026-52022) - High [541]
Description: An issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Kamailio is an open-source SIP server used for building scalable VoIP, instant messaging, and real-time communications systems. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00331, EPSS Percentile is 0.26258 |
debian: CVE-2026-52022 was patched at 2026-09-11, 2026-09-16
122.
Denial of Service - Kamailio (CVE-2026-52023) - High [541]
Description: An issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Kamailio is an open-source SIP server used for building scalable VoIP, instant messaging, and real-time communications systems. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00331, EPSS Percentile is 0.26258 |
debian: CVE-2026-52023 was patched at 2026-09-11, 2026-09-16
123.
Denial of Service - nltk (CVE-2026-66393) - High [541]
Description: NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00363, EPSS Percentile is 0.29931 |
debian: CVE-2026-66393 was patched at 2026-08-25
124.
Denial of Service - nltk (CVE-2026-81722) - High [541]
Description: nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00363, EPSS Percentile is 0.29931 |
debian: CVE-2026-81722 was patched at 2026-09-16
125.
Information Disclosure - OpenEXR (CVE-2026-59982) - High [541]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | OpenEXR is an open source high-dynamic-range image file format and reference implementation widely used in computer graphics, visual effects, animation, and motion picture production. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00314, EPSS Percentile is 0.24332 |
debian: CVE-2026-59982 was patched at 2026-09-16
126.
Path Traversal - GitPython (CVE-2026-76222) - High [541]
Description: GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule names that GitPython processes during submodule initialization, creating attacker-controlled Git repositories at escaped filesystem locations.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Product detected by a:gitpython_project:gitpython (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00333, EPSS Percentile is 0.2657 |
altlinux: CVE-2026-76222 was patched at 2026-09-01
debian: CVE-2026-76222 was patched at 2026-08-20
redos: CVE-2026-76222 was patched at 2026-09-01
127.
Path Traversal - nltk (CVE-2026-62385) - High [541]
Description: NLTK versions before 3.10.0 contain a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00367, EPSS Percentile is 0.30334 |
debian: CVE-2026-62385 was patched at 2026-08-25
128.
Path Traversal - Incus (CVE-2026-48753) - High [539]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Path Traversal | |
| 0.2 | 14 | Incus is an open source system container and virtual machine manager used to create, manage, and operate Linux containers and virtual machines. | |
| 1.0 | 10 | CVSS Base Score is 9.9. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00709, EPSS Percentile is 0.51801 |
redos: CVE-2026-48753 was patched at 2026-08-24
129.
Arbitrary File Writing - nltk (CVE-2026-81727) - High [538]
Description: NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00135, EPSS Percentile is 0.03347 |
debian: CVE-2026-81727 was patched at 2026-09-16
130.
Memory Corruption - Linux Kernel (CVE-2026-80521) - High [536]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:RIFKYARDS:CONTAINER_ESCAPE-CVE-2026-80521-CVE-2026-52910, BDU:PublicExploit websites | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02119 |
debian: CVE-2026-80521 was patched at 2026-09-16
131.
Remote Code Execution - WordPress (CVE-2026-65640) - High [530]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | WordPress is a widely-used open source content management system (CMS) for building websites and blogs. It provides a plugin and theme architecture and is written in PHP, typically paired with MySQL/MariaDB for storage. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.8 | 10 | EPSS Probability is 0.01947, EPSS Percentile is 0.79175 |
debian: CVE-2026-65640 was patched at 2026-08-20
132.
Arbitrary File Reading - GitPython (CVE-2026-78675) - High [529]
Description: GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0.5 | 14 | Product detected by a:gitpython_project:gitpython (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00119, EPSS Percentile is 0.02033 |
altlinux: CVE-2026-78675 was patched at 2026-09-01
debian: CVE-2026-78675 was patched at 2026-08-25
redos: CVE-2026-78675 was patched at 2026-09-08
133.
Arbitrary File Reading - GitPython (CVE-2026-87818) - High [529]
Description: GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0.5 | 14 | Product detected by a:gitpython_project:gitpython (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00228, EPSS Percentile is 0.13643 |
debian: CVE-2026-87818 was patched at 2026-09-16
134.
Denial of Service - GitPython (CVE-2026-87819) - High [529]
Description: GitPython before 3.1.60 contains a regular expression
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:gitpython_project:gitpython (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00279, EPSS Percentile is 0.20426 |
debian: CVE-2026-87819 was patched at 2026-09-16
135.
Denial of Service - nltk (CVE-2026-78681) - High [529]
Description: NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in document DTDs. Attackers can craft XML payloads with nested entity declarations that expand from hundreds of bytes to megabytes in memory, causing
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00294, EPSS Percentile is 0.22078 |
debian: CVE-2026-78681 was patched at 2026-08-25
136.
Memory Corruption - Libraw (CVE-2026-20911) - High [529]
Description: A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:www.talosintelligence.com website | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:libraw:libraw (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00629, EPSS Percentile is 0.48507 |
altlinux: CVE-2026-20911 was patched at 2026-08-21, 2026-08-26
137.
Server-Side Request Forgery - nltk (CVE-2026-63311) - High [524]
Description: NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the validate_network_url() function in nltk/pathsec.py. The _resolve_hostname() helper catches OSError and ValueError during socket.getaddrinfo() and returns an empty list; when DNS resolution fails, the validation loop executes no IP checks and the function fails open, allowing urlopen() to proceed without validation. An attacker who can trigger DNS resolution failures or use DNS rebinding can bypass SSRF protections and reach restricted network resources, including cloud metadata endpoints (e.g., 169.254.169.254).
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00241, EPSS Percentile is 0.1542 |
debian: CVE-2026-63311 was patched at 2026-08-25
138.
Cross Site Scripting - CommonMark (CVE-2026-86431) - High [523]
Description: league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability in the AttributesExtension. Prefixing an attribute name with a single U+000C form feed byte (e.g. {\x0Conclick="alert(1)"}) bypasses the AttributesHelper::filterAttributes() 'on*' event-handler filter because PHP's trim() does not strip U+000C, causing the attribute to be written verbatim into the output where browsers parse it as a genuine event handler. The same prefix also defeats the allow_unsafe_links check, allowing javascript: URIs through href/src attributes even when allow_unsafe_links is false. Exploitation requires processing untrusted Markdown with the AttributesExtension enabled; the injected script executes when the rendered HTML is viewed. Fixed in 2.9.1.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Product detected by a:thephpleague:commonmark (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00224, EPSS Percentile is 0.13148 |
debian: CVE-2026-86431 was patched at 2026-09-16
139.
Arbitrary File Reading - nltk (CVE-2026-62383) - High [517]
Description: nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00185, EPSS Percentile is 0.08329 |
debian: CVE-2026-62383 was patched at 2026-08-25
140.
Arbitrary File Reading - nltk (CVE-2026-70626) - High [517]
Description: NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 6.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.1067 |
debian: CVE-2026-70626 was patched at 2026-08-25
141.
Denial of Service - helm (CVE-2026-63308) - High [517]
Description: Helm through 4.2.3, fixed in commit ba6c9a2, contains a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:helm:helm (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00275, EPSS Percentile is 0.19964 |
altlinux: CVE-2026-63308 was patched at 2026-09-11
redos: CVE-2026-63308 was patched at 2026-09-08
142.
Information Disclosure - tesseract_ocr (CVE-2026-88048) - High [517]
Description: Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ against the weight-matrix dimensions. During FullyConnected::Forward, MatrixDotVector in src/lstm/weightmatrix.cpp writes w.dim1() results into temp_line, which is sized from no_, and reads w.dim2() minus one inputs from curr_input, which is sized from ni_. A crafted .traineddata NT_SOFTMAX layer can therefore use inconsistent dimensions to cause a heap out-of-bounds write and read on the default LSTM engine, resulting in heap corruption, a crash,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Product detected by a:tesseract-ocr:tesseract_ocr (does NOT exist in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00114, EPSS Percentile is 0.0171 |
debian: CVE-2026-88048 was patched at 2026-09-16
143.
Path Traversal - nltk (CVE-2026-81726) - High [517]
Description: NLTK through 3.10.3 contains a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0026, EPSS Percentile is 0.17863 |
debian: CVE-2026-81726 was patched at 2026-09-16
144.
Denial of Service - Net-SNMP (CVE-2026-89147) - High [513]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | Net-SNMP is a suite of applications and libraries implementing the Simple Network Management Protocol (SNMP), used for monitoring and managing networked systems and devices. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00276, EPSS Percentile is 0.2009 |
debian: CVE-2026-89147 was patched at 2026-09-16
145.
Cross Site Scripting - authelia (CVE-2026-33525) - High [511]
Description: Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In version 4.39.15, an attacker may potentially be able to inject javascript into the Authelia login page if several conditions are met simultaneously. Unless both the `script-src` and `connect-src` directives have been modified it's almost impossible for this to have a meaningful impact. However if both of these are and they are done so without consideration to their potential impact; there is a are situations where this vulnerability could be exploited. This is caused to the lack of neutralization of the `langauge` cookie value when rendering the HTML template. This vulnerability is likely difficult to discover though fingerprinting due to the way Authelia is designed but it should not be considered impossible. The additional requirement to identify the secondary application is however likely to be significantly harder to identify along side this, but also likely easier to fingerprint. Users should upgrade to 4.39.16 or downgrade to 4.39.14 to mitigate the issue. The overwhelming majority of installations will not be affected and no workarounds are necessary. The default value for the Content Security Policy makes exploiting this weakness completely impossible. It's only possible via the deliberate removal of the Content Security Policy or deliberate inclusion of clearly noted unsafe policies.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Product detected by a:authelia:authelia (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00226, EPSS Percentile is 0.13413 |
altlinux: CVE-2026-33525 was patched at 2026-08-30
146.
Memory Corruption - FreeRDP (CVE-2026-63652) - High [510]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00342, EPSS Percentile is 0.27562 |
almalinux: CVE-2026-63652 was patched at 2026-08-31
debian: CVE-2026-63652 was patched at 2026-08-25
oraclelinux: CVE-2026-63652 was patched at 2026-09-01
redos: CVE-2026-63652 was patched at 2026-09-07
147.
Command Injection - PHP (CVE-2026-76060) - High [508]
Description: An authenticated OS
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.8 | 10 | EPSS Probability is 0.02315, EPSS Percentile is 0.82559 |
debian: CVE-2026-76060 was patched at 2026-09-16
148.
Denial of Service - Chromium (CVE-2026-87486) - High [508]
Description: Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to spoof address bar via a co-installed app. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02405 |
altlinux: CVE-2026-87486 was patched at 2026-09-17
debian: CVE-2026-87486 was patched at 2026-09-16
149.
Denial of Service - gitoxide (CVE-2026-82254) - High [508]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.3 | 14 | gitoxide is an idiomatic, lean, fast & safe pure Rust implementation of Git, designed for correctness and performance, available both as a Rust library (gix crate) and command-line interface tools. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00351, EPSS Percentile is 0.28521 |
debian: CVE-2026-82254 was patched at 2026-09-16
150.
Cross Site Scripting - Horde IMP (CVE-2026-65053) - High [507]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:PACKETSTORM:229825 website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.4 | 14 | IMP is the Internet Messaging Program. It is written in PHP and provides webmail access to IMAP and POP3 accounts. It uses the best-of-class Horde/Imap_Client library to provide fast, robust connections to the remote IMAP/POP3 server. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00246, EPSS Percentile is 0.16097 |
debian: CVE-2026-65053 was patched at 2026-09-16
151.
Denial of Service - libevent (CVE-2026-63388) - High [505]
Description: Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | libevent is a portable event notification library that provides an asynchronous event loop and networking primitives for applications using sockets, timers, signals, DNS, and HTTP. | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.03852 |
debian: CVE-2026-63388 was patched at 2026-08-25, 2026-09-11
152.
Denial of Service - nltk (CVE-2026-80206) - High [505]
Description: NLTK before 3.10.3 contains a regular expression
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00264, EPSS Percentile is 0.18453 |
debian: CVE-2026-80206 was patched at 2026-09-16
153.
Denial of Service - openCryptoki (CVE-2026-22791) - High [505]
Description: openCryptoki is a PKCS#11 library and tools for Linux and AIX. In 3.25.0 and 3.26.0, there is a heap buffer overflow vulnerability in the CKM_ECDH_AES_KEY_WRAP implementation allows an attacker with local access to cause out-of-bounds writes in the host process by supplying a compressed EC public key and invoking C_WrapKey. This can lead to heap corruption, or
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:opencryptoki_project:opencryptoki (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00278, EPSS Percentile is 0.20309 |
ubuntu: CVE-2026-22791 was patched at 2026-08-31, 2026-09-16
154.
Denial of Service - tesseract_ocr (CVE-2026-88047) - High [505]
Description: Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>>(char*) to extract a whitespace-delimited token into a fixed 61-byte stack buffer without setting a stream width. The 100-byte line buffer can carry a token of up to 99 characters, so a token longer than 60 characters writes up to 39 attacker-controlled bytes past the buffer during TessBaseAPI::Init of the legacy engine, causing stack corruption,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:tesseract-ocr:tesseract_ocr (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00115, EPSS Percentile is 0.01783 |
debian: CVE-2026-88047 was patched at 2026-09-16
155.
Memory Corruption - libevent (CVE-2026-63387) - High [505]
Description: Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | libevent is a portable event notification library that provides an asynchronous event loop and networking primitives for applications using sockets, timers, signals, DNS, and HTTP. | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00416, EPSS Percentile is 0.3531 |
debian: CVE-2026-63387 was patched at 2026-08-25, 2026-09-11
156.
Path Traversal - nltk (CVE-2026-79676) - High [505]
Description: NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths using built-in open() instead of nltk.pathsec.open(), allowing symlinks to escape trusted roots. Attackers who stage symlinked corpus files under a trusted data root can disclose outside-root content through normal corpus reader methods like channels(), domains(), and synonyms().
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00307, EPSS Percentile is 0.23445 |
debian: CVE-2026-79676 was patched at 2026-09-16
157.
Remote Code Execution - Gitea (CVE-2026-56158) - High [505]
Description: This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:SAM00:CVE-2026-56158-.NET-FRAMEWORK-RCE-POC-EXPLOIT website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.75 | 14 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-56158 was patched at 2026-08-31, 2026-09-02
158.
Remote Code Execution - OpenSSL (CVE-2026-63073) - High [502]
Description: Issue summary:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.00929, EPSS Percentile is 0.58832 |
almalinux: CVE-2026-63073 was patched at 2026-09-14
altlinux: CVE-2026-63073 was patched at 2026-08-26
debian: CVE-2026-63073 was patched at 2026-08-25, 2026-09-16
oraclelinux: CVE-2026-63073 was patched at 2026-09-14
redhat: CVE-2026-63073 was patched at 2026-09-14
ubuntu: CVE-2026-63073 was patched at 2026-08-25, 2026-09-16
159.
Denial of Service - zstd-jni (CVE-2026-87824) - High [500]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.25 | 14 | zstd-jni provides Java Native Interface bindings for the Zstandard lossless compression library, enabling high-performance compression and decompression from Java, Android, and other JVM languages. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00389, EPSS Percentile is 0.32627 |
debian: CVE-2026-87824 was patched at 2026-09-16
160.
Memory Corruption - Mozilla Firefox (CVE-2026-84118) - High [496]
Description: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:SNEAKYNACHOS:CVE-2026-84118-WHO-LABELED-THE-CRIT-AS-A-HIGH website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00204, EPSS Percentile is 0.10558 |
altlinux: CVE-2026-84118 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
161.
Denial of Service - OpenEXR (CVE-2026-59983) - High [494]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | OpenEXR is an open source high-dynamic-range image file format and reference implementation widely used in computer graphics, visual effects, animation, and motion picture production. | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07824 |
debian: CVE-2026-59983 was patched at 2026-09-16
162.
Denial of Service - OpenEXR (CVE-2026-59984) - High [494]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | OpenEXR is an open source high-dynamic-range image file format and reference implementation widely used in computer graphics, visual effects, animation, and motion picture production. | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07824 |
debian: CVE-2026-59984 was patched at 2026-09-16
163.
Denial of Service - OpenEXR (CVE-2026-59985) - High [494]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | OpenEXR is an open source high-dynamic-range image file format and reference implementation widely used in computer graphics, visual effects, animation, and motion picture production. | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07824 |
debian: CVE-2026-59985 was patched at 2026-09-16
164.
Denial of Service - Pypdf (CVE-2026-84309) - High [494]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | PyPDF is a Python library for reading, manipulating, and writing PDF files, including extraction, splitting, merging, and encryption features. | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00127, EPSS Percentile is 0.02693 |
debian: CVE-2026-84309 was patched at 2026-09-16
165.
Denial of Service - nltk (CVE-2026-81724) - High [494]
Description: NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00267, EPSS Percentile is 0.18911 |
debian: CVE-2026-81724 was patched at 2026-09-16
166.
Denial of Service - tesseract_ocr (CVE-2026-88054) - High [494]
Description: Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rejects excessively large network stacks but accepts a zero-length stack for NT_SERIES, NT_PARALLEL, or NT_REVERSED layers in a crafted .traineddata model. During LSTMRecognizer initialization in src/lstm/lstmrecognizer.cpp, CacheXScaleFactor(XScaleFactor()) reaches Series::CacheXScaleFactor in src/lstm/series.cpp, which dereferences stack_[0] on the empty vector and invokes a virtual method through an invalid Network pointer. This causes a deterministic crash and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:tesseract-ocr:tesseract_ocr (does NOT exist in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00175, EPSS Percentile is 0.07249 |
debian: CVE-2026-88054 was patched at 2026-09-16
167.
Path Traversal - onnx (CVE-2026-49114) - High [494]
Description: In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check. A local attacker with write access to the directory where a victim serializes external data can deterministically pre-plant a symlink that is being followed, causing the victim's write to append to any file the victim can write, e.g. ~/.ssh/authorized_keys, cron files, or application configs. Fixed in 1.21.0.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Product detected by a:linuxfoundation:onnx (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00107, EPSS Percentile is 0.01297 |
debian: CVE-2026-49114 was patched at 2026-08-25
168.
Information Disclosure - GIMP (CVE-2026-80101) - High [493]
Description: A flaw was found in the file-xwd plugin in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | GIMP is an open-source image manipulation program used for photo editing, graphic design, and digital art creation. | |
| 0.4 | 10 | CVSS Base Score is 4.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.1402 |
debian: CVE-2026-80101 was patched at 2026-09-16
169.
Remote Code Execution - Chromium (CVE-2026-78985) - High [490]
Description: Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00594, EPSS Percentile is 0.46822 |
altlinux: CVE-2026-78985 was patched at 2026-08-28
debian: CVE-2026-78985 was patched at 2026-09-03, 2026-09-16
170.
Remote Code Execution - Chromium (CVE-2026-87464) - High [490]
Description: Use after free in WebGL in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00586, EPSS Percentile is 0.46471 |
altlinux: CVE-2026-87464 was patched at 2026-09-17
debian: CVE-2026-87464 was patched at 2026-09-16
171.
Remote Code Execution - OpenSSL (CVE-2026-18798) - High [490]
Description: Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.7 | 10 | EPSS Probability is 0.01481, EPSS Percentile is 0.72634 |
almalinux: CVE-2026-18798 was patched at 2026-09-14
debian: CVE-2026-18798 was patched at 2026-08-25, 2026-09-16
oraclelinux: CVE-2026-18798 was patched at 2026-09-14
redhat: CVE-2026-18798 was patched at 2026-09-14
ubuntu: CVE-2026-18798 was patched at 2026-08-25, 2026-09-16
172.
Remote Code Execution - OpenSSL (CVE-2026-63076) - High [490]
Description: Issue summary:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.7 | 10 | EPSS Probability is 0.0135, EPSS Percentile is 0.70081 |
almalinux: CVE-2026-63076 was patched at 2026-09-14
altlinux: CVE-2026-63076 was patched at 2026-08-26
debian: CVE-2026-63076 was patched at 2026-08-25, 2026-09-16
oraclelinux: CVE-2026-63076 was patched at 2026-09-14
redhat: CVE-2026-63076 was patched at 2026-09-14
ubuntu: CVE-2026-63076 was patched at 2026-08-25, 2026-09-16
173.
Spoofing - Chromium (CVE-2026-87445) - High [490]
Description: UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00261, EPSS Percentile is 0.17986 |
altlinux: CVE-2026-87445 was patched at 2026-09-17
debian: CVE-2026-87445 was patched at 2026-09-16
174.
Denial of Service - Python (CVE-2026-84305) - High [486]
Description: sqlparse is a non-validating SQL parser module for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02577 |
debian: CVE-2026-84305 was patched at 2026-09-16
175.
Memory Corruption - Binutils (CVE-2026-90829) - High [484]
Description: A weakness has been identified in GNU
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:sourceware.org website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04712 |
debian: CVE-2026-90829 was patched at 2026-09-16
176.
Memory Corruption - Chromium (CVE-2026-87586) - High [484]
Description: Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00187, EPSS Percentile is 0.08585 |
altlinux: CVE-2026-87586 was patched at 2026-09-17
debian: CVE-2026-87586 was patched at 2026-09-16
177.
Memory Corruption - Chromium (CVE-2026-87596) - High [484]
Description: Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00187, EPSS Percentile is 0.08585 |
altlinux: CVE-2026-87596 was patched at 2026-09-17
debian: CVE-2026-87596 was patched at 2026-09-16
178.
Information Disclosure - libtpms (CVE-2026-85769) - High [482]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:ISUKASANUJ:CVE-2026-85769 website | |
| 0.83 | 15 | Information Disclosure | |
| 0.08 | 14 | libtpms is a software library implementing a TPM 1.2 and TPM 2.0 emulator, commonly used by virtualization and software TPM components such as swtpm. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00384, EPSS Percentile is 0.32064 |
debian: CVE-2026-85769 was patched at 2026-09-16
179.
Denial of Service - kin-openapi (CVE-2026-77354) - High [478]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.12 | 14 | kin-openapi is a Go library for parsing, converting, validating, and working with OpenAPI and Swagger specifications and for validating HTTP requests and responses against OpenAPI schemas. | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00302, EPSS Percentile is 0.22866 |
debian: CVE-2026-77354 was patched at 2026-08-25
180.
Remote Code Execution - Chromium (CVE-2026-78900) - High [478]
Description: Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00435, EPSS Percentile is 0.37055 |
altlinux: CVE-2026-78900 was patched at 2026-08-28
debian: CVE-2026-78900 was patched at 2026-09-03, 2026-09-16
181.
Remote Code Execution - Chromium (CVE-2026-78909) - High [478]
Description: Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00435, EPSS Percentile is 0.37056 |
altlinux: CVE-2026-78909 was patched at 2026-08-28
debian: CVE-2026-78909 was patched at 2026-09-03, 2026-09-16
182.
Remote Code Execution - Chromium (CVE-2026-78935) - High [478]
Description: Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00509, EPSS Percentile is 0.42194 |
altlinux: CVE-2026-78935 was patched at 2026-08-28
debian: CVE-2026-78935 was patched at 2026-09-03, 2026-09-16
183.
Remote Code Execution - Chromium (CVE-2026-78948) - High [478]
Description: Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00487, EPSS Percentile is 0.40788 |
altlinux: CVE-2026-78948 was patched at 2026-08-28
debian: CVE-2026-78948 was patched at 2026-09-03, 2026-09-16
184.
Remote Code Execution - Chromium (CVE-2026-78950) - High [478]
Description: Integer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.0056, EPSS Percentile is 0.45137 |
altlinux: CVE-2026-78950 was patched at 2026-08-28
debian: CVE-2026-78950 was patched at 2026-09-03, 2026-09-16
185.
Remote Code Execution - Chromium (CVE-2026-78951) - High [478]
Description: Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00494, EPSS Percentile is 0.41217 |
altlinux: CVE-2026-78951 was patched at 2026-08-28
debian: CVE-2026-78951 was patched at 2026-09-03, 2026-09-16
186.
Remote Code Execution - Chromium (CVE-2026-78964) - High [478]
Description: Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00494, EPSS Percentile is 0.41217 |
altlinux: CVE-2026-78964 was patched at 2026-08-28
debian: CVE-2026-78964 was patched at 2026-09-03, 2026-09-16
187.
Remote Code Execution - Chromium (CVE-2026-78989) - High [478]
Description: Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00545, EPSS Percentile is 0.4435 |
altlinux: CVE-2026-78989 was patched at 2026-08-28
debian: CVE-2026-78989 was patched at 2026-09-03, 2026-09-16
188.
Remote Code Execution - Chromium (CVE-2026-79012) - High [478]
Description: Use after free in Safebrowsing in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00545, EPSS Percentile is 0.44351 |
altlinux: CVE-2026-79012 was patched at 2026-08-28
debian: CVE-2026-79012 was patched at 2026-09-03, 2026-09-16
189.
Remote Code Execution - Chromium (CVE-2026-79019) - High [478]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00466, EPSS Percentile is 0.39334 |
altlinux: CVE-2026-79019 was patched at 2026-08-28
debian: CVE-2026-79019 was patched at 2026-09-03, 2026-09-16
190.
Remote Code Execution - Chromium (CVE-2026-79026) - High [478]
Description: Use after free in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00431, EPSS Percentile is 0.36618 |
altlinux: CVE-2026-79026 was patched at 2026-08-28
debian: CVE-2026-79026 was patched at 2026-09-03, 2026-09-16
191.
Remote Code Execution - Chromium (CVE-2026-79043) - High [478]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00435, EPSS Percentile is 0.37055 |
altlinux: CVE-2026-79043 was patched at 2026-08-28
debian: CVE-2026-79043 was patched at 2026-09-03, 2026-09-16
192.
Remote Code Execution - Chromium (CVE-2026-79047) - High [478]
Description: Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00435, EPSS Percentile is 0.37055 |
altlinux: CVE-2026-79047 was patched at 2026-08-28
debian: CVE-2026-79047 was patched at 2026-09-03, 2026-09-16
193.
Remote Code Execution - Chromium (CVE-2026-79052) - High [478]
Description: Use after free in Aura in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00436, EPSS Percentile is 0.37104 |
altlinux: CVE-2026-79052 was patched at 2026-08-28
debian: CVE-2026-79052 was patched at 2026-09-03, 2026-09-16
194.
Remote Code Execution - Chromium (CVE-2026-79130) - High [478]
Description: Buffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00417, EPSS Percentile is 0.35448 |
altlinux: CVE-2026-79130 was patched at 2026-08-28
debian: CVE-2026-79130 was patched at 2026-09-03, 2026-09-16
195.
Remote Code Execution - Chromium (CVE-2026-79131) - High [478]
Description: Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00466, EPSS Percentile is 0.39335 |
altlinux: CVE-2026-79131 was patched at 2026-08-28
debian: CVE-2026-79131 was patched at 2026-09-03, 2026-09-16
196.
Remote Code Execution - Chromium (CVE-2026-79140) - High [478]
Description: Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00466, EPSS Percentile is 0.39334 |
altlinux: CVE-2026-79140 was patched at 2026-08-28
debian: CVE-2026-79140 was patched at 2026-09-03, 2026-09-16
197.
Remote Code Execution - Chromium (CVE-2026-79149) - High [478]
Description: Use after free in ANGLE in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00466, EPSS Percentile is 0.39336 |
altlinux: CVE-2026-79149 was patched at 2026-08-28
debian: CVE-2026-79149 was patched at 2026-09-03, 2026-09-16
198.
Remote Code Execution - Chromium (CVE-2026-79150) - High [478]
Description: Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00467, EPSS Percentile is 0.39384 |
altlinux: CVE-2026-79150 was patched at 2026-08-28
debian: CVE-2026-79150 was patched at 2026-09-03, 2026-09-16
199.
Remote Code Execution - Chromium (CVE-2026-79188) - High [478]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00466, EPSS Percentile is 0.39335 |
altlinux: CVE-2026-79188 was patched at 2026-08-28
debian: CVE-2026-79188 was patched at 2026-09-03, 2026-09-16
200.
Remote Code Execution - Chromium (CVE-2026-79275) - High [478]
Description: Use after free in ANGLE in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00466, EPSS Percentile is 0.39335 |
altlinux: CVE-2026-79275 was patched at 2026-08-28
debian: CVE-2026-79275 was patched at 2026-09-03, 2026-09-16
201.
Remote Code Execution - Chromium (CVE-2026-87438) - High [478]
Description: Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00552, EPSS Percentile is 0.44763 |
altlinux: CVE-2026-87438 was patched at 2026-09-17
debian: CVE-2026-87438 was patched at 2026-09-16
202.
Remote Code Execution - Chromium (CVE-2026-87448) - High [478]
Description: Use after free in DevTools in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00494, EPSS Percentile is 0.41217 |
altlinux: CVE-2026-87448 was patched at 2026-09-17
debian: CVE-2026-87448 was patched at 2026-09-16
203.
Remote Code Execution - Chromium (CVE-2026-87455) - High [478]
Description: Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00423, EPSS Percentile is 0.35994 |
altlinux: CVE-2026-87455 was patched at 2026-09-17
debian: CVE-2026-87455 was patched at 2026-09-16
204.
Remote Code Execution - Chromium (CVE-2026-87474) - High [478]
Description: Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00494, EPSS Percentile is 0.41218 |
altlinux: CVE-2026-87474 was patched at 2026-09-17
debian: CVE-2026-87474 was patched at 2026-09-16
205.
Remote Code Execution - Chromium (CVE-2026-87488) - High [478]
Description: Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00494, EPSS Percentile is 0.4124 |
altlinux: CVE-2026-87488 was patched at 2026-09-17
debian: CVE-2026-87488 was patched at 2026-09-16
206.
Remote Code Execution - Chromium (CVE-2026-87512) - High [478]
Description: Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00494, EPSS Percentile is 0.41217 |
altlinux: CVE-2026-87512 was patched at 2026-09-17
debian: CVE-2026-87512 was patched at 2026-09-16
207.
Remote Code Execution - Chromium (CVE-2026-87527) - High [478]
Description: Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00474, EPSS Percentile is 0.39894 |
altlinux: CVE-2026-87527 was patched at 2026-09-17
debian: CVE-2026-87527 was patched at 2026-09-16
208.
Remote Code Execution - Chromium (CVE-2026-87529) - High [478]
Description: Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00461, EPSS Percentile is 0.39001 |
altlinux: CVE-2026-87529 was patched at 2026-09-17
debian: CVE-2026-87529 was patched at 2026-09-16
209.
Remote Code Execution - Chromium (CVE-2026-87547) - High [478]
Description: Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0043, EPSS Percentile is 0.36603 |
altlinux: CVE-2026-87547 was patched at 2026-09-17
debian: CVE-2026-87547 was patched at 2026-09-16
210.
Remote Code Execution - Chromium (CVE-2026-87581) - High [478]
Description: Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00423, EPSS Percentile is 0.35994 |
altlinux: CVE-2026-87581 was patched at 2026-09-17
debian: CVE-2026-87581 was patched at 2026-09-16
211.
Remote Code Execution - Chromium (CVE-2026-87607) - High [478]
Description: Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00423, EPSS Percentile is 0.35994 |
altlinux: CVE-2026-87607 was patched at 2026-09-17
debian: CVE-2026-87607 was patched at 2026-09-16
212.
Remote Code Execution - OpenSSL (CVE-2026-14457) - High [478]
Description: Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted "signature_algorithms_cert" TLS extension. Impact summary: The impact is limited to a possible Denial of Service as a result of an application abort, no data disclosure or
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.00984, EPSS Percentile is 0.60586 |
almalinux: CVE-2026-14457 was patched at 2026-09-14
altlinux: CVE-2026-14457 was patched at 2026-08-26
debian: CVE-2026-14457 was patched at 2026-08-25, 2026-09-16
oraclelinux: CVE-2026-14457 was patched at 2026-09-14
redhat: CVE-2026-14457 was patched at 2026-09-14
ubuntu: CVE-2026-14457 was patched at 2026-08-25, 2026-09-16
213.
Spoofing - Chromium (CVE-2026-87484) - High [478]
Description: UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00215, EPSS Percentile is 0.12087 |
altlinux: CVE-2026-87484 was patched at 2026-09-17
debian: CVE-2026-87484 was patched at 2026-09-16
214.
Spoofing - Chromium (CVE-2026-87496) - High [478]
Description: UI misrepresentation in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00223, EPSS Percentile is 0.13058 |
altlinux: CVE-2026-87496 was patched at 2026-09-17
debian: CVE-2026-87496 was patched at 2026-09-16
215.
Spoofing - Chromium (CVE-2026-87501) - High [478]
Description: UI misrepresentation in Passwords in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00184, EPSS Percentile is 0.08252 |
altlinux: CVE-2026-87501 was patched at 2026-09-17
debian: CVE-2026-87501 was patched at 2026-09-16
216.
Spoofing - Chromium (CVE-2026-87540) - High [478]
Description: Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07547 |
altlinux: CVE-2026-87540 was patched at 2026-09-17
debian: CVE-2026-87540 was patched at 2026-09-16
217.
Denial of Service - GPAC (CVE-2026-50810) - High [477]
Description: A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0017, EPSS Percentile is 0.06711 |
redos: CVE-2026-50810 was patched at 2026-08-24
218.
Arbitrary File Reading - Gitea (CVE-2026-59774) - High [475]
Description: This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:MSF:AUXILIARY-GATHER-FORGEJO_ORGMODE_FILEREAD_CVE_2026_59774- website | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0.75 | 14 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-59774 was patched at 2026-08-27, 2026-08-29, 2026-09-04
219.
Incorrect Calculation - libxml2 (CVE-2026-86143) - High [475]
Description: In xmlIO in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:gitlab.gnome.org website | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.6 | 14 | libxml2 is an XML toolkit implemented in C, originally developed for the GNOME Project | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00127, EPSS Percentile is 0.0269 |
debian: CVE-2026-86143 was patched at 2026-09-16
220.
Memory Corruption - FreeRDP (CVE-2026-85090) - High [475]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00314, EPSS Percentile is 0.24325 |
altlinux: CVE-2026-85090 was patched at 2026-09-10, 2026-09-11
debian: CVE-2026-85090 was patched at 2026-09-16
221.
Denial of Service - Fast DDS (CVE-2026-22591) - High [471]
Description: eprosima
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.15 | 14 | eProsima Fast DDS is a C++ implementation of the OMG Data Distribution Service (DDS) and RTPS protocols, providing high-performance publish-subscribe middleware for distributed and real-time systems. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.18253 |
debian: CVE-2026-22591 was patched at 2026-09-16
222.
Denial of Service - Pypdf (CVE-2026-84310) - High [470]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | PyPDF is a Python library for reading, manipulating, and writing PDF files, including extraction, splitting, merging, and encryption features. | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00138, EPSS Percentile is 0.03549 |
debian: CVE-2026-84310 was patched at 2026-09-16
223.
Denial of Service - nltk (CVE-2026-81725) - High [470]
Description: NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying malformed TEI blocks with many unmatched opening tags. Attackers can exploit lazy regex patterns in the read_block method through public APIs like words() and tagged_words() to force repeated rescans and achieve near-quadratic runtime growth.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00229, EPSS Percentile is 0.13839 |
debian: CVE-2026-81725 was patched at 2026-09-16
224.
Memory Corruption - Pcre2 (CVE-2026-89160) - High [470]
Description: PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:pcre:pcre2 (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00221, EPSS Percentile is 0.12821 |
debian: CVE-2026-89160 was patched at 2026-09-16
225.
Memory Corruption - tesseract_ocr (CVE-2026-88051) - High [470]
Description: Tesseract is an open source OCR engine. In version 5.5.3 and earlier, the callback form of GenericVector::read in src/ccutil/genericvector.h reads the independent int32 fields reserved and size_used_ from a .traineddata model without a cap or an invariant check. reserve(reserved) allocates the backing array, but the callback loop writes size_used_ elements. A crafted TESSDATA_INTTEMP component with version_id 4 or later can therefore set reserved to a small value and size_used_ to a large value when fontinfo_table_.read(fp, read_info) is called from src/classify/intproto.cpp, causing a heap out-of-bounds write of FontInfo structures, heap corruption, a crash, or potentially controlled corruption. No fixed release is available as of this review.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:tesseract-ocr:tesseract_ocr (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00119, EPSS Percentile is 0.02 |
debian: CVE-2026-88051 was patched at 2026-09-16
226.
Memory Corruption - tesseract_ocr (CVE-2026-88052) - High [470]
Description: Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and uses id as an unchecked index into the unichars vector. unichar_insert_backwards_compatible can leave the vector unchanged for an empty, duplicate, or already-encodable representation, causing id to become larger than unichars.size(). Subsequent set_* calls and the write to unichars[id].properties.enabled then write UNICHAR_PROPERTIES beyond the vector during initialization in both the default LSTM and legacy engines, causing
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:tesseract-ocr:tesseract_ocr (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00118, EPSS Percentile is 0.01941 |
debian: CVE-2026-88052 was patched at 2026-09-16
227.
Memory Corruption - tesseract_ocr (CVE-2026-88053) - High [470]
Description: Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadIntTemplates in src/classify/intproto.cpp reads NumClassPruners, NumClasses, and NumProtoSets from the TESSDATA_INTTEMP component of a crafted .traineddata file and uses those values as loop bounds without validating them against MAX_NUM_CLASS_PRUNERS, MAX_NUM_CLASSES, and MAX_NUM_PROTO_SETS. The loops store heap pointers into fixed-capacity ClassPruners and ProtoSets arrays in INT_TEMPLATES_STRUCT and INT_CLASS_STRUCT, so an oversized count causes heap out-of-bounds pointer writes during legacy-classifier initialization before OCR begins, resulting in heap corruption, a crash, or potentially controlled corruption. No fixed release is available as of this review.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:tesseract-ocr:tesseract_ocr (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00119, EPSS Percentile is 0.02 |
debian: CVE-2026-88053 was patched at 2026-09-16
228.
XXE Injection - RDF4J (CVE-2018-1000644) - High [470]
Description: Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | XXE Injection | |
| 0.5 | 14 | Product detected by a:eclipse:rdf4j (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to NVD data source | |
| 0.8 | 10 | EPSS Probability is 0.01734, EPSS Percentile is 0.76502 |
debian: CVE-2018-1000644 was patched at 2026-08-25
229.
Information Disclosure - Pcre2 (CVE-2026-89162) - High [469]
Description: In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Product detected by a:pcre:pcre2 (exists in CPE dict) | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00105, EPSS Percentile is 0.01191 |
debian: CVE-2026-89162 was patched at 2026-09-16
230.
Code Injection - .NET (CVE-2026-69806) - High [468]
Description: Exposure of sensitive information to an unauthorized actor in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.7 | 14 | .NET | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.8 | 10 | EPSS Probability is 0.01821, EPSS Percentile is 0.77663 |
almalinux: CVE-2026-69806 was patched at 2026-09-15
oraclelinux: CVE-2026-69806 was patched at 2026-09-15, 2026-09-16
ubuntu: CVE-2026-69806 was patched at 2026-09-10, 2026-09-16
231.
Command Injection - RPM (CVE-2026-84837) - High [468]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.7 | 14 | RPM is a package management system and software packaging format widely used by Linux distributions in the Red Hat ecosystem and related systems, including tools for building RPM packages. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.7 | 10 | EPSS Probability is 0.01195, EPSS Percentile is 0.66471 |
debian: CVE-2026-84837 was patched at 2026-09-16
232.
Elevation of Privilege - Linux Kernel (CVE-2026-74752) - High [468]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00434, EPSS Percentile is 0.36985 |
debian: CVE-2026-74752 was patched at 2026-09-16
233.
Elevation of Privilege - Linux Kernel (CVE-2026-89610) - High [468]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00553, EPSS Percentile is 0.44806 |
debian: CVE-2026-89610 was patched at 2026-09-16
234.
Server-Side Request Forgery - Angular (CVE-2026-88056) - High [468]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00426, EPSS Percentile is 0.36218 |
debian: CVE-2026-88056 was patched at 2026-09-16
235.
Cross Site Scripting - Angular (CVE-2026-88060) - High [467]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.9 | 10 | CVSS Base Score is 8.6. According to Vulners data source | |
| 0.5 | 10 | EPSS Probability is 0.00696, EPSS Percentile is 0.51322 |
debian: CVE-2026-88060 was patched at 2026-09-16
236.
Remote Code Execution - Chromium (CVE-2026-76017) - High [466]
Description: Use after free in Chromoting in Google Chrome prior to 151.0.7922.173
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00428, EPSS Percentile is 0.36422 |
altlinux: CVE-2026-76017 was patched at 2026-08-21
debian: CVE-2026-76017 was patched at 2026-08-25, 2026-08-27
237.
Remote Code Execution - Chromium (CVE-2026-76021) - High [466]
Description: Use after free in DOM in Google Chrome prior to 151.0.7922.173
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00449, EPSS Percentile is 0.3815 |
altlinux: CVE-2026-76021 was patched at 2026-08-21
debian: CVE-2026-76021 was patched at 2026-08-25, 2026-08-27
238.
Remote Code Execution - Chromium (CVE-2026-76022) - High [466]
Description: Buffer overflow in Network in Google Chrome prior to 151.0.7922.173
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00468, EPSS Percentile is 0.39477 |
altlinux: CVE-2026-76022 was patched at 2026-08-21
debian: CVE-2026-76022 was patched at 2026-08-25, 2026-08-27
239.
Remote Code Execution - Chromium (CVE-2026-76023) - High [466]
Description: Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00456, EPSS Percentile is 0.3867 |
altlinux: CVE-2026-76023 was patched at 2026-08-21
debian: CVE-2026-76023 was patched at 2026-08-25, 2026-08-27
240.
Remote Code Execution - Chromium (CVE-2026-78891) - High [466]
Description: Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00417, EPSS Percentile is 0.35449 |
altlinux: CVE-2026-78891 was patched at 2026-08-28
debian: CVE-2026-78891 was patched at 2026-09-03, 2026-09-16
241.
Remote Code Execution - Chromium (CVE-2026-78899) - High [466]
Description: Use after free in V8 in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00435, EPSS Percentile is 0.37055 |
altlinux: CVE-2026-78899 was patched at 2026-08-28
debian: CVE-2026-78899 was patched at 2026-09-03, 2026-09-16
242.
Remote Code Execution - Chromium (CVE-2026-78910) - High [466]
Description: Buffer overflow in V8 in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00487, EPSS Percentile is 0.40788 |
altlinux: CVE-2026-78910 was patched at 2026-08-28
debian: CVE-2026-78910 was patched at 2026-09-03, 2026-09-16
243.
Remote Code Execution - Chromium (CVE-2026-78937) - High [466]
Description: Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30924 |
altlinux: CVE-2026-78937 was patched at 2026-08-28
debian: CVE-2026-78937 was patched at 2026-09-03, 2026-09-16
244.
Remote Code Execution - Chromium (CVE-2026-78939) - High [466]
Description: Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30925 |
altlinux: CVE-2026-78939 was patched at 2026-08-28
debian: CVE-2026-78939 was patched at 2026-09-03, 2026-09-16
245.
Remote Code Execution - Chromium (CVE-2026-78945) - High [466]
Description: Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30926 |
altlinux: CVE-2026-78945 was patched at 2026-08-28
debian: CVE-2026-78945 was patched at 2026-09-03, 2026-09-16
246.
Remote Code Execution - Chromium (CVE-2026-78963) - High [466]
Description: Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00442, EPSS Percentile is 0.37629 |
altlinux: CVE-2026-78963 was patched at 2026-08-28
debian: CVE-2026-78963 was patched at 2026-09-03, 2026-09-16
247.
Remote Code Execution - Chromium (CVE-2026-78978) - High [466]
Description: Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00442, EPSS Percentile is 0.37629 |
altlinux: CVE-2026-78978 was patched at 2026-08-28
debian: CVE-2026-78978 was patched at 2026-09-03, 2026-09-16
248.
Remote Code Execution - Chromium (CVE-2026-78990) - High [466]
Description: Use after free in Compositing in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00545, EPSS Percentile is 0.44351 |
altlinux: CVE-2026-78990 was patched at 2026-08-28
debian: CVE-2026-78990 was patched at 2026-09-03, 2026-09-16
249.
Remote Code Execution - Chromium (CVE-2026-79027) - High [466]
Description: Use after free in WebRTC in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00598, EPSS Percentile is 0.47057 |
altlinux: CVE-2026-79027 was patched at 2026-08-28
debian: CVE-2026-79027 was patched at 2026-09-03, 2026-09-16
250.
Remote Code Execution - Chromium (CVE-2026-79048) - High [466]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00545, EPSS Percentile is 0.44351 |
altlinux: CVE-2026-79048 was patched at 2026-08-28
debian: CVE-2026-79048 was patched at 2026-09-03, 2026-09-16
251.
Remote Code Execution - Chromium (CVE-2026-79056) - High [466]
Description: Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00395, EPSS Percentile is 0.33255 |
altlinux: CVE-2026-79056 was patched at 2026-08-28
debian: CVE-2026-79056 was patched at 2026-09-03, 2026-09-16
252.
Remote Code Execution - Chromium (CVE-2026-79064) - High [466]
Description: Use after free in Network in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0039, EPSS Percentile is 0.32785 |
altlinux: CVE-2026-79064 was patched at 2026-08-28
debian: CVE-2026-79064 was patched at 2026-09-03, 2026-09-16
253.
Remote Code Execution - Chromium (CVE-2026-79078) - High [466]
Description: Use after free in FedCM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30928 |
altlinux: CVE-2026-79078 was patched at 2026-08-28
debian: CVE-2026-79078 was patched at 2026-09-03, 2026-09-16
254.
Remote Code Execution - Chromium (CVE-2026-79091) - High [466]
Description: Use after free in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00338, EPSS Percentile is 0.2708 |
altlinux: CVE-2026-79091 was patched at 2026-08-28
debian: CVE-2026-79091 was patched at 2026-09-03, 2026-09-16
255.
Remote Code Execution - Chromium (CVE-2026-79111) - High [466]
Description: Improper input validation in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30925 |
altlinux: CVE-2026-79111 was patched at 2026-08-28
debian: CVE-2026-79111 was patched at 2026-09-03, 2026-09-16
256.
Remote Code Execution - Chromium (CVE-2026-79127) - High [466]
Description: Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00466, EPSS Percentile is 0.39336 |
altlinux: CVE-2026-79127 was patched at 2026-08-28
debian: CVE-2026-79127 was patched at 2026-09-03, 2026-09-16
257.
Remote Code Execution - Chromium (CVE-2026-79128) - High [466]
Description: Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30928 |
altlinux: CVE-2026-79128 was patched at 2026-08-28
debian: CVE-2026-79128 was patched at 2026-09-03, 2026-09-16
258.
Remote Code Execution - Chromium (CVE-2026-79129) - High [466]
Description: Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00344, EPSS Percentile is 0.27773 |
altlinux: CVE-2026-79129 was patched at 2026-08-28
debian: CVE-2026-79129 was patched at 2026-09-03, 2026-09-16
259.
Remote Code Execution - Chromium (CVE-2026-79138) - High [466]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30927 |
altlinux: CVE-2026-79138 was patched at 2026-08-28
debian: CVE-2026-79138 was patched at 2026-09-03, 2026-09-16
260.
Remote Code Execution - Chromium (CVE-2026-79142) - High [466]
Description: Buffer overflow in ANGLE in Google Chrome on on Android prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00417, EPSS Percentile is 0.35449 |
altlinux: CVE-2026-79142 was patched at 2026-08-28
debian: CVE-2026-79142 was patched at 2026-09-03, 2026-09-16
261.
Remote Code Execution - Chromium (CVE-2026-79189) - High [466]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30925 |
altlinux: CVE-2026-79189 was patched at 2026-08-28
debian: CVE-2026-79189 was patched at 2026-09-03, 2026-09-16
262.
Remote Code Execution - Chromium (CVE-2026-79200) - High [466]
Description: Use after free in Aura in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30979 |
altlinux: CVE-2026-79200 was patched at 2026-08-28
debian: CVE-2026-79200 was patched at 2026-09-03, 2026-09-16
263.
Remote Code Execution - Chromium (CVE-2026-79202) - High [466]
Description: Use after free in Chromecast in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00466, EPSS Percentile is 0.39335 |
altlinux: CVE-2026-79202 was patched at 2026-08-28
debian: CVE-2026-79202 was patched at 2026-09-03, 2026-09-16
264.
Remote Code Execution - Chromium (CVE-2026-79219) - High [466]
Description: Use after free in Bluetooth in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00431, EPSS Percentile is 0.36617 |
altlinux: CVE-2026-79219 was patched at 2026-08-28
debian: CVE-2026-79219 was patched at 2026-09-03, 2026-09-16
265.
Remote Code Execution - Chromium (CVE-2026-79231) - High [466]
Description: Buffer overflow in Media in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00417, EPSS Percentile is 0.35449 |
altlinux: CVE-2026-79231 was patched at 2026-08-28
debian: CVE-2026-79231 was patched at 2026-09-03, 2026-09-16
266.
Remote Code Execution - Chromium (CVE-2026-79232) - High [466]
Description: Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30924 |
altlinux: CVE-2026-79232 was patched at 2026-08-28
debian: CVE-2026-79232 was patched at 2026-09-03, 2026-09-16
267.
Remote Code Execution - Chromium (CVE-2026-79235) - High [466]
Description: Use after free in WebGL in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30927 |
altlinux: CVE-2026-79235 was patched at 2026-08-28
debian: CVE-2026-79235 was patched at 2026-09-03, 2026-09-16
268.
Remote Code Execution - Chromium (CVE-2026-79236) - High [466]
Description: Type confusion in V8 in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00509, EPSS Percentile is 0.42167 |
altlinux: CVE-2026-79236 was patched at 2026-08-28
debian: CVE-2026-79236 was patched at 2026-09-03, 2026-09-16
269.
Remote Code Execution - Chromium (CVE-2026-79257) - High [466]
Description: Use after free in Views in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30924 |
altlinux: CVE-2026-79257 was patched at 2026-08-28
debian: CVE-2026-79257 was patched at 2026-09-03, 2026-09-16
270.
Remote Code Execution - Chromium (CVE-2026-79282) - High [466]
Description: Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.004, EPSS Percentile is 0.33834 |
altlinux: CVE-2026-79282 was patched at 2026-08-28
debian: CVE-2026-79282 was patched at 2026-09-03, 2026-09-16
271.
Remote Code Execution - Chromium (CVE-2026-79290) - High [466]
Description: Use after free in Aura in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30979 |
altlinux: CVE-2026-79290 was patched at 2026-08-28
debian: CVE-2026-79290 was patched at 2026-09-03, 2026-09-16
272.
Remote Code Execution - Chromium (CVE-2026-85042) - High [466]
Description: Use after free in DevTools in Google Chrome prior to 152.0.7977.82
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00329, EPSS Percentile is 0.26012 |
altlinux: CVE-2026-85042 was patched at 2026-09-05
debian: CVE-2026-85042 was patched at 2026-09-05, 2026-09-16
273.
Remote Code Execution - Chromium (CVE-2026-85047) - High [466]
Description: Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00329, EPSS Percentile is 0.26058 |
altlinux: CVE-2026-85047 was patched at 2026-09-05
debian: CVE-2026-85047 was patched at 2026-09-05, 2026-09-16
274.
Remote Code Execution - Chromium (CVE-2026-85050) - High [466]
Description: Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00329, EPSS Percentile is 0.26012 |
altlinux: CVE-2026-85050 was patched at 2026-09-05
debian: CVE-2026-85050 was patched at 2026-09-05, 2026-09-16
275.
Remote Code Execution - Chromium (CVE-2026-87430) - High [466]
Description: Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00511, EPSS Percentile is 0.42345 |
altlinux: CVE-2026-87430 was patched at 2026-09-17
debian: CVE-2026-87430 was patched at 2026-09-16
276.
Remote Code Execution - Chromium (CVE-2026-87440) - High [466]
Description: Out of bounds read in Media in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00442, EPSS Percentile is 0.3763 |
altlinux: CVE-2026-87440 was patched at 2026-09-17
debian: CVE-2026-87440 was patched at 2026-09-16
277.
Remote Code Execution - Chromium (CVE-2026-87444) - High [466]
Description: Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00442, EPSS Percentile is 0.3763 |
altlinux: CVE-2026-87444 was patched at 2026-09-17
debian: CVE-2026-87444 was patched at 2026-09-16
278.
Remote Code Execution - Chromium (CVE-2026-87470) - High [466]
Description: Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00395, EPSS Percentile is 0.33255 |
altlinux: CVE-2026-87470 was patched at 2026-09-17
debian: CVE-2026-87470 was patched at 2026-09-16
279.
Remote Code Execution - Chromium (CVE-2026-87492) - High [466]
Description: Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.25622 |
altlinux: CVE-2026-87492 was patched at 2026-09-17
debian: CVE-2026-87492 was patched at 2026-09-16
280.
Remote Code Execution - Chromium (CVE-2026-87494) - High [466]
Description: Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00338, EPSS Percentile is 0.27081 |
altlinux: CVE-2026-87494 was patched at 2026-09-17
debian: CVE-2026-87494 was patched at 2026-09-16
281.
Remote Code Execution - Chromium (CVE-2026-87500) - High [466]
Description: Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00338, EPSS Percentile is 0.27081 |
altlinux: CVE-2026-87500 was patched at 2026-09-17
debian: CVE-2026-87500 was patched at 2026-09-16
282.
Remote Code Execution - Chromium (CVE-2026-87504) - High [466]
Description: Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0039, EPSS Percentile is 0.32785 |
altlinux: CVE-2026-87504 was patched at 2026-09-17
debian: CVE-2026-87504 was patched at 2026-09-16
283.
Remote Code Execution - Chromium (CVE-2026-87520) - High [466]
Description: Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00395, EPSS Percentile is 0.33255 |
altlinux: CVE-2026-87520 was patched at 2026-09-17
debian: CVE-2026-87520 was patched at 2026-09-16
284.
Remote Code Execution - Chromium (CVE-2026-87526) - High [466]
Description: Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00364, EPSS Percentile is 0.30029 |
altlinux: CVE-2026-87526 was patched at 2026-09-17
debian: CVE-2026-87526 was patched at 2026-09-16
285.
Remote Code Execution - Chromium (CVE-2026-87558) - High [466]
Description: Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00395, EPSS Percentile is 0.33255 |
altlinux: CVE-2026-87558 was patched at 2026-09-17
debian: CVE-2026-87558 was patched at 2026-09-16
286.
Remote Code Execution - Chromium (CVE-2026-87579) - High [466]
Description: Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00429, EPSS Percentile is 0.36465 |
altlinux: CVE-2026-87579 was patched at 2026-09-17
debian: CVE-2026-87579 was patched at 2026-09-16
287.
Remote Code Execution - Chromium (CVE-2026-87609) - High [466]
Description: Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0039, EPSS Percentile is 0.32785 |
altlinux: CVE-2026-87609 was patched at 2026-09-17
debian: CVE-2026-87609 was patched at 2026-09-16
288.
Remote Code Execution - Chromium (CVE-2026-87621) - High [466]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00324, EPSS Percentile is 0.25525 |
altlinux: CVE-2026-87621 was patched at 2026-09-17
debian: CVE-2026-87621 was patched at 2026-09-16
289.
Remote Code Execution - Chromium (CVE-2026-87634) - High [466]
Description: Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00395, EPSS Percentile is 0.33318 |
altlinux: CVE-2026-87634 was patched at 2026-09-17
debian: CVE-2026-87634 was patched at 2026-09-16
290.
Remote Code Execution - Chromium (CVE-2026-87643) - High [466]
Description: Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00395, EPSS Percentile is 0.33317 |
altlinux: CVE-2026-87643 was patched at 2026-09-17
debian: CVE-2026-87643 was patched at 2026-09-16
291.
Remote Code Execution - Chromium (CVE-2026-87646) - High [466]
Description: Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00358, EPSS Percentile is 0.29339 |
altlinux: CVE-2026-87646 was patched at 2026-09-17
debian: CVE-2026-87646 was patched at 2026-09-16
292.
Remote Code Execution - Chromium (CVE-2026-87654) - High [466]
Description: Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00361, EPSS Percentile is 0.29674 |
altlinux: CVE-2026-87654 was patched at 2026-09-17
debian: CVE-2026-87654 was patched at 2026-09-16
293.
Remote Code Execution - Chromium (CVE-2026-91728) - High [466]
Description: Integer overflow in V8 in Google Chrome prior to 153.0.8010.47
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0036, EPSS Percentile is 0.29592 |
altlinux: CVE-2026-91728 was patched at 2026-09-17
debian: CVE-2026-91728 was patched at 2026-09-16
294.
Remote Code Execution - Chromium (CVE-2026-91749) - High [466]
Description: Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00333, EPSS Percentile is 0.26562 |
altlinux: CVE-2026-91749 was patched at 2026-09-17
debian: CVE-2026-91749 was patched at 2026-09-16
295.
Remote Code Execution - PHP (CVE-2026-76174) - High [466]
Description: Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The application validates files solely based on the name provided by the client, without properly checking their content or securely restricting the permitted file types. This allows a user with administrator privileges to upload
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.9 | 10 | CVSS Base Score is 9.4. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00487, EPSS Percentile is 0.4075 |
debian: CVE-2026-76174 was patched at 2026-09-16
296.
Spoofing - Chromium (CVE-2026-87615) - High [466]
Description: Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:issues.chromium.org website | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00141, EPSS Percentile is 0.03829 |
altlinux: CVE-2026-87615 was patched at 2026-09-17
debian: CVE-2026-87615 was patched at 2026-09-16
297.
Memory Corruption - zstd-jni (CVE-2026-87795) - High [464]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.25 | 14 | zstd-jni provides Java Native Interface bindings for the Zstandard lossless compression library, enabling high-performance compression and decompression from Java, Android, and other JVM languages. | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00344, EPSS Percentile is 0.27756 |
debian: CVE-2026-87795 was patched at 2026-09-16
298.
Memory Corruption - libxml2 (CVE-2026-86137) - High [463]
Description: In
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:gitlab.gnome.org website | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | libxml2 is an XML toolkit implemented in C, originally developed for the GNOME Project | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0013, EPSS Percentile is 0.03033 |
debian: CVE-2026-86137 was patched at 2026-09-16
299.
Security Feature Bypass - Redis (CVE-2026-72568) - High [463]
Description: Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:PACKETSTORM:228325 website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | Redis is an open-source in-memory storage, used as a distributed, in-memory key–value database, cache and message broker, with optional durability | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
oraclelinux: CVE-2026-72568 was patched at 2026-09-09
redhat: CVE-2026-72568 was patched at 2026-09-08
300.
Memory Corruption - Binutils (CVE-2026-91781) - High [460]
Description: A security vulnerability has been detected in GNU
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:sourceware.org website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02142 |
debian: CVE-2026-91781 was patched at 2026-09-16
301.
Memory Corruption - Binutils (CVE-2026-91782) - High [460]
Description: A vulnerability was detected in GNU
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:vuldb.com website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02198 |
debian: CVE-2026-91782 was patched at 2026-09-16
302.
Open Redirect - WebOb (CVE-2026-54770) - High [460]
Description: WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.75 | 15 | Open Redirect | |
| 0.1 | 14 | WebOb is a Python library that provides objects for HTTP requests and responses, commonly used by Python web frameworks and applications. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00339, EPSS Percentile is 0.27265 |
debian: CVE-2026-54770 was patched at 2026-08-25
303.
Security Feature Bypass - Mozilla Firefox (CVE-2026-75874) - High [460]
Description: Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00455, EPSS Percentile is 0.38604 |
altlinux: CVE-2026-75874 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03, 2026-09-10
debian: CVE-2026-75874 was patched at 2026-09-02, 2026-09-04, 2026-09-16
oraclelinux: CVE-2026-75874 was patched at 2026-09-14
304.
Security Feature Bypass - RPC (CVE-2026-37236) - High [460]
Description: g
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Remote Procedure Call Runtime | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0044, EPSS Percentile is 0.37408 |
debian: CVE-2026-37236 was patched at 2026-09-16
305.
Incorrect Calculation - alsa-lib (CVE-2026-90781) - High [459]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:HARSHRAJSINGHANIA:CVE-2026-90781-ALSA-LIB-OOB, BDU:PublicExploit websites | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.65 | 14 | alsa-lib is the user-space library for the Advanced Linux Sound Architecture (ALSA), providing APIs for audio and MIDI device access and configuration on Linux systems. | |
| 0.4 | 10 | CVSS Base Score is 4.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00179, EPSS Percentile is 0.07697 |
debian: CVE-2026-90781 was patched at 2026-09-16
306.
Memory Corruption - Fast DDS (CVE-2026-22590) - High [459]
Description: eprosima
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.15 | 14 | eProsima Fast DDS is a C++ implementation of the OMG Data Distribution Service (DDS) and RTPS protocols, providing high-performance publish-subscribe middleware for distributed and real-time systems. | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00383, EPSS Percentile is 0.3198 |
debian: CVE-2026-22590 was patched at 2026-09-16
307.
Incorrect Calculation - Pcre2 (CVE-2026-89157) - High [458]
Description: PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:pcre:pcre2 (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00102, EPSS Percentile is 0.01048 |
debian: CVE-2026-89157 was patched at 2026-09-16
308.
Memory Corruption - OpenEXR (CVE-2026-61555) - High [458]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | OpenEXR is an open source high-dynamic-range image file format and reference implementation widely used in computer graphics, visual effects, animation, and motion picture production. | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06426 |
debian: CVE-2026-61555 was patched at 2026-09-16
309.
Remote Code Execution - pgAdmin (CVE-2026-12046) - High [457]
Description: Two state-mutating endpoints in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | pgAdmin is the most popular and feature rich Open Source administration and development platform for PostgreSQL, the most advanced Open Source database in the world | |
| 0.9 | 10 | CVSS Base Score is 9.0. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.01037, EPSS Percentile is 0.622 |
redos: CVE-2026-12046 was patched at 2026-09-07
310.
Cross Site Scripting - Angular (CVE-2026-88058) - High [455]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.9 | 10 | CVSS Base Score is 8.6. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00498, EPSS Percentile is 0.41449 |
debian: CVE-2026-88058 was patched at 2026-09-16
311.
Security Feature Bypass - Apache Tomcat (CVE-2026-65637) - High [455]
Description: Improper Input Validation vulnerability in Apache
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.7 | 14 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00754, EPSS Percentile is 0.53324 |
altlinux: CVE-2026-65637 was patched at 2026-08-26, 2026-08-27, 2026-09-11, 2026-09-16
debian: CVE-2026-65637 was patched at 2026-09-16
312.
Memory Corruption - kin-openapi (CVE-2026-76905) - High [454]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.12 | 14 | kin-openapi is a Go library for parsing, converting, validating, and working with OpenAPI and Swagger specifications and for validating HTTP requests and responses against OpenAPI schemas. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00421, EPSS Percentile is 0.358 |
debian: CVE-2026-76905 was patched at 2026-08-25
313.
Remote Code Execution - Chromium (CVE-2026-76018) - High [454]
Description: Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00386, EPSS Percentile is 0.3234 |
altlinux: CVE-2026-76018 was patched at 2026-08-21
debian: CVE-2026-76018 was patched at 2026-08-25, 2026-08-27
314.
Remote Code Execution - Chromium (CVE-2026-78956) - High [454]
Description: Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00385, EPSS Percentile is 0.32261 |
altlinux: CVE-2026-78956 was patched at 2026-08-28
debian: CVE-2026-78956 was patched at 2026-09-03, 2026-09-16
315.
Remote Code Execution - Chromium (CVE-2026-78983) - High [454]
Description: Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00433, EPSS Percentile is 0.36853 |
altlinux: CVE-2026-78983 was patched at 2026-08-28
debian: CVE-2026-78983 was patched at 2026-09-03, 2026-09-16
316.
Remote Code Execution - Chromium (CVE-2026-78999) - High [454]
Description: Improper privilege management in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0046, EPSS Percentile is 0.38886 |
altlinux: CVE-2026-78999 was patched at 2026-08-28
debian: CVE-2026-78999 was patched at 2026-09-03, 2026-09-16
317.
Remote Code Execution - Chromium (CVE-2026-79008) - High [454]
Description: Improper input validation in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00509, EPSS Percentile is 0.42211 |
altlinux: CVE-2026-79008 was patched at 2026-08-28
debian: CVE-2026-79008 was patched at 2026-09-03, 2026-09-16
318.
Remote Code Execution - Chromium (CVE-2026-79039) - High [454]
Description: Use after free in Mobile in Google Chrome on on iOS prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00512, EPSS Percentile is 0.42403 |
altlinux: CVE-2026-79039 was patched at 2026-08-28
debian: CVE-2026-79039 was patched at 2026-09-03, 2026-09-16
319.
Remote Code Execution - Chromium (CVE-2026-79069) - High [454]
Description: Memory corruption in Tint in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30926 |
altlinux: CVE-2026-79069 was patched at 2026-08-28
debian: CVE-2026-79069 was patched at 2026-09-03, 2026-09-16
320.
Remote Code Execution - Chromium (CVE-2026-79183) - High [454]
Description: Use after free in Accessibility in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00344, EPSS Percentile is 0.27774 |
altlinux: CVE-2026-79183 was patched at 2026-08-28
debian: CVE-2026-79183 was patched at 2026-09-03, 2026-09-16
321.
Remote Code Execution - Chromium (CVE-2026-79187) - High [454]
Description: Use after free in WebRTC in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30926 |
altlinux: CVE-2026-79187 was patched at 2026-08-28
debian: CVE-2026-79187 was patched at 2026-09-03, 2026-09-16
322.
Remote Code Execution - Chromium (CVE-2026-79194) - High [454]
Description: Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00512, EPSS Percentile is 0.42403 |
altlinux: CVE-2026-79194 was patched at 2026-08-28
debian: CVE-2026-79194 was patched at 2026-09-03, 2026-09-16
323.
Remote Code Execution - Chromium (CVE-2026-79195) - High [454]
Description: Use after free in Script in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30925 |
altlinux: CVE-2026-79195 was patched at 2026-08-28
debian: CVE-2026-79195 was patched at 2026-09-03, 2026-09-16
324.
Remote Code Execution - Chromium (CVE-2026-79198) - High [454]
Description: Use after free in Platform in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30928 |
altlinux: CVE-2026-79198 was patched at 2026-08-28
debian: CVE-2026-79198 was patched at 2026-09-03, 2026-09-16
325.
Remote Code Execution - Chromium (CVE-2026-79209) - High [454]
Description: Type confusion in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00406, EPSS Percentile is 0.34434 |
altlinux: CVE-2026-79209 was patched at 2026-08-28
debian: CVE-2026-79209 was patched at 2026-09-03, 2026-09-16
326.
Remote Code Execution - Chromium (CVE-2026-79215) - High [454]
Description: Integer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30927 |
altlinux: CVE-2026-79215 was patched at 2026-08-28
debian: CVE-2026-79215 was patched at 2026-09-03, 2026-09-16
327.
Remote Code Execution - Chromium (CVE-2026-79227) - High [454]
Description: Type confusion in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0033, EPSS Percentile is 0.26139 |
altlinux: CVE-2026-79227 was patched at 2026-08-28
debian: CVE-2026-79227 was patched at 2026-09-03, 2026-09-16
328.
Remote Code Execution - Chromium (CVE-2026-79240) - High [454]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30927 |
altlinux: CVE-2026-79240 was patched at 2026-08-28
debian: CVE-2026-79240 was patched at 2026-09-03, 2026-09-16
329.
Remote Code Execution - Chromium (CVE-2026-79256) - High [454]
Description: Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00446, EPSS Percentile is 0.37892 |
altlinux: CVE-2026-79256 was patched at 2026-08-28
debian: CVE-2026-79256 was patched at 2026-09-03, 2026-09-16
330.
Remote Code Execution - Chromium (CVE-2026-84333) - High [454]
Description: Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00282, EPSS Percentile is 0.20726 |
altlinux: CVE-2026-84333 was patched at 2026-09-03
debian: CVE-2026-84333 was patched at 2026-09-03, 2026-09-16
331.
Remote Code Execution - Chromium (CVE-2026-84352) - High [454]
Description: Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00313, EPSS Percentile is 0.24221 |
altlinux: CVE-2026-84352 was patched at 2026-09-03
debian: CVE-2026-84352 was patched at 2026-09-03, 2026-09-16
332.
Remote Code Execution - Chromium (CVE-2026-84353) - High [454]
Description: Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00313, EPSS Percentile is 0.24221 |
altlinux: CVE-2026-84353 was patched at 2026-09-03
debian: CVE-2026-84353 was patched at 2026-09-03, 2026-09-16
333.
Remote Code Execution - Chromium (CVE-2026-84354) - High [454]
Description: Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00271, EPSS Percentile is 0.1946 |
altlinux: CVE-2026-84354 was patched at 2026-09-03
debian: CVE-2026-84354 was patched at 2026-09-03, 2026-09-16
334.
Remote Code Execution - Chromium (CVE-2026-85051) - High [454]
Description: Type confusion in Compositing in Google Chrome prior to 152.0.7977.82
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00321, EPSS Percentile is 0.25139 |
altlinux: CVE-2026-85051 was patched at 2026-09-05
debian: CVE-2026-85051 was patched at 2026-09-05, 2026-09-16
335.
Remote Code Execution - Chromium (CVE-2026-87487) - High [454]
Description: Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00417, EPSS Percentile is 0.35397 |
altlinux: CVE-2026-87487 was patched at 2026-09-17
debian: CVE-2026-87487 was patched at 2026-09-16
336.
Remote Code Execution - Chromium (CVE-2026-87613) - High [454]
Description: Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 9.0. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0035, EPSS Percentile is 0.28458 |
altlinux: CVE-2026-87613 was patched at 2026-09-17
debian: CVE-2026-87613 was patched at 2026-09-16
337.
Remote Code Execution - Chromium (CVE-2026-87617) - High [454]
Description: Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00364, EPSS Percentile is 0.29978 |
altlinux: CVE-2026-87617 was patched at 2026-09-17
debian: CVE-2026-87617 was patched at 2026-09-16
338.
Remote Code Execution - Chromium (CVE-2026-87637) - High [454]
Description: Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00316, EPSS Percentile is 0.24499 |
altlinux: CVE-2026-87637 was patched at 2026-09-17
debian: CVE-2026-87637 was patched at 2026-09-16
339.
Remote Code Execution - Chromium (CVE-2026-87638) - High [454]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00316, EPSS Percentile is 0.24499 |
altlinux: CVE-2026-87638 was patched at 2026-09-17
debian: CVE-2026-87638 was patched at 2026-09-16
340.
Remote Code Execution - Chromium (CVE-2026-87650) - High [454]
Description: Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00316, EPSS Percentile is 0.24499 |
altlinux: CVE-2026-87650 was patched at 2026-09-17
debian: CVE-2026-87650 was patched at 2026-09-16
341.
Remote Code Execution - Chromium (CVE-2026-91709) - High [454]
Description: Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00359, EPSS Percentile is 0.29525 |
altlinux: CVE-2026-91709 was patched at 2026-09-17
debian: CVE-2026-91709 was patched at 2026-09-16
342.
Remote Code Execution - Chromium (CVE-2026-91721) - High [454]
Description: Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00341, EPSS Percentile is 0.27465 |
altlinux: CVE-2026-91721 was patched at 2026-09-17
debian: CVE-2026-91721 was patched at 2026-09-16
343.
Remote Code Execution - Chromium (CVE-2026-91729) - High [454]
Description: Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00246, EPSS Percentile is 0.15977 |
altlinux: CVE-2026-91729 was patched at 2026-09-17
debian: CVE-2026-91729 was patched at 2026-09-16
344.
Remote Code Execution - Chromium (CVE-2026-91731) - High [454]
Description: Type confusion in Compositing in Google Chrome prior to 153.0.8010.47
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00392, EPSS Percentile is 0.32994 |
altlinux: CVE-2026-91731 was patched at 2026-09-17
debian: CVE-2026-91731 was patched at 2026-09-16
345.
Remote Code Execution - Chromium (CVE-2026-91738) - High [454]
Description: Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00246, EPSS Percentile is 0.15977 |
altlinux: CVE-2026-91738 was patched at 2026-09-17
debian: CVE-2026-91738 was patched at 2026-09-16
346.
Remote Code Execution - Chromium (CVE-2026-91741) - High [454]
Description: Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00392, EPSS Percentile is 0.32994 |
altlinux: CVE-2026-91741 was patched at 2026-09-17
debian: CVE-2026-91741 was patched at 2026-09-16
347.
Memory Corruption - Linux Kernel (CVE-2026-80844) - High [453]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:HORKIMHAB:CVE-2026-80844, Vulners:PublicExploit:GitHub:0XBLACKASH:CVE-2026-80844, BDU:PublicExploit websites | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09459 |
debian: CVE-2026-80844 was patched at 2026-09-16
348.
Memory Corruption - BusyBox (CVE-2026-76014) - High [452]
Description: A vulnerability has been found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:MEETFIREAGAIN:CVE website | |
| 0.5 | 15 | Memory Corruption | |
| 0.75 | 14 | BusyBox combines many common Unix utilities into a small executable and is widely used in embedded Linux systems, appliances, containers, and recovery environments. | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02153 |
debian: CVE-2026-76014 was patched at 2026-08-20
349.
Authentication Bypass - Mozilla Firefox (CVE-2026-74979) - High [451]
Description: Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00306, EPSS Percentile is 0.23325 |
altlinux: CVE-2026-74979 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
350.
Code Injection - PHP (CVE-2026-76176) - High [449]
Description: SQL injection vulnerability in the endpoint /ocsreports/index.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.9 | 10 | CVSS Base Score is 8.6. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.0033, EPSS Percentile is 0.26111 |
debian: CVE-2026-76176 was patched at 2026-09-16
351.
Command Injection - Nodemailer (CVE-2026-82854) - High [447]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.5 | 14 | Nodemailer is a Node.js module for sending email, supporting SMTP, message composition, attachments, and multiple transport mechanisms. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.01134, EPSS Percentile is 0.64848 |
debian: CVE-2026-82854 was patched at 2026-09-16
352.
Authentication Bypass - Apache Tomcat (CVE-2026-66422) - High [446]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00574, EPSS Percentile is 0.45876 |
altlinux: CVE-2026-66422 was patched at 2026-08-26, 2026-08-27, 2026-09-11, 2026-09-16
debian: CVE-2026-66422 was patched at 2026-09-16
353.
Denial of Service - KeePass (CVE-2026-86776) - High [446]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | KeePass is a free open source password manager, which helps you to manage your passwords in a secure way | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00118, EPSS Percentile is 0.01928 |
debian: CVE-2026-86776 was patched at 2026-09-16
354.
Memory Corruption - Pcre2 (CVE-2026-89156) - High [446]
Description: PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:pcre:pcre2 (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00102, EPSS Percentile is 0.01048 |
debian: CVE-2026-89156 was patched at 2026-09-16
355.
Memory Corruption - libevent (CVE-2026-63381) - High [446]
Description: Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | libevent is a portable event notification library that provides an asynchronous event loop and networking primitives for applications using sockets, timers, signals, DNS, and HTTP. | |
| 0.6 | 10 | CVSS Base Score is 5.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02199 |
debian: CVE-2026-63381 was patched at 2026-08-25, 2026-09-11
ubuntu: CVE-2026-63381 was patched at 2026-09-01, 2026-09-16
356.
Memory Corruption - tesseract_ocr (CVE-2026-88049) - High [446]
Description: Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks to NetworkIO::CopyTimeStepGeneral and NetworkIO::Randomize in src/lstm/networkio.cpp but left NetworkIO::WriteTimeStepPart and NetworkIO::AddTimeStepPart unchecked. In LSTM::Forward in src/lstm/lstm.cpp, source_ is sized from the independently deserialized na_ field while the WriteTimeStepPart count is ns_, which comes from the CI gate WeightMatrix dim1() value. A crafted NT_LSTM layer can make ns_ much larger than na_, causing a heap out-of-bounds write during the first recognition step on the default LSTM engine and resulting in heap corruption, a crash, or potentially controlled corruption. No fixed release is available as of this review.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:tesseract-ocr:tesseract_ocr (does NOT exist in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0015, EPSS Percentile is 0.04571 |
debian: CVE-2026-88049 was patched at 2026-09-16
357.
Denial of Service - Incus (CVE-2026-47753) - High [444]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.2 | 14 | Incus is an open source system container and virtual machine manager used to create, manage, and operate Linux containers and virtual machines. | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00141, EPSS Percentile is 0.03828 |
redos: CVE-2026-47753 was patched at 2026-09-01
358.
Remote Code Execution - Chromium (CVE-2026-78911) - High [442]
Description: Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00367, EPSS Percentile is 0.30295 |
altlinux: CVE-2026-78911 was patched at 2026-08-28
debian: CVE-2026-78911 was patched at 2026-09-03, 2026-09-16
359.
Remote Code Execution - Chromium (CVE-2026-78934) - High [442]
Description: Race condition in ReadAloud in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00381, EPSS Percentile is 0.31767 |
altlinux: CVE-2026-78934 was patched at 2026-08-28
debian: CVE-2026-78934 was patched at 2026-09-03, 2026-09-16
360.
Remote Code Execution - Chromium (CVE-2026-78944) - High [442]
Description: Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00279, EPSS Percentile is 0.20478 |
altlinux: CVE-2026-78944 was patched at 2026-08-28
debian: CVE-2026-78944 was patched at 2026-09-03, 2026-09-16
361.
Remote Code Execution - Chromium (CVE-2026-78952) - High [442]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00381, EPSS Percentile is 0.31768 |
altlinux: CVE-2026-78952 was patched at 2026-08-28
debian: CVE-2026-78952 was patched at 2026-09-03, 2026-09-16
362.
Remote Code Execution - Chromium (CVE-2026-79033) - High [442]
Description: Insufficient control flow management in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00303, EPSS Percentile is 0.22977 |
altlinux: CVE-2026-79033 was patched at 2026-08-28
debian: CVE-2026-79033 was patched at 2026-09-03, 2026-09-16
363.
Remote Code Execution - Chromium (CVE-2026-79054) - High [442]
Description: Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00381, EPSS Percentile is 0.31815 |
altlinux: CVE-2026-79054 was patched at 2026-08-28
debian: CVE-2026-79054 was patched at 2026-09-03, 2026-09-16
364.
Remote Code Execution - Chromium (CVE-2026-79073) - High [442]
Description: Improper state validation in Parser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00303, EPSS Percentile is 0.22977 |
altlinux: CVE-2026-79073 was patched at 2026-08-28
debian: CVE-2026-79073 was patched at 2026-09-03, 2026-09-16
365.
Remote Code Execution - Chromium (CVE-2026-79097) - High [442]
Description: Use after free in V8 in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00303, EPSS Percentile is 0.22978 |
altlinux: CVE-2026-79097 was patched at 2026-08-28
debian: CVE-2026-79097 was patched at 2026-09-03, 2026-09-16
366.
Remote Code Execution - Chromium (CVE-2026-79109) - High [442]
Description: Improper input validation in Printing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00348, EPSS Percentile is 0.2827 |
altlinux: CVE-2026-79109 was patched at 2026-08-28
debian: CVE-2026-79109 was patched at 2026-09-03, 2026-09-16
367.
Remote Code Execution - Chromium (CVE-2026-79119) - High [442]
Description: Use after free in PDF in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00279, EPSS Percentile is 0.20478 |
altlinux: CVE-2026-79119 was patched at 2026-08-28
debian: CVE-2026-79119 was patched at 2026-09-03, 2026-09-16
368.
Remote Code Execution - Chromium (CVE-2026-79121) - High [442]
Description: Improper input validation in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00349, EPSS Percentile is 0.28306 |
altlinux: CVE-2026-79121 was patched at 2026-08-28
debian: CVE-2026-79121 was patched at 2026-09-03, 2026-09-16
369.
Remote Code Execution - Chromium (CVE-2026-79132) - High [442]
Description: Improper input validation in Input in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00348, EPSS Percentile is 0.28271 |
altlinux: CVE-2026-79132 was patched at 2026-08-28
debian: CVE-2026-79132 was patched at 2026-09-03, 2026-09-16
370.
Remote Code Execution - Chromium (CVE-2026-79139) - High [442]
Description: Improper input validation in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00354, EPSS Percentile is 0.28957 |
altlinux: CVE-2026-79139 was patched at 2026-08-28
debian: CVE-2026-79139 was patched at 2026-09-03, 2026-09-16
371.
Remote Code Execution - Chromium (CVE-2026-79175) - High [442]
Description: Type confusion in Accessibility in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00356, EPSS Percentile is 0.29137 |
altlinux: CVE-2026-79175 was patched at 2026-08-28
debian: CVE-2026-79175 was patched at 2026-09-03, 2026-09-16
372.
Remote Code Execution - Chromium (CVE-2026-79182) - High [442]
Description: Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00303, EPSS Percentile is 0.22975 |
altlinux: CVE-2026-79182 was patched at 2026-08-28
debian: CVE-2026-79182 was patched at 2026-09-03, 2026-09-16
373.
Remote Code Execution - Chromium (CVE-2026-79197) - High [442]
Description: Use after free in V8 in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00303, EPSS Percentile is 0.22976 |
altlinux: CVE-2026-79197 was patched at 2026-08-28
debian: CVE-2026-79197 was patched at 2026-09-03, 2026-09-16
374.
Remote Code Execution - Chromium (CVE-2026-79210) - High [442]
Description: Use after free in Audio in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00409, EPSS Percentile is 0.34628 |
altlinux: CVE-2026-79210 was patched at 2026-08-28
debian: CVE-2026-79210 was patched at 2026-09-03, 2026-09-16
375.
Remote Code Execution - Chromium (CVE-2026-79216) - High [442]
Description: Buffer overflow in Blink in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00365, EPSS Percentile is 0.30145 |
altlinux: CVE-2026-79216 was patched at 2026-08-28
debian: CVE-2026-79216 was patched at 2026-09-03, 2026-09-16
376.
Remote Code Execution - Chromium (CVE-2026-79224) - High [442]
Description: Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00327, EPSS Percentile is 0.25757 |
altlinux: CVE-2026-79224 was patched at 2026-08-28
debian: CVE-2026-79224 was patched at 2026-09-03, 2026-09-16
377.
Remote Code Execution - Chromium (CVE-2026-79230) - High [442]
Description: Improper input validation in ANGLE in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00303, EPSS Percentile is 0.22977 |
altlinux: CVE-2026-79230 was patched at 2026-08-28
debian: CVE-2026-79230 was patched at 2026-09-03, 2026-09-16
378.
Remote Code Execution - Chromium (CVE-2026-79244) - High [442]
Description: Use after free in Animation in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00303, EPSS Percentile is 0.22977 |
altlinux: CVE-2026-79244 was patched at 2026-08-28
debian: CVE-2026-79244 was patched at 2026-09-03, 2026-09-16
379.
Remote Code Execution - Chromium (CVE-2026-79247) - High [442]
Description: Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00377, EPSS Percentile is 0.31385 |
altlinux: CVE-2026-79247 was patched at 2026-08-28
debian: CVE-2026-79247 was patched at 2026-09-03, 2026-09-16
380.
Remote Code Execution - Chromium (CVE-2026-79292) - High [442]
Description: Integer overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00409, EPSS Percentile is 0.34628 |
altlinux: CVE-2026-79292 was patched at 2026-08-28
debian: CVE-2026-79292 was patched at 2026-09-03, 2026-09-16
381.
Remote Code Execution - Chromium (CVE-2026-84324) - High [442]
Description: Use after free in Proxy in Google Chrome prior to 152.0.7977.75
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 9.0. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00292, EPSS Percentile is 0.21791 |
altlinux: CVE-2026-84324 was patched at 2026-09-03
debian: CVE-2026-84324 was patched at 2026-09-03, 2026-09-16
382.
Remote Code Execution - Chromium (CVE-2026-84326) - High [442]
Description: Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00305, EPSS Percentile is 0.23196 |
altlinux: CVE-2026-84326 was patched at 2026-09-03
debian: CVE-2026-84326 was patched at 2026-09-03, 2026-09-16
383.
Remote Code Execution - Chromium (CVE-2026-84347) - High [442]
Description: Use after free in WebRTC in Google Chrome prior to 152.0.7977.75
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00319, EPSS Percentile is 0.24865 |
altlinux: CVE-2026-84347 was patched at 2026-09-03
debian: CVE-2026-84347 was patched at 2026-09-03, 2026-09-16
384.
Remote Code Execution - Chromium (CVE-2026-85049) - High [442]
Description: Use after free in Skia in Google Chrome prior to 152.0.7977.82
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00295, EPSS Percentile is 0.22146 |
altlinux: CVE-2026-85049 was patched at 2026-09-05
debian: CVE-2026-85049 was patched at 2026-09-05, 2026-09-16
385.
Remote Code Execution - Chromium (CVE-2026-85053) - High [442]
Description: Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00294, EPSS Percentile is 0.2211 |
altlinux: CVE-2026-85053 was patched at 2026-09-05
debian: CVE-2026-85053 was patched at 2026-09-05, 2026-09-16
386.
Remote Code Execution - Chromium (CVE-2026-87460) - High [442]
Description: Use after free in Platform in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00303, EPSS Percentile is 0.22976 |
altlinux: CVE-2026-87460 was patched at 2026-09-17
debian: CVE-2026-87460 was patched at 2026-09-16
387.
Remote Code Execution - Chromium (CVE-2026-87479) - High [442]
Description: Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00345, EPSS Percentile is 0.27951 |
altlinux: CVE-2026-87479 was patched at 2026-09-17
debian: CVE-2026-87479 was patched at 2026-09-16
388.
Remote Code Execution - Chromium (CVE-2026-87480) - High [442]
Description: Use after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00345, EPSS Percentile is 0.27951 |
altlinux: CVE-2026-87480 was patched at 2026-09-17
debian: CVE-2026-87480 was patched at 2026-09-16
389.
Remote Code Execution - Chromium (CVE-2026-87481) - High [442]
Description: Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00352, EPSS Percentile is 0.28641 |
altlinux: CVE-2026-87481 was patched at 2026-09-17
debian: CVE-2026-87481 was patched at 2026-09-16
390.
Remote Code Execution - Chromium (CVE-2026-87510) - High [442]
Description: Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00369, EPSS Percentile is 0.30467 |
altlinux: CVE-2026-87510 was patched at 2026-09-17
debian: CVE-2026-87510 was patched at 2026-09-16
391.
Remote Code Execution - Chromium (CVE-2026-87524) - High [442]
Description: Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00345, EPSS Percentile is 0.27951 |
altlinux: CVE-2026-87524 was patched at 2026-09-17
debian: CVE-2026-87524 was patched at 2026-09-16
392.
Remote Code Execution - Chromium (CVE-2026-87536) - High [442]
Description: Use after free in V8 in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00303, EPSS Percentile is 0.22978 |
altlinux: CVE-2026-87536 was patched at 2026-09-17
debian: CVE-2026-87536 was patched at 2026-09-16
393.
Remote Code Execution - Chromium (CVE-2026-87542) - High [442]
Description: Use after free in Input in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00303, EPSS Percentile is 0.22976 |
altlinux: CVE-2026-87542 was patched at 2026-09-17
debian: CVE-2026-87542 was patched at 2026-09-16
394.
Remote Code Execution - Chromium (CVE-2026-87553) - High [442]
Description: Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00369, EPSS Percentile is 0.30467 |
altlinux: CVE-2026-87553 was patched at 2026-09-17
debian: CVE-2026-87553 was patched at 2026-09-16
395.
Remote Code Execution - Chromium (CVE-2026-87582) - High [442]
Description: Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00357, EPSS Percentile is 0.29243 |
altlinux: CVE-2026-87582 was patched at 2026-09-17
debian: CVE-2026-87582 was patched at 2026-09-16
396.
Remote Code Execution - Chromium (CVE-2026-87585) - High [442]
Description: Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00279, EPSS Percentile is 0.20479 |
altlinux: CVE-2026-87585 was patched at 2026-09-17
debian: CVE-2026-87585 was patched at 2026-09-16
397.
Remote Code Execution - Chromium (CVE-2026-87587) - High [442]
Description: Use after free in V8 in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00303, EPSS Percentile is 0.22976 |
altlinux: CVE-2026-87587 was patched at 2026-09-17
debian: CVE-2026-87587 was patched at 2026-09-16
398.
Remote Code Execution - Chromium (CVE-2026-87588) - High [442]
Description: Use after free in Chromecast in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00303, EPSS Percentile is 0.22978 |
altlinux: CVE-2026-87588 was patched at 2026-09-17
debian: CVE-2026-87588 was patched at 2026-09-16
399.
Remote Code Execution - Chromium (CVE-2026-87612) - High [442]
Description: Type confusion in V8 in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00317, EPSS Percentile is 0.24614 |
altlinux: CVE-2026-87612 was patched at 2026-09-17
debian: CVE-2026-87612 was patched at 2026-09-16
400.
Remote Code Execution - Chromium (CVE-2026-87616) - High [442]
Description: Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00388, EPSS Percentile is 0.32555 |
altlinux: CVE-2026-87616 was patched at 2026-09-17
debian: CVE-2026-87616 was patched at 2026-09-16
401.
Remote Code Execution - Chromium (CVE-2026-87618) - High [442]
Description: Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.25309 |
altlinux: CVE-2026-87618 was patched at 2026-09-17
debian: CVE-2026-87618 was patched at 2026-09-16
402.
Remote Code Execution - Chromium (CVE-2026-87625) - High [442]
Description: Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00268, EPSS Percentile is 0.19067 |
altlinux: CVE-2026-87625 was patched at 2026-09-17
debian: CVE-2026-87625 was patched at 2026-09-16
403.
Remote Code Execution - Chromium (CVE-2026-87636) - High [442]
Description: Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00308, EPSS Percentile is 0.23637 |
altlinux: CVE-2026-87636 was patched at 2026-09-17
debian: CVE-2026-87636 was patched at 2026-09-16
404.
Remote Code Execution - Chromium (CVE-2026-87639) - High [442]
Description: Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00366, EPSS Percentile is 0.3024 |
altlinux: CVE-2026-87639 was patched at 2026-09-17
debian: CVE-2026-87639 was patched at 2026-09-16
405.
Remote Code Execution - Chromium (CVE-2026-91710) - High [442]
Description: Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.14643 |
altlinux: CVE-2026-91710 was patched at 2026-09-17
debian: CVE-2026-91710 was patched at 2026-09-16
406.
Remote Code Execution - Chromium (CVE-2026-91715) - High [442]
Description: Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00256, EPSS Percentile is 0.17481 |
altlinux: CVE-2026-91715 was patched at 2026-09-17
debian: CVE-2026-91715 was patched at 2026-09-16
407.
Remote Code Execution - Chromium (CVE-2026-91716) - High [442]
Description: Use after free in Auth in Google Chrome prior to 153.0.8010.47
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.14643 |
altlinux: CVE-2026-91716 was patched at 2026-09-17
debian: CVE-2026-91716 was patched at 2026-09-16
408.
Remote Code Execution - Chromium (CVE-2026-91718) - High [442]
Description: Use after free in Core in Google Chrome prior to 153.0.8010.47
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.14642 |
altlinux: CVE-2026-91718 was patched at 2026-09-17
debian: CVE-2026-91718 was patched at 2026-09-16
409.
Remote Code Execution - Chromium (CVE-2026-91736) - High [442]
Description: Use after free in DOM in Google Chrome prior to 153.0.8010.47
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.003, EPSS Percentile is 0.22659 |
altlinux: CVE-2026-91736 was patched at 2026-09-17
debian: CVE-2026-91736 was patched at 2026-09-16
410.
Remote Code Execution - Chromium (CVE-2026-91737) - High [442]
Description: Use after free in PDF in Google Chrome prior to 153.0.8010.47
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00246, EPSS Percentile is 0.15977 |
altlinux: CVE-2026-91737 was patched at 2026-09-17
debian: CVE-2026-91737 was patched at 2026-09-16
411.
Remote Code Execution - Chromium (CVE-2026-91745) - High [442]
Description: Use after free in V8 in Google Chrome prior to 153.0.8010.47
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00246, EPSS Percentile is 0.15977 |
altlinux: CVE-2026-91745 was patched at 2026-09-17
debian: CVE-2026-91745 was patched at 2026-09-16
412.
Remote Code Execution - jackson-databind (CVE-2026-83557) - High [442]
Description: DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of "unsafe base types", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang.Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Jackson Databind is a widely used Java library for converting JSON data to and from Java objects, providing data-binding functionality within the Jackson JSON processing ecosystem. | |
| 0.6 | 10 | CVSS Base Score is 5.6. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00586, EPSS Percentile is 0.46479 |
debian: CVE-2026-83557 was patched at 2026-09-16
413.
Authentication Bypass - Perl (CVE-2026-86219) - High [441]
Description: Authen::SASL::
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00486, EPSS Percentile is 0.4072 |
debian: CVE-2026-86219 was patched at 2026-09-16
414.
Authentication Bypass - Rclone (CVE-2026-88018) - High [441]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers, supporting over 40 cloud storage products including S3, Google Drive, Dropbox, OneDrive, and many more. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.005, EPSS Percentile is 0.41614 |
altlinux: CVE-2026-88018 was patched at 2026-09-09
debian: CVE-2026-88018 was patched at 2026-09-16
415.
Memory Corruption - zstd-jni (CVE-2026-87877) - High [440]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.25 | 14 | zstd-jni provides Java Native Interface bindings for the Zstandard lossless compression library, enabling high-performance compression and decompression from Java, Android, and other JVM languages. | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00201, EPSS Percentile is 0.10247 |
debian: CVE-2026-87877 was patched at 2026-09-16
416.
Remote Code Execution - SPIP (CVE-2026-72710) - High [440]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | SPIP is an open-source software content management system designed for web site publishing, oriented towards online collaborative editing | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00621, EPSS Percentile is 0.48122 |
debian: CVE-2026-72710 was patched at 2026-09-16
417.
Authentication Bypass - 389 Directory Server (CVE-2026-18922) - High [436]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | 389 Directory Server is a highly usable, fully featured, reliable and secure LDAP server implementation | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.0056, EPSS Percentile is 0.45178 |
almalinux: CVE-2026-18922 was patched at 2026-09-08
altlinux: CVE-2026-18922 was patched at 2026-09-08, 2026-09-11
debian: CVE-2026-18922 was patched at 2026-09-16
oraclelinux: CVE-2026-18922 was patched at 2026-09-08, 2026-09-10
redhat: CVE-2026-18922 was patched at 2026-09-08
418.
Security Feature Bypass - Chromium (CVE-2026-84325) - High [436]
Description: Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00249, EPSS Percentile is 0.16445 |
altlinux: CVE-2026-84325 was patched at 2026-09-03
debian: CVE-2026-84325 was patched at 2026-09-03, 2026-09-16
419.
Security Feature Bypass - Chromium (CVE-2026-85043) - High [436]
Description: Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00328, EPSS Percentile is 0.25965 |
altlinux: CVE-2026-85043 was patched at 2026-09-05
debian: CVE-2026-85043 was patched at 2026-09-05, 2026-09-16
420.
Security Feature Bypass - Chromium (CVE-2026-87544) - High [436]
Description: Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0026, EPSS Percentile is 0.17894 |
altlinux: CVE-2026-87544 was patched at 2026-09-17
debian: CVE-2026-87544 was patched at 2026-09-16
421.
Security Feature Bypass - Mozilla Firefox (CVE-2026-74938) - High [436]
Description: Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00322, EPSS Percentile is 0.25272 |
altlinux: CVE-2026-74938 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
422.
Security Feature Bypass - Mozilla Firefox (CVE-2026-84135) - High [436]
Description: Other issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00253, EPSS Percentile is 0.17027 |
altlinux: CVE-2026-84135 was patched at 2026-09-01, 2026-09-05
423.
Security Feature Bypass - PHP (CVE-2026-49283) - High [436]
Description: The SimpleSAMLphp SAML2 library is a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00344, EPSS Percentile is 0.27784 |
debian: CVE-2026-49283 was patched at 2026-08-25
424.
Authentication Bypass - MinIO (CVE-2026-40344) - High [434]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | MinIO is a high-performance, S3-compatible object storage system designed for large-scale data infrastructure. It supports cloud-native workloads and provides APIs for storing, retrieving, and managing unstructured data such as photos, videos, log files, and backups, with a focus on scalability, speed, and simplicity. | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00418, EPSS Percentile is 0.35566 |
redos: CVE-2026-40344 was patched at 2026-09-02
425.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-71113) - High [434]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00417, EPSS Percentile is 0.35403 |
altlinux: CVE-2026-71113 was patched at 2026-08-21
426.
Memory Corruption - Pypdf (CVE-2026-84311) - High [434]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | PyPDF is a Python library for reading, manipulating, and writing PDF files, including extraction, splitting, merging, and encryption features. | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00138, EPSS Percentile is 0.03549 |
debian: CVE-2026-84311 was patched at 2026-09-16
427.
Remote Code Execution - FreeRDP (CVE-2026-91964) - High [433]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00549, EPSS Percentile is 0.44578 |
debian: CVE-2026-91964 was patched at 2026-09-16
428.
Authentication Bypass - Active Directory (CVE-2026-11861) - High [432]
Description: A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.9 | 14 | Active Directory is a directory service developed by Microsoft for Windows domain networks | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00187, EPSS Percentile is 0.08558 |
altlinux: CVE-2026-11861 was patched at 2026-08-20
debian: CVE-2026-11861 was patched at 2026-08-25
429.
Denial of Service - Incus (CVE-2026-48754) - High [432]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.2 | 14 | Incus is an open source system container and virtual machine manager used to create, manage, and operate Linux containers and virtual machines. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00226, EPSS Percentile is 0.13431 |
redos: CVE-2026-48754 was patched at 2026-08-24
430.
Server-Side Request Forgery - Chromium (CVE-2026-87595) - High [431]
Description: Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00312, EPSS Percentile is 0.24102 |
altlinux: CVE-2026-87595 was patched at 2026-09-17
debian: CVE-2026-87595 was patched at 2026-09-16
431.
Authentication Bypass - Gitea (CVE-2026-20779) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.75 | 14 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00481, EPSS Percentile is 0.40373 |
altlinux: CVE-2026-20779 was patched at 2026-08-27, 2026-08-29, 2026-09-04
432.
Authentication Bypass - Gitea (CVE-2026-58508) - High [430]
Description: Two SSRF vulnerabilities in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.75 | 14 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00268, EPSS Percentile is 0.1901 |
altlinux: CVE-2026-58508 was patched at 2026-08-27, 2026-08-29, 2026-09-04
redos: CVE-2026-58508 was patched at 2026-08-20
433.
Remote Code Execution - .NET Framework (CVE-2026-62897) - High [430]
Description: Integer overflow or wraparound in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | .NET Framework | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00336, EPSS Percentile is 0.26848 |
altlinux: CVE-2026-62897 was patched at 2026-08-31, 2026-09-02
redos: CVE-2026-62897 was patched at 2026-09-07
434.
Remote Code Execution - Chromium (CVE-2026-76020) - High [430]
Description: Race condition in V8 in Google Chrome prior to 151.0.7922.173
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00301, EPSS Percentile is 0.22794 |
altlinux: CVE-2026-76020 was patched at 2026-08-21
debian: CVE-2026-76020 was patched at 2026-08-25, 2026-08-27
435.
Remote Code Execution - Chromium (CVE-2026-78901) - High [430]
Description: Race condition in V8 in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16158 |
altlinux: CVE-2026-78901 was patched at 2026-08-28
debian: CVE-2026-78901 was patched at 2026-09-03, 2026-09-16
436.
Remote Code Execution - Chromium (CVE-2026-78906) - High [430]
Description: Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00304, EPSS Percentile is 0.23145 |
altlinux: CVE-2026-78906 was patched at 2026-08-28
debian: CVE-2026-78906 was patched at 2026-09-03, 2026-09-16
437.
Remote Code Execution - Chromium (CVE-2026-78913) - High [430]
Description: Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00313, EPSS Percentile is 0.24255 |
altlinux: CVE-2026-78913 was patched at 2026-08-28
debian: CVE-2026-78913 was patched at 2026-09-03, 2026-09-16
438.
Remote Code Execution - Chromium (CVE-2026-79071) - High [430]
Description: Race condition in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0026, EPSS Percentile is 0.17945 |
altlinux: CVE-2026-79071 was patched at 2026-08-28
debian: CVE-2026-79071 was patched at 2026-09-03, 2026-09-16
439.
Remote Code Execution - Chromium (CVE-2026-79083) - High [430]
Description: Improper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00265, EPSS Percentile is 0.18545 |
altlinux: CVE-2026-79083 was patched at 2026-08-28
debian: CVE-2026-79083 was patched at 2026-09-03, 2026-09-16
440.
Remote Code Execution - Chromium (CVE-2026-79155) - High [430]
Description: Race condition in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0026, EPSS Percentile is 0.17945 |
altlinux: CVE-2026-79155 was patched at 2026-08-28
debian: CVE-2026-79155 was patched at 2026-09-03, 2026-09-16
441.
Remote Code Execution - Chromium (CVE-2026-79218) - High [430]
Description: Incorrect authorization in Sandbox in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00314, EPSS Percentile is 0.24323 |
altlinux: CVE-2026-79218 was patched at 2026-08-28
debian: CVE-2026-79218 was patched at 2026-09-03, 2026-09-16
442.
Remote Code Execution - Chromium (CVE-2026-79263) - High [430]
Description: Race condition in Extensions in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00307, EPSS Percentile is 0.23473 |
altlinux: CVE-2026-79263 was patched at 2026-08-28
debian: CVE-2026-79263 was patched at 2026-09-03, 2026-09-16
443.
Remote Code Execution - Chromium (CVE-2026-84349) - High [430]
Description: Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00246, EPSS Percentile is 0.16106 |
altlinux: CVE-2026-84349 was patched at 2026-09-03
debian: CVE-2026-84349 was patched at 2026-09-03, 2026-09-16
444.
Remote Code Execution - Chromium (CVE-2026-84350) - High [430]
Description: Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00223, EPSS Percentile is 0.13097 |
altlinux: CVE-2026-84350 was patched at 2026-09-03
debian: CVE-2026-84350 was patched at 2026-09-03, 2026-09-16
445.
Remote Code Execution - Chromium (CVE-2026-84351) - High [430]
Description: Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00276, EPSS Percentile is 0.20098 |
altlinux: CVE-2026-84351 was patched at 2026-09-03
debian: CVE-2026-84351 was patched at 2026-09-03, 2026-09-16
446.
Remote Code Execution - Chromium (CVE-2026-85048) - High [430]
Description: Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00296, EPSS Percentile is 0.22329 |
altlinux: CVE-2026-85048 was patched at 2026-09-05
debian: CVE-2026-85048 was patched at 2026-09-05, 2026-09-16
447.
Remote Code Execution - Chromium (CVE-2026-87489) - High [430]
Description: Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00233, EPSS Percentile is 0.14316 |
altlinux: CVE-2026-87489 was patched at 2026-09-17
debian: CVE-2026-87489 was patched at 2026-09-16
448.
Remote Code Execution - Chromium (CVE-2026-87506) - High [430]
Description: Privilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00296, EPSS Percentile is 0.22263 |
altlinux: CVE-2026-87506 was patched at 2026-09-17
debian: CVE-2026-87506 was patched at 2026-09-16
449.
Remote Code Execution - Chromium (CVE-2026-87537) - High [430]
Description: Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00302, EPSS Percentile is 0.22895 |
altlinux: CVE-2026-87537 was patched at 2026-09-17
debian: CVE-2026-87537 was patched at 2026-09-16
450.
Remote Code Execution - Chromium (CVE-2026-87572) - High [430]
Description: Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00308, EPSS Percentile is 0.23651 |
altlinux: CVE-2026-87572 was patched at 2026-09-17
debian: CVE-2026-87572 was patched at 2026-09-16
451.
Remote Code Execution - Chromium (CVE-2026-87604) - High [430]
Description: Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00296, EPSS Percentile is 0.22263 |
altlinux: CVE-2026-87604 was patched at 2026-09-17
debian: CVE-2026-87604 was patched at 2026-09-16
452.
Remote Code Execution - Chromium (CVE-2026-87633) - High [430]
Description: Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05477 |
altlinux: CVE-2026-87633 was patched at 2026-09-17
debian: CVE-2026-87633 was patched at 2026-09-16
453.
Remote Code Execution - Chromium (CVE-2026-87644) - High [430]
Description: Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00266, EPSS Percentile is 0.18653 |
altlinux: CVE-2026-87644 was patched at 2026-09-17
debian: CVE-2026-87644 was patched at 2026-09-16
454.
Remote Code Execution - Chromium (CVE-2026-87648) - High [430]
Description: Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00276, EPSS Percentile is 0.20134 |
altlinux: CVE-2026-87648 was patched at 2026-09-17
debian: CVE-2026-87648 was patched at 2026-09-16
455.
Remote Code Execution - Chromium (CVE-2026-91711) - High [430]
Description: Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.14643 |
altlinux: CVE-2026-91711 was patched at 2026-09-17
debian: CVE-2026-91711 was patched at 2026-09-16
456.
Remote Code Execution - Chromium (CVE-2026-91712) - High [430]
Description: Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0025, EPSS Percentile is 0.16551 |
altlinux: CVE-2026-91712 was patched at 2026-09-17
debian: CVE-2026-91712 was patched at 2026-09-16
457.
Remote Code Execution - Chromium (CVE-2026-91722) - High [430]
Description: Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.14643 |
altlinux: CVE-2026-91722 was patched at 2026-09-17
debian: CVE-2026-91722 was patched at 2026-09-16
458.
Remote Code Execution - Chromium (CVE-2026-91724) - High [430]
Description: Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00314, EPSS Percentile is 0.2428 |
altlinux: CVE-2026-91724 was patched at 2026-09-17
debian: CVE-2026-91724 was patched at 2026-09-16
459.
Remote Code Execution - Chromium (CVE-2026-91735) - High [430]
Description: Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0029, EPSS Percentile is 0.21621 |
altlinux: CVE-2026-91735 was patched at 2026-09-17
debian: CVE-2026-91735 was patched at 2026-09-16
460.
Remote Code Execution - FreeIPA (CVE-2026-18147) - High [430]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | FreeIPA is a free and open source identity management system | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00293, EPSS Percentile is 0.21916 |
debian: CVE-2026-18147 was patched at 2026-09-16
461.
Remote Code Execution - The Qt Company Qt (CVE-2026-11573) - High [430]
Description: Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Qt is a cross-platform application development framework used to build graphical user interfaces and applications for desktop, mobile, and embedded systems. It provides a comprehensive set of libraries, tools, and APIs, including Qt Quick for declarative UI development using QML. The vulnerability affects the Qt Quick Text component, where improper validation of width and height attributes in the | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00387, EPSS Percentile is 0.32409 |
debian: CVE-2026-11573 was patched at 2026-09-16
462.
Denial of Service - Linux Kernel (CVE-2026-89657) - High [429]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00603, EPSS Percentile is 0.4727 |
debian: CVE-2026-89657 was patched at 2026-09-16
463.
Memory Corruption - zstd-jni (CVE-2026-87825) - High [428]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.25 | 14 | zstd-jni provides Java Native Interface bindings for the Zstandard lossless compression library, enabling high-performance compression and decompression from Java, Android, and other JVM languages. | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00133, EPSS Percentile is 0.03193 |
debian: CVE-2026-87825 was patched at 2026-09-16
464.
Remote Code Execution - 389 Directory Server (CVE-2026-18355) - High [428]
Description: A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | 389 Directory Server is a highly usable, fully featured, reliable and secure LDAP server implementation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.00837, EPSS Percentile is 0.55975 |
almalinux: CVE-2026-18355 was patched at 2026-09-08
altlinux: CVE-2026-18355 was patched at 2026-09-08, 2026-09-11
debian: CVE-2026-18355 was patched at 2026-09-16
oraclelinux: CVE-2026-18355 was patched at 2026-09-08, 2026-09-10
redhat: CVE-2026-18355 was patched at 2026-09-08
465.
Remote Code Execution - nltk (CVE-2026-71513) - High [428]
Description: NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside the allowlisted namespace. Attackers can craft untrusted transition-parser models that
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00784, EPSS Percentile is 0.54299 |
debian: CVE-2026-71513 was patched at 2026-08-25
466.
Authentication Bypass - Mozilla Firefox (CVE-2026-84117) - High [427]
Description: Privilege escalation in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00234, EPSS Percentile is 0.14447 |
altlinux: CVE-2026-84117 was patched at 2026-09-01, 2026-09-05
467.
Authentication Bypass - Mozilla Firefox (CVE-2026-84128) - High [427]
Description: Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00233, EPSS Percentile is 0.14328 |
altlinux: CVE-2026-84128 was patched at 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
468.
Authentication Bypass - Node.js (CVE-2026-90711) - High [427]
Description: proxy-addr is a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00187, EPSS Percentile is 0.08567 |
debian: CVE-2026-90711 was patched at 2026-09-16
469.
Code Injection - Chromium (CVE-2026-91719) - High [425]
Description: Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.1733 |
altlinux: CVE-2026-91719 was patched at 2026-09-17
debian: CVE-2026-91719 was patched at 2026-09-16
470.
Security Feature Bypass - Chromium (CVE-2026-87433) - High [425]
Description: Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00297, EPSS Percentile is 0.2241 |
altlinux: CVE-2026-87433 was patched at 2026-09-17
debian: CVE-2026-87433 was patched at 2026-09-16
471.
Security Feature Bypass - Chromium (CVE-2026-87471) - High [425]
Description: Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00339, EPSS Percentile is 0.27251 |
altlinux: CVE-2026-87471 was patched at 2026-09-17
debian: CVE-2026-87471 was patched at 2026-09-16
472.
Security Feature Bypass - Mozilla Firefox (CVE-2026-84129) - High [425]
Description: Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00185, EPSS Percentile is 0.0834 |
altlinux: CVE-2026-84129 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
473.
Security Feature Bypass - Mozilla Firefox (CVE-2026-84133) - High [425]
Description: Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00185, EPSS Percentile is 0.0834 |
altlinux: CVE-2026-84133 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
474.
Security Feature Bypass - Mozilla Firefox (CVE-2026-84140) - High [425]
Description: Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00182, EPSS Percentile is 0.08044 |
altlinux: CVE-2026-84140 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
475.
Information Disclosure - Mozilla Firefox (CVE-2026-74986) - High [424]
Description: Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.25332 |
altlinux: CVE-2026-74986 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
476.
Information Disclosure - Mozilla Firefox (CVE-2026-84134) - High [424]
Description: Other issue in the Profile Backup component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00309, EPSS Percentile is 0.23716 |
altlinux: CVE-2026-84134 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
477.
Information Disclosure - Mozilla Firefox (CVE-2026-84142) - High [424]
Description: Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00304, EPSS Percentile is 0.23152 |
altlinux: CVE-2026-84142 was patched at 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
478.
Information Disclosure - Safari (CVE-2026-64713) - High [424]
Description: This issue was addressed with improved checks. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00467, EPSS Percentile is 0.39359 |
altlinux: CVE-2026-64713 was patched at 2026-08-24
debian: CVE-2026-64713 was patched at 2026-08-24, 2026-08-25
ubuntu: CVE-2026-64713 was patched at 2026-08-31, 2026-09-16
479.
Authentication Bypass - Dovecot (CVE-2026-73208) - High [423]
Description: An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the audience claim is used in its place and checked against the configured required scopes. These are different concepts, and the audience claim does not describe what a token is allowed to do. A token that grants no relevant permissions can be accepted because its intended recipient value happens to match a configured scope name, granting access that should have been denied. It also hides an identity provider misconfiguration where scopes are not being issued at all. Ensure the identity provider issues a scope claim for all tokens used with
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.85 | 14 | Open-source IMAP and POP3 email server with authentication and indexing features. | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00256, EPSS Percentile is 0.17411 |
altlinux: CVE-2026-73208 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-73208 was patched at 2026-09-16
480.
Authentication Bypass - Ruby on Rails (CVE-2026-44476) - High [423]
Description: Doorkeeper is an OAuth 2 provider for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.85 | 14 | Full-stack Ruby web framework with MVC architecture and built-in view helpers and storage system. | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.25314 |
debian: CVE-2026-44476 was patched at 2026-09-16
481.
Code Injection - n8n (CVE-2026-54310) - High [423]
Description: n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could supply a crafted parameters to the TimescaleDB and/or legacy Postgres v1 node's allowing arbitrary SQL to be injected and executed against the connected database within the privileges of the configured database account. This vulnerability is fixed in 2.25.7 and 2.26.2.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.5 | 14 | Product detected by a:n8n:n8n (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.9. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00545, EPSS Percentile is 0.44338 |
altlinux: CVE-2026-54310 was patched at 2026-08-26, 2026-08-28, 2026-08-29, 2026-09-01
482.
Remote Code Execution - Linux Kernel (CVE-2026-89489) - High [423]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00136, EPSS Percentile is 0.03402 |
debian: CVE-2026-89489 was patched at 2026-09-16
483.
Authentication Bypass - MinIO (CVE-2026-41145) - High [422]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | MinIO is a high-performance, S3-compatible object storage system designed for large-scale data infrastructure. It supports cloud-native workloads and provides APIs for storing, retrieving, and managing unstructured data such as photos, videos, log files, and backups, with a focus on scalability, speed, and simplicity. | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00349, EPSS Percentile is 0.28404 |
redos: CVE-2026-41145 was patched at 2026-09-02
484.
Remote Code Execution - FreeRDP (CVE-2026-91963) - High [421]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.0064, EPSS Percentile is 0.48964 |
debian: CVE-2026-91963 was patched at 2026-09-16
485.
Remote Code Execution - Puma (CVE-2026-68006) - High [421]
Description: An issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Puma is a Ruby/Rack web server built for parallelism | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30946 |
debian: CVE-2026-68006 was patched at 2026-09-16
486.
Remote Code Execution - Python (CVE-2026-87874) - High [421]
Description: A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00426, EPSS Percentile is 0.36217 |
debian: CVE-2026-87874 was patched at 2026-09-16
487.
Path Traversal - MinIO (CVE-2026-42600) - High [420]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.7 | 14 | MinIO is a high-performance, S3-compatible object storage system designed for large-scale data infrastructure. It supports cloud-native workloads and provides APIs for storing, retrieving, and managing unstructured data such as photos, videos, log files, and backups, with a focus on scalability, speed, and simplicity. | |
| 0.5 | 10 | CVSS Base Score is 4.9. According to NVD data source | |
| 1.0 | 10 | EPSS Probability is 0.09491, EPSS Percentile is 0.95179 |
redos: CVE-2026-42600 was patched at 2026-08-31
488.
Remote Code Execution - Chromium (CVE-2026-84335) - High [419]
Description: Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00228, EPSS Percentile is 0.1369 |
altlinux: CVE-2026-84335 was patched at 2026-09-03
debian: CVE-2026-84335 was patched at 2026-09-03, 2026-09-16
489.
Remote Code Execution - Chromium (CVE-2026-87601) - High [419]
Description: Race condition in V8 in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00182, EPSS Percentile is 0.08025 |
altlinux: CVE-2026-87601 was patched at 2026-09-17
debian: CVE-2026-87601 was patched at 2026-09-16
490.
Remote Code Execution - Chromium (CVE-2026-87628) - High [419]
Description: Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06535 |
altlinux: CVE-2026-87628 was patched at 2026-09-17
debian: CVE-2026-87628 was patched at 2026-09-16
491.
Remote Code Execution - Chromium (CVE-2026-91743) - High [419]
Description: Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.1461 |
altlinux: CVE-2026-91743 was patched at 2026-09-17
debian: CVE-2026-91743 was patched at 2026-09-16
492.
Remote Code Execution - Chromium (CVE-2026-91748) - High [419]
Description: Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00212, EPSS Percentile is 0.11727 |
altlinux: CVE-2026-91748 was patched at 2026-09-17
debian: CVE-2026-91748 was patched at 2026-09-16
493.
Remote Code Execution - GNOME desktop (CVE-2026-85197) - High [419]
Description: A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | GNOME originally an acronym for GNU Network Object Model Environment, is a free and open-source desktop environment for Linux and other Unix-like operating systems | |
| 0.8 | 10 | CVSS Base Score is 7.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00215, EPSS Percentile is 0.12058 |
debian: CVE-2026-85197 was patched at 2026-09-16
494.
Server-Side Request Forgery - PHP (CVE-2026-62993) - High [419]
Description: Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 4.5.7 and 5.8.2, depending on the release line, Smarty's {fetch} handling in libs/plugins/function.fetch.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.0042, EPSS Percentile is 0.3574 |
debian: CVE-2026-62993 was patched at 2026-09-16
495.
Memory Corruption - Linux Kernel (CVE-2026-89492) - High [417]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00605, EPSS Percentile is 0.47377 |
debian: CVE-2026-89492 was patched at 2026-09-16
496.
Memory Corruption - Linux Kernel (CVE-2026-89494) - High [417]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00704, EPSS Percentile is 0.51597 |
debian: CVE-2026-89494 was patched at 2026-09-16
497.
Memory Corruption - Linux Kernel (CVE-2026-89495) - High [417]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00704, EPSS Percentile is 0.51597 |
debian: CVE-2026-89495 was patched at 2026-09-16
498.
Memory Corruption - Linux Kernel (CVE-2026-89555) - High [417]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00684, EPSS Percentile is 0.50857 |
debian: CVE-2026-89555 was patched at 2026-09-16
499.
Memory Corruption - Linux Kernel (CVE-2026-89636) - High [417]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00653, EPSS Percentile is 0.49601 |
debian: CVE-2026-89636 was patched at 2026-09-16
500.
Memory Corruption - Linux Kernel (CVE-2026-89637) - High [417]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00588, EPSS Percentile is 0.46574 |
debian: CVE-2026-89637 was patched at 2026-09-16
501.
Memory Corruption - Linux Kernel (CVE-2026-89651) - High [417]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00626, EPSS Percentile is 0.48359 |
debian: CVE-2026-89651 was patched at 2026-09-16
502.
Memory Corruption - Linux Kernel (CVE-2026-89658) - High [417]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00608, EPSS Percentile is 0.47505 |
debian: CVE-2026-89658 was patched at 2026-09-16
503.
Memory Corruption - Linux Kernel (CVE-2026-89660) - High [417]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00588, EPSS Percentile is 0.46574 |
debian: CVE-2026-89660 was patched at 2026-09-16
504.
Memory Corruption - Linux Kernel (CVE-2026-89662) - High [417]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00684, EPSS Percentile is 0.50858 |
debian: CVE-2026-89662 was patched at 2026-09-16
505.
Memory Corruption - Linux Kernel (CVE-2026-89669) - High [417]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00684, EPSS Percentile is 0.50857 |
debian: CVE-2026-89669 was patched at 2026-09-16
506.
Memory Corruption - Linux Kernel (CVE-2026-89688) - High [417]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00608, EPSS Percentile is 0.47505 |
debian: CVE-2026-89688 was patched at 2026-09-16
507.
Memory Corruption - Linux Kernel (CVE-2026-89703) - High [417]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00608, EPSS Percentile is 0.47505 |
debian: CVE-2026-89703 was patched at 2026-09-16
508.
Path Traversal - Rust (CVE-2026-82253) - High [417]
Description: gitoxide (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.9 | 14 | Rust is a modern, high-performance systems programming language focused on safety, concurrency, and memory management. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00497, EPSS Percentile is 0.41414 |
debian: CVE-2026-82253 was patched at 2026-09-16
509.
Security Feature Bypass - Rust (CVE-2026-53600) - High [417]
Description: async-tar is a tar archive reading/writing library for async
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | Rust is a modern, high-performance systems programming language focused on safety, concurrency, and memory management. | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00324, EPSS Percentile is 0.25444 |
debian: CVE-2026-53600 was patched at 2026-09-16
510.
Information Disclosure - Gitea (CVE-2026-25038) - High [416]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.75 | 14 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00482, EPSS Percentile is 0.40429 |
altlinux: CVE-2026-25038 was patched at 2026-08-27, 2026-08-29, 2026-09-04
511.
Authentication Bypass - Keycloak (CVE-2026-18215) - High [415]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00188, EPSS Percentile is 0.08591 |
altlinux: CVE-2026-18215 was patched at 2026-09-01, 2026-09-04, 2026-09-07
512.
Security Feature Bypass - FreeRDP (CVE-2026-91949) - High [415]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00446, EPSS Percentile is 0.37959 |
debian: CVE-2026-91949 was patched at 2026-09-16
513.
Security Feature Bypass - Perl (CVE-2026-72889) - High [415]
Description: Net::OAuth versions before 0.33 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00347, EPSS Percentile is 0.28116 |
debian: CVE-2026-72889 was patched at 2026-08-20
514.
Code Injection - Vim (CVE-2026-73073) - High [414]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.95 | 14 | Highly configurable command-line text editor used in development and system administration. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00147, EPSS Percentile is 0.04285 |
debian: CVE-2026-73073 was patched at 2026-08-20
redos: CVE-2026-73073 was patched at 2026-09-08
ubuntu: CVE-2026-73073 was patched at 2026-08-25, 2026-09-16
515.
Authentication Bypass - haproxy (CVE-2016-2102) - High [413]
Description: HAProxy statistics in openstack-tripleo-image-elements are non-authenticated over the network.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:haproxy:haproxy (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.8 | 10 | EPSS Probability is 0.02008, EPSS Percentile is 0.79849 |
altlinux: CVE-2016-2102 was patched at 2026-08-24
516.
Denial of Service - Chromium (CVE-2026-79090) - High [413]
Description: Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00391, EPSS Percentile is 0.32805 |
altlinux: CVE-2026-79090 was patched at 2026-08-28
debian: CVE-2026-79090 was patched at 2026-09-03, 2026-09-16
517.
Denial of Service - OpenSSL (CVE-2026-63072) - High [413]
Description: Issue summary:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00676, EPSS Percentile is 0.50529 |
almalinux: CVE-2026-63072 was patched at 2026-09-14
altlinux: CVE-2026-63072 was patched at 2026-08-26
debian: CVE-2026-63072 was patched at 2026-08-25, 2026-09-16
oraclelinux: CVE-2026-63072 was patched at 2026-09-14
redhat: CVE-2026-63072 was patched at 2026-09-14
ubuntu: CVE-2026-63072 was patched at 2026-08-25, 2026-09-16
518.
Denial of Service - PHP (CVE-2026-49289) - High [413]
Description: The SimpleSAMLphp SAML2 library is a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.0056, EPSS Percentile is 0.45162 |
debian: CVE-2026-49289 was patched at 2026-08-25
519.
Denial of Service - jackson-databind (CVE-2026-68497) - High [413]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Jackson Databind is a widely used Java library for converting JSON data to and from Java objects, providing data-binding functionality within the Jackson JSON processing ecosystem. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00581, EPSS Percentile is 0.46199 |
debian: CVE-2026-68497 was patched at 2026-09-16
520.
Security Feature Bypass - Chromium (CVE-2026-79013) - High [413]
Description: Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00472, EPSS Percentile is 0.39739 |
altlinux: CVE-2026-79013 was patched at 2026-08-28
debian: CVE-2026-79013 was patched at 2026-09-03, 2026-09-16
521.
Security Feature Bypass - Chromium (CVE-2026-79076) - High [413]
Description: Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00348, EPSS Percentile is 0.28274 |
altlinux: CVE-2026-79076 was patched at 2026-08-28
debian: CVE-2026-79076 was patched at 2026-09-03, 2026-09-16
522.
Security Feature Bypass - Chromium (CVE-2026-87499) - High [413]
Description: Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0024, EPSS Percentile is 0.15283 |
altlinux: CVE-2026-87499 was patched at 2026-09-17
debian: CVE-2026-87499 was patched at 2026-09-16
523.
Security Feature Bypass - Chromium (CVE-2026-87570) - High [413]
Description: Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00226, EPSS Percentile is 0.13484 |
altlinux: CVE-2026-87570 was patched at 2026-09-17
debian: CVE-2026-87570 was patched at 2026-09-16
524.
Security Feature Bypass - Mozilla Firefox (CVE-2026-84137) - High [413]
Description: Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02859 |
altlinux: CVE-2026-84137 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
525.
Security Feature Bypass - Safari (CVE-2026-64728) - High [413]
Description: A permissions issue was addressed with improved validation. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30953 |
altlinux: CVE-2026-64728 was patched at 2026-08-24
debian: CVE-2026-64728 was patched at 2026-08-24, 2026-08-25
ubuntu: CVE-2026-64728 was patched at 2026-08-31, 2026-09-16
526.
Information Disclosure - Chromium (CVE-2026-78955) - High [412]
Description: Observable discrepancy in PerformanceAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00441, EPSS Percentile is 0.37487 |
altlinux: CVE-2026-78955 was patched at 2026-08-28
debian: CVE-2026-78955 was patched at 2026-09-03, 2026-09-16
527.
Information Disclosure - Chromium (CVE-2026-78975) - High [412]
Description: Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00424, EPSS Percentile is 0.36095 |
altlinux: CVE-2026-78975 was patched at 2026-08-28
debian: CVE-2026-78975 was patched at 2026-09-03, 2026-09-16
528.
Information Disclosure - Chromium (CVE-2026-79023) - High [412]
Description: Incorrect authorization in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00424, EPSS Percentile is 0.36095 |
altlinux: CVE-2026-79023 was patched at 2026-08-28
debian: CVE-2026-79023 was patched at 2026-09-03, 2026-09-16
529.
Information Disclosure - Chromium (CVE-2026-87431) - High [412]
Description: Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00358, EPSS Percentile is 0.29427 |
altlinux: CVE-2026-87431 was patched at 2026-09-17
debian: CVE-2026-87431 was patched at 2026-09-16
530.
Information Disclosure - Mozilla Firefox (CVE-2026-74961) - High [412]
Description: Side-channel in the Web Audio component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00252, EPSS Percentile is 0.16787 |
altlinux: CVE-2026-74961 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
531.
Information Disclosure - Mozilla Firefox (CVE-2026-84136) - High [412]
Description: Other issue in the DOM: Navigation component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00202, EPSS Percentile is 0.10391 |
altlinux: CVE-2026-84136 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
532.
Remote Code Execution - Spring Framework (CVE-2026-47884) - High [411]
Description: Use of XsltView in a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | The Spring Framework is an application framework and inversion of control container for the Java platform | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00422, EPSS Percentile is 0.35929 |
debian: CVE-2026-47884 was patched at 2026-09-16
533.
Remote Code Execution - U-Boot (CVE-2025-70290) - High [411]
Description: An issue was discovered in Denx
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | Das U-Boot (U-Boot) is an open-source universal boot loader used on many embedded boards and SoCs to initialize hardware, provide low-level diagnostics, and load an operating system kernel. It is implemented primarily in C with board-specific assembly. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0046, EPSS Percentile is 0.38908 |
debian: CVE-2025-70290 was patched at 2026-09-16
534.
Remote Code Execution - U-Boot (CVE-2025-70293) - High [411]
Description: An issue was discovered in Denx
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | Das U-Boot (U-Boot) is an open-source universal boot loader used on many embedded boards and SoCs to initialize hardware, provide low-level diagnostics, and load an operating system kernel. It is implemented primarily in C with board-specific assembly. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00535, EPSS Percentile is 0.438 |
debian: CVE-2025-70293 was patched at 2026-09-16
535.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-71130) - High [410]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00262, EPSS Percentile is 0.18153 |
altlinux: CVE-2026-71130 was patched at 2026-08-21
536.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-71131) - High [410]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00175, EPSS Percentile is 0.07265 |
altlinux: CVE-2026-71131 was patched at 2026-08-21
537.
Remote Code Execution - Redis (CVE-2026-81934) - High [409]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Redis is an open-source in-memory storage, used as a distributed, in-memory key–value database, cache and message broker, with optional durability | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00435, EPSS Percentile is 0.37035 |
almalinux: CVE-2026-81934 was patched at 2026-09-08
altlinux: CVE-2026-81934 was patched at 2026-09-14
debian: CVE-2026-81934 was patched at 2026-09-16
oraclelinux: CVE-2026-81934 was patched at 2026-09-09, 2026-09-14
redhat: CVE-2026-81934 was patched at 2026-09-08
538.
Cross Site Scripting - Angular (CVE-2026-88057) - High [408]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00408, EPSS Percentile is 0.34597 |
debian: CVE-2026-88057 was patched at 2026-09-16
539.
Denial of Service - Apache Tomcat (CVE-2026-68763) - High [408]
Description: Uncontrolled Resource Consumption vulnerability in Apache
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.0083, EPSS Percentile is 0.55762 |
altlinux: CVE-2026-68763 was patched at 2026-08-26, 2026-08-27, 2026-09-11, 2026-09-16
debian: CVE-2026-68763 was patched at 2026-09-16
540.
Elevation of Privilege - Linux Kernel (CVE-2026-89579) - High [408]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00167, EPSS Percentile is 0.06351 |
debian: CVE-2026-89579 was patched at 2026-09-16
541.
Elevation of Privilege - Linux Kernel (CVE-2026-89638) - High [408]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0017, EPSS Percentile is 0.06702 |
debian: CVE-2026-89638 was patched at 2026-09-16
542.
Remote Code Execution - Chromium (CVE-2026-78915) - High [407]
Description: Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00115, EPSS Percentile is 0.01773 |
altlinux: CVE-2026-78915 was patched at 2026-08-28
debian: CVE-2026-78915 was patched at 2026-09-03, 2026-09-16
543.
Remote Code Execution - Chromium (CVE-2026-79057) - High [407]
Description: Race condition in Start in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging social engineering to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00091, EPSS Percentile is 0.00542 |
altlinux: CVE-2026-79057 was patched at 2026-08-28
debian: CVE-2026-79057 was patched at 2026-09-03, 2026-09-16
544.
Remote Code Execution - Chromium (CVE-2026-79245) - High [407]
Description: Use after free in UI in Google Chrome prior to 152.0.7977.65 allowed a local attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00103, EPSS Percentile is 0.01109 |
altlinux: CVE-2026-79245 was patched at 2026-08-28
debian: CVE-2026-79245 was patched at 2026-09-03, 2026-09-16
545.
Remote Code Execution - Chromium (CVE-2026-84334) - High [407]
Description: Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00085, EPSS Percentile is 0.00364 |
altlinux: CVE-2026-84334 was patched at 2026-09-03
debian: CVE-2026-84334 was patched at 2026-09-03, 2026-09-16
546.
Remote Code Execution - Chromium (CVE-2026-87457) - High [407]
Description: Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00079, EPSS Percentile is 0.00168 |
altlinux: CVE-2026-87457 was patched at 2026-09-17
debian: CVE-2026-87457 was patched at 2026-09-16
547.
Remote Code Execution - Chromium (CVE-2026-87467) - High [407]
Description: Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00079, EPSS Percentile is 0.00167 |
altlinux: CVE-2026-87467 was patched at 2026-09-17
debian: CVE-2026-87467 was patched at 2026-09-16
548.
Remote Code Execution - Chromium (CVE-2026-87509) - High [407]
Description: Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00104, EPSS Percentile is 0.01132 |
altlinux: CVE-2026-87509 was patched at 2026-09-17
debian: CVE-2026-87509 was patched at 2026-09-16
549.
Remote Code Execution - Chromium (CVE-2026-87514) - High [407]
Description: Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.02301 |
altlinux: CVE-2026-87514 was patched at 2026-09-17
debian: CVE-2026-87514 was patched at 2026-09-16
550.
Remote Code Execution - Chromium (CVE-2026-87530) - High [407]
Description: Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00135, EPSS Percentile is 0.03311 |
altlinux: CVE-2026-87530 was patched at 2026-09-17
debian: CVE-2026-87530 was patched at 2026-09-16
551.
Remote Code Execution - Chromium (CVE-2026-87554) - High [407]
Description: Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00092, EPSS Percentile is 0.0058 |
altlinux: CVE-2026-87554 was patched at 2026-09-17
debian: CVE-2026-87554 was patched at 2026-09-16
552.
Remote Code Execution - Chromium (CVE-2026-87578) - High [407]
Description: Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00131, EPSS Percentile is 0.03097 |
altlinux: CVE-2026-87578 was patched at 2026-09-17
debian: CVE-2026-87578 was patched at 2026-09-16
553.
Remote Code Execution - Chromium (CVE-2026-91727) - High [407]
Description: Incorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00093, EPSS Percentile is 0.00665 |
altlinux: CVE-2026-91727 was patched at 2026-09-17
debian: CVE-2026-91727 was patched at 2026-09-16
554.
Memory Corruption - Linux Kernel (CVE-2026-74587) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.005, EPSS Percentile is 0.41591 |
debian: CVE-2026-74587 was patched at 2026-08-25
oraclelinux: CVE-2026-74587 was patched at 2026-09-04
555.
Memory Corruption - Linux Kernel (CVE-2026-74588) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.005, EPSS Percentile is 0.4159 |
debian: CVE-2026-74588 was patched at 2026-08-25
oraclelinux: CVE-2026-74588 was patched at 2026-09-04
556.
Memory Corruption - Linux Kernel (CVE-2026-74608) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00477, EPSS Percentile is 0.40111 |
debian: CVE-2026-74608 was patched at 2026-08-25
oraclelinux: CVE-2026-74608 was patched at 2026-09-04
557.
Memory Corruption - Linux Kernel (CVE-2026-74628) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.005, EPSS Percentile is 0.41591 |
debian: CVE-2026-74628 was patched at 2026-08-25
558.
Memory Corruption - Linux Kernel (CVE-2026-74669) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00514, EPSS Percentile is 0.42539 |
debian: CVE-2026-74669 was patched at 2026-08-25
oraclelinux: CVE-2026-74669 was patched at 2026-09-04
559.
Memory Corruption - Linux Kernel (CVE-2026-74688) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.005, EPSS Percentile is 0.41591 |
debian: CVE-2026-74688 was patched at 2026-08-25
oraclelinux: CVE-2026-74688 was patched at 2026-09-04
560.
Memory Corruption - Linux Kernel (CVE-2026-74705) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.005, EPSS Percentile is 0.41591 |
debian: CVE-2026-74705 was patched at 2026-08-25
oraclelinux: CVE-2026-74705 was patched at 2026-09-04
561.
Memory Corruption - Linux Kernel (CVE-2026-74730) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0051, EPSS Percentile is 0.42265 |
debian: CVE-2026-74730 was patched at 2026-08-25
oraclelinux: CVE-2026-74730 was patched at 2026-09-04
562.
Memory Corruption - Linux Kernel (CVE-2026-74743) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00519, EPSS Percentile is 0.42834 |
debian: CVE-2026-74743 was patched at 2026-09-16
563.
Memory Corruption - Linux Kernel (CVE-2026-74744) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00519, EPSS Percentile is 0.42834 |
debian: CVE-2026-74744 was patched at 2026-09-16
564.
Memory Corruption - Linux Kernel (CVE-2026-74746) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00543, EPSS Percentile is 0.44254 |
debian: CVE-2026-74746 was patched at 2026-09-16
oraclelinux: CVE-2026-74746 was patched at 2026-09-04
565.
Memory Corruption - Linux Kernel (CVE-2026-80600) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00506, EPSS Percentile is 0.41984 |
debian: CVE-2026-80600 was patched at 2026-09-16
redos: CVE-2026-80600 was patched at 2026-09-16
566.
Memory Corruption - Linux Kernel (CVE-2026-80681) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00506, EPSS Percentile is 0.41983 |
debian: CVE-2026-80681 was patched at 2026-09-16
oraclelinux: CVE-2026-80681 was patched at 2026-09-04
567.
Memory Corruption - Linux Kernel (CVE-2026-80725) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00455, EPSS Percentile is 0.38607 |
debian: CVE-2026-80725 was patched at 2026-08-29, 2026-09-16
568.
Memory Corruption - Linux Kernel (CVE-2026-80926) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00435, EPSS Percentile is 0.37071 |
debian: CVE-2026-80926 was patched at 2026-09-16
569.
Memory Corruption - Linux Kernel (CVE-2026-89479) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00506, EPSS Percentile is 0.41984 |
debian: CVE-2026-89479 was patched at 2026-09-16
570.
Memory Corruption - Linux Kernel (CVE-2026-89493) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00632, EPSS Percentile is 0.48653 |
debian: CVE-2026-89493 was patched at 2026-09-16
571.
Memory Corruption - Linux Kernel (CVE-2026-89652) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00463, EPSS Percentile is 0.39129 |
debian: CVE-2026-89652 was patched at 2026-09-16
572.
Memory Corruption - Linux Kernel (CVE-2026-89659) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00435, EPSS Percentile is 0.37071 |
debian: CVE-2026-89659 was patched at 2026-09-16
573.
Memory Corruption - Linux Kernel (CVE-2026-89674) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00521, EPSS Percentile is 0.42954 |
debian: CVE-2026-89674 was patched at 2026-09-16
574.
Memory Corruption - Linux Kernel (CVE-2026-89708) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00435, EPSS Percentile is 0.37071 |
debian: CVE-2026-89708 was patched at 2026-09-16
575.
Security Feature Bypass - Sudo (CVE-2026-82474) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | Sudo is a widely used Unix/Linux utility that allows permitted users to execute commands with elevated (typically root) privileges while providing extensive logging and fine-grained security controls. It is a foundational component in most Linux and BSD distributions. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00131, EPSS Percentile is 0.03071 |
debian: CVE-2026-82474 was patched at 2026-09-16
576.
Remote Code Execution - NGINX (CVE-2026-78689) - High [404]
Description: Description
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Nginx is an open-source web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00453, EPSS Percentile is 0.38455 |
debian: CVE-2026-78689 was patched at 2026-09-16
577.
Remote Code Execution - TLS (CVE-2026-56684) - High [404]
Description: Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pending_list while an authenticated client can trigger CLIENT KILL, causing conn
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | TLS | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00523, EPSS Percentile is 0.43134 |
almalinux: CVE-2026-56684 was patched at 2026-09-08
altlinux: CVE-2026-56684 was patched at 2026-08-20, 2026-08-23
debian: CVE-2026-56684 was patched at 2026-08-25
oraclelinux: CVE-2026-56684 was patched at 2026-09-08
redhat: CVE-2026-56684 was patched at 2026-09-08
578.
Authentication Bypass - Keycloak (CVE-2026-14613) - High [403]
Description: A vulnerability was discovered in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.5 | 10 | CVSS Base Score is 4.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0033, EPSS Percentile is 0.26095 |
altlinux: CVE-2026-14613 was patched at 2026-08-20, 2026-08-26, 2026-08-28
579.
Authentication Bypass - Keycloak (CVE-2026-16072) - High [403]
Description: A flaw was found in the organization management component of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.5 | 10 | CVSS Base Score is 4.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00345, EPSS Percentile is 0.27947 |
altlinux: CVE-2026-16072 was patched at 2026-09-01, 2026-09-04, 2026-09-07
580.
Authentication Bypass - Keycloak (CVE-2026-16104) - High [403]
Description: A flaw was found in the authentication configuration endpoint of the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11578 |
altlinux: CVE-2026-16104 was patched at 2026-09-01, 2026-09-04, 2026-09-07
581.
Authentication Bypass - Traefik (CVE-2026-88007) - High [401]
Description: Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport instead of a transport dedicated to each frontend connection. With HTTP/3 enabled, a backend using connection-bound NTLM or Negotiate authentication, and backend keep-alive, an unrelated client can reuse a backend connection authenticated for a victim, read victim-only data, and act as that victim without the victim credentials. This issue is fixed in 2.11.57 and 3.7.13.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:traefik:traefik (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00331, EPSS Percentile is 0.26287 |
altlinux: CVE-2026-88007 was patched at 2026-09-15, 2026-09-16
582.
Authentication Bypass - nsd (CVE-2026-18664) - High [401]
Description: When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little endian systems, IPs that were meant to be allowed may be denied, and, IPs that were meant to be denied access could be allowed. An IPv4 address is compared with IPv4 ranges as unsigned 32 bit numbers directly with the endianness of the host, but the values to compare are in network byte order (big-endian). With IPv6 addresses the comparison is done in 4 times a unsigned 32 bit number comparison, again with the endianness of the host where all values are actually in network bye order.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:nlnetlabs:nsd (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0033, EPSS Percentile is 0.26183 |
altlinux: CVE-2026-18664 was patched at 2026-08-27, 2026-08-28, 2026-09-01
debian: CVE-2026-18664 was patched at 2026-09-16
583.
Code Injection - Chromium (CVE-2026-79249) - High [401]
Description: Code injection in Bisection in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted file. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00228, EPSS Percentile is 0.13726 |
altlinux: CVE-2026-79249 was patched at 2026-08-28
debian: CVE-2026-79249 was patched at 2026-09-03, 2026-09-16
584.
Denial of Service - FreeIPA (CVE-2026-79678) - High [401]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | FreeIPA is a free and open source identity management system | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00466, EPSS Percentile is 0.3929 |
altlinux: CVE-2026-79678 was patched at 2026-09-07
debian: CVE-2026-79678 was patched at 2026-09-16
585.
Denial of Service - Mozilla Firefox (CVE-2026-74985) - High [401]
Description: Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00307, EPSS Percentile is 0.23429 |
altlinux: CVE-2026-74985 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
586.
Denial of Service - OpenSSL (CVE-2026-54874) - High [401]
Description: Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00524, EPSS Percentile is 0.43142 |
almalinux: CVE-2026-54874 was patched at 2026-09-14
altlinux: CVE-2026-54874 was patched at 2026-08-26
debian: CVE-2026-54874 was patched at 2026-08-25, 2026-09-16
oraclelinux: CVE-2026-54874 was patched at 2026-09-14
redhat: CVE-2026-54874 was patched at 2026-09-14
ubuntu: CVE-2026-54874 was patched at 2026-08-25, 2026-09-16
587.
Denial of Service - OpenSSL (CVE-2026-63075) - High [401]
Description: Issue summary: When
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0048, EPSS Percentile is 0.40341 |
almalinux: CVE-2026-63075 was patched at 2026-09-14
altlinux: CVE-2026-63075 was patched at 2026-08-26
debian: CVE-2026-63075 was patched at 2026-08-25, 2026-09-16
oraclelinux: CVE-2026-63075 was patched at 2026-09-14
redhat: CVE-2026-63075 was patched at 2026-09-14
ubuntu: CVE-2026-63075 was patched at 2026-08-25, 2026-09-16
588.
Security Feature Bypass - Chromium (CVE-2026-79032) - High [401]
Description: Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00298, EPSS Percentile is 0.22501 |
altlinux: CVE-2026-79032 was patched at 2026-08-28
debian: CVE-2026-79032 was patched at 2026-09-03, 2026-09-16
589.
Security Feature Bypass - Chromium (CVE-2026-79099) - High [401]
Description: Missing authorization in Network in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00273, EPSS Percentile is 0.19787 |
altlinux: CVE-2026-79099 was patched at 2026-08-28
debian: CVE-2026-79099 was patched at 2026-09-03, 2026-09-16
590.
Security Feature Bypass - Chromium (CVE-2026-79253) - High [401]
Description: Improper input validation in Network in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16184 |
altlinux: CVE-2026-79253 was patched at 2026-08-28
debian: CVE-2026-79253 was patched at 2026-09-03, 2026-09-16
591.
Security Feature Bypass - Chromium (CVE-2026-79260) - High [401]
Description: Improper input validation in Cookies in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00249, EPSS Percentile is 0.16438 |
altlinux: CVE-2026-79260 was patched at 2026-08-28
debian: CVE-2026-79260 was patched at 2026-09-03, 2026-09-16
592.
Security Feature Bypass - Chromium (CVE-2026-79288) - High [401]
Description: Improper input validation in Autofill in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00312, EPSS Percentile is 0.24037 |
altlinux: CVE-2026-79288 was patched at 2026-08-28
debian: CVE-2026-79288 was patched at 2026-09-03, 2026-09-16
593.
Security Feature Bypass - Chromium (CVE-2026-87541) - High [401]
Description: Information leak in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00249, EPSS Percentile is 0.16438 |
altlinux: CVE-2026-87541 was patched at 2026-09-17
debian: CVE-2026-87541 was patched at 2026-09-16
594.
Security Feature Bypass - Chromium (CVE-2026-87591) - High [401]
Description: Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00242, EPSS Percentile is 0.15566 |
altlinux: CVE-2026-87591 was patched at 2026-09-17
debian: CVE-2026-87591 was patched at 2026-09-16
595.
Security Feature Bypass - Chromium (CVE-2026-87600) - High [401]
Description: Improper input validation in Safebrowsing in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00272, EPSS Percentile is 0.19704 |
altlinux: CVE-2026-87600 was patched at 2026-09-17
debian: CVE-2026-87600 was patched at 2026-09-16
596.
Security Feature Bypass - Chromium (CVE-2026-87608) - High [401]
Description: Improper certificate validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00206, EPSS Percentile is 0.10936 |
altlinux: CVE-2026-87608 was patched at 2026-09-17
debian: CVE-2026-87608 was patched at 2026-09-16
597.
Security Feature Bypass - Chromium (CVE-2026-87626) - High [401]
Description: Incorrect authorization in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00246, EPSS Percentile is 0.16006 |
altlinux: CVE-2026-87626 was patched at 2026-09-17
debian: CVE-2026-87626 was patched at 2026-09-16
598.
Security Feature Bypass - PHP (CVE-2026-56706) - High [401]
Description: Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value in every token (format (rand XOR secret):rand), allowing anyone who observes a single CSRF token (e.g., via network sniffing, log files, Referrer header, or XSS) to recover the session secret with a single XOR operation and forge unlimited valid tokens. The implementation is further weakened by a low-entropy session token (rand(1,1e6), ~20 bits) that permits blind brute-force, and by use of loose comparison (==) in token verification, enabling
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00294, EPSS Percentile is 0.22051 |
debian: CVE-2026-56706 was patched at 2026-09-16
599.
Information Disclosure - Chromium (CVE-2026-78893) - High [400]
Description: Information leak in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00364, EPSS Percentile is 0.30003 |
altlinux: CVE-2026-78893 was patched at 2026-08-28
debian: CVE-2026-78893 was patched at 2026-09-03, 2026-09-16
600.
Information Disclosure - Chromium (CVE-2026-78960) - High [400]
Description: Information leak in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.25313 |
altlinux: CVE-2026-78960 was patched at 2026-08-28
debian: CVE-2026-78960 was patched at 2026-09-03, 2026-09-16
601.
Information Disclosure - Chromium (CVE-2026-79024) - High [400]
Description: Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00377, EPSS Percentile is 0.3139 |
altlinux: CVE-2026-79024 was patched at 2026-08-28
debian: CVE-2026-79024 was patched at 2026-09-03, 2026-09-16
602.
Information Disclosure - Chromium (CVE-2026-79038) - High [400]
Description: Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00384, EPSS Percentile is 0.3209 |
altlinux: CVE-2026-79038 was patched at 2026-08-28
debian: CVE-2026-79038 was patched at 2026-09-03, 2026-09-16
603.
Information Disclosure - Chromium (CVE-2026-79176) - High [400]
Description: UI misrepresentation in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00348, EPSS Percentile is 0.28273 |
altlinux: CVE-2026-79176 was patched at 2026-08-28
debian: CVE-2026-79176 was patched at 2026-09-03, 2026-09-16
604.
Information Disclosure - Chromium (CVE-2026-87443) - High [400]
Description: Missing authorization in Actor in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00337, EPSS Percentile is 0.26918 |
altlinux: CVE-2026-87443 was patched at 2026-09-17
debian: CVE-2026-87443 was patched at 2026-09-16
605.
Information Disclosure - Chromium (CVE-2026-87450) - High [400]
Description: Incorrect authorization in Permissions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00307, EPSS Percentile is 0.2346 |
altlinux: CVE-2026-87450 was patched at 2026-09-17
debian: CVE-2026-87450 was patched at 2026-09-16
606.
Information Disclosure - Chromium (CVE-2026-87478) - High [400]
Description: Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0035, EPSS Percentile is 0.28412 |
altlinux: CVE-2026-87478 was patched at 2026-09-17
debian: CVE-2026-87478 was patched at 2026-09-16
607.
Information Disclosure - Mozilla Firefox (CVE-2026-74954) - High [400]
Description: Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00256, EPSS Percentile is 0.17431 |
altlinux: CVE-2026-74954 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
608.
Information Disclosure - Mozilla Firefox (CVE-2026-84130) - High [400]
Description: Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00256, EPSS Percentile is 0.17432 |
altlinux: CVE-2026-84130 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
609.
Information Disclosure - Mozilla Firefox (CVE-2026-84132) - High [400]
Description: Information disclosure in the Networking: HTTP component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00256, EPSS Percentile is 0.17432 |
altlinux: CVE-2026-84132 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
610.
Information Disclosure - Netty (CVE-2026-48040) - High [400]
Description: The
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Netty is a non-blocking I/O client-server framework for the development of Java network applications such as protocol servers and clients | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00174, EPSS Percentile is 0.07151 |
redos: CVE-2026-48040 was patched at 2026-09-04
611.
Authentication Bypass - Oracle MySQL (CVE-2026-60725) - Medium [398]
Description: Vulnerability in the MySQL Router product of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | MySQL is an open-source relational database management system | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00317, EPSS Percentile is 0.24664 |
altlinux: CVE-2026-60725 was patched at 2026-08-24
612.
Information Disclosure - Visual Studio 2022 (CVE-2026-62898) - Medium [398]
Description: Use after free in Microsoft QUIC allows an unauthorized attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Product detected by a:microsoft:visual_studio_2022 (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.01112, EPSS Percentile is 0.64305 |
altlinux: CVE-2026-62898 was patched at 2026-08-31, 2026-09-02
redos: CVE-2026-62898 was patched at 2026-09-07
613.
Security Feature Bypass - Thunderbird (CVE-2026-84637) - Medium [398]
Description: Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:mozilla:thunderbird (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0034, EPSS Percentile is 0.27291 |
altlinux: CVE-2026-84637 was patched at 2026-09-03, 2026-09-09
614.
Elevation of Privilege - Linux Kernel (CVE-2026-80560) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02908 |
debian: CVE-2026-80560 was patched at 2026-09-16
615.
Security Feature Bypass - Dovecot (CVE-2026-33604) - Medium [397]
Description: An attacker that can get
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.85 | 14 | Open-source IMAP and POP3 email server with authentication and indexing features. | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00269, EPSS Percentile is 0.19217 |
altlinux: CVE-2026-33604 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-33604 was patched at 2026-09-16
616.
Remote Code Execution - Chromium (CVE-2026-79286) - Medium [395]
Description: Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00094, EPSS Percentile is 0.00692 |
altlinux: CVE-2026-79286 was patched at 2026-08-28
debian: CVE-2026-79286 was patched at 2026-09-03, 2026-09-16
617.
Remote Code Execution - Chromium (CVE-2026-91734) - Medium [395]
Description: Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0009, EPSS Percentile is 0.00514 |
altlinux: CVE-2026-91734 was patched at 2026-09-17
debian: CVE-2026-91734 was patched at 2026-09-16
618.
Remote Code Execution - Mozilla Firefox (CVE-2026-90648) - Medium [395]
Description: wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a "table flip" attack. It does not check the return value of calloc() in wasm_rt_allocate_funcref_table() (wasm2c/wasm-rt-impl-tableops.inc). When the funcref table allocation fails, table->data is left NULL while table->size keeps the guest-declared element count; thus, bounds checks still pass and table element accesses resolve to absolute memory addresses (i * sizeof(wasm_rt_funcref_t)). This gives arbitrary read and write of host process memory and - via table.get, table.set, and call_indirect - arbitrary
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.0015, EPSS Percentile is 0.04516 |
debian: CVE-2026-90648 was patched at 2026-09-16
619.
Authentication Bypass - strongSwan (CVE-2026-78135) - Medium [394]
Description: libcharon in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | strongSwan is an open source IPsec-based VPN solution that provides secure network connectivity using IKEv1 and IKEv2 protocols, widely used on Linux systems for site-to-site and remote access VPN deployments. | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00336, EPSS Percentile is 0.26892 |
altlinux: CVE-2026-78135 was patched at 2026-09-11
debian: CVE-2026-78135 was patched at 2026-09-07, 2026-09-16
620.
Denial of Service - Linux Kernel (CVE-2026-81003) - Medium [394]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00313, EPSS Percentile is 0.24247 |
debian: CVE-2026-81003 was patched at 2026-09-16
621.
Memory Corruption - Linux Kernel (CVE-2026-80589) - Medium [394]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00375, EPSS Percentile is 0.31166 |
debian: CVE-2026-80589 was patched at 2026-09-16
622.
Memory Corruption - Linux Kernel (CVE-2026-80603) - Medium [394]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00425, EPSS Percentile is 0.36126 |
debian: CVE-2026-80603 was patched at 2026-09-16
oraclelinux: CVE-2026-80603 was patched at 2026-09-04
redos: CVE-2026-80603 was patched at 2026-09-16
623.
Memory Corruption - Linux Kernel (CVE-2026-89511) - Medium [394]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00716, EPSS Percentile is 0.52057 |
debian: CVE-2026-89511 was patched at 2026-09-16
624.
Memory Corruption - Linux Kernel (CVE-2026-89528) - Medium [394]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00627, EPSS Percentile is 0.48423 |
debian: CVE-2026-89528 was patched at 2026-09-16
625.
Memory Corruption - Linux Kernel (CVE-2026-89532) - Medium [394]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00509, EPSS Percentile is 0.42178 |
debian: CVE-2026-89532 was patched at 2026-09-16
626.
Memory Corruption - Linux Kernel (CVE-2026-89544) - Medium [394]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00567, EPSS Percentile is 0.45535 |
debian: CVE-2026-89544 was patched at 2026-09-16
627.
Memory Corruption - Linux Kernel (CVE-2026-89650) - Medium [394]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00509, EPSS Percentile is 0.42178 |
debian: CVE-2026-89650 was patched at 2026-09-16
628.
Memory Corruption - Linux Kernel (CVE-2026-89663) - Medium [394]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00455, EPSS Percentile is 0.38577 |
debian: CVE-2026-89663 was patched at 2026-09-16
629.
Memory Corruption - Linux Kernel (CVE-2026-89671) - Medium [394]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00487, EPSS Percentile is 0.40754 |
debian: CVE-2026-89671 was patched at 2026-09-16
630.
Memory Corruption - Linux Kernel (CVE-2026-89696) - Medium [394]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00762, EPSS Percentile is 0.53601 |
debian: CVE-2026-89696 was patched at 2026-09-16
631.
Command Injection - Jetty (CVE-2026-19203) - Medium [392]
Description: A client may issue specially crafted HTTP/1.1 chunked requests to a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.6 | 14 | Jetty is a Java based web server and servlet engine | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00289, EPSS Percentile is 0.21512 |
debian: CVE-2026-19203 was patched at 2026-09-16
632.
Elevation of Privilege - RPC (CVE-2026-18917) - Medium [392]
Description: A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Remote Procedure Call Runtime | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0016, EPSS Percentile is 0.05546 |
debian: CVE-2026-18917 was patched at 2026-08-25
633.
Remote Code Execution - .NET (CVE-2026-62871) - Medium [392]
Description: Out-of-bounds write in .NET allows an unauthorized attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:microsoft:.net (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00396, EPSS Percentile is 0.33386 |
altlinux: CVE-2026-62871 was patched at 2026-08-31, 2026-09-02
redos: CVE-2026-62871 was patched at 2026-09-07
634.
Security Feature Bypass - MongoDB (CVE-2026-18691) - Medium [391]
Description: An issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00238, EPSS Percentile is 0.15036 |
altlinux: CVE-2026-18691 was patched at 2026-08-26
635.
Denial of Service - Chromium (CVE-2026-79226) - Medium [389]
Description: Improper privilege management in Regional Capabilities in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.003, EPSS Percentile is 0.22731 |
altlinux: CVE-2026-79226 was patched at 2026-08-28
debian: CVE-2026-79226 was patched at 2026-09-03, 2026-09-16
636.
Denial of Service - FreeIPA (CVE-2026-73197) - Medium [389]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | FreeIPA is a free and open source identity management system | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00333, EPSS Percentile is 0.2644 |
altlinux: CVE-2026-73197 was patched at 2026-08-20
debian: CVE-2026-73197 was patched at 2026-08-25
637.
Denial of Service - FreeIPA (CVE-2026-73198) - Medium [389]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | FreeIPA is a free and open source identity management system | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00333, EPSS Percentile is 0.2644 |
altlinux: CVE-2026-73198 was patched at 2026-08-20
debian: CVE-2026-73198 was patched at 2026-08-25
638.
Denial of Service - Mozilla Firefox (CVE-2026-84139) - Medium [389]
Description: Clickjacking issue in the DOM: Events component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07737 |
altlinux: CVE-2026-84139 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
639.
Denial of Service - Mozilla Firefox (CVE-2026-92015) - Medium [389]
Description: Privilege escalation in the WebExtensions component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00271, EPSS Percentile is 0.19393 |
altlinux: CVE-2026-92015 was patched at 2026-09-16
debian: CVE-2026-92015 was patched at 2026-09-16, 2026-09-17
640.
Denial of Service - Mozilla Firefox (CVE-2026-92017) - Medium [389]
Description: Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00249, EPSS Percentile is 0.16414 |
altlinux: CVE-2026-92017 was patched at 2026-09-16
debian: CVE-2026-92017 was patched at 2026-09-16, 2026-09-17
641.
Denial of Service - Mozilla Firefox (CVE-2026-92053) - Medium [389]
Description: Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00262, EPSS Percentile is 0.18162 |
altlinux: CVE-2026-92053 was patched at 2026-09-16
642.
Denial of Service - Mozilla Firefox (CVE-2026-92055) - Medium [389]
Description: Privilege escalation in the DevTools component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00241, EPSS Percentile is 0.15392 |
altlinux: CVE-2026-92055 was patched at 2026-09-16
643.
Denial of Service - Safari (CVE-2026-43804) - Medium [389]
Description: This issue was addressed through improved state management. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00433, EPSS Percentile is 0.36904 |
altlinux: CVE-2026-43804 was patched at 2026-08-24
debian: CVE-2026-43804 was patched at 2026-08-24, 2026-08-25
ubuntu: CVE-2026-43804 was patched at 2026-08-31, 2026-09-16
644.
Security Feature Bypass - Chromium (CVE-2026-78966) - Medium [389]
Description: Externally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00455, EPSS Percentile is 0.38559 |
altlinux: CVE-2026-78966 was patched at 2026-08-28
debian: CVE-2026-78966 was patched at 2026-09-03, 2026-09-16
645.
Security Feature Bypass - Chromium (CVE-2026-79017) - Medium [389]
Description: Race condition in Extensions in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.13933 |
altlinux: CVE-2026-79017 was patched at 2026-08-28
debian: CVE-2026-79017 was patched at 2026-09-03, 2026-09-16
646.
Security Feature Bypass - Chromium (CVE-2026-79094) - Medium [389]
Description: Race condition in Workers in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00227, EPSS Percentile is 0.13503 |
altlinux: CVE-2026-79094 was patched at 2026-08-28
debian: CVE-2026-79094 was patched at 2026-09-03, 2026-09-16
647.
Security Feature Bypass - Chromium (CVE-2026-79123) - Medium [389]
Description: Improper input validation in NTP Footer in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00225, EPSS Percentile is 0.13337 |
altlinux: CVE-2026-79123 was patched at 2026-08-28
debian: CVE-2026-79123 was patched at 2026-09-03, 2026-09-16
648.
Security Feature Bypass - Chromium (CVE-2026-79243) - Medium [389]
Description: Improper input validation in ReadingList in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00225, EPSS Percentile is 0.13338 |
altlinux: CVE-2026-79243 was patched at 2026-08-28
debian: CVE-2026-79243 was patched at 2026-09-03, 2026-09-16
649.
Security Feature Bypass - Chromium (CVE-2026-84332) - Medium [389]
Description: Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07343 |
altlinux: CVE-2026-84332 was patched at 2026-09-03
debian: CVE-2026-84332 was patched at 2026-09-03, 2026-09-16
650.
Security Feature Bypass - Chromium (CVE-2026-84357) - Medium [389]
Description: Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07334 |
altlinux: CVE-2026-84357 was patched at 2026-09-03
debian: CVE-2026-84357 was patched at 2026-09-03, 2026-09-16
651.
Security Feature Bypass - Chromium (CVE-2026-87590) - Medium [389]
Description: Improper input validation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via crafted network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00303, EPSS Percentile is 0.22985 |
altlinux: CVE-2026-87590 was patched at 2026-09-17
debian: CVE-2026-87590 was patched at 2026-09-16
652.
Security Feature Bypass - Chromium (CVE-2026-87603) - Medium [389]
Description: Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00217, EPSS Percentile is 0.12259 |
altlinux: CVE-2026-87603 was patched at 2026-09-17
debian: CVE-2026-87603 was patched at 2026-09-16
653.
Security Feature Bypass - Chromium (CVE-2026-87610) - Medium [389]
Description: Incorrect authorization in Omnibox in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00217, EPSS Percentile is 0.12259 |
altlinux: CVE-2026-87610 was patched at 2026-09-17
debian: CVE-2026-87610 was patched at 2026-09-16
654.
Security Feature Bypass - Mozilla Firefox (CVE-2026-74981) - Medium [389]
Description: Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00148, EPSS Percentile is 0.04351 |
altlinux: CVE-2026-74981 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
655.
Information Disclosure - Chromium (CVE-2026-78897) - Medium [388]
Description: Missing authorization in BrowserTag in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00271, EPSS Percentile is 0.19437 |
altlinux: CVE-2026-78897 was patched at 2026-08-28
debian: CVE-2026-78897 was patched at 2026-09-03, 2026-09-16
656.
Information Disclosure - Chromium (CVE-2026-78981) - Medium [388]
Description: Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to potentially obtain sensitive information via a local program. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00258, EPSS Percentile is 0.177 |
altlinux: CVE-2026-78981 was patched at 2026-08-28
debian: CVE-2026-78981 was patched at 2026-09-03, 2026-09-16
657.
Information Disclosure - Chromium (CVE-2026-79018) - Medium [388]
Description: Information leak in FoldableAPIs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00299, EPSS Percentile is 0.22609 |
altlinux: CVE-2026-79018 was patched at 2026-08-28
debian: CVE-2026-79018 was patched at 2026-09-03, 2026-09-16
658.
Information Disclosure - Chromium (CVE-2026-79075) - Medium [388]
Description: Information leak in Geolocation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00299, EPSS Percentile is 0.22609 |
altlinux: CVE-2026-79075 was patched at 2026-08-28
debian: CVE-2026-79075 was patched at 2026-09-03, 2026-09-16
659.
Information Disclosure - Chromium (CVE-2026-79124) - Medium [388]
Description: Information leak in Intents in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16182 |
altlinux: CVE-2026-79124 was patched at 2026-08-28
debian: CVE-2026-79124 was patched at 2026-09-03, 2026-09-16
660.
Information Disclosure - Chromium (CVE-2026-79125) - Medium [388]
Description: Information leak in XR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16183 |
altlinux: CVE-2026-79125 was patched at 2026-08-28
debian: CVE-2026-79125 was patched at 2026-09-03, 2026-09-16
661.
Information Disclosure - Chromium (CVE-2026-79133) - Medium [388]
Description: Incorrect authorization in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00238, EPSS Percentile is 0.15005 |
altlinux: CVE-2026-79133 was patched at 2026-08-28
debian: CVE-2026-79133 was patched at 2026-09-03, 2026-09-16
662.
Information Disclosure - Chromium (CVE-2026-79134) - Medium [388]
Description: Incorrect authorization in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00238, EPSS Percentile is 0.15005 |
altlinux: CVE-2026-79134 was patched at 2026-08-28
debian: CVE-2026-79134 was patched at 2026-09-03, 2026-09-16
663.
Information Disclosure - Chromium (CVE-2026-79234) - Medium [388]
Description: Injection in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16184 |
altlinux: CVE-2026-79234 was patched at 2026-08-28
debian: CVE-2026-79234 was patched at 2026-09-03, 2026-09-16
664.
Information Disclosure - Chromium (CVE-2026-79246) - Medium [388]
Description: Information leak in DataTransfer in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00299, EPSS Percentile is 0.22608 |
altlinux: CVE-2026-79246 was patched at 2026-08-28
debian: CVE-2026-79246 was patched at 2026-09-03, 2026-09-16
665.
Information Disclosure - Chromium (CVE-2026-79271) - Medium [388]
Description: Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00312, EPSS Percentile is 0.24038 |
altlinux: CVE-2026-79271 was patched at 2026-08-28
debian: CVE-2026-79271 was patched at 2026-09-03, 2026-09-16
666.
Information Disclosure - Chromium (CVE-2026-79291) - Medium [388]
Description: Information leak in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16184 |
altlinux: CVE-2026-79291 was patched at 2026-08-28
debian: CVE-2026-79291 was patched at 2026-09-03, 2026-09-16
667.
Information Disclosure - Chromium (CVE-2026-79293) - Medium [388]
Description: Information leak in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00312, EPSS Percentile is 0.24037 |
altlinux: CVE-2026-79293 was patched at 2026-08-28
debian: CVE-2026-79293 was patched at 2026-09-03, 2026-09-16
668.
Information Disclosure - Chromium (CVE-2026-87437) - Medium [388]
Description: Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00291, EPSS Percentile is 0.21692 |
altlinux: CVE-2026-87437 was patched at 2026-09-17
debian: CVE-2026-87437 was patched at 2026-09-16
669.
Information Disclosure - Chromium (CVE-2026-87454) - Medium [388]
Description: Information leak in Enterprise in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16184 |
altlinux: CVE-2026-87454 was patched at 2026-09-17
debian: CVE-2026-87454 was patched at 2026-09-16
670.
Information Disclosure - Chromium (CVE-2026-87459) - Medium [388]
Description: Observable discrepancy in Select in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16183 |
altlinux: CVE-2026-87459 was patched at 2026-09-17
debian: CVE-2026-87459 was patched at 2026-09-16
671.
Information Disclosure - Chromium (CVE-2026-87476) - Medium [388]
Description: Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00278, EPSS Percentile is 0.2032 |
altlinux: CVE-2026-87476 was patched at 2026-09-17
debian: CVE-2026-87476 was patched at 2026-09-16
672.
Information Disclosure - Chromium (CVE-2026-87477) - Medium [388]
Description: Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00291, EPSS Percentile is 0.21692 |
altlinux: CVE-2026-87477 was patched at 2026-09-17
debian: CVE-2026-87477 was patched at 2026-09-16
673.
Information Disclosure - Chromium (CVE-2026-87545) - Medium [388]
Description: Information leak in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16183 |
altlinux: CVE-2026-87545 was patched at 2026-09-17
debian: CVE-2026-87545 was patched at 2026-09-16
674.
Information Disclosure - Chromium (CVE-2026-87565) - Medium [388]
Description: Information leak in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00299, EPSS Percentile is 0.22609 |
altlinux: CVE-2026-87565 was patched at 2026-09-17
debian: CVE-2026-87565 was patched at 2026-09-16
675.
Information Disclosure - Zabbix (CVE-2026-23937) - Medium [388]
Description: The
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Zabbix is an open-source software tool to monitor IT infrastructure such as networks, servers, virtual machines, and cloud services | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00279, EPSS Percentile is 0.20393 |
altlinux: CVE-2026-23937 was patched at 2026-08-26, 2026-08-27, 2026-08-28
debian: CVE-2026-23937 was patched at 2026-08-20
676.
Remote Code Execution - GVfs (CVE-2026-84268) - Medium [388]
Description: A flaw was found in the SFTP backend in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | GVfs (GNOME Virtual File System) is userspace virtual filesystem software for GNOME that provides backends (including FTP) to access different remote and local file systems transparently. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00328, EPSS Percentile is 0.2587 |
debian: CVE-2026-84268 was patched at 2026-09-16
677.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-71116) - Medium [386]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00136, EPSS Percentile is 0.03434 |
altlinux: CVE-2026-71116 was patched at 2026-08-21
678.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-71126) - Medium [386]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02226 |
altlinux: CVE-2026-71126 was patched at 2026-08-21
679.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-71129) - Medium [386]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.03302 |
altlinux: CVE-2026-71129 was patched at 2026-08-21
680.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-71141) - Medium [386]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00154, EPSS Percentile is 0.04914 |
altlinux: CVE-2026-71141 was patched at 2026-08-21
681.
Security Feature Bypass - Visual Studio 2022 (CVE-2026-62902) - Medium [386]
Description: Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:microsoft:visual_studio_2022 (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00778, EPSS Percentile is 0.54124 |
altlinux: CVE-2026-62902 was patched at 2026-08-31, 2026-09-02
redos: CVE-2026-62902 was patched at 2026-09-07
682.
Remote Code Execution - Python (CVE-2026-34398) - Medium [385]
Description: FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mod/BIM/bimcommands/BimProjectManager.py in the BIM Project Manager Load Template flow passes attacker-controlled FCStd Meta property values for wpposition, wpu, wpv, and wpaxis directly to eval(), allowing arbitrary
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00219, EPSS Percentile is 0.12496 |
debian: CVE-2026-34398 was patched at 2026-08-25, 2026-08-26
683.
Security Feature Bypass - .NET (CVE-2026-58649) - Medium [384]
Description: Origin validation error in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.7 | 14 | .NET | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00272, EPSS Percentile is 0.19672 |
almalinux: CVE-2026-58649 was patched at 2026-09-15
oraclelinux: CVE-2026-58649 was patched at 2026-09-15, 2026-09-16
ubuntu: CVE-2026-58649 was patched at 2026-09-10, 2026-09-16
684.
Arbitrary File Writing - Ant (CVE-2026-78254) - Medium [383]
Description: The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0.5 | 14 | Product detected by a:apache:ant (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0054, EPSS Percentile is 0.44057 |
debian: CVE-2026-78254 was patched at 2026-09-16
685.
Remote Code Execution - PHP (CVE-2026-59944) - Medium [383]
Description: Composer is a dependency Manager for the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-59944 was patched at 2026-09-16
686.
Authentication Bypass - MongoDB (CVE-2026-82070) - Medium [382]
Description: A security issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00248, EPSS Percentile is 0.16257 |
altlinux: CVE-2026-82070 was patched at 2026-09-09, 2026-09-10
687.
Memory Corruption - Linux Kernel (CVE-2026-74678) - Medium [382]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00479, EPSS Percentile is 0.40226 |
debian: CVE-2026-74678 was patched at 2026-08-25
oraclelinux: CVE-2026-74678 was patched at 2026-09-04
688.
Memory Corruption - Linux Kernel (CVE-2026-80614) - Medium [382]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00432, EPSS Percentile is 0.3673 |
debian: CVE-2026-80614 was patched at 2026-09-16
689.
Memory Corruption - Linux Kernel (CVE-2026-89569) - Medium [382]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00339, EPSS Percentile is 0.27268 |
debian: CVE-2026-89569 was patched at 2026-09-16
690.
Memory Corruption - Linux Kernel (CVE-2026-89729) - Medium [382]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0035, EPSS Percentile is 0.28508 |
debian: CVE-2026-89729 was patched at 2026-09-16
691.
Path Traversal - Windows Kernel (CVE-2026-19672) - Medium [382]
Description: The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given. Only empty directories are created outside the destination. Member contents are still extracted inside it. To return to the destination the member's name must contain the destination directory's own final component, so extraction into a secure randomised directory is not affected. This affects POSIX platforms only. On
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.9 | 14 | Windows Kernel | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00409, EPSS Percentile is 0.34645 |
debian: CVE-2026-19672 was patched at 2026-09-16
692.
Remote Code Execution - GPU Display Driver (CVE-2026-24187) - Medium [380]
Description: NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:nvidia:gpu_display_driver (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00188, EPSS Percentile is 0.08648 |
redos: CVE-2026-24187 was patched at 2026-09-08
693.
Remote Code Execution - Visual Studio 2022 (CVE-2026-70354) - Medium [380]
Description: Out-of-bounds write in .NET allows an unauthorized attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:microsoft:visual_studio_2022 (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00294, EPSS Percentile is 0.22066 |
altlinux: CVE-2026-70354 was patched at 2026-08-31, 2026-09-02
redos: CVE-2026-70354 was patched at 2026-09-07
694.
Authentication Bypass - Chromium (CVE-2026-79201) - Medium [379]
Description: Improper access control in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00266, EPSS Percentile is 0.18876 |
altlinux: CVE-2026-79201 was patched at 2026-08-28
debian: CVE-2026-79201 was patched at 2026-09-03, 2026-09-16
695.
Cross Site Scripting - Grafana (CVE-2026-17033) - Medium [379]
Description: An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert containing a controlled generatorURL. The attacker is authorized to create the alert, but not to execute script in another user's
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.85 | 14 | Grafana is an open-source analytics and monitoring platform that provides dashboards and visualization tools for metrics collected from various data sources. | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11392 |
redos: CVE-2026-17033 was patched at 2026-09-08
696.
Information Disclosure - FreeRDP (CVE-2026-91946) - Medium [379]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00427, EPSS Percentile is 0.36312 |
debian: CVE-2026-91946 was patched at 2026-09-16
697.
Remote Code Execution - FFmpeg (CVE-2026-18393) - Medium [378]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.1722 |
debian: CVE-2026-18393 was patched at 2026-09-16
698.
Remote Code Execution - RPM (CVE-2026-84233) - Medium [378]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | RPM is a package management system and software packaging format widely used by Linux distributions in the Red Hat ecosystem and related systems, including tools for building RPM packages. | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0013, EPSS Percentile is 0.03027 |
debian: CVE-2026-84233 was patched at 2026-09-16
699.
Authentication Bypass - Traefik (CVE-2026-88009) - Medium [377]
Description: Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.57, and 3.7.13, Traefik accepts a rootless HTTP/1 request target that Go stores in URL.Opaque while leaving URL.Path empty. The rewriteRequestBuilder path evaluates routing, path sanitization, forwardAuth, encodedCharacters, and access logging against a path normalized to / but forwards URL.Opaque verbatim to the backend, allowing cross-vhost routing bypass, path-scoped
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:traefik:traefik (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0027, EPSS Percentile is 0.19219 |
altlinux: CVE-2026-88009 was patched at 2026-09-15, 2026-09-16
700.
Authentication Bypass - libevent (CVE-2026-63379) - Medium [377]
Description: Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | libevent is a portable event notification library that provides an asynchronous event loop and networking primitives for applications using sockets, timers, signals, DNS, and HTTP. | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00518, EPSS Percentile is 0.42816 |
debian: CVE-2026-63379 was patched at 2026-08-25, 2026-09-11
701.
Authentication Bypass - nsd (CVE-2026-19538) - Medium [377]
Description: The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:nlnetlabs:nsd (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00302, EPSS Percentile is 0.22916 |
altlinux: CVE-2026-19538 was patched at 2026-08-27, 2026-08-28, 2026-09-01
debian: CVE-2026-19538 was patched at 2026-09-16
702.
Denial of Service - Mozilla Firefox (CVE-2026-74950) - Medium [377]
Description: Privilege escalation in the Downloads API component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00221, EPSS Percentile is 0.12809 |
altlinux: CVE-2026-74950 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
703.
Denial of Service - Mozilla Firefox (CVE-2026-74952) - Medium [377]
Description: Privilege escalation in the Application Update component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00226, EPSS Percentile is 0.13426 |
altlinux: CVE-2026-74952 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
704.
Denial of Service - Mozilla Firefox (CVE-2026-74955) - Medium [377]
Description: Privilege escalation in the Request Handling component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00221, EPSS Percentile is 0.12809 |
altlinux: CVE-2026-74955 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
705.
Denial of Service - Mozilla Firefox (CVE-2026-74958) - Medium [377]
Description: Information disclosure in the WebRTC component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00264, EPSS Percentile is 0.1843 |
altlinux: CVE-2026-74958 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
706.
Denial of Service - Mozilla Firefox (CVE-2026-74982) - Medium [377]
Description: Denial-of-service in the Widget component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00311, EPSS Percentile is 0.2397 |
altlinux: CVE-2026-74982 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
707.
Denial of Service - Mozilla Firefox (CVE-2026-92033) - Medium [377]
Description: Privilege escalation in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10746 |
altlinux: CVE-2026-92033 was patched at 2026-09-16
708.
Denial of Service - Mozilla Firefox (CVE-2026-92047) - Medium [377]
Description: Privilege escalation in the Crash Reporting component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00236, EPSS Percentile is 0.14748 |
altlinux: CVE-2026-92047 was patched at 2026-09-16
709.
Denial of Service - Mozilla Firefox (CVE-2026-92062) - Medium [377]
Description: Privilege escalation in the Session Restore component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00236, EPSS Percentile is 0.14748 |
altlinux: CVE-2026-92062 was patched at 2026-09-16
710.
Denial of Service - Mozilla Firefox (CVE-2026-92073) - Medium [377]
Description: Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00236, EPSS Percentile is 0.14747 |
altlinux: CVE-2026-92073 was patched at 2026-09-16
711.
Denial of Service - Node.js (CVE-2026-87908) - Medium [377]
Description: multiparty is a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00297, EPSS Percentile is 0.22389 |
debian: CVE-2026-87908 was patched at 2026-09-16
712.
Denial of Service - OpenSSL (CVE-2026-63074) - Medium [377]
Description: Issue summary: The
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00495, EPSS Percentile is 0.41289 |
almalinux: CVE-2026-63074 was patched at 2026-09-14
altlinux: CVE-2026-63074 was patched at 2026-08-26
debian: CVE-2026-63074 was patched at 2026-08-25, 2026-09-16
oraclelinux: CVE-2026-63074 was patched at 2026-09-14
redhat: CVE-2026-63074 was patched at 2026-09-14
ubuntu: CVE-2026-63074 was patched at 2026-08-25, 2026-09-16
713.
Denial of Service - PHP (CVE-2024-58382) - Medium [377]
Description: league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allow attackers to cause
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00278, EPSS Percentile is 0.20378 |
debian: CVE-2024-58382 was patched at 2026-09-16
714.
Incorrect Calculation - Mozilla Firefox (CVE-2026-84141) - Medium [377]
Description: Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00342, EPSS Percentile is 0.27558 |
altlinux: CVE-2026-84141 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
715.
Information Disclosure - Angular (CVE-2026-88059) - Medium [377]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.4 | 10 | CVSS Base Score is 4.0. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00296, EPSS Percentile is 0.22313 |
debian: CVE-2026-88059 was patched at 2026-09-16
716.
Memory Corruption - Mozilla Firefox (CVE-2026-74988) - Medium [377]
Description: Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0035, EPSS Percentile is 0.28468 |
altlinux: CVE-2026-74988 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
717.
Memory Corruption - Mozilla Firefox (CVE-2026-74989) - Medium [377]
Description: Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00332, EPSS Percentile is 0.26332 |
altlinux: CVE-2026-74989 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
718.
Memory Corruption - Safari (CVE-2026-64757) - Medium [377]
Description: A memory corruption issue was addressed with improved state management. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00468, EPSS Percentile is 0.39454 |
altlinux: CVE-2026-64757 was patched at 2026-08-24
debian: CVE-2026-64757 was patched at 2026-08-24, 2026-08-25
ubuntu: CVE-2026-64757 was patched at 2026-08-31, 2026-09-16
719.
Memory Corruption - Safari (CVE-2026-64783) - Medium [377]
Description: A use-after-free issue was addressed with improved memory management. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00429, EPSS Percentile is 0.36485 |
altlinux: CVE-2026-64783 was patched at 2026-08-24
debian: CVE-2026-64783 was patched at 2026-08-24, 2026-08-25
ubuntu: CVE-2026-64783 was patched at 2026-08-31, 2026-09-16
720.
Security Feature Bypass - Chromium (CVE-2026-78940) - Medium [377]
Description: Improper initialization in Network in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00376, EPSS Percentile is 0.31229 |
altlinux: CVE-2026-78940 was patched at 2026-08-28
debian: CVE-2026-78940 was patched at 2026-09-03, 2026-09-16
721.
Security Feature Bypass - Chromium (CVE-2026-78976) - Medium [377]
Description: Improper input validation in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0037, EPSS Percentile is 0.30628 |
altlinux: CVE-2026-78976 was patched at 2026-08-28
debian: CVE-2026-78976 was patched at 2026-09-03, 2026-09-16
722.
Security Feature Bypass - Chromium (CVE-2026-78987) - Medium [377]
Description: Information leak in Canvas in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0037, EPSS Percentile is 0.30628 |
altlinux: CVE-2026-78987 was patched at 2026-08-28
debian: CVE-2026-78987 was patched at 2026-09-03, 2026-09-16
723.
Security Feature Bypass - Chromium (CVE-2026-79049) - Medium [377]
Description: Incorrect reference resolution in Passwords in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00358, EPSS Percentile is 0.29407 |
altlinux: CVE-2026-79049 was patched at 2026-08-28
debian: CVE-2026-79049 was patched at 2026-09-03, 2026-09-16
724.
Security Feature Bypass - Chromium (CVE-2026-79050) - Medium [377]
Description: Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00332, EPSS Percentile is 0.26343 |
altlinux: CVE-2026-79050 was patched at 2026-08-28
debian: CVE-2026-79050 was patched at 2026-09-03, 2026-09-16
725.
Security Feature Bypass - Chromium (CVE-2026-79136) - Medium [377]
Description: Incorrect authorization in ServiceWorker in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00322, EPSS Percentile is 0.25286 |
altlinux: CVE-2026-79136 was patched at 2026-08-28
debian: CVE-2026-79136 was patched at 2026-09-03, 2026-09-16
726.
Security Feature Bypass - Chromium (CVE-2026-79237) - Medium [377]
Description: Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00339, EPSS Percentile is 0.27267 |
altlinux: CVE-2026-79237 was patched at 2026-08-28
debian: CVE-2026-79237 was patched at 2026-09-03, 2026-09-16
727.
Security Feature Bypass - Chromium (CVE-2026-79262) - Medium [377]
Description: Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00322, EPSS Percentile is 0.25287 |
altlinux: CVE-2026-79262 was patched at 2026-08-28
debian: CVE-2026-79262 was patched at 2026-09-03, 2026-09-16
728.
Security Feature Bypass - Chromium (CVE-2026-79264) - Medium [377]
Description: Incorrect reference resolution in Preload in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00389, EPSS Percentile is 0.32669 |
altlinux: CVE-2026-79264 was patched at 2026-08-28
debian: CVE-2026-79264 was patched at 2026-09-03, 2026-09-16
729.
Security Feature Bypass - Keycloak (CVE-2026-16093) - Medium [377]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00304, EPSS Percentile is 0.23139 |
altlinux: CVE-2026-16093 was patched at 2026-09-01, 2026-09-04, 2026-09-07
730.
Authentication Bypass - Dovecot (CVE-2026-42008) - Medium [376]
Description: Forwarding information received from a host listed as a trusted proxy is not kept separate from
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.85 | 14 | Open-source IMAP and POP3 email server with authentication and indexing features. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00193, EPSS Percentile is 0.09215 |
debian: CVE-2026-42008 was patched at 2026-09-16
731.
Information Disclosure - Chromium (CVE-2026-79028) - Medium [376]
Description: Observable discrepancy in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00324, EPSS Percentile is 0.25423 |
altlinux: CVE-2026-79028 was patched at 2026-08-28
debian: CVE-2026-79028 was patched at 2026-09-03, 2026-09-16
732.
Information Disclosure - Chromium (CVE-2026-79030) - Medium [376]
Description: Observable discrepancy in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00324, EPSS Percentile is 0.25423 |
altlinux: CVE-2026-79030 was patched at 2026-08-28
debian: CVE-2026-79030 was patched at 2026-09-03, 2026-09-16
733.
Information Disclosure - Chromium (CVE-2026-79044) - Medium [376]
Description: Missing authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00399, EPSS Percentile is 0.33705 |
altlinux: CVE-2026-79044 was patched at 2026-08-28
debian: CVE-2026-79044 was patched at 2026-09-03, 2026-09-16
734.
Information Disclosure - Chromium (CVE-2026-79104) - Medium [376]
Description: Missing authorization in Sensor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.25375 |
altlinux: CVE-2026-79104 was patched at 2026-08-28
debian: CVE-2026-79104 was patched at 2026-09-03, 2026-09-16
735.
Information Disclosure - Chromium (CVE-2026-79122) - Medium [376]
Description: Information leak in SignIn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00313, EPSS Percentile is 0.24166 |
altlinux: CVE-2026-79122 was patched at 2026-08-28
debian: CVE-2026-79122 was patched at 2026-09-03, 2026-09-16
736.
Information Disclosure - Chromium (CVE-2026-79154) - Medium [376]
Description: Missing authorization in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0022, EPSS Percentile is 0.12605 |
altlinux: CVE-2026-79154 was patched at 2026-08-28
debian: CVE-2026-79154 was patched at 2026-09-03, 2026-09-16
737.
Information Disclosure - Chromium (CVE-2026-79207) - Medium [376]
Description: Information leak in Passwords in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00183, EPSS Percentile is 0.0811 |
altlinux: CVE-2026-79207 was patched at 2026-08-28
debian: CVE-2026-79207 was patched at 2026-09-03, 2026-09-16
738.
Information Disclosure - Chromium (CVE-2026-84327) - Medium [376]
Description: Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0019, EPSS Percentile is 0.08889 |
altlinux: CVE-2026-84327 was patched at 2026-09-03
debian: CVE-2026-84327 was patched at 2026-09-03, 2026-09-16
739.
Information Disclosure - Chromium (CVE-2026-84348) - Medium [376]
Description: Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00197, EPSS Percentile is 0.09753 |
altlinux: CVE-2026-84348 was patched at 2026-09-03
debian: CVE-2026-84348 was patched at 2026-09-03, 2026-09-16
740.
Information Disclosure - Chromium (CVE-2026-87490) - Medium [376]
Description: Information leak in Transactions Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00206, EPSS Percentile is 0.10837 |
altlinux: CVE-2026-87490 was patched at 2026-09-17
debian: CVE-2026-87490 was patched at 2026-09-16
741.
Information Disclosure - Chromium (CVE-2026-87523) - Medium [376]
Description: Race condition in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00215, EPSS Percentile is 0.12076 |
altlinux: CVE-2026-87523 was patched at 2026-09-17
debian: CVE-2026-87523 was patched at 2026-09-16
742.
Information Disclosure - Chromium (CVE-2026-87593) - Medium [376]
Description: Information leak in Editing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00206, EPSS Percentile is 0.10838 |
altlinux: CVE-2026-87593 was patched at 2026-09-17
debian: CVE-2026-87593 was patched at 2026-09-16
743.
Information Disclosure - Chromium (CVE-2026-87620) - Medium [376]
Description: Observable discrepancy in SVG in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00237, EPSS Percentile is 0.14927 |
altlinux: CVE-2026-87620 was patched at 2026-09-17
debian: CVE-2026-87620 was patched at 2026-09-16
744.
Information Disclosure - Chromium (CVE-2026-87623) - Medium [376]
Description: Observable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00237, EPSS Percentile is 0.14927 |
altlinux: CVE-2026-87623 was patched at 2026-09-17
debian: CVE-2026-87623 was patched at 2026-09-16
745.
Information Disclosure - GNOME desktop (CVE-2026-77680) - Medium [376]
Description: An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix. CVE-2025-32907 addressed memory amplification when a client repeated the same range many times in a single Range header. Commit 9bb92f7a corrected merge correctness in soup_message_headers_get_ranges_internal() in libsoup/soup-message-headers.c, but the coalescing loop still removes merged ranges using g_array_remove_index() for each coalesced element. Because GArray is contiguous, each mid-array removal performs an O(N) memmove. When many identical satisfiable ranges are supplied (for example bytes=0-0 repeated thousands of times), the loop performs O(N²) work coalescing them into a single range. The vulnerable path is reachable server-side from handle_partial_get() in libsoup/server/http1/soup-server-message-io-http1.c when a SoupServer handler returns HTTP 200 with a non-empty body. No authentication is required. The number of ranges is bounded only by the maximum request header size (~100 KiB), allowing roughly 25,000 ranges per request. Reporter measurements on libsoup HEAD containing the CVE-2025-32907 fix show ~90 ms single-core CPU per such request at the wire maximum, blocking the server's event loop for that duration. This is a CPU exhaustion / availability issue only. No memory corruption or
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | GNOME originally an acronym for GNU Network Object Model Environment, is a free and open-source desktop environment for Linux and other Unix-like operating systems | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00344, EPSS Percentile is 0.27737 |
debian: CVE-2026-77680 was patched at 2026-09-16
746.
Information Disclosure - Keycloak (CVE-2026-16108) - Medium [376]
Description: A flaw was found in the default-groups REST endpoint and realm representation of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00174, EPSS Percentile is 0.07121 |
altlinux: CVE-2026-16108 was patched at 2026-09-01, 2026-09-04, 2026-09-07
747.
Information Disclosure - Keycloak (CVE-2026-17048) - Medium [376]
Description: A flaw was found in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.5 | 10 | CVSS Base Score is 4.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00354, EPSS Percentile is 0.28952 |
altlinux: CVE-2026-17048 was patched at 2026-08-20, 2026-08-26, 2026-08-28
748.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-71114) - Medium [375]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00167, EPSS Percentile is 0.06292 |
altlinux: CVE-2026-71114 was patched at 2026-08-21
749.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-71115) - Medium [375]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00167, EPSS Percentile is 0.06292 |
altlinux: CVE-2026-71115 was patched at 2026-08-21
750.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-71136) - Medium [375]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04702 |
altlinux: CVE-2026-71136 was patched at 2026-08-21
751.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-71138) - Medium [375]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04703 |
altlinux: CVE-2026-71138 was patched at 2026-08-21
752.
Code Injection - SPIP (CVE-2026-72708) - Medium [375]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.5 | 14 | SPIP is an open-source software content management system designed for web site publishing, oriented towards online collaborative editing | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00319, EPSS Percentile is 0.2487 |
debian: CVE-2026-72708 was patched at 2026-09-16
753.
Command Injection - Nodemailer (CVE-2026-82853) - Medium [375]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.5 | 14 | Nodemailer is a Node.js module for sending email, supporting SMTP, message composition, attachments, and multiple transport mechanisms. | |
| 0.5 | 10 | CVSS Base Score is 4.9. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00735, EPSS Percentile is 0.52703 |
debian: CVE-2026-82853 was patched at 2026-09-16
754.
Denial of Service - 389 Directory Server (CVE-2026-18453) - Medium [375]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | 389 Directory Server is a highly usable, fully featured, reliable and secure LDAP server implementation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.00847, EPSS Percentile is 0.56271 |
almalinux: CVE-2026-18453 was patched at 2026-09-08
altlinux: CVE-2026-18453 was patched at 2026-09-08, 2026-09-11
debian: CVE-2026-18453 was patched at 2026-09-16
oraclelinux: CVE-2026-18453 was patched at 2026-09-08, 2026-09-10
redhat: CVE-2026-18453 was patched at 2026-09-08
755.
Denial of Service - OpenTelemetry (CVE-2026-45292) - Medium [375]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | OpenTelemetry is a collection of APIs, SDKs, and tools. Use it to instrument, generate, collect, and export telemetry data (metrics, logs and traces) to help you analyze your software's performance and behavior | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.01097, EPSS Percentile is 0.63922 |
altlinux: CVE-2026-45292 was patched at 2026-08-20, 2026-08-26, 2026-08-28
756.
Server-Side Request Forgery - Perl (CVE-2026-19953) - Medium [374]
Description: URI versions before 5.36 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30948 |
debian: CVE-2026-19953 was patched at 2026-09-16
757.
Denial of Service - FFmpeg (CVE-2026-38350) - Medium [372]
Description: An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00324, EPSS Percentile is 0.25467 |
debian: CVE-2026-38350 was patched at 2026-09-16
758.
Denial of Service - MinIO (CVE-2026-39414) - Medium [372]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | MinIO is a high-performance, S3-compatible object storage system designed for large-scale data infrastructure. It supports cloud-native workloads and provides APIs for storing, retrieving, and managing unstructured data such as photos, videos, log files, and backups, with a focus on scalability, speed, and simplicity. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00485, EPSS Percentile is 0.40616 |
redos: CVE-2026-39414 was patched at 2026-09-01
759.
Denial of Service - Oracle MySQL (CVE-2026-60314) - Medium [372]
Description: Vulnerability in the MySQL Router product of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | MySQL is an open-source relational database management system | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00366, EPSS Percentile is 0.30168 |
altlinux: CVE-2026-60314 was patched at 2026-08-24
760.
Denial of Service - qs (CVE-2026-82397) - Medium [372]
Description: Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | qs is a popular JavaScript library for parsing and serializing URL query strings. It supports nested objects, arrays, custom parsing options, and is widely used in Node.js frameworks and middleware to handle HTTP query parameters and form-encoded data. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0035, EPSS Percentile is 0.285 |
debian: CVE-2026-82397 was patched at 2026-09-16
761.
Memory Corruption - Linux Kernel (CVE-2026-80601) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00258, EPSS Percentile is 0.17687 |
debian: CVE-2026-80601 was patched at 2026-09-16
oraclelinux: CVE-2026-80601 was patched at 2026-09-04
redos: CVE-2026-80601 was patched at 2026-09-16
762.
Memory Corruption - Linux Kernel (CVE-2026-80604) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00266, EPSS Percentile is 0.1861 |
debian: CVE-2026-80604 was patched at 2026-09-16
oraclelinux: CVE-2026-80604 was patched at 2026-09-04
763.
Memory Corruption - Linux Kernel (CVE-2026-80635) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0026, EPSS Percentile is 0.17845 |
debian: CVE-2026-80635 was patched at 2026-09-16
redos: CVE-2026-80635 was patched at 2026-09-16
764.
Memory Corruption - Linux Kernel (CVE-2026-80935) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00242, EPSS Percentile is 0.15531 |
debian: CVE-2026-80935 was patched at 2026-09-16
765.
Memory Corruption - Linux Kernel (CVE-2026-80937) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00318, EPSS Percentile is 0.24743 |
debian: CVE-2026-80937 was patched at 2026-09-16
766.
Memory Corruption - Linux Kernel (CVE-2026-89682) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00397, EPSS Percentile is 0.33508 |
debian: CVE-2026-89682 was patched at 2026-09-16
767.
Memory Corruption - Linux Kernel (CVE-2026-89709) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0033, EPSS Percentile is 0.2614 |
debian: CVE-2026-89709 was patched at 2026-09-16
768.
Memory Corruption - Linux Kernel (CVE-2026-89725) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00266, EPSS Percentile is 0.1861 |
debian: CVE-2026-89725 was patched at 2026-09-16
769.
Memory Corruption - Linux Kernel (CVE-2026-89783) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11445 |
debian: CVE-2026-89783 was patched at 2026-09-16
770.
Memory Corruption - Linux Kernel (CVE-2026-89788) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00189, EPSS Percentile is 0.08779 |
debian: CVE-2026-89788 was patched at 2026-09-16
771.
Remote Code Execution - GIMP (CVE-2026-90948) - Medium [369]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | GIMP is an open-source image manipulation program used for photo editing, graphic design, and digital art creation. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00225, EPSS Percentile is 0.13347 |
debian: CVE-2026-90948 was patched at 2026-09-16
772.
Remote Code Execution - GIMP (CVE-2026-92248) - Medium [369]
Description: A flaw was found in the file-psd plugin in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | GIMP is an open-source image manipulation program used for photo editing, graphic design, and digital art creation. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07875 |
debian: CVE-2026-92248 was patched at 2026-09-16
773.
Remote Code Execution - GPU Display Driver (CVE-2026-24190) - Medium [369]
Description: NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause improper access to GPU resources. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:nvidia:gpu_display_driver (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00221, EPSS Percentile is 0.12769 |
redos: CVE-2026-24190 was patched at 2026-09-08
774.
Remote Code Execution - GPU Display Driver (CVE-2026-24192) - Medium [369]
Description: NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between numeric types, leading to a heap buffer overflow. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:nvidia:gpu_display_driver (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00206, EPSS Percentile is 0.10833 |
redos: CVE-2026-24192 was patched at 2026-09-08
775.
Remote Code Execution - GPU Display Driver (CVE-2026-24193) - Medium [369]
Description: NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:nvidia:gpu_display_driver (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00197, EPSS Percentile is 0.09752 |
redos: CVE-2026-24193 was patched at 2026-09-08
776.
Code Injection - MongoDB (CVE-2026-18708) - Medium [368]
Description: An issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.6 | 10 | CVSS Base Score is 6.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00284, EPSS Percentile is 0.20948 |
altlinux: CVE-2026-18708 was patched at 2026-08-26
777.
Code Injection - Python (CVE-2026-34789) - Medium [368]
Description: FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/Property
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00196, EPSS Percentile is 0.09535 |
debian: CVE-2026-34789 was patched at 2026-08-25, 2026-08-26
778.
Denial of Service - FreeRDP (CVE-2026-91955) - Medium [367]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00452, EPSS Percentile is 0.38394 |
debian: CVE-2026-91955 was patched at 2026-09-16
779.
Denial of Service - ImageMagick (CVE-2026-86421) - Medium [367]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00441, EPSS Percentile is 0.37542 |
altlinux: CVE-2026-86421 was patched at 2026-08-31
debian: CVE-2026-86421 was patched at 2026-09-16
780.
Denial of Service - Perl (CVE-2026-19873) - Medium [367]
Description: HTML::FormFu versions through 2.08 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00517, EPSS Percentile is 0.42726 |
debian: CVE-2026-19873 was patched at 2026-09-16
781.
Security Feature Bypass - MongoDB (CVE-2026-18705) - Medium [367]
Description: An issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0027, EPSS Percentile is 0.19299 |
altlinux: CVE-2026-18705 was patched at 2026-08-26
782.
Security Feature Bypass - MongoDB (CVE-2026-82065) - Medium [367]
Description: A security issue in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00289, EPSS Percentile is 0.21561 |
altlinux: CVE-2026-82065 was patched at 2026-09-09, 2026-09-10
783.
Security Feature Bypass - strongSwan (CVE-2026-78134) - Medium [367]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | strongSwan is an open source IPsec-based VPN solution that provides secure network connectivity using IKEv1 and IKEv2 protocols, widely used on Linux systems for site-to-site and remote access VPN deployments. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00319, EPSS Percentile is 0.24859 |
altlinux: CVE-2026-78134 was patched at 2026-09-11
debian: CVE-2026-78134 was patched at 2026-09-07, 2026-09-16
784.
Elevation of Privilege - .NET (CVE-2026-58641) - Medium [366]
Description: Integer overflow or wraparound in .NET allows an unauthorized attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Product detected by a:microsoft:.net (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00404, EPSS Percentile is 0.34184 |
redos: CVE-2026-58641 was patched at 2026-09-07
785.
Elevation of Privilege - Visual Studio 2022 (CVE-2026-62886) - Medium [366]
Description: Integer overflow or wraparound in .NET allows an unauthorized attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Product detected by a:microsoft:visual_studio_2022 (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00404, EPSS Percentile is 0.34251 |
altlinux: CVE-2026-62886 was patched at 2026-08-31, 2026-09-02
redos: CVE-2026-62886 was patched at 2026-09-07
786.
Remote Code Execution - RPM (CVE-2026-82327) - Medium [366]
Description: A flaw was found in libsolv, a dependency-resolution library used by
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | RPM is a package management system and software packaging format widely used by Linux distributions in the Red Hat ecosystem and related systems, including tools for building RPM packages. | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00114, EPSS Percentile is 0.01651 |
debian: CVE-2026-82327 was patched at 2026-09-16
787.
Authentication Bypass - NGINX (CVE-2026-88011) - Medium [365]
Description: Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.56, and from 3.0.0 until 3.7.12, a client-supplied dot-form header such as X.Authenticated.User survives ForwardAuth replacement and underscoreHeadersStrategy because Go treats it as distinct from X-Authenticated-User while normalization-prone CGI, WSGI, PHP, and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Nginx is an open-source web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.14602 |
altlinux: CVE-2026-88011 was patched at 2026-09-15, 2026-09-16
788.
Authentication Bypass - NGINX (CVE-2026-88879) - Medium [365]
Description: Traefik is an HTTP reverse proxy and load balancer. In Traefik v1.x, v2.x through v2.11.55, and v3.0.0 through v3.7.11, header names are canonicalized only on dashes, so X-Auth-User, X_Auth_User and X.Auth.User are treated as three distinct headers by Traefik, while backends that derive variable names from header names (CGI, WSGI, PHP,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Nginx is an open-source web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00207, EPSS Percentile is 0.1097 |
altlinux: CVE-2026-88879 was patched at 2026-09-15, 2026-09-16
789.
Denial of Service - FreeIPA (CVE-2026-73196) - Medium [365]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | FreeIPA is a free and open source identity management system | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00244, EPSS Percentile is 0.15741 |
altlinux: CVE-2026-73196 was patched at 2026-08-20
debian: CVE-2026-73196 was patched at 2026-08-25
790.
Denial of Service - GNU C Library (CVE-2026-77117) - Medium [365]
Description: Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | The GNU C Library, commonly known as glibc, is the GNU Project's implementation of the C standard library | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00412, EPSS Percentile is 0.34952 |
debian: CVE-2026-77117 was patched at 2026-09-16
ubuntu: CVE-2026-77117 was patched at 2026-09-08, 2026-09-16
791.
Denial of Service - GNU C Library (CVE-2026-80489) - Medium [365]
Description: Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | The GNU C Library, commonly known as glibc, is the GNU Project's implementation of the C standard library | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00412, EPSS Percentile is 0.34952 |
debian: CVE-2026-80489 was patched at 2026-09-16
ubuntu: CVE-2026-80489 was patched at 2026-09-08, 2026-09-16
792.
Denial of Service - Mozilla Firefox (CVE-2026-74978) - Medium [365]
Description: Clickjacking issue in the Widget component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00229, EPSS Percentile is 0.13819 |
altlinux: CVE-2026-74978 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
793.
Denial of Service - Mozilla Firefox (CVE-2026-84138) - Medium [365]
Description: Denial-of-service in the PDF Viewer component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00204, EPSS Percentile is 0.10597 |
altlinux: CVE-2026-84138 was patched at 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
794.
Memory Corruption - Mozilla Firefox (CVE-2026-92006) - Medium [365]
Description: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00342, EPSS Percentile is 0.27591 |
altlinux: CVE-2026-92006 was patched at 2026-09-16
debian: CVE-2026-92006 was patched at 2026-09-16, 2026-09-17
795.
Memory Corruption - Safari (CVE-2026-64719) - Medium [365]
Description: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00415, EPSS Percentile is 0.35249 |
altlinux: CVE-2026-64719 was patched at 2026-08-24
debian: CVE-2026-64719 was patched at 2026-08-24, 2026-08-25
ubuntu: CVE-2026-64719 was patched at 2026-08-31, 2026-09-16
796.
Path Traversal - Keycloak (CVE-2026-19729) - Medium [365]
Description: A flaw was found in the key provider component of the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.5 | 10 | CVSS Base Score is 4.9. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00493, EPSS Percentile is 0.41142 |
altlinux: CVE-2026-19729 was patched at 2026-09-01, 2026-09-04, 2026-09-07
797.
Security Feature Bypass - Chromium (CVE-2026-78895) - Medium [365]
Description: Information leak in Paint in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00306, EPSS Percentile is 0.23297 |
altlinux: CVE-2026-78895 was patched at 2026-08-28
debian: CVE-2026-78895 was patched at 2026-09-03, 2026-09-16
798.
Security Feature Bypass - Chromium (CVE-2026-78908) - Medium [365]
Description: Information leak in Canvas in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00306, EPSS Percentile is 0.23297 |
altlinux: CVE-2026-78908 was patched at 2026-08-28
debian: CVE-2026-78908 was patched at 2026-09-03, 2026-09-16
799.
Security Feature Bypass - Chromium (CVE-2026-78942) - Medium [365]
Description: Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00318, EPSS Percentile is 0.24734 |
altlinux: CVE-2026-78942 was patched at 2026-08-28
debian: CVE-2026-78942 was patched at 2026-09-03, 2026-09-16
800.
Security Feature Bypass - Chromium (CVE-2026-79000) - Medium [365]
Description: Improper input validation in DeviceBoundSessionCredentials in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00271, EPSS Percentile is 0.194 |
altlinux: CVE-2026-79000 was patched at 2026-08-28
debian: CVE-2026-79000 was patched at 2026-09-03, 2026-09-16
801.
Security Feature Bypass - Chromium (CVE-2026-79002) - Medium [365]
Description: Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00321, EPSS Percentile is 0.25071 |
altlinux: CVE-2026-79002 was patched at 2026-08-28
debian: CVE-2026-79002 was patched at 2026-09-03, 2026-09-16
802.
Security Feature Bypass - Chromium (CVE-2026-79006) - Medium [365]
Description: Protection mechanism failure in HttpsUpgrades in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00292, EPSS Percentile is 0.21877 |
altlinux: CVE-2026-79006 was patched at 2026-08-28
debian: CVE-2026-79006 was patched at 2026-09-03, 2026-09-16
803.
Security Feature Bypass - Chromium (CVE-2026-79015) - Medium [365]
Description: Improper input validation in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00277, EPSS Percentile is 0.20256 |
altlinux: CVE-2026-79015 was patched at 2026-08-28
debian: CVE-2026-79015 was patched at 2026-09-03, 2026-09-16
804.
Security Feature Bypass - Chromium (CVE-2026-79031) - Medium [365]
Description: Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00333, EPSS Percentile is 0.26469 |
altlinux: CVE-2026-79031 was patched at 2026-08-28
debian: CVE-2026-79031 was patched at 2026-09-03, 2026-09-16
805.
Security Feature Bypass - Chromium (CVE-2026-79051) - Medium [365]
Description: Incorrect authorization in Loader in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00311, EPSS Percentile is 0.23965 |
altlinux: CVE-2026-79051 was patched at 2026-08-28
debian: CVE-2026-79051 was patched at 2026-09-03, 2026-09-16
806.
Security Feature Bypass - Chromium (CVE-2026-79065) - Medium [365]
Description: Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00317, EPSS Percentile is 0.24608 |
altlinux: CVE-2026-79065 was patched at 2026-08-28
debian: CVE-2026-79065 was patched at 2026-09-03, 2026-09-16
807.
Security Feature Bypass - Chromium (CVE-2026-79070) - Medium [365]
Description: Incorrect reference resolution in Cache in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.17265 |
altlinux: CVE-2026-79070 was patched at 2026-08-28
debian: CVE-2026-79070 was patched at 2026-09-03, 2026-09-16
808.
Security Feature Bypass - Chromium (CVE-2026-79106) - Medium [365]
Description: Improper input validation in Input in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00262, EPSS Percentile is 0.18134 |
altlinux: CVE-2026-79106 was patched at 2026-08-28
debian: CVE-2026-79106 was patched at 2026-09-03, 2026-09-16
809.
Security Feature Bypass - Chromium (CVE-2026-79110) - Medium [365]
Description: Missing authorization in Preload in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00266, EPSS Percentile is 0.18877 |
altlinux: CVE-2026-79110 was patched at 2026-08-28
debian: CVE-2026-79110 was patched at 2026-09-03, 2026-09-16
810.
Security Feature Bypass - Chromium (CVE-2026-79185) - Medium [365]
Description: Information leak in DOM in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00251, EPSS Percentile is 0.16705 |
altlinux: CVE-2026-79185 was patched at 2026-08-28
debian: CVE-2026-79185 was patched at 2026-09-03, 2026-09-16
811.
Security Feature Bypass - Chromium (CVE-2026-79192) - Medium [365]
Description: Improper input validation in Variations in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via crafted network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00242, EPSS Percentile is 0.15496 |
altlinux: CVE-2026-79192 was patched at 2026-08-28
debian: CVE-2026-79192 was patched at 2026-09-03, 2026-09-16
812.
Security Feature Bypass - Chromium (CVE-2026-79193) - Medium [365]
Description: Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00307, EPSS Percentile is 0.23496 |
altlinux: CVE-2026-79193 was patched at 2026-08-28
debian: CVE-2026-79193 was patched at 2026-09-03, 2026-09-16
813.
Security Feature Bypass - Chromium (CVE-2026-79213) - Medium [365]
Description: Incorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00248, EPSS Percentile is 0.16281 |
altlinux: CVE-2026-79213 was patched at 2026-08-28
debian: CVE-2026-79213 was patched at 2026-09-03, 2026-09-16
814.
Security Feature Bypass - Chromium (CVE-2026-79214) - Medium [365]
Description: Improper input validation in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00262, EPSS Percentile is 0.18133 |
altlinux: CVE-2026-79214 was patched at 2026-08-28
debian: CVE-2026-79214 was patched at 2026-09-03, 2026-09-16
815.
Security Feature Bypass - Chromium (CVE-2026-79251) - Medium [365]
Description: Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00275, EPSS Percentile is 0.20019 |
altlinux: CVE-2026-79251 was patched at 2026-08-28
debian: CVE-2026-79251 was patched at 2026-09-03, 2026-09-16
816.
Security Feature Bypass - Chromium (CVE-2026-79254) - Medium [365]
Description: Incorrect reference resolution in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00241, EPSS Percentile is 0.15446 |
altlinux: CVE-2026-79254 was patched at 2026-08-28
debian: CVE-2026-79254 was patched at 2026-09-03, 2026-09-16
817.
Security Feature Bypass - Chromium (CVE-2026-79255) - Medium [365]
Description: Improper input validation in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0032, EPSS Percentile is 0.25043 |
altlinux: CVE-2026-79255 was patched at 2026-08-28
debian: CVE-2026-79255 was patched at 2026-09-03, 2026-09-16
818.
Security Feature Bypass - Chromium (CVE-2026-87466) - Medium [365]
Description: Incorrect authorization in Workers in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00256, EPSS Percentile is 0.17395 |
altlinux: CVE-2026-87466 was patched at 2026-09-17
debian: CVE-2026-87466 was patched at 2026-09-16
819.
Security Feature Bypass - Chromium (CVE-2026-87472) - Medium [365]
Description: Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.18271 |
altlinux: CVE-2026-87472 was patched at 2026-09-17
debian: CVE-2026-87472 was patched at 2026-09-16
820.
Security Feature Bypass - Chromium (CVE-2026-87508) - Medium [365]
Description: Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16136 |
altlinux: CVE-2026-87508 was patched at 2026-09-17
debian: CVE-2026-87508 was patched at 2026-09-16
821.
Security Feature Bypass - Chromium (CVE-2026-87548) - Medium [365]
Description: Improper state validation in Installer in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00277, EPSS Percentile is 0.20256 |
altlinux: CVE-2026-87548 was patched at 2026-09-17
debian: CVE-2026-87548 was patched at 2026-09-16
822.
Security Feature Bypass - Chromium (CVE-2026-87556) - Medium [365]
Description: Missing authorization in Browser in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00282, EPSS Percentile is 0.2082 |
altlinux: CVE-2026-87556 was patched at 2026-09-17
debian: CVE-2026-87556 was patched at 2026-09-16
823.
Security Feature Bypass - Chromium (CVE-2026-87568) - Medium [365]
Description: Improper input validation in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05118 |
altlinux: CVE-2026-87568 was patched at 2026-09-17
debian: CVE-2026-87568 was patched at 2026-09-16
824.
Security Feature Bypass - Chromium (CVE-2026-87642) - Medium [365]
Description: Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00252, EPSS Percentile is 0.16774 |
altlinux: CVE-2026-87642 was patched at 2026-09-17
debian: CVE-2026-87642 was patched at 2026-09-16
825.
Security Feature Bypass - Chromium (CVE-2026-87645) - Medium [365]
Description: Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00167, EPSS Percentile is 0.0638 |
altlinux: CVE-2026-87645 was patched at 2026-09-17
debian: CVE-2026-87645 was patched at 2026-09-16
826.
Security Feature Bypass - Chromium (CVE-2026-87656) - Medium [365]
Description: Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00171, EPSS Percentile is 0.0679 |
altlinux: CVE-2026-87656 was patched at 2026-09-17
debian: CVE-2026-87656 was patched at 2026-09-16
827.
Security Feature Bypass - Netty (CVE-2026-41207) - Medium [365]
Description: The
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Netty is a non-blocking I/O client-server framework for the development of Java network applications such as protocol servers and clients | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00193, EPSS Percentile is 0.09186 |
redos: CVE-2026-41207 was patched at 2026-09-04
828.
Information Disclosure - Chromium (CVE-2026-78991) - Medium [364]
Description: Race condition in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00313, EPSS Percentile is 0.24193 |
altlinux: CVE-2026-78991 was patched at 2026-08-28
debian: CVE-2026-78991 was patched at 2026-09-03, 2026-09-16
829.
Information Disclosure - Chromium (CVE-2026-79001) - Medium [364]
Description: Information leak in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00311, EPSS Percentile is 0.23943 |
altlinux: CVE-2026-79001 was patched at 2026-08-28
debian: CVE-2026-79001 was patched at 2026-09-03, 2026-09-16
830.
Information Disclosure - Chromium (CVE-2026-79016) - Medium [364]
Description: Observable discrepancy in SVG in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00359, EPSS Percentile is 0.29459 |
altlinux: CVE-2026-79016 was patched at 2026-08-28
debian: CVE-2026-79016 was patched at 2026-09-03, 2026-09-16
831.
Information Disclosure - Chromium (CVE-2026-79074) - Medium [364]
Description: Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00277, EPSS Percentile is 0.20204 |
altlinux: CVE-2026-79074 was patched at 2026-08-28
debian: CVE-2026-79074 was patched at 2026-09-03, 2026-09-16
832.
Information Disclosure - Chromium (CVE-2026-79126) - Medium [364]
Description: Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00229, EPSS Percentile is 0.13888 |
altlinux: CVE-2026-79126 was patched at 2026-08-28
debian: CVE-2026-79126 was patched at 2026-09-03, 2026-09-16
833.
Information Disclosure - Chromium (CVE-2026-79220) - Medium [364]
Description: Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00266, EPSS Percentile is 0.18654 |
altlinux: CVE-2026-79220 was patched at 2026-08-28
debian: CVE-2026-79220 was patched at 2026-09-03, 2026-09-16
834.
Information Disclosure - Chromium (CVE-2026-79242) - Medium [364]
Description: Observable discrepancy in HTML in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00277, EPSS Percentile is 0.20203 |
altlinux: CVE-2026-79242 was patched at 2026-08-28
debian: CVE-2026-79242 was patched at 2026-09-03, 2026-09-16
835.
Information Disclosure - Chromium (CVE-2026-79265) - Medium [364]
Description: Incomplete cleanup in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0029, EPSS Percentile is 0.21654 |
altlinux: CVE-2026-79265 was patched at 2026-08-28
debian: CVE-2026-79265 was patched at 2026-09-03, 2026-09-16
836.
Information Disclosure - Chromium (CVE-2026-79287) - Medium [364]
Description: Observable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00277, EPSS Percentile is 0.20204 |
altlinux: CVE-2026-79287 was patched at 2026-08-28
debian: CVE-2026-79287 was patched at 2026-09-03, 2026-09-16
837.
Information Disclosure - Chromium (CVE-2026-87435) - Medium [364]
Description: Information leak in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00311, EPSS Percentile is 0.23943 |
altlinux: CVE-2026-87435 was patched at 2026-09-17
debian: CVE-2026-87435 was patched at 2026-09-16
838.
Information Disclosure - Chromium (CVE-2026-87439) - Medium [364]
Description: Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00311, EPSS Percentile is 0.23943 |
altlinux: CVE-2026-87439 was patched at 2026-09-17
debian: CVE-2026-87439 was patched at 2026-09-16
839.
Information Disclosure - Chromium (CVE-2026-87518) - Medium [364]
Description: Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00257, EPSS Percentile is 0.17513 |
altlinux: CVE-2026-87518 was patched at 2026-09-17
debian: CVE-2026-87518 was patched at 2026-09-16
840.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-71127) - Medium [363]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.0206 |
altlinux: CVE-2026-71127 was patched at 2026-08-21
841.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-71134) - Medium [363]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00149, EPSS Percentile is 0.04474 |
altlinux: CVE-2026-71134 was patched at 2026-08-21
842.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-71135) - Medium [363]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0015, EPSS Percentile is 0.04574 |
altlinux: CVE-2026-71135 was patched at 2026-08-21
843.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-71137) - Medium [363]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.0206 |
altlinux: CVE-2026-71137 was patched at 2026-08-21
844.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-71151) - Medium [363]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.6 | 10 | CVSS Base Score is 5.6. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02059 |
altlinux: CVE-2026-71151 was patched at 2026-08-21
845.
Command Injection - Unknown Product (CVE-2026-38820) - Medium [363]
Description: {'nvd_cve_data_all': 'openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.8 | 10 | EPSS Probability is 0.01743, EPSS Percentile is 0.76621 |
debian: CVE-2026-38820 was patched at 2026-09-16
846.
Security Feature Bypass - openssl (CVE-2026-75803) - Medium [363]
Description: Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and expecting the call to check the AEAD tag may accept forged messages. CWE: CWE-354 (Improper Validation of Integrity Check Value) Description: The EVP_Cipher() API call for AEAD ciphers behaves like a one shot encryption and decryption call. It also verifies the AEAD tag after the decryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers it skipped the AEAD tag verification when an empty ciphertext was passed to the function. The callers of this function might believe that a successful return indicates a valid AEAD tag for these ciphers, even when that has not truly been validated in this case. FIPS impact: no The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE as the affected algorithms are not FIPS approved and thus not implemented in the FIPS module.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:openssl:openssl (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00221, EPSS Percentile is 0.12735 |
altlinux: CVE-2026-75803 was patched at 2026-08-26
debian: CVE-2026-75803 was patched at 2026-08-25
ubuntu: CVE-2026-75803 was patched at 2026-08-25, 2026-09-16
847.
Server-Side Request Forgery - libxml2 (CVE-2026-86144) - Medium [362]
Description: In xinclude in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.6 | 14 | libxml2 is an XML toolkit implemented in C, originally developed for the GNOME Project | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07441 |
debian: CVE-2026-86144 was patched at 2026-09-16
848.
Cross Site Scripting - Python (CVE-2026-49825) - Medium [361]
Description: lxml is a library for processing XML and HTML in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0024, EPSS Percentile is 0.15237 |
almalinux: CVE-2026-49825 was patched at 2026-09-09
debian: CVE-2026-49825 was patched at 2026-08-25
oraclelinux: CVE-2026-49825 was patched at 2026-09-10
redhat: CVE-2026-49825 was patched at 2026-09-09
849.
Denial of Service - Asterisk (CVE-2026-76098) - Medium [360]
Description: Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | Asterisk is a free and open source framework for building communications applications and is sponsored by Sangoma | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00278, EPSS Percentile is 0.20383 |
debian: CVE-2026-76098 was patched at 2026-09-16
850.
Incorrect Calculation - Apache Tomcat (CVE-2026-65927) - Medium [360]
Description: Off-by-one Error vulnerability in Apache
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.7 | 14 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00779, EPSS Percentile is 0.54152 |
altlinux: CVE-2026-65927 was patched at 2026-08-26, 2026-08-27, 2026-09-11, 2026-09-16
debian: CVE-2026-65927 was patched at 2026-09-16
851.
Denial of Service - Erlang/OTP (CVE-2026-69664) - Medium [358]
Description: Missing Release of Resource after Effective Lifetime vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | Erlang/OTP is a set of libraries for the Erlang programming language | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.5 | 10 | EPSS Probability is 0.00686, EPSS Percentile is 0.50933 |
debian: CVE-2026-69664 was patched at 2026-09-16
852.
Incorrect Calculation - Linux Kernel (CVE-2026-80671) - Medium [358]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00158, EPSS Percentile is 0.05405 |
debian: CVE-2026-80671 was patched at 2026-09-16
853.
Memory Corruption - Linux Kernel (CVE-2026-74651) - Medium [358]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00274, EPSS Percentile is 0.19843 |
debian: CVE-2026-74651 was patched at 2026-08-25
oraclelinux: CVE-2026-74651 was patched at 2026-09-04
854.
Memory Corruption - Linux Kernel (CVE-2026-80726) - Medium [358]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07528 |
debian: CVE-2026-80726 was patched at 2026-09-16
855.
Memory Corruption - Linux Kernel (CVE-2026-80914) - Medium [358]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00232, EPSS Percentile is 0.14228 |
debian: CVE-2026-80914 was patched at 2026-09-16
856.
Memory Corruption - Linux Kernel (CVE-2026-89534) - Medium [358]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00218, EPSS Percentile is 0.12422 |
debian: CVE-2026-89534 was patched at 2026-09-16
857.
Memory Corruption - Linux Kernel (CVE-2026-89777) - Medium [358]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11446 |
debian: CVE-2026-89777 was patched at 2026-09-16
858.
Memory Corruption - Linux Kernel (CVE-2026-89786) - Medium [358]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10809 |
debian: CVE-2026-89786 was patched at 2026-09-16
859.
Arbitrary File Reading - Apache Tika (CVE-2026-66755) - Medium [357]
Description: Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0.4 | 14 | Apache Tika is an open source content analysis toolkit that detects and extracts metadata and structured text content from a wide range of file formats such as PDF, Microsoft Office, and multimedia files. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00443, EPSS Percentile is 0.37698 |
ubuntu: CVE-2026-66755 was patched at 2026-09-03, 2026-09-16
860.
Remote Code Execution - GIMP (CVE-2026-90947) - Medium [357]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | GIMP is an open-source image manipulation program used for photo editing, graphic design, and digital art creation. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00131, EPSS Percentile is 0.03099 |
debian: CVE-2026-90947 was patched at 2026-09-16
861.
Remote Code Execution - GPU Display Driver (CVE-2026-24194) - Medium [357]
Description: NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improper permission handling. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:nvidia:gpu_display_driver (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04721 |
redos: CVE-2026-24194 was patched at 2026-09-08
862.
Remote Code Execution - Unknown Product (CVE-2026-63639) - Medium [357]
Description: {'nvd_cve_data_all': 'Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.00888, EPSS Percentile is 0.57545 |
almalinux: CVE-2026-63639 was patched at 2026-09-08
altlinux: CVE-2026-63639 was patched at 2026-08-20, 2026-08-23
debian: CVE-2026-63639 was patched at 2026-08-25
oraclelinux: CVE-2026-63639 was patched at 2026-09-08
redhat: CVE-2026-63639 was patched at 2026-09-08
863.
Denial of Service - FreeRDP (CVE-2026-91953) - Medium [355]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00422, EPSS Percentile is 0.3592 |
debian: CVE-2026-91953 was patched at 2026-09-16
864.
Denial of Service - ImageMagick (CVE-2026-86420) - Medium [355]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00321, EPSS Percentile is 0.25113 |
altlinux: CVE-2026-86420 was patched at 2026-08-31
debian: CVE-2026-86420 was patched at 2026-09-16
865.
Denial of Service - Jetty (CVE-2026-12611) - Medium [355]
Description: A client may issue HTTP/2 requests to a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Jetty is a Java based web server and servlet engine | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00253, EPSS Percentile is 0.16922 |
debian: CVE-2026-12611 was patched at 2026-09-16
866.
Denial of Service - Jetty (CVE-2026-19204) - Medium [355]
Description: A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Jetty is a Java based web server and servlet engine | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00293, EPSS Percentile is 0.21937 |
debian: CVE-2026-19204 was patched at 2026-09-16
867.
Denial of Service - MongoDB (CVE-2026-18697) - Medium [355]
Description: An issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00346, EPSS Percentile is 0.28017 |
altlinux: CVE-2026-18697 was patched at 2026-08-26
868.
Denial of Service - TuneD (CVE-2026-19401) - Medium [355]
Description: Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Tuned is a daemon that uses udev to monitor connected devices and statically and dynamically tunes system settings according to a selected profile | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00357, EPSS Percentile is 0.29297 |
altlinux: CVE-2026-19401 was patched at 2026-08-27, 2026-08-28, 2026-09-01
debian: CVE-2026-19401 was patched at 2026-09-16
869.
Denial of Service - libxml2 (CVE-2026-74860) - Medium [355]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | libxml2 is an XML toolkit implemented in C, originally developed for the GNOME Project | |
| 0.8 | 10 | CVSS Base Score is 8.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00354, EPSS Percentile is 0.28943 |
debian: CVE-2026-74860 was patched at 2026-09-16
870.
Memory Corruption - Perl (CVE-2026-78183) - Medium [355]
Description: DBD::Pg version 3.21.0 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0055, EPSS Percentile is 0.44631 |
altlinux: CVE-2026-78183 was patched at 2026-08-25, 2026-08-26, 2026-08-27, 2026-08-28
871.
Authentication Bypass - Unknown Product (CVE-2026-58422) - Medium [353]
Description: {'nvd_cve_data_all': 'Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00621, EPSS Percentile is 0.48125 |
altlinux: CVE-2026-58422 was patched at 2026-08-27, 2026-08-29, 2026-09-04
872.
Authentication Bypass - undici (CVE-2026-85152) - Medium [353]
Description: undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant headers match, which permits cross-origin information disclosure and persistent cache poisoning. The reporter demonstrated a full
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:nodejs:undici (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06993 |
debian: CVE-2026-85152 was patched at 2026-09-16
873.
Denial of Service - Mozilla Firefox (CVE-2026-74951) - Medium [353]
Description: Clickjacking issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0016, EPSS Percentile is 0.05583 |
altlinux: CVE-2026-74951 was patched at 2026-08-20, 2026-08-28
874.
Denial of Service - Mozilla Firefox (CVE-2026-74980) - Medium [353]
Description: Clickjacking issue in the Downloads component in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00175, EPSS Percentile is 0.072 |
altlinux: CVE-2026-74980 was patched at 2026-08-20, 2026-08-28
875.
Incorrect Calculation - Chromium (CVE-2026-79148) - Medium [353]
Description: Off-by-one error in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially read memory inside the sandbox via a crafted Chrome extension. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.18365 |
altlinux: CVE-2026-79148 was patched at 2026-08-28
debian: CVE-2026-79148 was patched at 2026-09-03, 2026-09-16
876.
Incorrect Calculation - Mozilla Firefox (CVE-2026-74977) - Medium [353]
Description: Integer overflow in the Graphics component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0035, EPSS Percentile is 0.28416 |
altlinux: CVE-2026-74977 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
877.
Memory Corruption - Chromium (CVE-2026-79020) - Medium [353]
Description: Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted media file. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00358, EPSS Percentile is 0.29364 |
altlinux: CVE-2026-79020 was patched at 2026-08-28
debian: CVE-2026-79020 was patched at 2026-09-03, 2026-09-16
878.
Memory Corruption - Mozilla Firefox (CVE-2026-74937) - Medium [353]
Description: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00292, EPSS Percentile is 0.21833 |
altlinux: CVE-2026-74937 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
879.
Memory Corruption - Mozilla Firefox (CVE-2026-74947) - Medium [353]
Description: Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00244, EPSS Percentile is 0.15805 |
altlinux: CVE-2026-74947 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
880.
Memory Corruption - Mozilla Firefox (CVE-2026-92007) - Medium [353]
Description: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00269, EPSS Percentile is 0.19186 |
altlinux: CVE-2026-92007 was patched at 2026-09-16
debian: CVE-2026-92007 was patched at 2026-09-16, 2026-09-17
881.
Memory Corruption - Mozilla Firefox (CVE-2026-92008) - Medium [353]
Description: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00269, EPSS Percentile is 0.19185 |
altlinux: CVE-2026-92008 was patched at 2026-09-16
debian: CVE-2026-92008 was patched at 2026-09-16, 2026-09-17
882.
Memory Corruption - Mozilla Firefox (CVE-2026-92009) - Medium [353]
Description: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00269, EPSS Percentile is 0.19187 |
altlinux: CVE-2026-92009 was patched at 2026-09-16
debian: CVE-2026-92009 was patched at 2026-09-16, 2026-09-17
883.
Memory Corruption - Mozilla Firefox (CVE-2026-92010) - Medium [353]
Description: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00269, EPSS Percentile is 0.19185 |
altlinux: CVE-2026-92010 was patched at 2026-09-16
debian: CVE-2026-92010 was patched at 2026-09-16, 2026-09-17
884.
Memory Corruption - Mozilla Firefox (CVE-2026-92011) - Medium [353]
Description: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00269, EPSS Percentile is 0.19187 |
altlinux: CVE-2026-92011 was patched at 2026-09-16
debian: CVE-2026-92011 was patched at 2026-09-16, 2026-09-17
885.
Memory Corruption - Mozilla Firefox (CVE-2026-92012) - Medium [353]
Description: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00269, EPSS Percentile is 0.19186 |
altlinux: CVE-2026-92012 was patched at 2026-09-16
debian: CVE-2026-92012 was patched at 2026-09-16, 2026-09-17
886.
Memory Corruption - Mozilla Firefox (CVE-2026-92013) - Medium [353]
Description: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00269, EPSS Percentile is 0.19185 |
altlinux: CVE-2026-92013 was patched at 2026-09-16
debian: CVE-2026-92013 was patched at 2026-09-16, 2026-09-17
887.
Memory Corruption - Mozilla Firefox (CVE-2026-92014) - Medium [353]
Description: Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.17263 |
debian: CVE-2026-92014 was patched at 2026-09-16, 2026-09-17
888.
Memory Corruption - Mozilla Firefox (CVE-2026-92020) - Medium [353]
Description: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00269, EPSS Percentile is 0.19186 |
altlinux: CVE-2026-92020 was patched at 2026-09-16
debian: CVE-2026-92020 was patched at 2026-09-16, 2026-09-17
889.
Memory Corruption - Mozilla Firefox (CVE-2026-92043) - Medium [353]
Description: Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.17263 |
altlinux: CVE-2026-92043 was patched at 2026-09-16
890.
Memory Corruption - Mozilla Firefox (CVE-2026-92054) - Medium [353]
Description: Privilege escalation in the Memory component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0026, EPSS Percentile is 0.17941 |
altlinux: CVE-2026-92054 was patched at 2026-09-16
891.
Security Feature Bypass - Chromium (CVE-2026-78941) - Medium [353]
Description: Information leak in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00275, EPSS Percentile is 0.19951 |
altlinux: CVE-2026-78941 was patched at 2026-08-28
debian: CVE-2026-78941 was patched at 2026-09-03, 2026-09-16
892.
Security Feature Bypass - Chromium (CVE-2026-78943) - Medium [353]
Description: Improper input validation in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00251, EPSS Percentile is 0.16694 |
altlinux: CVE-2026-78943 was patched at 2026-08-28
debian: CVE-2026-78943 was patched at 2026-09-03, 2026-09-16
893.
Security Feature Bypass - Chromium (CVE-2026-78946) - Medium [353]
Description: Incorrect authorization in Select in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00233, EPSS Percentile is 0.14386 |
altlinux: CVE-2026-78946 was patched at 2026-08-28
debian: CVE-2026-78946 was patched at 2026-09-03, 2026-09-16
894.
Security Feature Bypass - Chromium (CVE-2026-78953) - Medium [353]
Description: Missing authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00296, EPSS Percentile is 0.22272 |
altlinux: CVE-2026-78953 was patched at 2026-08-28
debian: CVE-2026-78953 was patched at 2026-09-03, 2026-09-16
895.
Security Feature Bypass - Chromium (CVE-2026-78980) - Medium [353]
Description: Improper input validation in ReaderMode in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00229, EPSS Percentile is 0.13871 |
altlinux: CVE-2026-78980 was patched at 2026-08-28
debian: CVE-2026-78980 was patched at 2026-09-03, 2026-09-16
896.
Security Feature Bypass - Chromium (CVE-2026-79025) - Medium [353]
Description: Improper input validation in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00206, EPSS Percentile is 0.10824 |
altlinux: CVE-2026-79025 was patched at 2026-08-28
debian: CVE-2026-79025 was patched at 2026-09-03, 2026-09-16
897.
Security Feature Bypass - Chromium (CVE-2026-79053) - Medium [353]
Description: Missing authorization in Lighthouse in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00265, EPSS Percentile is 0.18521 |
altlinux: CVE-2026-79053 was patched at 2026-08-28
debian: CVE-2026-79053 was patched at 2026-09-03, 2026-09-16
898.
Security Feature Bypass - Chromium (CVE-2026-79066) - Medium [353]
Description: Improper input validation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00251, EPSS Percentile is 0.16694 |
altlinux: CVE-2026-79066 was patched at 2026-08-28
debian: CVE-2026-79066 was patched at 2026-09-03, 2026-09-16
899.
Security Feature Bypass - Chromium (CVE-2026-79077) - Medium [353]
Description: Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10028 |
altlinux: CVE-2026-79077 was patched at 2026-08-28
debian: CVE-2026-79077 was patched at 2026-09-03, 2026-09-16
900.
Security Feature Bypass - Chromium (CVE-2026-79105) - Medium [353]
Description: Improper input validation in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00238, EPSS Percentile is 0.14949 |
altlinux: CVE-2026-79105 was patched at 2026-08-28
debian: CVE-2026-79105 was patched at 2026-09-03, 2026-09-16
901.
Security Feature Bypass - Chromium (CVE-2026-79141) - Medium [353]
Description: Incorrect authorization in Browser in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11573 |
altlinux: CVE-2026-79141 was patched at 2026-08-28
debian: CVE-2026-79141 was patched at 2026-09-03, 2026-09-16
902.
Security Feature Bypass - Chromium (CVE-2026-79151) - Medium [353]
Description: Improper input validation in Safebrowsing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted file. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00225, EPSS Percentile is 0.13281 |
altlinux: CVE-2026-79151 was patched at 2026-08-28
debian: CVE-2026-79151 was patched at 2026-09-03, 2026-09-16
903.
Security Feature Bypass - Chromium (CVE-2026-79178) - Medium [353]
Description: Incorrect authorization in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.14656 |
altlinux: CVE-2026-79178 was patched at 2026-08-28
debian: CVE-2026-79178 was patched at 2026-09-03, 2026-09-16
904.
Security Feature Bypass - Chromium (CVE-2026-79199) - Medium [353]
Description: Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.14551 |
altlinux: CVE-2026-79199 was patched at 2026-08-28
debian: CVE-2026-79199 was patched at 2026-09-03, 2026-09-16
905.
Security Feature Bypass - Chromium (CVE-2026-79203) - Medium [353]
Description: Improper input validation in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00241, EPSS Percentile is 0.15468 |
altlinux: CVE-2026-79203 was patched at 2026-08-28
debian: CVE-2026-79203 was patched at 2026-09-03, 2026-09-16
906.
Security Feature Bypass - Chromium (CVE-2026-79205) - Medium [353]
Description: Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11573 |
altlinux: CVE-2026-79205 was patched at 2026-08-28
debian: CVE-2026-79205 was patched at 2026-09-03, 2026-09-16
907.
Security Feature Bypass - Chromium (CVE-2026-79217) - Medium [353]
Description: Incorrect authorization in Mobile in Google Chrome on on iOS prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.1455 |
altlinux: CVE-2026-79217 was patched at 2026-08-28
debian: CVE-2026-79217 was patched at 2026-09-03, 2026-09-16
908.
Security Feature Bypass - Chromium (CVE-2026-79228) - Medium [353]
Description: Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00289, EPSS Percentile is 0.21531 |
altlinux: CVE-2026-79228 was patched at 2026-08-28
debian: CVE-2026-79228 was patched at 2026-09-03, 2026-09-16
909.
Security Feature Bypass - Chromium (CVE-2026-79259) - Medium [353]
Description: Improper input validation in Safebrowsing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted file. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00225, EPSS Percentile is 0.13281 |
altlinux: CVE-2026-79259 was patched at 2026-08-28
debian: CVE-2026-79259 was patched at 2026-09-03, 2026-09-16
910.
Security Feature Bypass - Chromium (CVE-2026-79261) - Medium [353]
Description: Incorrect authorization in Controls in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10028 |
altlinux: CVE-2026-79261 was patched at 2026-08-28
debian: CVE-2026-79261 was patched at 2026-09-03, 2026-09-16
911.
Security Feature Bypass - Chromium (CVE-2026-79272) - Medium [353]
Description: Improper input validation in FindInPage in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00241, EPSS Percentile is 0.1539 |
altlinux: CVE-2026-79272 was patched at 2026-08-28
debian: CVE-2026-79272 was patched at 2026-09-03, 2026-09-16
912.
Security Feature Bypass - Chromium (CVE-2026-87449) - Medium [353]
Description: Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00207, EPSS Percentile is 0.11046 |
altlinux: CVE-2026-87449 was patched at 2026-09-17
debian: CVE-2026-87449 was patched at 2026-09-16
913.
Security Feature Bypass - Chromium (CVE-2026-87461) - Medium [353]
Description: Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00157, EPSS Percentile is 0.05247 |
altlinux: CVE-2026-87461 was patched at 2026-09-17
debian: CVE-2026-87461 was patched at 2026-09-16
914.
Security Feature Bypass - Chromium (CVE-2026-87469) - Medium [353]
Description: Improper input validation in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via crafted network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00179, EPSS Percentile is 0.0765 |
altlinux: CVE-2026-87469 was patched at 2026-09-17
debian: CVE-2026-87469 was patched at 2026-09-16
915.
Security Feature Bypass - Chromium (CVE-2026-87495) - Medium [353]
Description: Information leak in Scroll in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00201, EPSS Percentile is 0.10226 |
altlinux: CVE-2026-87495 was patched at 2026-09-17
debian: CVE-2026-87495 was patched at 2026-09-16
916.
Security Feature Bypass - Chromium (CVE-2026-87516) - Medium [353]
Description: Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.14645 |
altlinux: CVE-2026-87516 was patched at 2026-09-17
debian: CVE-2026-87516 was patched at 2026-09-16
917.
Security Feature Bypass - Chromium (CVE-2026-87543) - Medium [353]
Description: Missing authorization in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00189, EPSS Percentile is 0.08747 |
altlinux: CVE-2026-87543 was patched at 2026-09-17
debian: CVE-2026-87543 was patched at 2026-09-16
918.
Security Feature Bypass - Chromium (CVE-2026-87546) - Medium [353]
Description: Incorrect type conversion or cast in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00204, EPSS Percentile is 0.10616 |
altlinux: CVE-2026-87546 was patched at 2026-09-17
debian: CVE-2026-87546 was patched at 2026-09-16
919.
Security Feature Bypass - Chromium (CVE-2026-87560) - Medium [353]
Description: Missing authorization in Browser in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10028 |
altlinux: CVE-2026-87560 was patched at 2026-09-17
debian: CVE-2026-87560 was patched at 2026-09-16
920.
Security Feature Bypass - Chromium (CVE-2026-87561) - Medium [353]
Description: Incorrect authorization in Web Authentication in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10781 |
altlinux: CVE-2026-87561 was patched at 2026-09-17
debian: CVE-2026-87561 was patched at 2026-09-16
921.
Security Feature Bypass - Chromium (CVE-2026-87563) - Medium [353]
Description: Origin validation error in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.05985 |
altlinux: CVE-2026-87563 was patched at 2026-09-17
debian: CVE-2026-87563 was patched at 2026-09-16
922.
Security Feature Bypass - Chromium (CVE-2026-87571) - Medium [353]
Description: Improper certificate validation in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00111, EPSS Percentile is 0.01472 |
altlinux: CVE-2026-87571 was patched at 2026-09-17
debian: CVE-2026-87571 was patched at 2026-09-16
923.
Security Feature Bypass - Chromium (CVE-2026-87573) - Medium [353]
Description: Improper input validation in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00208, EPSS Percentile is 0.11108 |
altlinux: CVE-2026-87573 was patched at 2026-09-17
debian: CVE-2026-87573 was patched at 2026-09-16
924.
Security Feature Bypass - Chromium (CVE-2026-87598) - Medium [353]
Description: Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11573 |
altlinux: CVE-2026-87598 was patched at 2026-09-17
debian: CVE-2026-87598 was patched at 2026-09-16
925.
Security Feature Bypass - Chromium (CVE-2026-87619) - Medium [353]
Description: Observable discrepancy in Prefetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00193, EPSS Percentile is 0.09251 |
altlinux: CVE-2026-87619 was patched at 2026-09-17
debian: CVE-2026-87619 was patched at 2026-09-16
926.
Security Feature Bypass - Chromium (CVE-2026-87622) - Medium [353]
Description: Missing authorization in FedCM in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00203, EPSS Percentile is 0.10448 |
altlinux: CVE-2026-87622 was patched at 2026-09-17
debian: CVE-2026-87622 was patched at 2026-09-16
927.
Security Feature Bypass - Chromium (CVE-2026-87632) - Medium [353]
Description: Cross-site scripting in SanitizerAPI in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00233, EPSS Percentile is 0.14322 |
altlinux: CVE-2026-87632 was patched at 2026-09-17
debian: CVE-2026-87632 was patched at 2026-09-16
928.
Security Feature Bypass - Chromium (CVE-2026-87641) - Medium [353]
Description: Race condition in Browser in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00136, EPSS Percentile is 0.03409 |
altlinux: CVE-2026-87641 was patched at 2026-09-17
debian: CVE-2026-87641 was patched at 2026-09-16
929.
Security Feature Bypass - Mozilla Firefox (CVE-2026-74968) - Medium [353]
Description: Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00105, EPSS Percentile is 0.01196 |
altlinux: CVE-2026-74968 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
930.
Security Feature Bypass - Mozilla Firefox (CVE-2026-74970) - Medium [353]
Description: Site isolation issue in the Graphics component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.039 |
altlinux: CVE-2026-74970 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
931.
Security Feature Bypass - Node.js (CVE-2026-48932) - Medium [353]
Description: A flaw in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06871 |
debian: CVE-2026-48932 was patched at 2026-09-16
932.
Information Disclosure - Chromium (CVE-2026-78957) - Medium [352]
Description: Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.01528 |
altlinux: CVE-2026-78957 was patched at 2026-08-28
debian: CVE-2026-78957 was patched at 2026-09-03, 2026-09-16
933.
Information Disclosure - Chromium (CVE-2026-79095) - Medium [352]
Description: Information leak in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00254, EPSS Percentile is 0.1707 |
altlinux: CVE-2026-79095 was patched at 2026-08-28
debian: CVE-2026-79095 was patched at 2026-09-03, 2026-09-16
934.
Information Disclosure - Chromium (CVE-2026-79144) - Medium [352]
Description: Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00254, EPSS Percentile is 0.1707 |
altlinux: CVE-2026-79144 was patched at 2026-08-28
debian: CVE-2026-79144 was patched at 2026-09-03, 2026-09-16
935.
Information Disclosure - Chromium (CVE-2026-79146) - Medium [352]
Description: Information leak in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00106, EPSS Percentile is 0.01233 |
altlinux: CVE-2026-79146 was patched at 2026-08-28
debian: CVE-2026-79146 was patched at 2026-09-03, 2026-09-16
936.
Information Disclosure - Chromium (CVE-2026-79147) - Medium [352]
Description: Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0022, EPSS Percentile is 0.12608 |
altlinux: CVE-2026-79147 was patched at 2026-08-28
debian: CVE-2026-79147 was patched at 2026-09-03, 2026-09-16
937.
Information Disclosure - Chromium (CVE-2026-79181) - Medium [352]
Description: Observable discrepancy in Glic in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0022, EPSS Percentile is 0.12608 |
altlinux: CVE-2026-79181 was patched at 2026-08-28
debian: CVE-2026-79181 was patched at 2026-09-03, 2026-09-16
938.
Information Disclosure - Chromium (CVE-2026-79196) - Medium [352]
Description: Race condition in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00175, EPSS Percentile is 0.07313 |
altlinux: CVE-2026-79196 was patched at 2026-08-28
debian: CVE-2026-79196 was patched at 2026-09-03, 2026-09-16
939.
Information Disclosure - Chromium (CVE-2026-79274) - Medium [352]
Description: Information leak in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00254, EPSS Percentile is 0.1707 |
altlinux: CVE-2026-79274 was patched at 2026-08-28
debian: CVE-2026-79274 was patched at 2026-09-03, 2026-09-16
940.
Information Disclosure - Chromium (CVE-2026-84323) - Medium [352]
Description: Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00169, EPSS Percentile is 0.06609 |
altlinux: CVE-2026-84323 was patched at 2026-09-03
debian: CVE-2026-84323 was patched at 2026-09-03, 2026-09-16
941.
Information Disclosure - Chromium (CVE-2026-87552) - Medium [352]
Description: Missing authorization in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00114, EPSS Percentile is 0.01652 |
altlinux: CVE-2026-87552 was patched at 2026-09-17
debian: CVE-2026-87552 was patched at 2026-09-16
942.
Information Disclosure - Chromium (CVE-2026-87566) - Medium [352]
Description: Observable discrepancy in Layout in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0022, EPSS Percentile is 0.12608 |
altlinux: CVE-2026-87566 was patched at 2026-09-17
debian: CVE-2026-87566 was patched at 2026-09-16
943.
Information Disclosure - Chromium (CVE-2026-87574) - Medium [352]
Description: Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00244, EPSS Percentile is 0.1574 |
altlinux: CVE-2026-87574 was patched at 2026-09-17
debian: CVE-2026-87574 was patched at 2026-09-16
944.
Information Disclosure - Chromium (CVE-2026-87594) - Medium [352]
Description: Incorrect authorization in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00212, EPSS Percentile is 0.11626 |
altlinux: CVE-2026-87594 was patched at 2026-09-17
debian: CVE-2026-87594 was patched at 2026-09-16
945.
Information Disclosure - Chromium (CVE-2026-87605) - Medium [352]
Description: Missing authorization in Contacts in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07374 |
altlinux: CVE-2026-87605 was patched at 2026-09-17
debian: CVE-2026-87605 was patched at 2026-09-16
946.
Information Disclosure - Chromium (CVE-2026-91714) - Medium [352]
Description: Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00208, EPSS Percentile is 0.112 |
altlinux: CVE-2026-91714 was patched at 2026-09-17
debian: CVE-2026-91714 was patched at 2026-09-16
947.
Information Disclosure - Chromium (CVE-2026-91725) - Medium [352]
Description: Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive information via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00208, EPSS Percentile is 0.112 |
altlinux: CVE-2026-91725 was patched at 2026-09-17
debian: CVE-2026-91725 was patched at 2026-09-16
948.
Information Disclosure - Chromium (CVE-2026-91744) - Medium [352]
Description: Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00226, EPSS Percentile is 0.13391 |
altlinux: CVE-2026-91744 was patched at 2026-09-17
debian: CVE-2026-91744 was patched at 2026-09-16
949.
Information Disclosure - GNOME desktop (CVE-2026-91786) - Medium [352]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | GNOME originally an acronym for GNU Network Object Model Environment, is a free and open-source desktop environment for Linux and other Unix-like operating systems | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00131, EPSS Percentile is 0.03083 |
debian: CVE-2026-91786 was patched at 2026-09-16
950.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-71132) - Medium [351]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00135, EPSS Percentile is 0.03316 |
altlinux: CVE-2026-71132 was patched at 2026-08-21
951.
Security Feature Bypass - fast-uri (CVE-2026-75975) - Medium [351]
Description: fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6 destination. For example, a bracketed literal with invalid trailing characters is normalized to the unspecified address, which a Node HTTP client then connects to a local service over loopback, and other malformed literals collapse to private-range addresses. No error is set on the parsed result, so an application checking the error field cannot detect the rewrite. An application that normalizes untrusted URLs before outbound requests, redirects, proxy routing, or address-policy enforcement can be redirected to a local or private IPv6 target, giving a server-side request forgery and address-policy bypass primitive. The affected versions are 2.3.1 up to but not including 2.4.5, 3.0.0 up to but not including 3.1.6, and 4.0.0 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which validate bracketed IP literals against the full grammar and mark malformed literals as authority errors. Users should upgrade to a patched version.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:openjsf:fast-uri (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0022, EPSS Percentile is 0.12601 |
debian: CVE-2026-75975 was patched at 2026-08-25
952.
Security Feature Bypass - undici (CVE-2026-84961) - Medium [351]
Description: undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:nodejs:undici (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00146, EPSS Percentile is 0.04263 |
debian: CVE-2026-84961 was patched at 2026-09-16
953.
Cross Site Scripting - Perl (CVE-2026-19872) - Medium [350]
Description: HTML::FormHandler versions before 0.410000 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00327, EPSS Percentile is 0.25794 |
debian: CVE-2026-19872 was patched at 2026-09-16
954.
Information Disclosure - undici (CVE-2026-84933) - Medium [350]
Description: undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache mode, which is the default, an otherwise cacheable response that carries a Set-Cookie header, for example one marked with a public and max-age directive, is stored and then re-served to a later caller that matches the same cache key. As a result one caller's cookie is disclosed to a different caller, and an untrusted server can inject cookies into cached responses served to all subsequent callers. This violates the requirement that a shared cache must not store cookies. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Product detected by a:nodejs:undici (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00248, EPSS Percentile is 0.16264 |
debian: CVE-2026-84933 was patched at 2026-09-16
955.
Remote Code Execution - FreeRDP (CVE-2026-91957) - Medium [350]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00327, EPSS Percentile is 0.25841 |
debian: CVE-2026-91957 was patched at 2026-09-16
956.
Denial of Service - Apache Tomcat (CVE-2026-18047) - Medium [348]
Description: A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker can bypass the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00281, EPSS Percentile is 0.20704 |
redos: CVE-2026-18047 was patched at 2026-09-08
957.
Denial of Service - Erlang/OTP (CVE-2026-70399) - Medium [346]
Description: Allocation of Resources Without Limits or Throttling vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | Erlang/OTP is a set of libraries for the Erlang programming language | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00533, EPSS Percentile is 0.43689 |
debian: CVE-2026-70399 was patched at 2026-09-16
958.
Incorrect Calculation - Linux Kernel (CVE-2026-89559) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.05992 |
debian: CVE-2026-89559 was patched at 2026-09-16
959.
Memory Corruption - Linux Kernel (CVE-2026-74615) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02599 |
debian: CVE-2026-74615 was patched at 2026-08-25
oraclelinux: CVE-2026-74615 was patched at 2026-09-04
960.
Memory Corruption - Linux Kernel (CVE-2026-80693) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00131, EPSS Percentile is 0.0308 |
debian: CVE-2026-80693 was patched at 2026-09-16
961.
Memory Corruption - Linux Kernel (CVE-2026-80731) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07746 |
debian: CVE-2026-80731 was patched at 2026-09-16
oraclelinux: CVE-2026-80731 was patched at 2026-09-04
962.
Memory Corruption - Linux Kernel (CVE-2026-80732) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05491 |
debian: CVE-2026-80732 was patched at 2026-09-16
963.
Memory Corruption - Linux Kernel (CVE-2026-80752) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00182, EPSS Percentile is 0.08059 |
debian: CVE-2026-80752 was patched at 2026-09-16
964.
Memory Corruption - Linux Kernel (CVE-2026-80947) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05428 |
debian: CVE-2026-80947 was patched at 2026-09-16
965.
Memory Corruption - Linux Kernel (CVE-2026-80971) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.0549 |
debian: CVE-2026-80971 was patched at 2026-09-16
966.
Memory Corruption - Linux Kernel (CVE-2026-80982) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05489 |
debian: CVE-2026-80982 was patched at 2026-09-16
967.
Memory Corruption - Linux Kernel (CVE-2026-80991) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05426 |
debian: CVE-2026-80991 was patched at 2026-09-16
968.
Memory Corruption - Linux Kernel (CVE-2026-80992) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.05994 |
debian: CVE-2026-80992 was patched at 2026-09-16
969.
Memory Corruption - Linux Kernel (CVE-2026-80994) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.0549 |
debian: CVE-2026-80994 was patched at 2026-09-16
970.
Memory Corruption - Linux Kernel (CVE-2026-81001) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05489 |
debian: CVE-2026-81001 was patched at 2026-09-16
971.
Memory Corruption - Linux Kernel (CVE-2026-81008) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.0549 |
debian: CVE-2026-81008 was patched at 2026-09-16
972.
Memory Corruption - Linux Kernel (CVE-2026-81017) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00182, EPSS Percentile is 0.0806 |
debian: CVE-2026-81017 was patched at 2026-09-16
973.
Memory Corruption - Linux Kernel (CVE-2026-89442) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00163, EPSS Percentile is 0.05916 |
debian: CVE-2026-89442 was patched at 2026-09-16
974.
Memory Corruption - Linux Kernel (CVE-2026-89472) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05427 |
debian: CVE-2026-89472 was patched at 2026-09-16
975.
Memory Corruption - Linux Kernel (CVE-2026-89545) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00157, EPSS Percentile is 0.05254 |
debian: CVE-2026-89545 was patched at 2026-09-16
976.
Memory Corruption - Linux Kernel (CVE-2026-89622) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00157, EPSS Percentile is 0.05254 |
debian: CVE-2026-89622 was patched at 2026-09-16
977.
Memory Corruption - Linux Kernel (CVE-2026-89624) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06531 |
debian: CVE-2026-89624 was patched at 2026-09-16
978.
Memory Corruption - Linux Kernel (CVE-2026-89690) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05427 |
debian: CVE-2026-89690 was patched at 2026-09-16
979.
Memory Corruption - Linux Kernel (CVE-2026-89720) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00182, EPSS Percentile is 0.08058 |
debian: CVE-2026-89720 was patched at 2026-09-16
980.
Memory Corruption - Linux Kernel (CVE-2026-89724) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.05995 |
debian: CVE-2026-89724 was patched at 2026-09-16
981.
Memory Corruption - Linux Kernel (CVE-2026-89741) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.05989 |
debian: CVE-2026-89741 was patched at 2026-09-16
982.
Memory Corruption - Linux Kernel (CVE-2026-89742) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05491 |
debian: CVE-2026-89742 was patched at 2026-09-16
983.
Memory Corruption - Linux Kernel (CVE-2026-89746) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.0549 |
debian: CVE-2026-89746 was patched at 2026-09-16
984.
Memory Corruption - Linux Kernel (CVE-2026-89747) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05428 |
debian: CVE-2026-89747 was patched at 2026-09-16
985.
Memory Corruption - Linux Kernel (CVE-2026-89750) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05426 |
debian: CVE-2026-89750 was patched at 2026-09-16
986.
Memory Corruption - Linux Kernel (CVE-2026-89781) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10806 |
debian: CVE-2026-89781 was patched at 2026-09-16
987.
Memory Corruption - Linux Kernel (CVE-2026-89782) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10806 |
debian: CVE-2026-89782 was patched at 2026-09-16
988.
Memory Corruption - Linux Kernel (CVE-2026-89789) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11449 |
debian: CVE-2026-89789 was patched at 2026-09-16
989.
Remote Code Execution - Unknown Product (CVE-2026-84838) - Medium [345]
Description: {'nvd_cve_data_all': 'A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow invokes rpmuncompress on the malicious file, leading to high impact on the confidentiality, integrity, and availability of data accessible to the invoking user.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow invokes rpmuncompress on the malicious file, leading to high impact on the confidentiality, integrity, and availability of data accessible to the invoking user.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.01034, EPSS Percentile is 0.62125 |
debian: CVE-2026-84838 was patched at 2026-09-16
990.
Remote Code Execution - Unknown Product (CVE-2026-90558) - Medium [345]
Description: {'nvd_cve_data_all': 'sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack buffers and cause crashes or execute arbitrary code during packet parsing and rendering.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack buffers and cause crashes or execute arbitrary code during packet parsing and rendering.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00507, EPSS Percentile is 0.42046 |
debian: CVE-2026-90558 was patched at 2026-09-16
991.
Server-Side Request Forgery - fast-uri (CVE-2026-75899) - Medium [345]
Description: fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn nested percent-encoded input into a different network destination such as a loopback hostname or address. For example, a doubly encoded host that spells out a loopback name decodes to that live host in one operation, which contradicts RFC 3986 section 2.4 that an implementation must not decode the same string more than once. An application that normalizes or resolves an untrusted HTTP-family URI before outbound routing, redirect validation, or a host-policy check can receive a destination different from the one the original encoded host represented, giving a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.5 | 14 | Product detected by a:openjsf:fast-uri (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0022, EPSS Percentile is 0.12601 |
debian: CVE-2026-75899 was patched at 2026-08-25
992.
Server-Side Request Forgery - fast-uri (CVE-2026-76172) - Medium [345]
Description: fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and serialization writes the scheme back out verbatim, unlike the host component which is re-escaped. As a result an input whose scheme carries percent-encoded slashes parses as a scheme with no authority, so the parsed host and error are both undefined, yet resolving or normalizing that same input emits a network-path reference whose authority is attacker-chosen and re-parses to that host. An application that allowlists on the parsed host, or treats a reference with no authority as safe to resolve against its base, gets the opposite of what it checked, giving an off-site redirect,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.5 | 14 | Product detected by a:openjsf:fast-uri (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00232, EPSS Percentile is 0.14195 |
debian: CVE-2026-76172 was patched at 2026-08-25
993.
Server-Side Request Forgery - fast-uri (CVE-2026-84394) - Medium [345]
Description: fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but does not end with a closing bracket is neither validated as an IP literal nor canonicalized as a domain name, so parse() returns it as the host with error undefined, while Node's URL and the HTTP clients built on it resolve the same string to a different host. An application that reads the parsed host to make a host decision, such as an
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.5 | 14 | Product detected by a:openjsf:fast-uri (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00221, EPSS Percentile is 0.12804 |
debian: CVE-2026-84394 was patched at 2026-09-16
994.
Authentication Bypass - gitoxide (CVE-2026-82247) - Medium [344]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.3 | 14 | gitoxide is an idiomatic, lean, fast & safe pure Rust implementation of Git, designed for correctness and performance, available both as a Rust library (gix crate) and command-line interface tools. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00298, EPSS Percentile is 0.22481 |
debian: CVE-2026-82247 was patched at 2026-09-16
995.
Denial of Service - FreeRDP (CVE-2026-91951) - Medium [344]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00346, EPSS Percentile is 0.27989 |
debian: CVE-2026-91951 was patched at 2026-09-16
996.
Denial of Service - FreeRDP (CVE-2026-91952) - Medium [344]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00346, EPSS Percentile is 0.27989 |
debian: CVE-2026-91952 was patched at 2026-09-16
997.
Denial of Service - FreeRDP (CVE-2026-91954) - Medium [344]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00346, EPSS Percentile is 0.27989 |
debian: CVE-2026-91954 was patched at 2026-09-16
998.
Denial of Service - FreeRDP (CVE-2026-91961) - Medium [344]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00346, EPSS Percentile is 0.27988 |
debian: CVE-2026-91961 was patched at 2026-09-16
999.
Denial of Service - MongoDB (CVE-2026-82052) - Medium [344]
Description: The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00359, EPSS Percentile is 0.29494 |
altlinux: CVE-2026-82052 was patched at 2026-09-09, 2026-09-10
1000.
Denial of Service - MongoDB (CVE-2026-82064) - Medium [344]
Description: A security issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.003, EPSS Percentile is 0.22641 |
altlinux: CVE-2026-82064 was patched at 2026-09-09, 2026-09-10
1001.
Denial of Service - MongoDB (CVE-2026-82075) - Medium [344]
Description: An uncontrolled resource consumption weakness exists in the request-handling path of the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.003, EPSS Percentile is 0.22641 |
altlinux: CVE-2026-82075 was patched at 2026-09-09, 2026-09-10
1002.
Denial of Service - strongSwan (CVE-2026-78132) - Medium [344]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | strongSwan is an open source IPsec-based VPN solution that provides secure network connectivity using IKEv1 and IKEv2 protocols, widely used on Linux systems for site-to-site and remote access VPN deployments. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00315, EPSS Percentile is 0.24429 |
altlinux: CVE-2026-78132 was patched at 2026-09-11
debian: CVE-2026-78132 was patched at 2026-09-07, 2026-09-16
1003.
Information Disclosure - zstd-jni (CVE-2026-89046) - Medium [344]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.25 | 14 | zstd-jni provides Java Native Interface bindings for the Zstandard lossless compression library, enabling high-performance compression and decompression from Java, Android, and other JVM languages. | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00571, EPSS Percentile is 0.45751 |
debian: CVE-2026-89046 was patched at 2026-09-16
1004.
Security Feature Bypass - wpa_supplicant (CVE-2026-78807) - Medium [344]
Description: An issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | wpa_supplicant is a free software implementation of an IEEE 802.11i supplicant for Linux, FreeBSD, NetBSD, QNX, AROS, Microsoft Windows, Solaris, OS/2 (including ArcaOS and eComStation) and Haiku | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0008, EPSS Percentile is 0.00212 |
debian: CVE-2026-78807 was patched at 2026-09-16
1005.
Authentication Bypass - Xeon Bronze 3408U (CVE-2026-20885) - Medium [341]
Description: Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an information disclosure and escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by h:intel:xeon_bronze_3408u (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00143, EPSS Percentile is 0.03978 |
oraclelinux: CVE-2026-20885 was patched at 2026-09-02, 2026-09-16
1006.
Authentication Bypass - xeon_6315p (CVE-2026-20898) - Medium [341]
Description: Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by h:intel:xeon_6315p (does NOT exist in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00119, EPSS Percentile is 0.02003 |
oraclelinux: CVE-2026-20898 was patched at 2026-09-02, 2026-09-16
1007.
Denial of Service - Zabbix (CVE-2026-23938) - Medium [341]
Description: An authenticated administrator is able to crash
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Zabbix is an open-source software tool to monitor IT infrastructure such as networks, servers, virtual machines, and cloud services | |
| 0.5 | 10 | CVSS Base Score is 4.9. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00298, EPSS Percentile is 0.22541 |
altlinux: CVE-2026-23938 was patched at 2026-08-26, 2026-08-27, 2026-08-28
debian: CVE-2026-23938 was patched at 2026-08-20
1008.
Incorrect Calculation - Chromium (CVE-2026-79223) - Medium [341]
Description: Integer overflow in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00233, EPSS Percentile is 0.14372 |
altlinux: CVE-2026-79223 was patched at 2026-08-28
debian: CVE-2026-79223 was patched at 2026-09-03, 2026-09-16
1009.
Information Disclosure - Chromium (CVE-2026-78896) - Medium [341]
Description: Information leak in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.14645 |
altlinux: CVE-2026-78896 was patched at 2026-08-28
debian: CVE-2026-78896 was patched at 2026-09-03, 2026-09-16
1010.
Information Disclosure - Chromium (CVE-2026-79055) - Medium [341]
Description: Information leak in Sharing in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00102, EPSS Percentile is 0.01068 |
altlinux: CVE-2026-79055 was patched at 2026-08-28
debian: CVE-2026-79055 was patched at 2026-09-03, 2026-09-16
1011.
Information Disclosure - Chromium (CVE-2026-79068) - Medium [341]
Description: Improper resource exposure in StreamsAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy into a privileged page via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00208, EPSS Percentile is 0.11108 |
altlinux: CVE-2026-79068 was patched at 2026-08-28
debian: CVE-2026-79068 was patched at 2026-09-03, 2026-09-16
1012.
Information Disclosure - Chromium (CVE-2026-79086) - Medium [341]
Description: Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00106, EPSS Percentile is 0.01229 |
altlinux: CVE-2026-79086 was patched at 2026-08-28
debian: CVE-2026-79086 was patched at 2026-09-03, 2026-09-16
1013.
Information Disclosure - Chromium (CVE-2026-79252) - Medium [341]
Description: Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00201, EPSS Percentile is 0.10226 |
altlinux: CVE-2026-79252 was patched at 2026-08-28
debian: CVE-2026-79252 was patched at 2026-09-03, 2026-09-16
1014.
Information Disclosure - Chromium (CVE-2026-87658) - Medium [341]
Description: Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07739 |
altlinux: CVE-2026-87658 was patched at 2026-09-17
debian: CVE-2026-87658 was patched at 2026-09-16
1015.
Information Disclosure - Chromium (CVE-2026-91717) - Medium [341]
Description: Missing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00079, EPSS Percentile is 0.00178 |
altlinux: CVE-2026-91717 was patched at 2026-09-17
debian: CVE-2026-91717 was patched at 2026-09-16
1016.
Memory Corruption - Mozilla Firefox (CVE-2026-84123) - Medium [341]
Description: Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00233, EPSS Percentile is 0.1429 |
altlinux: CVE-2026-84123 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
1017.
Memory Corruption - Mozilla Firefox (CVE-2026-84144) - Medium [341]
Description: Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00241, EPSS Percentile is 0.15462 |
altlinux: CVE-2026-84144 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
1018.
Path Traversal - GNOME desktop (CVE-2026-74859) - Medium [341]
Description: The shell theme installer in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.8 | 14 | GNOME originally an acronym for GNU Network Object Model Environment, is a free and open-source desktop environment for Linux and other Unix-like operating systems | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02662 |
debian: CVE-2026-74859 was patched at 2026-09-16
1019.
Security Feature Bypass - Chromium (CVE-2026-78894) - Medium [341]
Description: Race condition in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11452 |
altlinux: CVE-2026-78894 was patched at 2026-08-28
debian: CVE-2026-78894 was patched at 2026-09-03, 2026-09-16
1020.
Security Feature Bypass - Chromium (CVE-2026-79034) - Medium [341]
Description: Information leak in CORS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00179, EPSS Percentile is 0.07682 |
altlinux: CVE-2026-79034 was patched at 2026-08-28
debian: CVE-2026-79034 was patched at 2026-09-03, 2026-09-16
1021.
Security Feature Bypass - Chromium (CVE-2026-79084) - Medium [341]
Description: Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.03284 |
altlinux: CVE-2026-79084 was patched at 2026-08-28
debian: CVE-2026-79084 was patched at 2026-09-03, 2026-09-16
1022.
Security Feature Bypass - Chromium (CVE-2026-79103) - Medium [341]
Description: Incorrect reference resolution in Speech in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00229, EPSS Percentile is 0.13882 |
altlinux: CVE-2026-79103 was patched at 2026-08-28
debian: CVE-2026-79103 was patched at 2026-09-03, 2026-09-16
1023.
Security Feature Bypass - Chromium (CVE-2026-79186) - Medium [341]
Description: Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00227, EPSS Percentile is 0.13504 |
altlinux: CVE-2026-79186 was patched at 2026-08-28
debian: CVE-2026-79186 was patched at 2026-09-03, 2026-09-16
1024.
Security Feature Bypass - Chromium (CVE-2026-79191) - Medium [341]
Description: Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00227, EPSS Percentile is 0.13504 |
altlinux: CVE-2026-79191 was patched at 2026-08-28
debian: CVE-2026-79191 was patched at 2026-09-03, 2026-09-16
1025.
Security Feature Bypass - Chromium (CVE-2026-79289) - Medium [341]
Description: Improper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00214, EPSS Percentile is 0.11958 |
altlinux: CVE-2026-79289 was patched at 2026-08-28
debian: CVE-2026-79289 was patched at 2026-09-03, 2026-09-16
1026.
Security Feature Bypass - Chromium (CVE-2026-87551) - Medium [341]
Description: Improper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00143, EPSS Percentile is 0.04011 |
altlinux: CVE-2026-87551 was patched at 2026-09-17
debian: CVE-2026-87551 was patched at 2026-09-16
1027.
Security Feature Bypass - Netty (CVE-2026-76816) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Netty is a non-blocking I/O client-server framework for the development of Java network applications such as protocol servers and clients | |
| 0.3 | 10 | CVSS Base Score is 3.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00174, EPSS Percentile is 0.07099 |
debian: CVE-2026-76816 was patched at 2026-09-16
1028.
Security Feature Bypass - PHP (CVE-2026-16434) - Medium [341]
Description: Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GHSA-8478-xrj3-h9c2). The validation guard (bootstrap.inc.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.2 | 10 | CVSS Base Score is 2.3. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00301, EPSS Percentile is 0.22773 |
debian: CVE-2026-16434 was patched at 2026-09-16
1029.
Remote Code Execution - Flatpak (CVE-2026-86320) - Medium [340]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | Flatpak is a utility for software deployment and package management for Linux | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-86320 was patched at 2026-09-12
debian: CVE-2026-86320 was patched at 2026-09-16
1030.
Remote Code Execution - Git (CVE-2026-77652) - Medium [340]
Description: A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer. In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette with: ren->pPal = g_new0(WPGColorRGB, 256); When handling a WPG_COLORMAP record, the parser reads a start index (i16) and number of colors (iNum16) from the file and reads palette data with: bRet &= (iNum16 == (int)fread(&ren->pPal[i16], sizeof(WPGColorRGB), iNum16, f)); The only bounds-related check is `if (i16 >= 0 && i16 <= iSize)`, where iSize is the WPG record size—not the palette capacity. There is no validation that i16 is less than 256 or that i16 + iNum16 does not exceed 256. A malicious WPG file can supply i16=256 and iNum16=264. That causes fread() to write 792 bytes starting at &pPal[256], while the palette buffer is only 768 bytes (256 entries × 3 bytes). This overflows into adjacent heap metadata and can crash Dia (SIGABRT / malloc corruption errors) or, depending on heap layout and exploit primitives, potentially lead to arbitrary
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | Git | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00151, EPSS Percentile is 0.04658 |
debian: CVE-2026-77652 was patched at 2026-09-16
1031.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-71139) - Medium [339]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.4 | 10 | CVSS Base Score is 4.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0015, EPSS Percentile is 0.04574 |
altlinux: CVE-2026-71139 was patched at 2026-08-21
1032.
Command Injection - Unknown Product (CVE-2026-38822) - Medium [339]
Description: {'nvd_cve_data_all': 'In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.6. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.00849, EPSS Percentile is 0.56358 |
debian: CVE-2026-38822 was patched at 2026-09-16
1033.
Denial of Service - 389 Directory Server (CVE-2026-78701) - Medium [339]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | 389 Directory Server is a highly usable, fully featured, reliable and secure LDAP server implementation | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00419, EPSS Percentile is 0.35633 |
almalinux: CVE-2026-78701 was patched at 2026-09-08
oraclelinux: CVE-2026-78701 was patched at 2026-09-08
redhat: CVE-2026-78701 was patched at 2026-09-08
1034.
Denial of Service - Cockpit (CVE-2026-76235) - Medium [339]
Description: A memory leak flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Cockpit is a web-based server administration tool for Linux systems that allows users to manage servers, containers, storage, and network configurations through a browser interface. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00355, EPSS Percentile is 0.29016 |
debian: CVE-2026-76235 was patched at 2026-08-20, 2026-08-27
1035.
Denial of Service - Crypto (CVE-2026-56855) - Medium [339]
Description: Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:golang:crypto (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00378, EPSS Percentile is 0.31491 |
debian: CVE-2026-56855 was patched at 2026-09-16
1036.
Denial of Service - Elasticsearch (CVE-2026-56148) - Medium [339]
Description: Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:elastic:elasticsearch (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00472, EPSS Percentile is 0.39702 |
redos: CVE-2026-56148 was patched at 2026-09-02
1037.
Denial of Service - NGINX (CVE-2026-78222) - Medium [339]
Description: A vulnerability exists in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Nginx is an open-source web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00372, EPSS Percentile is 0.30833 |
debian: CVE-2026-78222 was patched at 2026-09-16
1038.
Denial of Service - TimescaleDB (CVE-2026-70633) - Medium [339]
Description: TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compression reverse row iterator that allows authenticated attackers to cause a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:timescale:timescaledb (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00492, EPSS Percentile is 0.41053 |
altlinux: CVE-2026-70633 was patched at 2026-08-26, 2026-08-28, 2026-08-29, 2026-09-01
1039.
Denial of Service - nsd (CVE-2026-18916) - Medium [339]
Description: Any remote client
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:nlnetlabs:nsd (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00357, EPSS Percentile is 0.29296 |
altlinux: CVE-2026-18916 was patched at 2026-08-27, 2026-08-28, 2026-09-01
debian: CVE-2026-18916 was patched at 2026-09-16
1040.
Denial of Service - trivy (CVE-2026-54448) - Medium [339]
Description: Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(tr) and no size limit. An attacker who can place a malicious .tgz file in the scanned path can craft a small compressed archive that decompresses to gigabytes, causing the Trivy process to be killed by the OS OOM killer. This vulnerability is fixed in 0.71.0.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:aquasec:trivy (does NOT exist in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00443, EPSS Percentile is 0.37676 |
redos: CVE-2026-54448 was patched at 2026-09-02
1041.
Path Traversal - dart_software_development_kit (CVE-2026-27704) - Medium [339]
Description: The Dart and Flutter SDKs provide software development kits for the Dart programming language. In versions of the Dart SDK prior to 3.11.0 and the Flutter SDK prior to version 3.41.0, when the pub client (`dart pub` and `flutter pub`) extracts a package in the pub cache, a malicious package archive can have files extracted outside the destination directory in the `PUB_CACHE`. A fix has been landed in commit 26c6985c742593d081f8b58450f463a584a4203a. By normalizing the file path before writing file, the attacker can no longer traverse up via a symlink. This patch is released in Dart 3.11.0 and Flutter 3.41.0.vAll packages on pub.dev have been vetted for this vulnerability. New packages are no longer allowed to contain symlinks. The pub client itself doesn't upload symlinks, but duplicates the linked entry, and has been doing this for years. Those whose dependencies are all from pub.dev, third-party repositories trusted to not contain malicious code, or git dependencies are not affected by this vulnerability.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Product detected by a:dart:dart_software_development_kit (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00356, EPSS Percentile is 0.29141 |
altlinux: CVE-2026-27704 was patched at 2026-08-28
1042.
Cross Site Scripting - Perl (CVE-2026-85484) - Medium [338]
Description: HTML::FormHandler versions before 0.410002 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.17245 |
debian: CVE-2026-85484 was patched at 2026-09-16
1043.
Cross Site Scripting - Perl (CVE-2026-85630) - Medium [338]
Description: HTML::FormHandler versions before 0.410002 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.17245 |
debian: CVE-2026-85630 was patched at 2026-09-16
1044.
Information Disclosure - OpenEXR (CVE-2026-59189) - Medium [338]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | OpenEXR is an open source high-dynamic-range image file format and reference implementation widely used in computer graphics, visual effects, animation, and motion picture production. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16131 |
debian: CVE-2026-59189 was patched at 2026-09-16
1045.
Denial of Service - Envoy (CVE-2026-73547) - Medium [336]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-73547 was patched at 2026-08-28, 2026-08-31
1046.
Spoofing - Safari (CVE-2026-64730) - Medium [335]
Description: The issue was addressed with improved UI. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00485, EPSS Percentile is 0.40599 |
altlinux: CVE-2026-64730 was patched at 2026-08-24
debian: CVE-2026-64730 was patched at 2026-08-24, 2026-08-25
ubuntu: CVE-2026-64730 was patched at 2026-08-31, 2026-09-16
1047.
Denial of Service - Erlang/OTP (CVE-2026-71380) - Medium [334]
Description: Missing Release of Resource after Effective Lifetime vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | Erlang/OTP is a set of libraries for the Erlang programming language | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00387, EPSS Percentile is 0.32457 |
debian: CVE-2026-71380 was patched at 2026-09-16
1048.
Denial of Service - Spring Framework (CVE-2026-47891) - Medium [334]
Description: A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | The Spring Framework is an application framework and inversion of control container for the Java platform | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0029, EPSS Percentile is 0.21665 |
debian: CVE-2026-47891 was patched at 2026-09-16
1049.
Memory Corruption - Linux Kernel (CVE-2026-64502) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00119, EPSS Percentile is 0.02005 |
ubuntu: CVE-2026-64502 was patched at 2026-09-07, 2026-09-16
1050.
Memory Corruption - Linux Kernel (CVE-2026-64601) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.02443 |
ubuntu: CVE-2026-64601 was patched at 2026-09-07, 2026-09-16
1051.
Memory Corruption - Linux Kernel (CVE-2026-74582) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.0212 |
debian: CVE-2026-74582 was patched at 2026-08-25
oraclelinux: CVE-2026-74582 was patched at 2026-09-04
redhat: CVE-2026-74582 was patched at 2026-09-04
1052.
Memory Corruption - Linux Kernel (CVE-2026-74583) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.01886 |
debian: CVE-2026-74583 was patched at 2026-08-25
oraclelinux: CVE-2026-74583 was patched at 2026-09-04
1053.
Memory Corruption - Linux Kernel (CVE-2026-74589) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00138, EPSS Percentile is 0.03533 |
debian: CVE-2026-74589 was patched at 2026-08-25
oraclelinux: CVE-2026-74589 was patched at 2026-09-04
1054.
Memory Corruption - Linux Kernel (CVE-2026-74604) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00138, EPSS Percentile is 0.03533 |
debian: CVE-2026-74604 was patched at 2026-08-25
oraclelinux: CVE-2026-74604 was patched at 2026-09-04
1055.
Memory Corruption - Linux Kernel (CVE-2026-74606) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02545 |
debian: CVE-2026-74606 was patched at 2026-08-25
oraclelinux: CVE-2026-74606 was patched at 2026-09-04
1056.
Memory Corruption - Linux Kernel (CVE-2026-74609) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02598 |
debian: CVE-2026-74609 was patched at 2026-08-25
oraclelinux: CVE-2026-74609 was patched at 2026-09-04
1057.
Memory Corruption - Linux Kernel (CVE-2026-74610) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02872 |
debian: CVE-2026-74610 was patched at 2026-08-25
oraclelinux: CVE-2026-74610 was patched at 2026-09-04
1058.
Memory Corruption - Linux Kernel (CVE-2026-74613) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02599 |
debian: CVE-2026-74613 was patched at 2026-08-25
oraclelinux: CVE-2026-74613 was patched at 2026-09-04
1059.
Memory Corruption - Linux Kernel (CVE-2026-74630) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02831 |
debian: CVE-2026-74630 was patched at 2026-08-25
oraclelinux: CVE-2026-74630 was patched at 2026-09-04
1060.
Memory Corruption - Linux Kernel (CVE-2026-74631) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00138, EPSS Percentile is 0.03533 |
debian: CVE-2026-74631 was patched at 2026-08-25
1061.
Memory Corruption - Linux Kernel (CVE-2026-74634) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02546 |
debian: CVE-2026-74634 was patched at 2026-08-25
oraclelinux: CVE-2026-74634 was patched at 2026-09-04
1062.
Memory Corruption - Linux Kernel (CVE-2026-74635) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02932 |
debian: CVE-2026-74635 was patched at 2026-08-25
oraclelinux: CVE-2026-74635 was patched at 2026-09-04
1063.
Memory Corruption - Linux Kernel (CVE-2026-74637) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02603 |
debian: CVE-2026-74637 was patched at 2026-08-25
1064.
Memory Corruption - Linux Kernel (CVE-2026-74656) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02594 |
debian: CVE-2026-74656 was patched at 2026-08-25
oraclelinux: CVE-2026-74656 was patched at 2026-09-04
1065.
Memory Corruption - Linux Kernel (CVE-2026-74660) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.0259 |
debian: CVE-2026-74660 was patched at 2026-08-25
oraclelinux: CVE-2026-74660 was patched at 2026-09-04
1066.
Memory Corruption - Linux Kernel (CVE-2026-74661) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02543 |
debian: CVE-2026-74661 was patched at 2026-08-25
oraclelinux: CVE-2026-74661 was patched at 2026-09-04
1067.
Memory Corruption - Linux Kernel (CVE-2026-74700) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02543 |
debian: CVE-2026-74700 was patched at 2026-08-25
oraclelinux: CVE-2026-74700 was patched at 2026-09-04
1068.
Memory Corruption - Linux Kernel (CVE-2026-74711) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0014, EPSS Percentile is 0.03748 |
debian: CVE-2026-74711 was patched at 2026-08-25
1069.
Memory Corruption - Linux Kernel (CVE-2026-74714) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02592 |
debian: CVE-2026-74714 was patched at 2026-08-25
oraclelinux: CVE-2026-74714 was patched at 2026-09-04
1070.
Memory Corruption - Linux Kernel (CVE-2026-74724) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02384 |
debian: CVE-2026-74724 was patched at 2026-08-25
oraclelinux: CVE-2026-74724 was patched at 2026-09-04
1071.
Memory Corruption - Linux Kernel (CVE-2026-74725) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02546 |
debian: CVE-2026-74725 was patched at 2026-08-25
oraclelinux: CVE-2026-74725 was patched at 2026-09-04
1072.
Memory Corruption - Linux Kernel (CVE-2026-74739) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00138, EPSS Percentile is 0.03599 |
debian: CVE-2026-74739 was patched at 2026-09-16
1073.
Memory Corruption - Linux Kernel (CVE-2026-80536) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04027 |
debian: CVE-2026-80536 was patched at 2026-08-29, 2026-09-16
1074.
Memory Corruption - Linux Kernel (CVE-2026-80556) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02533 |
debian: CVE-2026-80556 was patched at 2026-09-16
1075.
Memory Corruption - Linux Kernel (CVE-2026-80568) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00133, EPSS Percentile is 0.03192 |
debian: CVE-2026-80568 was patched at 2026-09-16
1076.
Memory Corruption - Linux Kernel (CVE-2026-80570) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.03301 |
debian: CVE-2026-80570 was patched at 2026-09-16
1077.
Memory Corruption - Linux Kernel (CVE-2026-80593) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04029 |
debian: CVE-2026-80593 was patched at 2026-09-16
oraclelinux: CVE-2026-80593 was patched at 2026-09-04
redos: CVE-2026-80593 was patched at 2026-09-16
1078.
Memory Corruption - Linux Kernel (CVE-2026-80598) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02911 |
debian: CVE-2026-80598 was patched at 2026-09-16
redos: CVE-2026-80598 was patched at 2026-09-16
1079.
Memory Corruption - Linux Kernel (CVE-2026-80622) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02576 |
debian: CVE-2026-80622 was patched at 2026-09-16
oraclelinux: CVE-2026-80622 was patched at 2026-09-04
redos: CVE-2026-80622 was patched at 2026-09-16
1080.
Memory Corruption - Linux Kernel (CVE-2026-80678) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.0403 |
debian: CVE-2026-80678 was patched at 2026-09-16
oraclelinux: CVE-2026-80678 was patched at 2026-09-04
1081.
Memory Corruption - Linux Kernel (CVE-2026-80932) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0014, EPSS Percentile is 0.0369 |
debian: CVE-2026-80932 was patched at 2026-09-16
1082.
Memory Corruption - Linux Kernel (CVE-2026-80952) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02576 |
debian: CVE-2026-80952 was patched at 2026-09-16
1083.
Memory Corruption - Linux Kernel (CVE-2026-89469) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0014, EPSS Percentile is 0.03691 |
debian: CVE-2026-89469 was patched at 2026-09-16
1084.
Memory Corruption - Linux Kernel (CVE-2026-89470) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04029 |
debian: CVE-2026-89470 was patched at 2026-09-16
1085.
Memory Corruption - Linux Kernel (CVE-2026-89471) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.0403 |
debian: CVE-2026-89471 was patched at 2026-09-16
1086.
Memory Corruption - Linux Kernel (CVE-2026-89488) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02577 |
debian: CVE-2026-89488 was patched at 2026-09-16
1087.
Memory Corruption - Linux Kernel (CVE-2026-89508) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02577 |
debian: CVE-2026-89508 was patched at 2026-09-16
1088.
Memory Corruption - Linux Kernel (CVE-2026-89548) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02576 |
debian: CVE-2026-89548 was patched at 2026-09-16
1089.
Memory Corruption - Linux Kernel (CVE-2026-89553) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.0328 |
debian: CVE-2026-89553 was patched at 2026-09-16
1090.
Memory Corruption - Linux Kernel (CVE-2026-89580) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.0285 |
debian: CVE-2026-89580 was patched at 2026-09-16
1091.
Memory Corruption - Linux Kernel (CVE-2026-89587) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.03923 |
debian: CVE-2026-89587 was patched at 2026-09-16
1092.
Memory Corruption - Linux Kernel (CVE-2026-89596) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06988 |
debian: CVE-2026-89596 was patched at 2026-09-16
1093.
Memory Corruption - Linux Kernel (CVE-2026-89603) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.03905 |
debian: CVE-2026-89603 was patched at 2026-09-16
1094.
Memory Corruption - Linux Kernel (CVE-2026-89731) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00158, EPSS Percentile is 0.05315 |
debian: CVE-2026-89731 was patched at 2026-09-16
1095.
Memory Corruption - Linux Kernel (CVE-2026-89736) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02627 |
debian: CVE-2026-89736 was patched at 2026-09-16
1096.
Memory Corruption - Linux Kernel (CVE-2026-89743) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04027 |
debian: CVE-2026-89743 was patched at 2026-09-16
1097.
Memory Corruption - Linux Kernel (CVE-2026-89761) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02058 |
debian: CVE-2026-89761 was patched at 2026-09-16
1098.
Memory Corruption - Linux Kernel (CVE-2026-89763) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00115, EPSS Percentile is 0.01762 |
debian: CVE-2026-89763 was patched at 2026-09-16
1099.
Denial of Service - MongoDB (CVE-2026-18688) - Medium [332]
Description: An issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00268, EPSS Percentile is 0.19097 |
altlinux: CVE-2026-18688 was patched at 2026-08-26
1100.
Denial of Service - MongoDB (CVE-2026-18693) - Medium [332]
Description: An issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.8 | 10 | CVSS Base Score is 7.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00229, EPSS Percentile is 0.13807 |
altlinux: CVE-2026-18693 was patched at 2026-08-26
1101.
Denial of Service - MongoDB (CVE-2026-18694) - Medium [332]
Description: An issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00268, EPSS Percentile is 0.19098 |
altlinux: CVE-2026-18694 was patched at 2026-08-26
1102.
Denial of Service - MongoDB (CVE-2026-18695) - Medium [332]
Description: An issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0029, EPSS Percentile is 0.21593 |
altlinux: CVE-2026-18695 was patched at 2026-08-26
1103.
Denial of Service - MongoDB (CVE-2026-18699) - Medium [332]
Description: An issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00289, EPSS Percentile is 0.2156 |
altlinux: CVE-2026-18699 was patched at 2026-08-26
1104.
Denial of Service - MongoDB (CVE-2026-18700) - Medium [332]
Description: An issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00289, EPSS Percentile is 0.21562 |
altlinux: CVE-2026-18700 was patched at 2026-08-26
1105.
Denial of Service - MongoDB (CVE-2026-18701) - Medium [332]
Description: An issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00302, EPSS Percentile is 0.22931 |
altlinux: CVE-2026-18701 was patched at 2026-08-26
1106.
Denial of Service - MongoDB (CVE-2026-82054) - Medium [332]
Description: A security issue exists in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00289, EPSS Percentile is 0.21562 |
altlinux: CVE-2026-82054 was patched at 2026-09-09, 2026-09-10
1107.
Denial of Service - MongoDB (CVE-2026-82058) - Medium [332]
Description: A flaw in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00289, EPSS Percentile is 0.21563 |
altlinux: CVE-2026-82058 was patched at 2026-09-09, 2026-09-10
1108.
Denial of Service - MongoDB (CVE-2026-82059) - Medium [332]
Description: An internal aggregation expression in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.17216 |
altlinux: CVE-2026-82059 was patched at 2026-09-09, 2026-09-10
1109.
Denial of Service - MongoDB (CVE-2026-82068) - Medium [332]
Description: A security issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00289, EPSS Percentile is 0.21561 |
altlinux: CVE-2026-82068 was patched at 2026-09-09, 2026-09-10
1110.
Denial of Service - MongoDB (CVE-2026-82076) - Medium [332]
Description: An integer overflow in the query planning component of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0029, EPSS Percentile is 0.2163 |
altlinux: CVE-2026-82076 was patched at 2026-09-09, 2026-09-10
1111.
Denial of Service - Perl (CVE-2026-73639) - Medium [332]
Description: Imager::File::PNG versions from 1.003 before 1.004 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-73639 was patched at 2026-08-26, 2026-08-27
debian: CVE-2026-73639 was patched at 2026-08-20
1112.
Denial of Service - Rclone (CVE-2026-79775) - Medium [332]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers, supporting over 40 cloud storage products including S3, Google Drive, Dropbox, OneDrive, and many more. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00307, EPSS Percentile is 0.23425 |
debian: CVE-2026-79775 was patched at 2026-09-16
1113.
Denial of Service - strongSwan (CVE-2026-78129) - Medium [332]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | strongSwan is an open source IPsec-based VPN solution that provides secure network connectivity using IKEv1 and IKEv2 protocols, widely used on Linux systems for site-to-site and remote access VPN deployments. | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00413, EPSS Percentile is 0.34998 |
altlinux: CVE-2026-78129 was patched at 2026-09-11
debian: CVE-2026-78129 was patched at 2026-09-07, 2026-09-16
1114.
Memory Corruption - strongSwan (CVE-2026-78133) - Medium [332]
Description: libcharon in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | strongSwan is an open source IPsec-based VPN solution that provides secure network connectivity using IKEv1 and IKEv2 protocols, widely used on Linux systems for site-to-site and remote access VPN deployments. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00426, EPSS Percentile is 0.3627 |
altlinux: CVE-2026-78133 was patched at 2026-09-11
debian: CVE-2026-78133 was patched at 2026-09-07, 2026-09-16
1115.
Path Traversal - Rclone (CVE-2026-79781) - Medium [332]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.6 | 14 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers, supporting over 40 cloud storage products including S3, Google Drive, Dropbox, OneDrive, and many more. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.1721 |
debian: CVE-2026-79781 was patched at 2026-09-16
1116.
Information Disclosure - Rclone (CVE-2026-79776) - Medium [331]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers, supporting over 40 cloud storage products including S3, Google Drive, Dropbox, OneDrive, and many more. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00304, EPSS Percentile is 0.23184 |
debian: CVE-2026-79776 was patched at 2026-09-16
1117.
Information Disclosure - gdk-pixbuf (CVE-2026-18090) - Medium [331]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | gdk-pixbuf is an open source image loading and manipulation library used primarily in GNOME-based applications for handling various image formats, including JPEG, PNG, and GIF. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00167, EPSS Percentile is 0.06342 |
debian: CVE-2026-18090 was patched at 2026-09-16
1118.
Authentication Bypass - Unknown Product (CVE-2026-58421) - Medium [329]
Description: {'nvd_cve_data_all': 'Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00582, EPSS Percentile is 0.46272 |
altlinux: CVE-2026-58421 was patched at 2026-08-27, 2026-08-29, 2026-09-04
1119.
Denial of Service - Chromium (CVE-2026-79276) - Medium [329]
Description: Improper privilege management in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00275, EPSS Percentile is 0.19913 |
altlinux: CVE-2026-79276 was patched at 2026-08-28
debian: CVE-2026-79276 was patched at 2026-09-03, 2026-09-16
1120.
Denial of Service - Chromium (CVE-2026-87655) - Medium [329]
Description: Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00182, EPSS Percentile is 0.08012 |
altlinux: CVE-2026-87655 was patched at 2026-09-17
debian: CVE-2026-87655 was patched at 2026-09-16
1121.
Denial of Service - GNU C Library (CVE-2026-89092) - Medium [329]
Description: The nscd service in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | The GNU C Library, commonly known as glibc, is the GNU Project's implementation of the C standard library | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00241, EPSS Percentile is 0.15406 |
debian: CVE-2026-89092 was patched at 2026-09-16
1122.
Information Disclosure - Chromium (CVE-2026-79059) - Medium [329]
Description: Information leak in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00179, EPSS Percentile is 0.07682 |
altlinux: CVE-2026-79059 was patched at 2026-08-28
debian: CVE-2026-79059 was patched at 2026-09-03, 2026-09-16
1123.
Information Disclosure - Chromium (CVE-2026-87451) - Medium [329]
Description: Information leak in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00217, EPSS Percentile is 0.12259 |
altlinux: CVE-2026-87451 was patched at 2026-09-17
debian: CVE-2026-87451 was patched at 2026-09-16
1124.
Information Disclosure - Chromium (CVE-2026-87521) - Medium [329]
Description: Information leak in WebMCP in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00209, EPSS Percentile is 0.11276 |
altlinux: CVE-2026-87521 was patched at 2026-09-17
debian: CVE-2026-87521 was patched at 2026-09-16
1125.
Information Disclosure - Chromium (CVE-2026-87531) - Medium [329]
Description: Information leak in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00179, EPSS Percentile is 0.07682 |
altlinux: CVE-2026-87531 was patched at 2026-09-17
debian: CVE-2026-87531 was patched at 2026-09-16
1126.
Information Disclosure - Chromium (CVE-2026-87539) - Medium [329]
Description: Observable discrepancy in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00215, EPSS Percentile is 0.12078 |
altlinux: CVE-2026-87539 was patched at 2026-09-17
debian: CVE-2026-87539 was patched at 2026-09-16
1127.
Memory Corruption - Chromium (CVE-2026-79112) - Medium [329]
Description: Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16182 |
altlinux: CVE-2026-79112 was patched at 2026-08-28
debian: CVE-2026-79112 was patched at 2026-09-03, 2026-09-16
1128.
Memory Corruption - Chromium (CVE-2026-79206) - Medium [329]
Description: Out of bounds read in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to read memory outside the sandbox via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16183 |
altlinux: CVE-2026-79206 was patched at 2026-08-28
debian: CVE-2026-79206 was patched at 2026-09-03, 2026-09-16
1129.
Memory Corruption - Chromium (CVE-2026-79239) - Medium [329]
Description: Out of bounds read in Tint in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16185 |
altlinux: CVE-2026-79239 was patched at 2026-08-28
debian: CVE-2026-79239 was patched at 2026-09-03, 2026-09-16
1130.
Memory Corruption - Chromium (CVE-2026-79241) - Medium [329]
Description: Out of bounds read in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00312, EPSS Percentile is 0.24037 |
altlinux: CVE-2026-79241 was patched at 2026-08-28
debian: CVE-2026-79241 was patched at 2026-09-03, 2026-09-16
1131.
Memory Corruption - Mozilla Firefox (CVE-2026-92050) - Medium [329]
Description: Sandbox escape due to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.03879 |
altlinux: CVE-2026-92050 was patched at 2026-09-16
1132.
Memory Corruption - OpenSSL (CVE-2026-78123) - Medium [329]
Description: strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00413, EPSS Percentile is 0.34997 |
altlinux: CVE-2026-78123 was patched at 2026-09-11
debian: CVE-2026-78123 was patched at 2026-09-07, 2026-09-16
1133.
Path Traversal - PHP (CVE-2026-34967) - Medium [329]
Description: Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00237, EPSS Percentile is 0.14873 |
debian: CVE-2026-34967 was patched at 2026-09-16
1134.
Security Feature Bypass - Chromium (CVE-2026-84359) - Medium [329]
Description: Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00151, EPSS Percentile is 0.0466 |
altlinux: CVE-2026-84359 was patched at 2026-09-03
debian: CVE-2026-84359 was patched at 2026-09-03, 2026-09-16
1135.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74737) - Medium [328]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG On the packet reception path, the ID of the MAC Port on which the packet was received, is embedded in the RX DMA Descriptor's metadata. The ID is extracted using the helper function cppi5_desc_get_tags_ids() which fills in the 16-bit Source Tag into the 'port_id' variable. However, it is only the lower 8-bits of the 16-bit Source Tag that represent the MAC Port ID, while the upper 8-bits are Hardware-Reserved and carry an arbitrary value. With the existing logic, sporadic kernel crash is observed due to the subsequent driver code accessing out-of-bound memory because of an invalid port_id. Hence, fix the port_id extraction logic to use only the lower 8-bits of the Source Tag as the MAC Port ID.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG\n\nOn the packet reception path, the ID of the MAC Port on which the packet\nwas received, is embedded in the RX DMA Descriptor's metadata. The ID is\nextracted using the helper function cppi5_desc_get_tags_ids() which fills\nin the 16-bit Source Tag into the 'port_id' variable. However, it is only\nthe lower 8-bits of the 16-bit Source Tag that represent the MAC Port ID,\nwhile the upper 8-bits are Hardware-Reserved and carry an arbitrary value.\nWith the existing logic, sporadic kernel crash is observed due to the\nsubsequent driver code accessing out-of-bound memory because of an invalid\nport_id.\n\nHence, fix the port_id extraction logic to use only the lower 8-bits of the\nSource Tag as the MAC Port ID.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00559, EPSS Percentile is 0.45095 |
debian: CVE-2026-74737 was patched at 2026-09-16
1136.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80976) - Medium [328]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: seg6: reset IP6CB after IPv6 decapsulation decap_and_validate() pulls the outer SRv6 headers and makes the inner packet the skb network header. The IPv6 control block still contains values collected while parsing the outer packet, including nhoff and extension-header flags. End.DX6 and End.DT6 route the inner IPv6 packet directly to the IPv6 input path. An unprivileged user can reach End.DT6 from a user and net namespace by installing a local SID and injecting an outer packet with Hop-by-Hop and Destination Options headers followed by an SRH and a minimal inner IPv6 packet. The outer extension headers leave a large nhoff in IP6CB. After decapsulation, ip6_protocol_deliver_rcu() uses that stale offset on the inner packet and reads beyond the skb head. KASAN reports: BUG: KASAN: slab-out-of-bounds in ip6_protocol_deliver_rcu ip6_protocol_deliver_rcu+0x1118/0x1450 ip6_input_finish+0x11b/0x240 seg6_local_input_core+0xed/0x2e0 lwtunnel_input+0x1e9/0x4e0 ipv6_rthdr_rcv+0x525f/0x6c50 ip6_protocol_deliver_rcu+0xcb7/0x1450 Before clearing IP6CB for an inner IPv6 packet, save its incoming interface index and L3 slave state. Restore both after the clear and set nhoff to the inner IPv6 base-header nexthdr field. Use IP6CB(skb)->iif rather than skb->skb_iif because VRF processing can replace skb_iif with the L3 master while IP6CB keeps the receiving interface. Preserve IP6SKB_L3SLAVE for the same reason.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nseg6: reset IP6CB after IPv6 decapsulation\n\ndecap_and_validate() pulls the outer SRv6 headers and makes the inner\npacket the skb network header. The IPv6 control block still contains\nvalues collected while parsing the outer packet, including nhoff and\nextension-header flags.\n\nEnd.DX6 and End.DT6 route the inner IPv6 packet directly to the IPv6\ninput path. An unprivileged user can reach End.DT6 from a user and net\nnamespace by installing a local SID and injecting an outer packet with\nHop-by-Hop and Destination Options headers followed by an SRH and a\nminimal inner IPv6 packet.\n\nThe outer extension headers leave a large nhoff in IP6CB. After\ndecapsulation, ip6_protocol_deliver_rcu() uses that stale offset on the\ninner packet and reads beyond the skb head. KASAN reports:\n\n BUG: KASAN: slab-out-of-bounds in ip6_protocol_deliver_rcu\n ip6_protocol_deliver_rcu+0x1118/0x1450\n ip6_input_finish+0x11b/0x240\n seg6_local_input_core+0xed/0x2e0\n lwtunnel_input+0x1e9/0x4e0\n ipv6_rthdr_rcv+0x525f/0x6c50\n ip6_protocol_deliver_rcu+0xcb7/0x1450\n\nBefore clearing IP6CB for an inner IPv6 packet, save its incoming\ninterface index and L3 slave state. Restore both after the clear and set\nnhoff to the inner IPv6 base-header nexthdr field.\n\nUse IP6CB(skb)->iif rather than skb->skb_iif because VRF processing can\nreplace skb_iif with the L3 master while IP6CB keeps the receiving\ninterface. Preserve IP6SKB_L3SLAVE for the same reason.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00704, EPSS Percentile is 0.51597 |
debian: CVE-2026-80976 was patched at 2026-09-16
1137.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80980) - Medium [328]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/smc: stop killed, freed and out_of_sync sharing a byte The three connection state flags are single-bit bitfields, so they occupy one byte of struct smc_connection and every store to one is a read-modify-write of the other two: u8 killed : 1; u8 freed : 1; u8 out_of_sync : 1; They are not written under a common lock. smc_cdc_msg_validate() sets out_of_sync from the receive tasklet, while smc_conn_kill() sets killed from process context under lock_sock(), and the receive path does not defer to the backlog when the socket is owned -- smc_cdc_msg_recv() takes only bh_lock_sock(). Give each flag its own byte so a store no longer touches its neighbours. All readers test them as booleans and are unchanged. struct smc_connection grows by two bytes.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: stop killed, freed and out_of_sync sharing a byte\n\nThe three connection state flags are single-bit bitfields, so they occupy\none byte of struct smc_connection and every store to one is a\nread-modify-write of the other two:\n\n u8 killed : 1;\n u8 freed : 1;\n u8 out_of_sync : 1;\n\nThey are not written under a common lock. smc_cdc_msg_validate() sets\nout_of_sync from the receive tasklet, while smc_conn_kill() sets killed\nfrom process context under lock_sock(), and the receive path does not defer\nto the backlog when the socket is owned -- smc_cdc_msg_recv() takes only\nbh_lock_sock().\n\nGive each flag its own byte so a store no longer touches its neighbours.\nAll readers test them as booleans and are unchanged. struct smc_connection\ngrows by two bytes.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00605, EPSS Percentile is 0.47378 |
debian: CVE-2026-80980 was patched at 2026-09-16
1138.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89482) - Medium [328]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone Commit 25e5cb780e62 ("nvme-tcp: fix possible crash in write_zeroes processing") established that blk_rq_payload_bytes() must not be read without first checking blk_rq_nr_phys_segments(), and recorded the result in nvme_tcp_setup_cmd_pdu() as req->data_len. The receive side was left as it was. The two differ for REQ_OP_WRITE_ZEROES, which has no physical segments but a non-zero blk_rq_bytes(), so setup leaves req->iter untouched while the receive gate lets a C2HData through and nvme_tcp_recv_data() copies into whatever the previous command on that tag left there. The driver-private area is zeroed only when the tag set is allocated. Reproduced with a test target that leaves a residual iterator on a tag and then sends a C2HData for a WRITE_ZEROES command on the same tag: BUG: KASAN: wild-memory-access in _copy_to_iter+0x642/0x1330 Write of size 512 at addr ffe728c2175dfa81 by task kworker/0:1H/103 CPU: 0 UID: 0 PID: 103 Comm: kworker/0:1H Not tainted 7.2.0-rc5-NVMETCP-gf5098b6bae76 #1 PREEMPT(lazy) Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Workqueue: nvme_tcp_wq nvme_tcp_io_work Call Trace: <TASK> dump_stack_lvl+0x53/0x70 kasan_report+0xce/0x100 ? _copy_to_iter+0x642/0x1330 kasan_check_range+0x105/0x1b0 __asan_memcpy+0x3c/0x60 _copy_to_iter+0x642/0x1330 ? __pfx_sock_has_perm+0x10/0x10 ? worker_thread+0x45b/0xd10 ? __pfx__copy_to_iter+0x10/0x10 ? _raw_spin_lock_bh+0x83/0xe0 ? __pfx__raw_spin_lock_bh+0x10/0x10 __skb_datagram_iter+0xf3/0x820 ? __pfx_simple_copy_to_iter+0x10/0x10 ? __asan_memcpy+0x3c/0x60 ? skb_copy_bits+0x58d/0x830 skb_copy_datagram_iter+0x37/0x120 nvme_tcp_recv_skb+0xa07/0x4320 ? __pfx_nvme_tcp_recv_skb+0x10/0x10 __tcp_read_sock+0x1ab/0x810 ? __pfx_nvme_tcp_recv_skb+0x10/0x10 ? __pfx_lock_sock_nested+0x10/0x10 ? __pfx___tcp_read_sock+0x10/0x10 nvme_tcp_try_recv+0x152/0x1e0 ? __pfx_nvme_tcp_try_recv+0x10/0x10 ? __pfx_mutex_unlock+0x10/0x10 nvme_tcp_io_work+0x1e4/0x6c0 ? __schedule+0x181a/0x49f0 ? __pfx_nvme_tcp_io_work+0x10/0x10 process_one_work+0x633/0x1030 Keep the blk_rq_payload_bytes() test and add req->data_len to it. The old test is what rejects a C2HData naming a tag that is no longer in flight, because blk_update_request() zeroes rq->__data_len on completion; req->data_len and req->curr_bio are driver-private and survive completion, so they cannot stand in for it. Setup initialises the iterator only when both req->curr_bio and req->data_len are set, so the gate now tests the same two.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone\n\nCommit 25e5cb780e62 ("nvme-tcp: fix possible crash in write_zeroes\nprocessing") established that blk_rq_payload_bytes() must not be read\nwithout first checking blk_rq_nr_phys_segments(), and recorded the\nresult in nvme_tcp_setup_cmd_pdu() as req->data_len. The receive side\nwas left as it was.\n\nThe two differ for REQ_OP_WRITE_ZEROES, which has no physical segments\nbut a non-zero blk_rq_bytes(), so setup leaves req->iter untouched\nwhile the receive gate lets a C2HData through and nvme_tcp_recv_data()\ncopies into whatever the previous command on that tag left there. The\ndriver-private area is zeroed only when the tag set is allocated.\n\nReproduced with a test target that leaves a residual iterator on a tag\nand then sends a C2HData for a WRITE_ZEROES command on the same tag:\n\nBUG: KASAN: wild-memory-access in _copy_to_iter+0x642/0x1330\nWrite of size 512 at addr ffe728c2175dfa81 by task kworker/0:1H/103\n\nCPU: 0 UID: 0 PID: 103 Comm: kworker/0:1H Not tainted 7.2.0-rc5-NVMETCP-gf5098b6bae76 #1 PREEMPT(lazy)\nHardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nWorkqueue: nvme_tcp_wq nvme_tcp_io_work\nCall Trace:\n <TASK>\n dump_stack_lvl+0x53/0x70\n kasan_report+0xce/0x100\n ? _copy_to_iter+0x642/0x1330\n kasan_check_range+0x105/0x1b0\n __asan_memcpy+0x3c/0x60\n _copy_to_iter+0x642/0x1330\n ? __pfx_sock_has_perm+0x10/0x10\n ? worker_thread+0x45b/0xd10\n ? __pfx__copy_to_iter+0x10/0x10\n ? _raw_spin_lock_bh+0x83/0xe0\n ? __pfx__raw_spin_lock_bh+0x10/0x10\n __skb_datagram_iter+0xf3/0x820\n ? __pfx_simple_copy_to_iter+0x10/0x10\n ? __asan_memcpy+0x3c/0x60\n ? skb_copy_bits+0x58d/0x830\n skb_copy_datagram_iter+0x37/0x120\n nvme_tcp_recv_skb+0xa07/0x4320\n ? __pfx_nvme_tcp_recv_skb+0x10/0x10\n __tcp_read_sock+0x1ab/0x810\n ? __pfx_nvme_tcp_recv_skb+0x10/0x10\n ? __pfx_lock_sock_nested+0x10/0x10\n ? __pfx___tcp_read_sock+0x10/0x10\n nvme_tcp_try_recv+0x152/0x1e0\n ? __pfx_nvme_tcp_try_recv+0x10/0x10\n ? __pfx_mutex_unlock+0x10/0x10\n nvme_tcp_io_work+0x1e4/0x6c0\n ? __schedule+0x181a/0x49f0\n ? __pfx_nvme_tcp_io_work+0x10/0x10\n process_one_work+0x633/0x1030\n\nKeep the blk_rq_payload_bytes() test and add req->data_len to it. The\nold test is what rejects a C2HData naming a tag that is no longer in\nflight, because blk_update_request() zeroes rq->__data_len on\ncompletion; req->data_len and req->curr_bio are driver-private and\nsurvive completion, so they cannot stand in for it. Setup initialises\nthe iterator only when both req->curr_bio and req->data_len are set, so\nthe gate now tests the same two.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00704, EPSS Percentile is 0.51597 |
debian: CVE-2026-89482 was patched at 2026-09-16
1139.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89485) - Medium [328]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: lockd: pin next file across nlm_inspect_file lock-drop nlm_traverse_files() pins the current file with f_count++ across a mutex_unlock for nlm_inspect_file(), but nothing pins the saved next pointer. A concurrent nlm_release_file() can kfree the next file during the unlock window, and the iterator dereferences freed memory on the next loop step. Pin both current and next before the lock-drop. Advance by swapping the pinned cursors at the end of each iteration so next is always held alive across the unlock. Always call nlm_file_release() after dropping the iteration pin, regardless of whether the file matched the predicate. Use nlm_file_inuse(), which does a live walk of the inode lock list, rather than the cached f_locks field, so skipped files that never ran nlm_inspect_file() are evaluated correctly. Because every file in a hash bucket is now pinned and released, files skipped by the is_failover_file predicate that have no locks, blocks, shares, or external references are deleted during traversal. The old code never evaluated skipped files for cleanup. The new behavior is intentional: such files are stale and should not persist in the table.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nlockd: pin next file across nlm_inspect_file lock-drop\n\nnlm_traverse_files() pins the current file with f_count++ across\na mutex_unlock for nlm_inspect_file(), but nothing pins the saved\nnext pointer. A concurrent nlm_release_file() can kfree the next\nfile during the unlock window, and the iterator dereferences freed\nmemory on the next loop step.\n\nPin both current and next before the lock-drop. Advance by\nswapping the pinned cursors at the end of each iteration so next\nis always held alive across the unlock.\n\nAlways call nlm_file_release() after dropping the iteration pin,\nregardless of whether the file matched the predicate. Use\nnlm_file_inuse(), which does a live walk of the inode lock list,\nrather than the cached f_locks field, so skipped files that never\nran nlm_inspect_file() are evaluated correctly.\n\nBecause every file in a hash bucket is now pinned and released,\nfiles skipped by the is_failover_file predicate that have no\nlocks, blocks, shares, or external references are deleted during\ntraversal. The old code never evaluated skipped files for\ncleanup. The new behavior is intentional: such files are stale\nand should not persist in the table.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00704, EPSS Percentile is 0.51596 |
debian: CVE-2026-89485 was patched at 2026-09-16
1140.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89526) - Medium [328]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: svcrdma: Validate Read chunk positions before reconstruction The RPC/RDMA Read chunk position field is supplied by the remote client and stored verbatim in the parsed chunk list. xdr_count_read_segments() checks only 4-byte alignment; it never compares the position against the received inline body length. In the single-chunk path, svc_rdma_read_complete_one() splits the head and tail kvecs at ch_position. A position past the inline body underflows the tail length, exposing adjacent slab memory to the upper XDR decoder. In the multi-chunk path, svc_rdma_read_multiple_chunks() computes gap lengths between chunks as unsigned subtractions from ch_position. Overlapping Read chunks cause these subtractions to underflow. A final position past the inline body likewise underflows the trailing gap length. svc_rdma_copy_inline_range() then copies past the receive buffer into request pages that are returned to the client through the Reply channel. Bound inline-range copies in svc_rdma_copy_inline_range() against the decoded inline RPC body saved in rc_saved_arg. Reject a single Read chunk positioned beyond that body, and reject multi-chunk lists where accumulated read bytes exceed the next chunk's position. Apply the same position and overlap checks in the call-chunk interleaving path.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: Validate Read chunk positions before reconstruction\n\nThe RPC/RDMA Read chunk position field is supplied by the remote\nclient and stored verbatim in the parsed chunk list.\nxdr_count_read_segments() checks only 4-byte alignment; it never\ncompares the position against the received inline body length.\n\nIn the single-chunk path, svc_rdma_read_complete_one() splits the\nhead and tail kvecs at ch_position. A position past the inline\nbody underflows the tail length, exposing adjacent slab memory to\nthe upper XDR decoder.\n\nIn the multi-chunk path, svc_rdma_read_multiple_chunks() computes\ngap lengths between chunks as unsigned subtractions from\nch_position. Overlapping Read chunks cause these subtractions to\nunderflow. A final position past the inline body likewise\nunderflows the trailing gap length. svc_rdma_copy_inline_range()\nthen copies past the receive buffer into request pages that are\nreturned to the client through the Reply channel.\n\nBound inline-range copies in svc_rdma_copy_inline_range() against\nthe decoded inline RPC body saved in rc_saved_arg. Reject a\nsingle Read chunk positioned beyond that body, and reject\nmulti-chunk lists where accumulated read bytes exceed the next\nchunk's position. Apply the same position and overlap checks in\nthe call-chunk interleaving path.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00626, EPSS Percentile is 0.48358 |
debian: CVE-2026-89526 was patched at 2026-09-16
1141.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89536) - Medium [328]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: SUNRPC: wait for in-flight client TLS handshake callback xs_tls_handshake_sync() gives xs_tls_handshake_done() a reference to the lower transport before submitting the handshake request. On timeout or signal, the synchronous waiter drops that reference after calling tls_handshake_cancel(). handshake_req_cancel() returns false when handshake_complete() has already marked the request complete. In that case the completion callback can still be running, so dropping the callback-owned reference in the waiter can free the lower transport before xs_tls_handshake_done() stores xprt_err or drops its own reference. If cancellation loses to completion, wait until xs_tls_handshake_done() signals handshake_done and let the callback release its reference. This mirrors the server-side handshake lifetime handling and keeps the timeout or signal return value unchanged.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: wait for in-flight client TLS handshake callback\n\nxs_tls_handshake_sync() gives xs_tls_handshake_done() a reference to the\nlower transport before submitting the handshake request. On timeout or\nsignal, the synchronous waiter drops that reference after calling\ntls_handshake_cancel().\n\nhandshake_req_cancel() returns false when handshake_complete() has\nalready marked the request complete. In that case the completion callback\ncan still be running, so dropping the callback-owned reference in the\nwaiter can free the lower transport before xs_tls_handshake_done() stores\nxprt_err or drops its own reference.\n\nIf cancellation loses to completion, wait until xs_tls_handshake_done()\nsignals handshake_done and let the callback release its reference. This\nmirrors the server-side handshake lifetime handling and keeps the timeout\nor signal return value unchanged.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00626, EPSS Percentile is 0.48358 |
debian: CVE-2026-89536 was patched at 2026-09-16
1142.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89538) - Medium [328]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field gss_krb5_unwrap_v2() sets buf->len to a logical length, which can be much smaller than head[0].iov_len (the allocated receive-page capacity). It then calls xdr_buf_trim() with a trim length derived from the 16-bit "extra count" (ec) field in the Kerberos v2 token header. The ec field is authenticated by the post-decrypt memcmp() against the encrypted header copy, so a randomly-mutated value is rejected. However, any peer holding a valid GSS context can legitimately encrypt a token whose ec exceeds the plaintext length. Per RFC 4121, such a token is structurally malformed. Although xdr_buf_trim() now clamps the buf->len subtraction to avoid unsigned underflow, the buffer is still left in a semantically invalid state (zero length, inconsistent iov lengths) when ec is oversized. Reject these tokens before calling xdr_buf_trim(), giving callers a well-defined GSS_S_DEFECTIVE_TOKEN error and keeping the xdr_buf internally consistent. The wrapped blob begins at a nonzero offset -- both callers pass len as offset + opaque_len -- so buf->len still counts the offset bytes that precede the blob. Compare the trim length against the remaining wrapped segment, buf->len - offset, rather than the whole buffer; comparing against buf->len alone leaves an offset-wide window in which an oversized ec passes the test and xdr_buf_trim() cuts into the bytes ahead of the blob.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: Reject krb5 v2 wrap tokens with oversized ec field\n\ngss_krb5_unwrap_v2() sets buf->len to a logical\nlength, which can be much smaller than head[0].iov_len\n(the allocated receive-page capacity). It then calls\nxdr_buf_trim() with a trim length derived from the 16-bit\n"extra count" (ec) field in the Kerberos v2 token header.\n\nThe ec field is authenticated by the post-decrypt memcmp()\nagainst the encrypted header copy, so a randomly-mutated\nvalue is rejected. However, any peer holding a valid GSS\ncontext can legitimately encrypt a token whose ec exceeds\nthe plaintext length. Per RFC 4121, such a token is\nstructurally malformed.\n\nAlthough xdr_buf_trim() now clamps the buf->len subtraction\nto avoid unsigned underflow, the buffer is still left in a\nsemantically invalid state (zero length, inconsistent iov\nlengths) when ec is oversized.\n\nReject these tokens before calling xdr_buf_trim(), giving\ncallers a well-defined GSS_S_DEFECTIVE_TOKEN error and\nkeeping the xdr_buf internally consistent. The wrapped blob\nbegins at a nonzero offset -- both callers pass len as\noffset + opaque_len -- so buf->len still counts the offset\nbytes that precede the blob. Compare the trim length\nagainst the remaining wrapped segment, buf->len - offset,\nrather than the whole buffer; comparing against buf->len\nalone leaves an offset-wide window in which an oversized ec\npasses the test and xdr_buf_trim() cuts into the bytes ahead\nof the blob.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00704, EPSS Percentile is 0.51596 |
debian: CVE-2026-89538 was patched at 2026-09-16
1143.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89558) - Medium [328]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix still_degraded being inverted in raid10_sync_request() Commit fe6a19d40ceb ("md/md-bitmap: merge md_bitmap_start_sync() into bitmap_operations") converted still_degraded from int to bool, but inverted the assignment in the loop that checks whether the array will still be degraded after the current device is recovered: "still_degraded = 1" became "still_degraded = false". As a result, recovering a device while another mirror is still missing calls md_bitmap_start_sync() with degraded == false, which clears bitmap bits that the still-missing device needs. When that device is re-added, its bitmap-based recovery finds the bits already cleared and skips every region written while the array was degraded, so it is marked In_sync while holding stale data: silent corruption. Reproducer (raid10 near=2, 4 disks, internal bitmap): - fail and remove one disk of each mirror pair - write to the degraded array - re-add both disks and let recovery finish - "check" reports mismatch_cnt=262272 after 256 MiB of degraded writes and file contents differ; the second disk's "recovery" completes in milliseconds because everything is skipped The same conversion in raid1 got it right (still_degraded = true). Restore the correct value.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid10: fix still_degraded being inverted in raid10_sync_request()\n\nCommit fe6a19d40ceb ("md/md-bitmap: merge md_bitmap_start_sync() into\nbitmap_operations") converted still_degraded from int to bool, but\ninverted the assignment in the loop that checks whether the array will\nstill be degraded after the current device is recovered:\n"still_degraded = 1" became "still_degraded = false".\n\nAs a result, recovering a device while another mirror is still missing\ncalls md_bitmap_start_sync() with degraded == false, which clears bitmap\nbits that the still-missing device needs. When that device is re-added,\nits bitmap-based recovery finds the bits already cleared and skips every\nregion written while the array was degraded, so it is marked In_sync\nwhile holding stale data: silent corruption.\n\nReproducer (raid10 near=2, 4 disks, internal bitmap):\n - fail and remove one disk of each mirror pair\n - write to the degraded array\n - re-add both disks and let recovery finish\n - "check" reports mismatch_cnt=262272 after 256 MiB of degraded\n writes and file contents differ; the second disk's "recovery"\n completes in milliseconds because everything is skipped\n\nThe same conversion in raid1 got it right (still_degraded = true).\nRestore the correct value.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00626, EPSS Percentile is 0.48359 |
debian: CVE-2026-89558 was patched at 2026-09-16
1144.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89643) - Medium [328]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: audit: avoid dropping live tree ref on fsnotify rule autoremove audit_del_rule() is used for both netlink deletion templates and internal fsnotify autoremove. The former passes a parsed template which owns a temporary tree reference; the latter passes the installed entry itself. The unconditional audit_put_tree() at the end of audit_del_rule() assumes the template case. For mixed AUDIT_DIR plus AUDIT_EXE rules, an fsnotify autoremove event therefore drops the installed rule's live tree reference. Repeating this across rules sharing the same tree can free the tree while another rule still references it, and a later autoremove dereferences the freed pathname while comparing rules. Move the temporary-tree put to audit_rule_change(), the caller that owns deletion templates. Keep it in the AUDIT_DEL_RULE cleanup so both successful deletion and -ENOENT still release the parser-owned tree. [PM: dropped unnecessary comment for line length reasons]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\naudit: avoid dropping live tree ref on fsnotify rule autoremove\n\naudit_del_rule() is used for both netlink deletion templates and internal\nfsnotify autoremove. The former passes a parsed template which owns a\ntemporary tree reference; the latter passes the installed entry itself.\n\nThe unconditional audit_put_tree() at the end of audit_del_rule() assumes\nthe template case. For mixed AUDIT_DIR plus AUDIT_EXE rules, an fsnotify\nautoremove event therefore drops the installed rule's live tree reference.\nRepeating this across rules sharing the same tree can free the tree while\nanother rule still references it, and a later autoremove dereferences the\nfreed pathname while comparing rules.\n\nMove the temporary-tree put to audit_rule_change(), the caller that owns\ndeletion templates. Keep it in the AUDIT_DEL_RULE cleanup so both\nsuccessful deletion and -ENOENT still release the parser-owned tree.\n\n[PM: dropped unnecessary comment for line length reasons]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00704, EPSS Percentile is 0.51594 |
debian: CVE-2026-89643 was patched at 2026-09-16
1145.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89655) - Medium [328]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock list_for_each_entry() iterates ci->i_cap_flush_list but drops i_ceph_lock to send cap messages. During the unlock window, handle_cap_flush_ack() can acquire i_ceph_lock, detach cf entries with tid <= flush_tid from the list, release i_ceph_lock, and free them via ceph_free_cap_flush() outside any lock. When the original thread reacquires i_ceph_lock and the for-loop macro advances via cf = list_next_entry(cf, i_list), it dereferences cf->i_list.next on freed memory. The race timeline: __kick_flushing_caps() handle_cap_flush_ack() ----------------------- ----------------------- holds i_ceph_lock <--- iterates to cf (tid=10) prepares FLUSH message drops i_ceph_lock <--- __send_cap() ── FLUSH(tid=10) \t MDS sends FLUSH_ACK(tid=10) ---> acquires i_ceph_lock cf->tid(10) <= flush_tid(10), detaches cf from i_cap_flush_list drops i_ceph_lock ceph_free_cap_flush(cf) <- frees it! acquires i_ceph_lock <--- for-loop advances: cf = list_next_entry(cf, i_list) -- UAF on freed cf->i_list.next The cf was just sent by __kick_flushing_caps itself via __send_cap(). The MDS may respond with FLUSH_ACK quickly enough that handle_cap_flush_ack() frees cf before __kick_flushing_caps can finish the iteration. Fix by converting to a manual while loop: save the next pointer under i_ceph_lock before dropping it, then use the saved pointer after reacquiring, so the potentially-freed cf is never accessed again.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock\n\nlist_for_each_entry() iterates ci->i_cap_flush_list but drops\ni_ceph_lock to send cap messages. During the unlock window,\nhandle_cap_flush_ack() can acquire i_ceph_lock, detach cf entries\nwith tid <= flush_tid from the list, release i_ceph_lock, and free\nthem via ceph_free_cap_flush() outside any lock. When the original\nthread reacquires i_ceph_lock and the for-loop macro advances via\ncf = list_next_entry(cf, i_list), it dereferences cf->i_list.next\non freed memory.\n\nThe race timeline:\n\n __kick_flushing_caps() handle_cap_flush_ack()\n ----------------------- -----------------------\n holds i_ceph_lock <---\n iterates to cf (tid=10)\n prepares FLUSH message\n drops i_ceph_lock <---\n __send_cap() ── FLUSH(tid=10)\n\t MDS sends FLUSH_ACK(tid=10)\n ---> acquires i_ceph_lock\n cf->tid(10) <= flush_tid(10),\n detaches cf from i_cap_flush_list\n drops i_ceph_lock\n ceph_free_cap_flush(cf) <- frees it!\n acquires i_ceph_lock <---\n for-loop advances:\n cf = list_next_entry(cf, i_list)\n -- UAF on freed cf->i_list.next\n\nThe cf was just sent by __kick_flushing_caps itself via __send_cap().\nThe MDS may respond with FLUSH_ACK quickly enough that\nhandle_cap_flush_ack() frees cf before __kick_flushing_caps can\nfinish the iteration.\n\nFix by converting to a manual while loop: save the next pointer\nunder i_ceph_lock before dropping it, then use the saved pointer\nafter reacquiring, so the potentially-freed cf is never accessed again.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00704, EPSS Percentile is 0.51596 |
debian: CVE-2026-89655 was patched at 2026-09-16
1146.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89686) - Medium [328]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke nfsd4_alloc_layout_stateid reads fp->fi_deleg_file without holding fi_lock when the parent stateid is a delegation. A concurrent delegation revoke via the laundromat can clear fi_deleg_file under fi_lock, causing nfsd_file_get() to return NULL and triggering the BUG_ON. This race is client-reachable: two NFS clients can trigger it by having one hold a delegation while another opens the same file to force a recall. When the first client doesn't respond to the recall, the laundromat revokes it. A concurrent LAYOUTGET from any client using the delegation stateid hits the race window. Fix this by taking fi_lock around the fi_deleg_file read in the SC_TYPE_DELEG path, matching the locking discipline of the find_any_file() arm, and replacing the BUG_ON with a graceful error return that cleans up the partially-initialized layout stateid.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke\n\nnfsd4_alloc_layout_stateid reads fp->fi_deleg_file without holding\nfi_lock when the parent stateid is a delegation. A concurrent delegation\nrevoke via the laundromat can clear fi_deleg_file under fi_lock, causing\nnfsd_file_get() to return NULL and triggering the BUG_ON.\n\nThis race is client-reachable: two NFS clients can trigger it by having\none hold a delegation while another opens the same file to force a\nrecall. When the first client doesn't respond to the recall, the\nlaundromat revokes it. A concurrent LAYOUTGET from any client using the\ndelegation stateid hits the race window.\n\nFix this by taking fi_lock around the fi_deleg_file read in the\nSC_TYPE_DELEG path, matching the locking discipline of the\nfind_any_file() arm, and replacing the BUG_ON with a graceful error\nreturn that cleans up the partially-initialized layout stateid.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00671, EPSS Percentile is 0.50318 |
debian: CVE-2026-89686 was patched at 2026-09-16
1147.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89712) - Medium [328]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock nfsd4_ssc_expire_umount() walks nn->nfsd_ssc_mount_list with list_for_each_entry_safe(ni, tmp, ...). For each expired entry it sets nsui_busy = true, drops nfsd_ssc_lock to run mntput() on the source vfsmount, then reacquires the lock to list_del + kfree the entry and continue iterating via the macro's saved tmp pointer. The nsui_busy flag protects the current ni from concurrent nfsd4_ssc_setup_dul() finders during the lock-drop window, but it does not pin tmp. Another nfsd RPC thread that fails its source- server mount and reaches nfsd4_ssc_cancel_dul() will, during that same window, take nfsd_ssc_lock, list_del + kfree its own ssc_umount item, and release the lock. If that item is the saved tmp of the expire walk, the next iteration dereferences a freed nfsd4_ssc_umount_item. Restart the walk from the head after the mntput() unlock window so no saved next pointer survives the lock-drop. The list is bounded by the number of active inter-server source mounts (typically small) and the expire delayed-work runs periodically rather than per-IO, so the restart is cheap.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock\n\nnfsd4_ssc_expire_umount() walks nn->nfsd_ssc_mount_list with\nlist_for_each_entry_safe(ni, tmp, ...). For each expired entry it\nsets nsui_busy = true, drops nfsd_ssc_lock to run mntput() on the\nsource vfsmount, then reacquires the lock to list_del + kfree the\nentry and continue iterating via the macro's saved tmp pointer.\n\nThe nsui_busy flag protects the current ni from concurrent\nnfsd4_ssc_setup_dul() finders during the lock-drop window, but it\ndoes not pin tmp. Another nfsd RPC thread that fails its source-\nserver mount and reaches nfsd4_ssc_cancel_dul() will, during that\nsame window, take nfsd_ssc_lock, list_del + kfree its own ssc_umount\nitem, and release the lock. If that item is the saved tmp of the\nexpire walk, the next iteration dereferences a freed\nnfsd4_ssc_umount_item.\n\nRestart the walk from the head after the mntput() unlock window so\nno saved next pointer survives the lock-drop. The list is bounded\nby the number of active inter-server source mounts (typically small)\nand the expire delayed-work runs periodically rather than per-IO,\nso the restart is cheap.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00704, EPSS Percentile is 0.51595 |
debian: CVE-2026-89712 was patched at 2026-09-16
1148.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-71140) - Medium [327]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.3 | 10 | CVSS Base Score is 3.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00119, EPSS Percentile is 0.02031 |
altlinux: CVE-2026-71140 was patched at 2026-08-21
1149.
Denial of Service - CommonMark (CVE-2026-86428) - Medium [327]
Description: commonmark versions from 1.5.0 before 2.10.0 contain a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:thephpleague:commonmark (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00279, EPSS Percentile is 0.20425 |
debian: CVE-2026-86428 was patched at 2026-09-16
1150.
Denial of Service - CommonMark (CVE-2026-86429) - Medium [327]
Description: The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they are not enabled by default and are excluded from the standard CommonMark and GitHub-Flavored Markdown converters), an unauthenticated attacker can submit small, specially crafted Markdown documents — such as text alternating with unpaired quotes, contiguous runs of block-level attribute blocks, or repeated class attributes — to trigger disproportionate CPU consumption and cause a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:thephpleague:commonmark (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00291, EPSS Percentile is 0.21756 |
debian: CVE-2026-86429 was patched at 2026-09-16
1151.
Denial of Service - CommonMark (CVE-2026-86430) - Medium [327]
Description: league/commonmark versions before 2.9.1 contain multiple
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:thephpleague:commonmark (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00285, EPSS Percentile is 0.21049 |
debian: CVE-2026-86430 was patched at 2026-09-16
1152.
Denial of Service - Crypto (CVE-2026-78662) - Medium [327]
Description: Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:golang:crypto (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00315, EPSS Percentile is 0.24462 |
debian: CVE-2026-78662 was patched at 2026-09-16
1153.
Denial of Service - libexpat (CVE-2026-76956) - Medium [327]
Description: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:libexpat_project:libexpat (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00287, EPSS Percentile is 0.21347 |
debian: CVE-2026-76956 was patched at 2026-08-25
1154.
Denial of Service - nokogiri (CVE-2026-79770) - Medium [327]
Description: Nokogiri versions before 1.19.3 contain regular expression
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:nokogiri:nokogiri (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00278, EPSS Percentile is 0.20376 |
debian: CVE-2026-79770 was patched at 2026-09-16
1155.
Security Feature Bypass - GPU Display Driver (CVE-2025-33221) - Medium [327]
Description: NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an incorrect permission assignment for a critical resource. A successful exploit of this vulnerability might lead to data tampering and denial of service.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:nvidia:gpu_display_driver (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00175, EPSS Percentile is 0.07259 |
redos: CVE-2025-33221 was patched at 2026-09-08
1156.
Security Feature Bypass - GPU Display Driver (CVE-2026-24195) - Medium [327]
Description: NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user could cause improper input validation. A successful exploit of this vulnerability might lead to denial of service.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:nvidia:gpu_display_driver (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00162, EPSS Percentile is 0.05849 |
redos: CVE-2026-24195 was patched at 2026-09-08
1157.
Security Feature Bypass - Nodemailer (CVE-2026-82662) - Medium [327]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Nodemailer is a Node.js module for sending email, supporting SMTP, message composition, attachments, and multiple transport mechanisms. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.02459 |
debian: CVE-2026-82662 was patched at 2026-09-16
1158.
Security Feature Bypass - OpenEXR (CVE-2026-55371) - Medium [327]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | OpenEXR is an open source high-dynamic-range image file format and reference implementation widely used in computer graphics, visual effects, animation, and motion picture production. | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.01862 |
debian: CVE-2026-55371 was patched at 2026-09-16
1159.
Security Feature Bypass - TLS (CVE-2026-78323) - Medium [327]
Description: A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | TLS | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00114, EPSS Percentile is 0.01649 |
debian: CVE-2026-78323 was patched at 2026-08-25
1160.
Security Feature Bypass - TLS (CVE-2026-87872) - Medium [327]
Description: A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request helper disables
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | TLS | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00091, EPSS Percentile is 0.00558 |
debian: CVE-2026-87872 was patched at 2026-09-16
1161.
Cross Site Scripting - Perl (CVE-2026-85485) - Medium [326]
Description: HTML::FormHandler versions before 0.410002 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00207, EPSS Percentile is 0.10986 |
debian: CVE-2026-85485 was patched at 2026-09-16
1162.
Information Disclosure - GPU Display Driver (CVE-2026-24196) - Medium [326]
Description: NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to denial of service and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Product detected by a:nvidia:gpu_display_driver (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06284 |
redos: CVE-2026-24196 was patched at 2026-09-08
1163.
Denial of Service - FFmpeg (CVE-2026-90816) - Medium [324]
Description: A vulnerability was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0035, EPSS Percentile is 0.28492 |
debian: CVE-2026-90816 was patched at 2026-09-16
1164.
Denial of Service - Oracle VM VirtualBox (CVE-2026-71128) - Medium [324]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05416 |
altlinux: CVE-2026-71128 was patched at 2026-08-21
1165.
Memory Corruption - FFmpeg (CVE-2026-75146) - Medium [324]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00261, EPSS Percentile is 0.18099 |
debian: CVE-2026-75146 was patched at 2026-08-20
ubuntu: CVE-2026-75146 was patched at 2026-09-03, 2026-09-16
1166.
Memory Corruption - cpp-httplib (CVE-2026-77358) - Medium [324]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00287, EPSS Percentile is 0.21282 |
debian: CVE-2026-77358 was patched at 2026-09-16
1167.
Code Injection - Spring Framework (CVE-2026-59281) - Medium [323]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.4 | 14 | The Spring Framework is an application framework and inversion of control container for the Java platform | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00181, EPSS Percentile is 0.07942 |
debian: CVE-2026-59281 was patched at 2026-09-16
1168.
Spoofing - Netty (CVE-2026-62380) - Medium [323]
Description: Netty (io.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Netty is a non-blocking I/O client-server framework for the development of Java network applications such as protocol servers and clients | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00253, EPSS Percentile is 0.16904 |
debian: CVE-2026-62380 was patched at 2026-08-25
1169.
Denial of Service - Erlang/OTP (CVE-2026-55951) - Medium [322]
Description: The
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | Erlang/OTP is a set of libraries for the Erlang programming language | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00382, EPSS Percentile is 0.3187 |
debian: CVE-2026-55951 was patched at 2026-09-16
1170.
Denial of Service - Spring Framework (CVE-2026-47886) - Medium [322]
Description: Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | The Spring Framework is an application framework and inversion of control container for the Java platform | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00324, EPSS Percentile is 0.25514 |
debian: CVE-2026-47886 was patched at 2026-09-16
1171.
Denial of Service - Spring Framework (CVE-2026-59282) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | The Spring Framework is an application framework and inversion of control container for the Java platform | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00324, EPSS Percentile is 0.25464 |
debian: CVE-2026-59282 was patched at 2026-09-16
1172.
Memory Corruption - Linux Kernel (CVE-2026-74689) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00139, EPSS Percentile is 0.03645 |
debian: CVE-2026-74689 was patched at 2026-08-25
oraclelinux: CVE-2026-74689 was patched at 2026-09-04
1173.
Memory Corruption - Linux Kernel (CVE-2026-80664) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00127, EPSS Percentile is 0.02744 |
debian: CVE-2026-80664 was patched at 2026-09-16
oraclelinux: CVE-2026-80664 was patched at 2026-09-04
redos: CVE-2026-80664 was patched at 2026-09-16
1174.
Remote Code Execution - Unknown Product (CVE-2026-15686) - Medium [321]
Description: {'nvd_cve_data_all': 'Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is required to exploit this vulnerability. The specific flaw exists within the multi_query method. The issue results from an incorrect check of a function return value. An attacker can leverage this vulnerability to execute code in the context of the web server. Was ZDI-CAN-28201.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is required to exploit this vulnerability.\n\nThe specific flaw exists within the multi_query method. The issue results from an incorrect check of a function return value. An attacker can leverage this vulnerability to execute code in the context of the web server. Was ZDI-CAN-28201.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00724, EPSS Percentile is 0.52336 |
debian: CVE-2026-15686 was patched at 2026-08-25
1175.
Remote Code Execution - Unknown Product (CVE-2026-75538) - Medium [321]
Description: {'nvd_cve_data_all': 'An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an incorrect packet length calculation to overflow the receive buffer into the VM allocator area and beyond up to about 2 GB. This would easily trash the allocated block's allocator metadata footer, and the next block, if any, and most likely cause the BEAM VM to crash. Utilizing this with precision enough to achieve Remote Code Execution would be extremely unfeasible. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to erts from 6.0 before 15.2.7.13, from 16.0 before 16.4.0.6, and from 17.0 before 17.0.6. Whether OTP before OTP 17.0, corresponding to erts before 6.0, is affected is unknown.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an incorrect packet length calculation to overflow the receive buffer into the VM allocator area and beyond up to about 2 GB.\n\nThis would easily trash the allocated block's allocator metadata footer, and the next block, if any, and most likely cause the BEAM VM to crash. Utilizing this with precision enough to achieve Remote Code Execution would be extremely unfeasible.\n\nThis issue affects OTP from OTP\xa017.0 before OTP\xa027.3.4.17, from OTP\xa028.0 before OTP\xa028.5.0.6, and from OTP\xa029.0 before OTP\xa029.0.6, corresponding to erts from 6.0 before 15.2.7.13, from 16.0 before 16.4.0.6, and from 17.0 before 17.0.6. Whether OTP before OTP\xa017.0, corresponding to erts before 6.0, is affected is unknown.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00491, EPSS Percentile is 0.41024 |
debian: CVE-2026-75538 was patched at 2026-09-16
1176.
Authentication Bypass - gitoxide (CVE-2026-82255) - Medium [320]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.3 | 14 | gitoxide is an idiomatic, lean, fast & safe pure Rust implementation of Git, designed for correctness and performance, available both as a Rust library (gix crate) and command-line interface tools. | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00233, EPSS Percentile is 0.14387 |
debian: CVE-2026-82255 was patched at 2026-09-16
1177.
Denial of Service - Libsoup (CVE-2026-85534) - Medium [320]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | libsoup is an HTTP client/server library for GNOME. It uses GObjects and the glib main loop to integrate well with GNOME applications and also has a synchronous API for use in CLI tools. | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00315, EPSS Percentile is 0.24472 |
debian: CVE-2026-85534 was patched at 2026-09-16
1178.
Denial of Service - Rclone (CVE-2026-88015) - Medium [320]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers, supporting over 40 cloud storage products including S3, Google Drive, Dropbox, OneDrive, and many more. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00354, EPSS Percentile is 0.28955 |
debian: CVE-2026-88015 was patched at 2026-09-16
1179.
Memory Corruption - FreeRDP (CVE-2026-91950) - Medium [320]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00451, EPSS Percentile is 0.38295 |
debian: CVE-2026-91950 was patched at 2026-09-16
1180.
Server-Side Request Forgery - Oj (CVE-2026-4200) - Medium [320]
Description: A security flaw has been discovered in glowxq glowxq-
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.35 | 14 | Oj (Optimized JSON) is a high-performance JSON parser and object serialization library packaged as a Ruby gem, designed to provide fast JSON encoding and decoding for Ruby applications. | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00294, EPSS Percentile is 0.22046 |
altlinux: CVE-2026-4200 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-42007 was patched at 2026-09-16
debian: CVE-2026-42008 was patched at 2026-09-16
1181.
Elevation of Privilege - Suricata (CVE-2026-57223) - Medium [318]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Suricata is an open-source intrusion detection and prevention system (IDS/IPS) and network security monitoring engine that supports deep packet inspection and threat detection. | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-57223 was patched at 2026-09-16
1182.
Authentication Bypass - Unknown Product (CVE-2026-58423) - Medium [317]
Description: {'nvd_cve_data_all': 'LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00536, EPSS Percentile is 0.43899 |
altlinux: CVE-2026-58423 was patched at 2026-08-27, 2026-08-29, 2026-09-04
1183.
Denial of Service - Chromium (CVE-2026-87538) - Medium [317]
Description: Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00203, EPSS Percentile is 0.10474 |
altlinux: CVE-2026-87538 was patched at 2026-09-17
debian: CVE-2026-87538 was patched at 2026-09-16
1184.
Information Disclosure - Chromium (CVE-2026-78936) - Medium [317]
Description: Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 2.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00107, EPSS Percentile is 0.01272 |
altlinux: CVE-2026-78936 was patched at 2026-08-28
debian: CVE-2026-78936 was patched at 2026-09-03, 2026-09-16
1185.
Information Disclosure - Chromium (CVE-2026-78949) - Medium [317]
Description: Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 2.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00099, EPSS Percentile is 0.00934 |
altlinux: CVE-2026-78949 was patched at 2026-08-28
debian: CVE-2026-78949 was patched at 2026-09-03, 2026-09-16
1186.
Memory Corruption - GNOME desktop (CVE-2026-77658) - Medium [317]
Description: A stack-based
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | GNOME originally an acronym for GNU Network Object Model Environment, is a free and open-source desktop environment for Linux and other Unix-like operating systems | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04031 |
debian: CVE-2026-77658 was patched at 2026-09-16
1187.
Memory Corruption - Zabbix (CVE-2026-23935) - Medium [317]
Description: A
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Zabbix is an open-source software tool to monitor IT infrastructure such as networks, servers, virtual machines, and cloud services | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00175, EPSS Percentile is 0.07214 |
altlinux: CVE-2026-23935 was patched at 2026-08-26, 2026-08-27, 2026-08-28
debian: CVE-2026-23935 was patched at 2026-08-20
1188.
Code Injection - Unknown Product (CVE-2026-19546) - Medium [316]
Description: {'nvd_cve_data_all': 'A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mitigation please reffer to the original https://access.redhat.com/security/cve/cve-2026-19546.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z.\n\nFor a detailed Statement, Description and Mitigation please reffer to the original https://access.redhat.com/security/cve/cve-2026-19546.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00352, EPSS Percentile is 0.28684 |
almalinux: CVE-2026-19546 was patched at 2026-09-09
oraclelinux: CVE-2026-19546 was patched at 2026-09-10
redhat: CVE-2026-19546 was patched at 2026-09-09
1189.
Code Injection - Unknown Product (CVE-2026-76175) - Medium [316]
Description: {'nvd_cve_data_all': 'SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list endpoint. Input provided by an authenticated user with operator privileges is incorporated into an SQL query without proper parameterisation or validation, allowing the query to be manipulated and information to be extracted from the database using SQL injection techniques.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list endpoint. Input provided by an authenticated user with operator privileges is incorporated into an SQL query without proper parameterisation or validation, allowing the query to be manipulated and information to be extracted from the database using SQL injection techniques.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.6. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.0033, EPSS Percentile is 0.26111 |
debian: CVE-2026-76175 was patched at 2026-09-16
1190.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64257) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 responses Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to responses without data area") restricted the implied bcc[0] length exception to responses without a data area. However, the overlap handling in __smb2_calc_size() clears data_length, which can make an invalid response appear to have no data area and so qualify for the exception. Track data area overlap separately and reject such responses before applying the length compatibility exceptions.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: reject overlapping data areas in SMB2 responses\n\nCommit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to\nresponses without data area") restricted the implied bcc[0] length\nexception to responses without a data area. However, the overlap\nhandling in __smb2_calc_size() clears data_length, which can make an\ninvalid response appear to have no data area and so qualify for the\nexception.\n\nTrack data area overlap separately and reject such responses before\napplying the length compatibility exceptions.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00664, EPSS Percentile is 0.50018 |
oraclelinux: CVE-2026-64257 was patched at 2026-09-04
1191.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64459) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: tcp: restore RCU grace period in tcp_ao_destroy_sock Commit 51e547e8c89c ("tcp: Free TCP-AO/TCP-MD5 info/keys without RCU") removed the call_rcu() callback from tcp_ao_destroy_sock(), arguing that "the destruction of info/keys is delayed until the socket destructor" and therefore "no one can discover it anymore". That argument does not hold for the call site in tcp_connect() (net/ipv4/tcp_output.c:4327-4332). At that point the socket is in TCP_SYN_SENT, has already been inserted into the inet ehash by inet_hash_connect() in tcp_v4_connect(), and is therefore very much discoverable: any softirq running tcp_v4_rcv() on another CPU can take the socket out of the ehash, walk into tcp_inbound_hash(), and load tp->ao_info via implicit RCU before bh_lock_sock_nested() is taken on the destroying CPU. The reader path then enters __tcp_ao_do_lookup() (net/ipv4/tcp_ao.c:208) which re-loads tp->ao_info via rcu_dereference_check(); the re-load can still observe the (about-to-be-freed) pointer because there is no synchronize_rcu() between rcu_assign_pointer(tp->ao_info, NULL) and tcp_ao_info_free() in tcp_ao_destroy_sock(). The captured pointer is then walked at line 223: \thlist_for_each_entry_rcu(key, &ao->head, node, ...) The writer's synchronous kfree() is free to complete between the line 218 re-fetch and the line 223 hlist iteration. The slab is reused (or simply LIST_POISON1-stamped if not yet reused) and the iteration walks attacker-controlled or poison memory in softirq context. Reproducer (no debug shim, stock x86_64 v7.1-rc2 SMP+KASAN, QEMU+KVM): an unprivileged uid=1000 process inside CLONE_NEWUSER|CLONE_NEWNET installs TCP_MD5SIG + TCP_AO_ADD_KEY on a TCP socket, sprays forged TCP-AO segments toward its eventual 4-tuple via raw sockets, then calls connect(). The md5-wins reconciliation in tcp_connect() fires tcp_ao_destroy_sock(); the softirq backlog reader on the loopback NAPI path crashes on the freed ao->head.first walk: Oops: general protection fault, probably for non-canonical address 0xfbd59c000000002f KASAN: maybe wild-memory-access in range [0xdead000000000178-0xdead00000000017f] CPU: 0 UID: 1000 PID: 100 Comm: repro_userns RIP: 0010:__tcp_ao_do_lookup+0x107/0x1c0 Call Trace: <IRQ> __tcp_ao_do_lookup+0x107/0x1c0 tcp_ao_inbound_lookup.constprop.0+0x12a/0x200 tcp_inbound_ao_hash+0x5ea/0x1520 tcp_inbound_hash+0x7ce/0x1240 tcp_v4_rcv+0x1e7a/0x3e10 ... Restore the RCU grace period: re-add struct rcu_head to tcp_ao_info and replace the synchronous tcp_ao_info_free() with a call_rcu() callback. Readers that captured tp->ao_info before rcu_assign_pointer NULLed it now see the object remain valid until rcu_read_unlock(). With the patch applied the reproducer runs cleanly for 2000 iterations on the same kernel build.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: restore RCU grace period in tcp_ao_destroy_sock\n\nCommit 51e547e8c89c ("tcp: Free TCP-AO/TCP-MD5 info/keys without RCU")\nremoved the call_rcu() callback from tcp_ao_destroy_sock(), arguing that\n"the destruction of info/keys is delayed until the socket destructor"\nand therefore "no one can discover it anymore".\n\nThat argument does not hold for the call site in tcp_connect()\n(net/ipv4/tcp_output.c:4327-4332). At that point the socket is in\nTCP_SYN_SENT, has already been inserted into the inet ehash by\ninet_hash_connect() in tcp_v4_connect(), and is therefore very much\ndiscoverable: any softirq running tcp_v4_rcv() on another CPU can take\nthe socket out of the ehash, walk into tcp_inbound_hash(), and load\ntp->ao_info via implicit RCU before bh_lock_sock_nested() is taken on\nthe destroying CPU.\n\nThe reader path then enters __tcp_ao_do_lookup() (net/ipv4/tcp_ao.c:208)\nwhich re-loads tp->ao_info via rcu_dereference_check(); the re-load can\nstill observe the (about-to-be-freed) pointer because there is no\nsynchronize_rcu() between rcu_assign_pointer(tp->ao_info, NULL) and\ntcp_ao_info_free() in tcp_ao_destroy_sock(). The captured pointer is\nthen walked at line 223:\n\n\thlist_for_each_entry_rcu(key, &ao->head, node, ...)\n\nThe writer's synchronous kfree() is free to complete between the line\n218 re-fetch and the line 223 hlist iteration. The slab is reused\n(or simply LIST_POISON1-stamped if not yet reused) and the iteration\nwalks attacker-controlled or poison memory in softirq context.\n\nReproducer (no debug shim, stock x86_64 v7.1-rc2 SMP+KASAN, QEMU+KVM):\nan unprivileged uid=1000 process inside CLONE_NEWUSER|CLONE_NEWNET\ninstalls TCP_MD5SIG + TCP_AO_ADD_KEY on a TCP socket, sprays forged\nTCP-AO segments toward its eventual 4-tuple via raw sockets, then\ncalls connect(). The md5-wins reconciliation in tcp_connect() fires\ntcp_ao_destroy_sock(); the softirq backlog reader on the loopback\nNAPI path crashes on the freed ao->head.first walk:\n\n Oops: general protection fault, probably for non-canonical\n address 0xfbd59c000000002f\n KASAN: maybe wild-memory-access in range\n [0xdead000000000178-0xdead00000000017f]\n CPU: 0 UID: 1000 PID: 100 Comm: repro_userns\n RIP: 0010:__tcp_ao_do_lookup+0x107/0x1c0\n Call Trace: <IRQ>\n __tcp_ao_do_lookup+0x107/0x1c0\n tcp_ao_inbound_lookup.constprop.0+0x12a/0x200\n tcp_inbound_ao_hash+0x5ea/0x1520\n tcp_inbound_hash+0x7ce/0x1240\n tcp_v4_rcv+0x1e7a/0x3e10\n ...\n\nRestore the RCU grace period: re-add struct rcu_head to tcp_ao_info\nand replace the synchronous tcp_ao_info_free() with a call_rcu()\ncallback. Readers that captured tp->ao_info before rcu_assign_pointer\nNULLed it now see the object remain valid until rcu_read_unlock().\nWith the patch applied the reproducer runs cleanly for 2000 iterations\non the same kernel build.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00475, EPSS Percentile is 0.39937 |
ubuntu: CVE-2026-64459 was patched at 2026-09-07, 2026-09-16
1192.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74597) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip6ip6_err() ip6ip6_err() clones an outer IPv6 ICMP error skb, pulls it to the quoted inner IPv6 packet, and then passes the clone to icmpv6_send(). The clone still carries the outer packet's inet6_skb_parm in skb->cb. If the outer packet had a Home Address Option, IP6CB(skb2)->dsthao remains non-zero after skb_pull(). icmpv6_send() later calls mip6_addr_swap(), which uses that stale dsthao offset against the quoted inner packet. A malformed inner destination-options header can then make the HAO lookup and address swap run past the end of the quoted packet and corrupt skb_shared_info. Clear skb2->cb[] before pulling the quoted inner IPv6 packet so the reply path does not reuse metadata left by the outer IPv6 stack.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nip6_tunnel: clear skb2->cb[] in ip6ip6_err()\n\nip6ip6_err() clones an outer IPv6 ICMP error skb, pulls it to the\nquoted inner IPv6 packet, and then passes the clone to icmpv6_send().\nThe clone still carries the outer packet's inet6_skb_parm in skb->cb.\n\nIf the outer packet had a Home Address Option, IP6CB(skb2)->dsthao\nremains non-zero after skb_pull(). icmpv6_send() later calls\nmip6_addr_swap(), which uses that stale dsthao offset against the quoted\ninner packet. A malformed inner destination-options header can then make\nthe HAO lookup and address swap run past the end of the quoted packet\nand corrupt skb_shared_info.\n\nClear skb2->cb[] before pulling the quoted inner IPv6 packet so the\nreply path does not reuse metadata left by the outer IPv6 stack.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00514, EPSS Percentile is 0.42533 |
debian: CVE-2026-74597 was patched at 2026-08-25
oraclelinux: CVE-2026-74597 was patched at 2026-09-04
1193.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74611) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: tls: rx: restore msg_iter before TLS 1.3 optimistic retry tls_decrypt_sg() advances msg->msg_iter when it maps user pages for the optimistic TLS 1.3 zero-copy path. If the decrypted record turns out not to be unpadded application data, tls_decrypt_sw() retries into a kernel skb, but leaves the iterator advanced. The subsequent copy from the skb then writes decrypted bytes again at a later point in the caller iovecs while recvmsg() reports only the post-retry length. A TLS peer can trigger this after the receiver enables TLS_RX_EXPECT_NO_PAD. Revert the iterator by the number of bytes consumed by the optimistic mapping before retrying without zero-copy. Add a selftest which sends a TLS 1.3 control record with TLS_RX_EXPECT_NO_PAD enabled and verifies that recvmsg() does not overwrite later iovecs beyond the returned length.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntls: rx: restore msg_iter before TLS 1.3 optimistic retry\n\ntls_decrypt_sg() advances msg->msg_iter when it maps user pages for\nthe optimistic TLS 1.3 zero-copy path. If the decrypted record turns\nout not to be unpadded application data, tls_decrypt_sw() retries into\na kernel skb, but leaves the iterator advanced.\n\nThe subsequent copy from the skb then writes decrypted bytes again at\na later point in the caller iovecs while recvmsg() reports only the\npost-retry length. A TLS peer can trigger this after the receiver\nenables TLS_RX_EXPECT_NO_PAD.\n\nRevert the iterator by the number of bytes consumed by the optimistic\nmapping before retrying without zero-copy.\n\nAdd a selftest which sends a TLS 1.3 control record with\nTLS_RX_EXPECT_NO_PAD enabled and verifies that recvmsg() does not\noverwrite later iovecs beyond the returned length.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00442, EPSS Percentile is 0.37611 |
debian: CVE-2026-74611 was patched at 2026-08-25
1194.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74612) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: veth: fix skb length accounting after XDP frag adjustment veth exposes non-linear skb fragments through an xdp_buff. If an XDP program adjusts the fragment area, veth_xdp_rcv_skb() copies xdp_frags_size back to skb->data_len but leaves skb->len containing the old fragment contribution. After a fragment shrink, this makes skb_headlen() larger than the actual linear area. In the reproduced UDP receive path, __skb_datagram_iter() copied 1024 bytes past the actual linear tail to userspace, starting at struct skb_shared_info. The copied bytes included the affected skb's nr_frags, xdp_frags_size, and a kernel pointer from skb_shinfo(skb)->frags[0]. Real packet data was displaced by the same amount and truncated at the end. Subtract the old data_len before replacing it and add the new data_len afterwards, keeping skb->len and skb->data_len synchronized. Additionally, bpf_xdp_pull_data() can advance data_end while leaving frags present. The skb is then still non-linear, so the old __skb_put(skb, off) triggers SKB_LINEAR_ASSERT(). Use skb_set_tail_pointer() and update skb->len explicitly instead, following bpf_prog_run_generic_xdp(). Unlike __skb_put(), skb_set_tail_pointer() does not require a linear skb. A 60000-byte UDP datagram on a veth pair with MTU 64000 was shortened by 1024 bytes from its fragment area. Before the fix, all 10 runs produced corrupted payloads. After the fix, all 10 runs matched the expected payload exactly. A forced-tailroom reproducer also exercises bpf_xdp_pull_data() with frags still present; the old code triggers SKB_LINEAR_ASSERT(), while this fix passes 10/10 runs.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nveth: fix skb length accounting after XDP frag adjustment\n\nveth exposes non-linear skb fragments through an xdp_buff. If an XDP\nprogram adjusts the fragment area, veth_xdp_rcv_skb() copies\nxdp_frags_size back to skb->data_len but leaves skb->len containing the\nold fragment contribution.\n\nAfter a fragment shrink, this makes skb_headlen() larger than the actual\nlinear area. In the reproduced UDP receive path, __skb_datagram_iter()\ncopied 1024 bytes past the actual linear tail to userspace, starting at\nstruct skb_shared_info. The copied bytes included the affected skb's\nnr_frags, xdp_frags_size, and a kernel pointer from\nskb_shinfo(skb)->frags[0]. Real packet data was displaced by the same\namount and truncated at the end.\n\nSubtract the old data_len before replacing it and add the new data_len\nafterwards, keeping skb->len and skb->data_len synchronized.\n\nAdditionally, bpf_xdp_pull_data() can advance data_end while leaving\nfrags present. The skb is then still non-linear, so the old\n__skb_put(skb, off) triggers SKB_LINEAR_ASSERT().\n\nUse skb_set_tail_pointer() and update skb->len explicitly instead,\nfollowing bpf_prog_run_generic_xdp(). Unlike __skb_put(),\nskb_set_tail_pointer() does not require a linear skb.\n\nA 60000-byte UDP datagram on a veth pair with MTU 64000 was shortened by\n1024 bytes from its fragment area. Before the fix, all 10 runs produced\ncorrupted payloads. After the fix, all 10 runs matched the expected\npayload exactly. A forced-tailroom reproducer also exercises\nbpf_xdp_pull_data() with frags still present; the old code triggers\nSKB_LINEAR_ASSERT(), while this fix passes 10/10 runs.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00491, EPSS Percentile is 0.41016 |
debian: CVE-2026-74612 was patched at 2026-08-25
oraclelinux: CVE-2026-74612 was patched at 2026-09-04
1195.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74616) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xdp: reject clones that overrun skb_shared_info tailroom xdpf_clone() clones broadcast copies into a single page and sets frame_sz to PAGE_SIZE. __xdp_build_skb_from_frame() later treats that page like a normal XDP frame and expects the usual skb_shared_info tailroom at the end of the buffer. The current check only rejects frames whose linear xdp_frame header, headroom, and packet data exceed PAGE_SIZE. A source frame backed by a larger allocation can still satisfy that check while extending into the clone's required shared-info area. When such a clone is converted back into an skb, build_skb_around() places skb_shared_info over live packet bytes and later writes can corrupt XDP return metadata. Reject clones unless their linear area fits inside SKB_WITH_OVERHEAD(PAGE_SIZE), matching the tailroom requirement already enforced by the XDP-to-skb conversion path.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxdp: reject clones that overrun skb_shared_info tailroom\n\nxdpf_clone() clones broadcast copies into a single page and sets\nframe_sz to PAGE_SIZE. __xdp_build_skb_from_frame() later treats that\npage like a normal XDP frame and expects the usual skb_shared_info\ntailroom at the end of the buffer.\n\nThe current check only rejects frames whose linear xdp_frame header,\nheadroom, and packet data exceed PAGE_SIZE. A source frame backed by a\nlarger allocation can still satisfy that check while extending into the\nclone's required shared-info area. When such a clone is converted back\ninto an skb, build_skb_around() places skb_shared_info over live packet\nbytes and later writes can corrupt XDP return metadata.\n\nReject clones unless their linear area fits inside\nSKB_WITH_OVERHEAD(PAGE_SIZE), matching the tailroom requirement already\nenforced by the XDP-to-skb conversion path.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00513, EPSS Percentile is 0.42444 |
debian: CVE-2026-74616 was patched at 2026-08-25
oraclelinux: CVE-2026-74616 was patched at 2026-09-04
1196.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74662) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: inet: frags: publish queues before arming timer inet_frag_create() arms the fragment queue timer before inserting the queue into the fqdir rhashtable. If the namespace fragment timeout is zero or negative, the timer can run before the queue is published. The timer callback then marks the queue complete, tries to remove a node that is not in the hash table yet, and drops the anticipated hash reference. Creation can subsequently publish the completed queue without restoring that reference, leaving a stale hash node after the caller drops the remaining reference. Publish the queue first and arm the timer while holding the queue lock. This makes timer expiry wait until the queue is visible in the hash table, so inet_frag_kill() can remove the node and balance the hash reference.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ninet: frags: publish queues before arming timer\n\ninet_frag_create() arms the fragment queue timer before inserting the\nqueue into the fqdir rhashtable. If the namespace fragment timeout is\nzero or negative, the timer can run before the queue is published.\n\nThe timer callback then marks the queue complete, tries to remove a node\nthat is not in the hash table yet, and drops the anticipated hash\nreference. Creation can subsequently publish the completed queue without\nrestoring that reference, leaving a stale hash node after the caller drops\nthe remaining reference.\n\nPublish the queue first and arm the timer while holding the queue lock.\nThis makes timer expiry wait until the queue is visible in the hash table,\nso inet_frag_kill() can remove the node and balance the hash reference.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00514, EPSS Percentile is 0.42539 |
debian: CVE-2026-74662 was patched at 2026-08-25, 2026-08-29
1197.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80528) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ceph: avoid fs reclaim while using current->journal_info handle_reply() stores a `ceph_mds_request` pointer in `current->journal_info` while filling the inode and dentry cache from an MDS reply. An allocation in this section can enter direct reclaim and prune dentries from another filesystem. If this dirties an ext4 inode, ext4 starts a JBD2 transaction. JBD2 interprets the Ceph request in `current->journal_info` as a journal handle and dereferences the request's `r_tid` as `h_transaction`, causing a kernel crash, e.g.: Unable to handle kernel paging request at virtual address 00000000077b4818 [...] Internal error: Oops: 0000000096000004 [#1] SMP Modules linked in: CPU: 6 UID: 0 PID: 2699135 Comm: kworker/6:3 Tainted: G W 6.18.38-i3 #1113 NONE [...] Workqueue: ceph-msgr ceph_con_workfn pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : jbd2__journal_start+0x2c/0x208 lr : __ext4_journal_start_sb+0x100/0x178 [...] Call trace: jbd2__journal_start+0x2c/0x208 (P) __ext4_journal_start_sb+0x100/0x178 ext4_dirty_inode+0x3c/0x90 __mark_inode_dirty+0x58/0x400 iput.part.0+0x2b0/0x370 iput+0x18/0x30 dentry_unlink_inode+0xc0/0x158 __dentry_kill+0x80/0x250 shrink_dentry_list+0x90/0x130 prune_dcache_sb+0x60/0x98 super_cache_scan+0xe8/0x190 do_shrink_slab+0x174/0x388 shrink_slab+0xd8/0x4c0 shrink_node+0x31c/0x908 do_try_to_free_pages+0xd0/0x508 try_to_free_pages+0x11c/0x238 __alloc_frozen_pages_noprof+0x4d0/0xdd0 __folio_alloc_noprof+0x18/0x70 __filemap_get_folio+0x248/0x440 ceph_readdir_prepopulate+0x570/0x9e8 mds_dispatch+0x1424/0x1ba0 ceph_con_process_message+0x74/0xa0 ceph_con_v1_try_read+0x3a0/0x1510 ceph_con_workfn+0x260/0x460 Enter a scoped NOFS allocation context and leave it after clearing `journal_info`. This prevents filesystem reclaim from recursing into another filesystem while the field contains Ceph-private data.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nceph: avoid fs reclaim while using current->journal_info\n\nhandle_reply() stores a `ceph_mds_request` pointer in\n`current->journal_info` while filling the inode and dentry cache from\nan MDS reply.\n\nAn allocation in this section can enter direct reclaim and prune\ndentries from another filesystem. If this dirties an ext4 inode, ext4\nstarts a JBD2 transaction. JBD2 interprets the Ceph request in\n`current->journal_info` as a journal handle and dereferences the\nrequest's `r_tid` as `h_transaction`, causing a kernel crash, e.g.:\n\n Unable to handle kernel paging request at virtual address 00000000077b4818\n [...]\n Internal error: Oops: 0000000096000004 [#1] SMP\n Modules linked in:\n CPU: 6 UID: 0 PID: 2699135 Comm: kworker/6:3 Tainted: G W 6.18.38-i3 #1113 NONE\n [...]\n Workqueue: ceph-msgr ceph_con_workfn\n pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : jbd2__journal_start+0x2c/0x208\n lr : __ext4_journal_start_sb+0x100/0x178\n [...]\n Call trace:\n jbd2__journal_start+0x2c/0x208 (P)\n __ext4_journal_start_sb+0x100/0x178\n ext4_dirty_inode+0x3c/0x90\n __mark_inode_dirty+0x58/0x400\n iput.part.0+0x2b0/0x370\n iput+0x18/0x30\n dentry_unlink_inode+0xc0/0x158\n __dentry_kill+0x80/0x250\n shrink_dentry_list+0x90/0x130\n prune_dcache_sb+0x60/0x98\n super_cache_scan+0xe8/0x190\n do_shrink_slab+0x174/0x388\n shrink_slab+0xd8/0x4c0\n shrink_node+0x31c/0x908\n do_try_to_free_pages+0xd0/0x508\n try_to_free_pages+0x11c/0x238\n __alloc_frozen_pages_noprof+0x4d0/0xdd0\n __folio_alloc_noprof+0x18/0x70\n __filemap_get_folio+0x248/0x440\n ceph_readdir_prepopulate+0x570/0x9e8\n mds_dispatch+0x1424/0x1ba0\n ceph_con_process_message+0x74/0xa0\n ceph_con_v1_try_read+0x3a0/0x1510\n ceph_con_workfn+0x260/0x460\n\nEnter a scoped NOFS allocation context and leave it after clearing\n`journal_info`. This prevents filesystem reclaim from recursing into\nanother filesystem while the field contains Ceph-private data.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00521, EPSS Percentile is 0.42955 |
debian: CVE-2026-80528 was patched at 2026-09-16
oraclelinux: CVE-2026-80528 was patched at 2026-09-04
1198.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80557) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: libceph: fix OOB read in decode_watchers() via missing bounds check ceph_start_decoding() validates that struct_len bytes remain in the buffer after the encoding header, but accepts struct_len=0 as valid: ceph_decode_need(p, end, 0, bad) always passes. When a malicious or compromised OSD sends an obj_list_watch_response_t reply with struct_len=0, ceph_start_decoding() returns success with p == end, leaving zero bytes guaranteed for subsequent reads. The immediately following ceph_decode_32(p) in decode_watchers() has no preceding bounds check. With p == end this is a 4-byte read past the validated buffer boundary. The garbage value is then passed directly to kzalloc_objs() as the watcher count. The sibling function decode_watcher() already uses the safe variants (ceph_decode_copy_safe, ceph_decode_64_safe, ceph_decode_skip_32) after its own ceph_start_decoding() call. decode_watchers() is the only site that uses the bare variant, confirming an oversight. Fix by replacing ceph_decode_32(p) with ceph_decode_32_safe(p, end, *num_watchers, bad), consistent with the established pattern. Attacker model: a malicious or compromised OSD in a multi-tenant Ceph deployment (e.g. cloud) can trigger this against any kernel client that calls CEPH_OSD_OP_LIST_WATCHERS, without any further privileges beyond OSD session establishment. [ idryomov: trim changelog ]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: fix OOB read in decode_watchers() via missing bounds check\n\nceph_start_decoding() validates that struct_len bytes remain in the\nbuffer after the encoding header, but accepts struct_len=0 as valid:\nceph_decode_need(p, end, 0, bad) always passes. When a malicious or\ncompromised OSD sends an obj_list_watch_response_t reply with\nstruct_len=0, ceph_start_decoding() returns success with p == end,\nleaving zero bytes guaranteed for subsequent reads.\n\nThe immediately following ceph_decode_32(p) in decode_watchers() has\nno preceding bounds check. With p == end this is a 4-byte read past\nthe validated buffer boundary. The garbage value is then passed\ndirectly to kzalloc_objs() as the watcher count.\n\nThe sibling function decode_watcher() already uses the safe variants\n(ceph_decode_copy_safe, ceph_decode_64_safe, ceph_decode_skip_32)\nafter its own ceph_start_decoding() call. decode_watchers() is the\nonly site that uses the bare variant, confirming an oversight.\n\nFix by replacing ceph_decode_32(p) with ceph_decode_32_safe(p, end,\n*num_watchers, bad), consistent with the established pattern.\n\nAttacker model: a malicious or compromised OSD in a multi-tenant Ceph\ndeployment (e.g. cloud) can trigger this against any kernel client\nthat calls CEPH_OSD_OP_LIST_WATCHERS, without any further privileges\nbeyond OSD session establishment.\n\n[ idryomov: trim changelog ]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00521, EPSS Percentile is 0.42955 |
debian: CVE-2026-80557 was patched at 2026-08-29, 2026-09-16
1199.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80558) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: libceph: Avoid using invalid osd indices from primary_temp A corrupted osdmap received from a Ceph monitor or OSD may contain osd indices in its pg_temp, primary_temp, pg_upmap, and pg_upmap_items parts that don't exist, i.e., that are greater than max_osd or smaller than CEPH_HOMELESS_OSD (-1). These indices are used to create the up and acting set in ceph_pg_to_up_acting_osds(), called from calc_target(). While most of these osd indices are checked, the one from primary_temp is not. Subsequently, this may lead to calc_target() returning this (potentially invalid) index as target osd for a (linger) request. Because the osd_state, osd_weight, and osd_addr arrays only contain max_osd entries (with indices 0 to max_osd -1), this leads to out-of-bounds accesses when trying to read values from these arrays. This patch fixes the issue by adding a check to get_temp_osds(), so that only valid osd indices from primary_temp are used, and it falls back to using the primary from pg_temp or the up set if it is invalid. [ idryomov: changelog ]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Avoid using invalid osd indices from primary_temp\n\nA corrupted osdmap received from a Ceph monitor or OSD may contain osd\nindices in its pg_temp, primary_temp, pg_upmap, and pg_upmap_items parts\nthat don't exist, i.e., that are greater than max_osd or smaller than\nCEPH_HOMELESS_OSD (-1). These indices are used to create the up and\nacting set in ceph_pg_to_up_acting_osds(), called from calc_target().\nWhile most of these osd indices are checked, the one from primary_temp\nis not. Subsequently, this may lead to calc_target() returning this\n(potentially invalid) index as target osd for a (linger) request.\nBecause the osd_state, osd_weight, and osd_addr arrays only contain\nmax_osd entries (with indices 0 to max_osd -1), this leads to\nout-of-bounds accesses when trying to read values from these arrays.\n\nThis patch fixes the issue by adding a check to get_temp_osds(), so that\nonly valid osd indices from primary_temp are used, and it falls back to\nusing the primary from pg_temp or the up set if it is invalid.\n\n[ idryomov: changelog ]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00521, EPSS Percentile is 0.42955 |
debian: CVE-2026-80558 was patched at 2026-09-16
oraclelinux: CVE-2026-80558 was patched at 2026-09-04
1200.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80561) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: libceph: fix multiple unsafe decodes in decode_locker() decode_locker() in cls_lock_client.c contains three unsafe decode operations that allow a malicious or compromised OSD to trigger slab-out-of-bounds reads: 1. ceph_decode_copy() at the locker_id_t name field has no preceding bounds check. With p == end after ceph_start_decoding() accepts struct_len=0, this reads sizeof(ceph_entity_name) = 9 bytes past the validated buffer boundary. 2. *p += sizeof(struct ceph_timespec) after the locker_info_t header is an unchecked pointer advance. A malicious OSD can position p past end, causing all subsequent _safe checks to pass against a bogus boundary. 3. len = ceph_decode_32(p) has no preceding bounds check, and the immediately following *p += len is uncapped. A malicious OSD can send len=0xffffffff, advancing p gigabytes past end and escaping the decode window entirely. Fix all three by replacing bare operations with their safe variants: ceph_decode_copy -> ceph_decode_copy_safe *p += sizeof(...) -> ceph_decode_skip_n ceph_decode_32(p) -> ceph_decode_32_safe *p += len -> ceph_decode_skip_n A new label is added to return -EINVAL on any bounds violation. -EINVAL is appropriate here: the data received from the OSD is structurally malformed, which is an invalid argument to the decode contract regardless of whether the caller or the wire is at fault. Attacker model: a malicious or compromised OSD in a multi-tenant Ceph deployment can trigger this against any kernel client that issues the lock.get_info class method (e.g. during RBD exclusive lock acquisition) without any further privileges beyond OSD session establishment. [ idryomov: use ceph_decode_skip_string() to skip description, trim changelog ]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: fix multiple unsafe decodes in decode_locker()\n\ndecode_locker() in cls_lock_client.c contains three unsafe decode\noperations that allow a malicious or compromised OSD to trigger\nslab-out-of-bounds reads:\n\n1. ceph_decode_copy() at the locker_id_t name field has no preceding\n bounds check. With p == end after ceph_start_decoding() accepts\n struct_len=0, this reads sizeof(ceph_entity_name) = 9 bytes past\n the validated buffer boundary.\n\n2. *p += sizeof(struct ceph_timespec) after the locker_info_t header\n is an unchecked pointer advance. A malicious OSD can position p\n past end, causing all subsequent _safe checks to pass against a\n bogus boundary.\n\n3. len = ceph_decode_32(p) has no preceding bounds check, and the\n immediately following *p += len is uncapped. A malicious OSD can\n send len=0xffffffff, advancing p gigabytes past end and escaping\n the decode window entirely.\n\nFix all three by replacing bare operations with their safe variants:\n ceph_decode_copy -> ceph_decode_copy_safe\n *p += sizeof(...) -> ceph_decode_skip_n\n ceph_decode_32(p) -> ceph_decode_32_safe\n *p += len -> ceph_decode_skip_n\n\nA new label is added to return -EINVAL on any bounds violation.\n-EINVAL is appropriate here: the data received from the OSD\nis structurally malformed, which is an invalid argument to the decode\ncontract regardless of whether the caller or the wire is at fault.\n\nAttacker model: a malicious or compromised OSD in a multi-tenant Ceph\ndeployment can trigger this against any kernel client that issues the\nlock.get_info class method (e.g. during RBD exclusive lock acquisition)\nwithout any further privileges beyond OSD session establishment.\n\n[ idryomov: use ceph_decode_skip_string() to skip description, trim\n changelog ]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00521, EPSS Percentile is 0.42955 |
debian: CVE-2026-80561 was patched at 2026-09-16
oraclelinux: CVE-2026-80561 was patched at 2026-09-04
1201.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80590) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: inet: frags: strip GSO state from fragments before reassembly A virtio_net_hdr (tun/tap, or AF_PACKET with PACKET_VNET_HDR) can mark an IPv4 or IPv6 fragment as GSO; nothing relates gso_type to frag_off. inet_frag_reasm_prepare()/inet_frag_reasm_finish() keep the first fragment's skb as the head of the reassembled datagram, including its shinfo->gso_size/gso_type/gso_segs, and chain the remaining fragments on frag_list with whatever linear/paged layout they arrived with. After ip_defrag() (ip_local_deliver(), nf_defrag_ipv4, ...) the reassembled skb therefore still claims to be GSO (SKB_GSO_DODGY), and the next software segmentation point - udp_rcv_segment() on local delivery, validate_xmit_skb(), or the ip_finish_output_gso() slow path - hands it to skb_segment(). skb_segment()'s frag_list walk assumes GRO-shaped input and hits one of its BUG_ON()s. Two writes to a tap by an unprivileged user in its own userns are enough: kernel BUG at net/core/skbuff.c:4899! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI CPU: 0 UID: 1000 PID: 82 Comm: poc Not tainted 7.2.0-pentest+ #2 RIP: 0010:skb_segment+0x20ca/0x48b0 Call Trace: <TASK> __udp_gso_segment+0x29a/0x27d0 udp4_ufo_fragment+0x458/0x6c0 inet_gso_segment+0x429/0x1340 skb_mac_gso_segment+0x233/0x4f0 __skb_gso_segment+0x308/0x660 udp_queue_rcv_skb+0x440/0xad0 udp_unicast_rcv_skb+0xc7/0x2c0 udp_rcv+0x16ce/0x2260 ip_protocol_deliver_rcu+0x197/0x2d0 ip_local_deliver+0x430/0x690 ip_rcv+0x16f/0x1f0 __netif_receive_skb_one_core+0x15e/0x1c0 __netif_receive_skb+0x1e/0x110 netif_receive_skb+0xf6/0x5c0 tun_rx_batched.isra.0+0x3ab/0x790 tun_get_user+0x17c3/0x3550 tun_chr_write_iter+0xba/0x1b0 vfs_write+0x646/0x1130 </TASK> Kernel panic - not syncing: Fatal exception in interrupt This runs with BH disabled, so it is a panic rather than an oops. The same is reachable with CAP_NET_RAW in a netns where a defrag point precedes a GSO point, and from a guest whose VMM forwards virtio_net_hdr to a tap. The SKB_GSO_DODGY frag_list checks added by commit 3dcbdb134f32 ("net: gso: Fix skb_segment splat when splitting gso_size mangled skb having linear-headed frag_list") and by commit 9e4b7a99a03a ("net: gso: fix panic on frag_list with mixed head alloc types") do not cover it: page-backed heads skip them, and kmalloc heads skip them when gso_size == skb_headlen(head), which the sender controls. An skb entering a frag queue is an IP fragment by definition and cannot legitimately carry GSO state: GRO does not merge fragments and the stack segments before it fragments, so only untrusted sources are affected. This has been reachable since commit f43798c27684 ("tun: Allow GSO using virtio_net_hdr"), the first path that let userspace attach GSO metadata to an IP fragment. Reset the GSO fields of every fragment as it is queued, in inet_frag_queue_insert(), which IPv4, IPv6, nf_conntrack_reasm and 6lowpan reassembly share; then neither the head nor the frag_list members of the reassembled skb carry them (the members matter too: the ip_do_fragment()/ip6_fragment() fast paths send them out as they are). The head may remain CHECKSUM_PARTIAL; that is already accepted on receive and resolved by skb_checksum_help() in ip_do_fragment()/ip6_fragment() on forward. Tested on top of net.git (dc4b95b8fee9), x86_64: the tap reproducer above, two further IPv4 frag_list geometries that reach BUG_ON(i >= nfrags) and BUG_ON(!list_skb->head_frag), and an IPv6 fragment-header variant (udp6_ufo_fragment()) each panic the unpatched kernel; with this patch all four datagrams are delivered intact and nothing is logged.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ninet: frags: strip GSO state from fragments before reassembly\n\nA virtio_net_hdr (tun/tap, or AF_PACKET with PACKET_VNET_HDR) can mark\nan IPv4 or IPv6 fragment as GSO; nothing relates gso_type to frag_off.\ninet_frag_reasm_prepare()/inet_frag_reasm_finish() keep the first\nfragment's skb as the head of the reassembled datagram, including its\nshinfo->gso_size/gso_type/gso_segs, and chain the remaining fragments\non frag_list with whatever linear/paged layout they arrived with.\n\nAfter ip_defrag() (ip_local_deliver(), nf_defrag_ipv4, ...) the\nreassembled skb therefore still claims to be GSO (SKB_GSO_DODGY), and\nthe next software segmentation point - udp_rcv_segment() on local\ndelivery, validate_xmit_skb(), or the ip_finish_output_gso() slow\npath - hands it to skb_segment(). skb_segment()'s frag_list walk\nassumes GRO-shaped input and hits one of its BUG_ON()s. Two writes to\na tap by an unprivileged user in its own userns are enough:\n\n kernel BUG at net/core/skbuff.c:4899!\n Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\n CPU: 0 UID: 1000 PID: 82 Comm: poc Not tainted 7.2.0-pentest+ #2\n RIP: 0010:skb_segment+0x20ca/0x48b0\n Call Trace:\n <TASK>\n __udp_gso_segment+0x29a/0x27d0\n udp4_ufo_fragment+0x458/0x6c0\n inet_gso_segment+0x429/0x1340\n skb_mac_gso_segment+0x233/0x4f0\n __skb_gso_segment+0x308/0x660\n udp_queue_rcv_skb+0x440/0xad0\n udp_unicast_rcv_skb+0xc7/0x2c0\n udp_rcv+0x16ce/0x2260\n ip_protocol_deliver_rcu+0x197/0x2d0\n ip_local_deliver+0x430/0x690\n ip_rcv+0x16f/0x1f0\n __netif_receive_skb_one_core+0x15e/0x1c0\n __netif_receive_skb+0x1e/0x110\n netif_receive_skb+0xf6/0x5c0\n tun_rx_batched.isra.0+0x3ab/0x790\n tun_get_user+0x17c3/0x3550\n tun_chr_write_iter+0xba/0x1b0\n vfs_write+0x646/0x1130\n </TASK>\n Kernel panic - not syncing: Fatal exception in interrupt\n\nThis runs with BH disabled, so it is a panic rather than an oops. The\nsame is reachable with CAP_NET_RAW in a netns where a defrag point\nprecedes a GSO point, and from a guest whose VMM forwards\nvirtio_net_hdr to a tap. The SKB_GSO_DODGY frag_list checks added by\ncommit 3dcbdb134f32 ("net: gso: Fix skb_segment splat when splitting\ngso_size mangled skb having linear-headed frag_list") and by\ncommit 9e4b7a99a03a ("net: gso: fix panic on frag_list with mixed head\nalloc types") do not cover it: page-backed heads skip them, and kmalloc\nheads skip them when gso_size == skb_headlen(head), which the sender\ncontrols.\n\nAn skb entering a frag queue is an IP fragment by definition and\ncannot legitimately carry GSO state: GRO does not merge fragments and\nthe stack segments before it fragments, so only untrusted sources are\naffected. This has been reachable since\ncommit f43798c27684 ("tun: Allow GSO using virtio_net_hdr"), the first\npath that let userspace attach GSO metadata to an IP fragment. Reset\nthe GSO fields of every fragment as it is queued, in\ninet_frag_queue_insert(), which IPv4, IPv6, nf_conntrack_reasm and\n6lowpan reassembly share; then neither the head nor the frag_list\nmembers of the reassembled skb carry them (the members matter too:\nthe ip_do_fragment()/ip6_fragment() fast paths send them out as they\nare). The head may remain CHECKSUM_PARTIAL; that is already accepted\non receive and resolved by skb_checksum_help() in\nip_do_fragment()/ip6_fragment() on forward.\n\nTested on top of net.git (dc4b95b8fee9), x86_64: the tap reproducer\nabove, two further IPv4 frag_list geometries that reach\nBUG_ON(i >= nfrags) and BUG_ON(!list_skb->head_frag), and an IPv6\nfragment-header variant (udp6_ufo_fragment()) each panic the unpatched\nkernel; with this patch all four datagrams are delivered intact and\nnothing is logged.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.6. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00586, EPSS Percentile is 0.46445 |
debian: CVE-2026-80590 was patched at 2026-08-29, 2026-09-16
oraclelinux: CVE-2026-80590 was patched at 2026-09-04
1202.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80609) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: qede: fix out-of-bounds check for cqe->len_list[] Move index check before element access.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nqede: fix out-of-bounds check for cqe->len_list[]\n\nMove index check before element access.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00509, EPSS Percentile is 0.42177 |
debian: CVE-2026-80609 was patched at 2026-09-16
oraclelinux: CVE-2026-80609 was patched at 2026-09-04
redos: CVE-2026-80609 was patched at 2026-09-16
1203.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80630) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen Whenever fq_codel drops packets during peek, it calls qdisc_tree_reduce_backlog. An issue arises because it calls qdisc_tree_reduce_backlog before it reincrements the qlen. If qlen drops to zero, but peek returns an skb, the parent's qlen_notify callback will be executed even though fq_codel still has 1 packet on the queue and, thus, will mistakenly deactivate the parent's class causing issues like a recent report [1] and a wild memory access in qfq: [ 29.371146][ T360] Oops: general protection fault, probably for non-canonical address 0xfbd59c0000000024: 0000 [#1] SMP KASAN NOPTI [ 29.371666][ T360] KASAN: maybe wild-memory-access in range [0xdead000000000120-0xdead000000000127] [ 29.371987][ T360] CPU: 6 UID: 0 PID: 360 Comm: tc Not tainted 7.1.0-rc5-00285-gc530e5b2dbc6-dirty #82 PREEMPT(full) [ 29.372384][ T360] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 29.372620][ T360] RIP: 0010:qfq_deactivate_agg (include/linux/list.h:1029 (discriminator 2) include/linux/list.h:1043 (discriminator 2) net/sched/sch_qfq.c:1369 (discriminator 2) net/sched/sch_qfq.c:1395 (discriminator 2)) sch_qfq [ 29.373544][ T360] RSP: 0018:ffff888102417370 EFLAGS: 00010216 [ 29.373800][ T360] RAX: 0000000000000000 RBX: ffff88811224d568 RCX: dffffc0000000000 [ 29.374079][ T360] RDX: 1ffff11021fe1543 RSI: ffff88810ff0aa00 RDI: dffffc0000000000 [ 29.374368][ T360] RBP: ffff88811224c280 R08: dead000000000122 R09: 1bd5a00000000024 [ 29.374649][ T360] R10: fffffbfff7940329 R11: fffffbfff7940329 R12: 0000000000000000 [ 29.374926][ T360] R13: dead000000000100 R14: ffff88811224d580 R15: ffff88811224d578 [ 29.375207][ T360] FS: 00007f5b794e5780(0000) GS:ffff88815d1e9000(0000) knlGS:0000000000000000 [ 29.375545][ T360] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 29.375823][ T360] CR2: 000055ffb091f000 CR3: 000000010a305000 CR4: 0000000000750ef0 [ 29.376103][ T360] PKRU: 55555554 [ 29.376258][ T360] Call Trace: [ 29.376401][ T360] <TASK> ... [ 29.376885][ T360] qfq_reset_qdisc (net/sched/sch_qfq.c:357 net/sched/sch_qfq.c:1487) sch_qfq [ 29.377074][ T360] qdisc_reset (net/sched/sch_generic.c:1057) [ 29.377414][ T360] __qdisc_destroy (net/sched/sch_generic.c:1096) [ 29.377600][ T360] qdisc_graft (net/sched/sch_api.c:1062 net/sched/sch_api.c:1053 net/sched/sch_api.c:1159) [ 29.378593][ T360] tc_get_qdisc (net/sched/sch_api.c:1528 net/sched/sch_api.c:1556) Fix this by only calling qdisc_tree_reduce_backlog in peek after the qlen is restored. [1] http://lore.kernel.org/netdev/CAN2cbVe79oj0O9==m4+4x3v+O+qzRagA=2=wkrp9i9=CqYvyZA@mail.gmail.com/', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen\n\nWhenever fq_codel drops packets during peek, it calls\nqdisc_tree_reduce_backlog. An issue arises because it calls\nqdisc_tree_reduce_backlog before it reincrements the qlen. If qlen drops\nto zero, but peek returns an skb, the parent's qlen_notify callback will be\nexecuted even though fq_codel still has 1 packet on the queue and, thus,\nwill mistakenly deactivate the parent's class causing issues like a recent\nreport [1] and a wild memory access in qfq:\n\n[ 29.371146][ T360] Oops: general protection fault, probably for non-canonical address 0xfbd59c0000000024: 0000 [#1] SMP KASAN NOPTI\n[ 29.371666][ T360] KASAN: maybe wild-memory-access in range [0xdead000000000120-0xdead000000000127]\n[ 29.371987][ T360] CPU: 6 UID: 0 PID: 360 Comm: tc Not tainted 7.1.0-rc5-00285-gc530e5b2dbc6-dirty #82 PREEMPT(full)\n[ 29.372384][ T360] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011\n[ 29.372620][ T360] RIP: 0010:qfq_deactivate_agg (include/linux/list.h:1029 (discriminator 2) include/linux/list.h:1043 (discriminator 2) net/sched/sch_qfq.c:1369 (discriminator 2) net/sched/sch_qfq.c:1395 (discriminator 2)) sch_qfq\n[ 29.373544][ T360] RSP: 0018:ffff888102417370 EFLAGS: 00010216\n[ 29.373800][ T360] RAX: 0000000000000000 RBX: ffff88811224d568 RCX: dffffc0000000000\n[ 29.374079][ T360] RDX: 1ffff11021fe1543 RSI: ffff88810ff0aa00 RDI: dffffc0000000000\n[ 29.374368][ T360] RBP: ffff88811224c280 R08: dead000000000122 R09: 1bd5a00000000024\n[ 29.374649][ T360] R10: fffffbfff7940329 R11: fffffbfff7940329 R12: 0000000000000000\n[ 29.374926][ T360] R13: dead000000000100 R14: ffff88811224d580 R15: ffff88811224d578\n[ 29.375207][ T360] FS: 00007f5b794e5780(0000) GS:ffff88815d1e9000(0000) knlGS:0000000000000000\n[ 29.375545][ T360] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 29.375823][ T360] CR2: 000055ffb091f000 CR3: 000000010a305000 CR4: 0000000000750ef0\n[ 29.376103][ T360] PKRU: 55555554\n[ 29.376258][ T360] Call Trace:\n[ 29.376401][ T360] <TASK>\n...\n[ 29.376885][ T360] qfq_reset_qdisc (net/sched/sch_qfq.c:357 net/sched/sch_qfq.c:1487) sch_qfq\n[ 29.377074][ T360] qdisc_reset (net/sched/sch_generic.c:1057)\n[ 29.377414][ T360] __qdisc_destroy (net/sched/sch_generic.c:1096)\n[ 29.377600][ T360] qdisc_graft (net/sched/sch_api.c:1062 net/sched/sch_api.c:1053 net/sched/sch_api.c:1159)\n[ 29.378593][ T360] tc_get_qdisc (net/sched/sch_api.c:1528 net/sched/sch_api.c:1556)\n\nFix this by only calling qdisc_tree_reduce_backlog in peek after the\nqlen is restored.\n\n[1] http://lore.kernel.org/netdev/CAN2cbVe79oj0O9==m4+4x3v+O+qzRagA=2=wkrp9i9=CqYvyZA@mail.gmail.com/', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00521, EPSS Percentile is 0.42957 |
debian: CVE-2026-80630 was patched at 2026-09-16
oraclelinux: CVE-2026-80630 was patched at 2026-09-04
redos: CVE-2026-80630 was patched at 2026-09-16
1204.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80694) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller mtk_handle_irq_rx expects a struct mtk_eth * (matching the request_irq cookie), but mtk_poll_controller incorrectly passed the net_device *. Calling ndo_poll_controller with CONFIG_NET_POLL_CONTROLLER enabled would then crash.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller\n\nmtk_handle_irq_rx expects a struct mtk_eth * (matching the request_irq\ncookie), but mtk_poll_controller incorrectly passed the net_device *.\nCalling ndo_poll_controller with CONFIG_NET_POLL_CONTROLLER enabled\nwould then crash.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00463, EPSS Percentile is 0.39129 |
debian: CVE-2026-80694 was patched at 2026-09-16
1205.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-81002) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xdp: fix zero-copy frame layout xdp_convert_zc_to_xdp_frame() clones an XSK packet into an order-0 page and advertises PAGE_SIZE as its frame size. It allows the copied frame to occupy the page tail needed by skb_shared_info and records zero headroom even when metadata separates the frame header from packet data. An AF_XDP zero-copy packet redirected through cpumap can therefore make the skb overlap skb_shared_info or place it beyond the allocated page. Limit the copied layout to SKB_WITH_OVERHEAD(PAGE_SIZE) and include the metadata length in frame headroom. Redirect callers already handle a NULL conversion result. BUG: KASAN: slab-out-of-bounds in skb_gro_receive Write of size 4 at addr ffff88800cf37004 by task cpumap/1/map:1/146 Call Trace: skb_gro_receive (net/core/gro.c:174) udp_gro_receive (net/ipv4/udp_offload.c:812) inet_gro_receive (net/ipv4/af_inet.c:1539) dev_gro_receive (net/core/gro.c:515) gro_receive_skb (net/core/gro.c:633) cpu_map_kthread_run (kernel/bpf/cpumap.c:395) kthread (kernel/kthread.c:436) ret_from_fork (arch/x86/kernel/process.c:164) ret_from_fork_asm (arch/x86/entry/entry_64.S:255) Kernel panic - not syncing: KASAN: panic_on_warn set ...', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxdp: fix zero-copy frame layout\n\nxdp_convert_zc_to_xdp_frame() clones an XSK packet into an order-0 page\nand advertises PAGE_SIZE as its frame size. It allows the copied frame\nto occupy the page tail needed by skb_shared_info and records zero\nheadroom even when metadata separates the frame header from packet data.\nAn AF_XDP zero-copy packet redirected through cpumap can therefore make\nthe skb overlap skb_shared_info or place it beyond the allocated page.\n\nLimit the copied layout to SKB_WITH_OVERHEAD(PAGE_SIZE) and include the\nmetadata length in frame headroom. Redirect callers already handle a\nNULL conversion result.\n\nBUG: KASAN: slab-out-of-bounds in skb_gro_receive\nWrite of size 4 at addr ffff88800cf37004 by task cpumap/1/map:1/146\nCall Trace:\n skb_gro_receive (net/core/gro.c:174)\n udp_gro_receive (net/ipv4/udp_offload.c:812)\n inet_gro_receive (net/ipv4/af_inet.c:1539)\n dev_gro_receive (net/core/gro.c:515)\n gro_receive_skb (net/core/gro.c:633)\n cpu_map_kthread_run (kernel/bpf/cpumap.c:395)\n kthread (kernel/kthread.c:436)\n ret_from_fork (arch/x86/kernel/process.c:164)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:255)\nKernel panic - not syncing: KASAN: panic_on_warn set ...', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00521, EPSS Percentile is 0.42957 |
debian: CVE-2026-81002 was patched at 2026-09-16
1206.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89478) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: sctp: drop a chunk if its transport was removed sctp_rcv() resolves the transport once per packet and leaves it in chunk->transport. The lookup reference, or the one sctp_add_backlog() takes if the socket is owned by userspace, keeps it around until the chunk has been processed. An authenticated ASCONF DEL-IP can remove it in the meantime. sctp_assoc_rm_peer() takes the transport out of the association and calls sctp_transport_free(), which tags it dead and drops the reference the association held. There is a window on both paths: the packet can sit on the socket backlog, and on the direct path the lookup completes before bh_lock_sock(). The DATA chunk in that packet puts the removed transport back into asoc->peer.last_data_from. Once the packet is done that reference goes away and the transport is freed by RCU, so the next delayed SACK carries the pointer into the SACK chunk and sctp_outq_select_transport() reads the freed transport's state. Drop the chunk in sctp_inq_push(), next to the existing rcvr->dead check. Both paths reach it with the association's socket lock held. The peer retransmits it.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: drop a chunk if its transport was removed\n\nsctp_rcv() resolves the transport once per packet and leaves it in\nchunk->transport. The lookup reference, or the one sctp_add_backlog() takes\nif the socket is owned by userspace, keeps it around until the chunk has\nbeen processed.\n\nAn authenticated ASCONF DEL-IP can remove it in the meantime.\nsctp_assoc_rm_peer() takes the transport out of the association and calls\nsctp_transport_free(), which tags it dead and drops the reference the\nassociation held. There is a window on both paths: the packet can sit on\nthe socket backlog, and on the direct path the lookup completes before\nbh_lock_sock().\n\nThe DATA chunk in that packet puts the removed transport back into\nasoc->peer.last_data_from. Once the packet is done that reference goes\naway and the transport is freed by RCU, so the next delayed SACK carries\nthe pointer into the SACK chunk and sctp_outq_select_transport() reads the\nfreed transport's state.\n\nDrop the chunk in sctp_inq_push(), next to the existing rcvr->dead check.\nBoth paths reach it with the association's socket lock held. The peer\nretransmits it.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00521, EPSS Percentile is 0.42956 |
debian: CVE-2026-89478 was patched at 2026-09-16
1207.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89530) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject inline replies that overflow the pull-up buffer An RPC-over-RDMA client can request a reply, such as an NFS READ payload, without providing a Write list or a Reply chunk to carry it. When such a reply needs more scatter/gather entries than the device's Send Queue supports, svc_rdma_pull_up_needed() selects pull-up and svc_rdma_pull_up_reply_msg() linearizes the whole reply into sctxt->sc_xprt_buf. That buffer is only sc_max_req_size bytes, while the reply on this path is bounded only by the client's request, so svc_rdma_xb_linearize() copies past the end of the buffer and corrupts adjacent slab memory. The oversized length is then stored in sc_sges[0].length and posted, so the device also reads beyond the mapped region. The SGE-exhaustion branch is the only pull-up path that can exceed the buffer: the threshold branch pulls up only replies smaller than RPCRDMA_PULLUP_THRESH, and replies that fit the device's SGE budget are sent directly without linearization. Make svc_rdma_pull_up_needed() report -E2BIG when the reply it would pull up cannot fit sc_max_req_size, and fail the request with ERR_CHUNK as RFC 8166 Section 4.5.3 directs rather than dropping the connection. The helper no longer answers a simple yes/no question: it now reports pull-up, no pull-up, or -E2BIG for a reply too large to linearize. Rename svc_rdma_pull_up_needed() to svc_rdma_check_pull_up() so its name no longer implies a boolean predicate.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: Reject inline replies that overflow the pull-up buffer\n\nAn RPC-over-RDMA client can request a reply, such as an NFS READ\npayload, without providing a Write list or a Reply chunk to carry\nit. When such a reply needs more scatter/gather entries than the\ndevice's Send Queue supports, svc_rdma_pull_up_needed() selects\npull-up and svc_rdma_pull_up_reply_msg() linearizes the whole\nreply into sctxt->sc_xprt_buf. That buffer is only sc_max_req_size\nbytes, while the reply on this path is bounded only by the client's\nrequest, so svc_rdma_xb_linearize() copies past the end of the\nbuffer and corrupts adjacent slab memory. The oversized length is\nthen stored in sc_sges[0].length and posted, so the device also\nreads beyond the mapped region.\n\nThe SGE-exhaustion branch is the only pull-up path that can exceed\nthe buffer: the threshold branch pulls up only replies smaller\nthan RPCRDMA_PULLUP_THRESH, and replies that fit the device's SGE\nbudget are sent directly without linearization. Make\nsvc_rdma_pull_up_needed() report -E2BIG when the reply it would\npull up cannot fit sc_max_req_size, and fail the request with\nERR_CHUNK as RFC 8166 Section 4.5.3 directs rather than dropping\nthe connection.\n\nThe helper no longer answers a simple yes/no question: it now\nreports pull-up, no pull-up, or -E2BIG for a reply too large to\nlinearize. Rename svc_rdma_pull_up_needed() to\nsvc_rdma_check_pull_up() so its name no longer implies a boolean\npredicate.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00463, EPSS Percentile is 0.39129 |
debian: CVE-2026-89530 was patched at 2026-09-16
1208.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89533) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: svcrdma: Fix offset arithmetic in read_chunk_range svc_rdma_read_chunk_range() walks a Read chunk's segment list to build a sub-range starting at byte offset and spanning length bytes for a Position-Zero or Call chunk. Two arithmetic defects in the per-segment loop produce wrong DMA lengths and a u32 underflow: pcl_for_each_segment(segment, chunk) { if (offset > segment->rs_length) { offset -= segment->rs_length; continue; } dummy.rs_handle = segment->rs_handle; dummy.rs_length = min_t(u32, length, segment->rs_length) - offset; dummy.rs_offset = segment->rs_offset + offset; First, the skip predicate uses '>' instead of '>='. When offset equals the segment's full rs_length, the segment is fully consumed and should be skipped, but the loop falls through into the body. The resulting dummy.rs_length is min_t(u32, length, rs_length) - rs_length, which underflows to a near-UINT_MAX u32 when length is smaller than rs_length, or is zero otherwise. Second, the length formula subtracts offset from the min_t() result rather than from segment->rs_length before the cap. For offset > 0 the segment's residual is rs_length - offset, not rs_length, so the cap must be applied to the residual. With the current bracketing, whenever length is smaller than rs_length - offset the per-segment length becomes length - offset instead of length, silently dropping offset bytes from the rebuilt chunk. Combined with the boundary case above it also enables the u32 underflow path, which propagates a huge nr_bvec into svc_rdma_build_read_segment() and a multi-MiB kmalloc_array_node() in svc_rdma_get_rw_ctxt(). Additionally, svc_rdma_read_call_chunk() can invoke this function with length == 0 when the last Read chunk ends exactly at the end of the Call chunk. With the corrected >= predicate, every segment is skipped and the function returns the initial -EINVAL, rejecting a valid request. Return success immediately when length is zero. Also break out of the loop once length is fully consumed to avoid passing zero-length segments to svc_rdma_build_read_segment(). Fix by using '>=' so a fully-consumed segment is skipped, by moving '- offset' inside min_t() so the cap is applied to the segment's residual length, by returning success for zero-length requests, and by stopping iteration when the requested range has been consumed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: Fix offset arithmetic in read_chunk_range\n\nsvc_rdma_read_chunk_range() walks a Read chunk's segment list to\nbuild a sub-range starting at byte offset and spanning length bytes\nfor a Position-Zero or Call chunk. Two arithmetic defects in the\nper-segment loop produce wrong DMA lengths and a u32 underflow:\n\n pcl_for_each_segment(segment, chunk) {\n if (offset > segment->rs_length) {\n offset -= segment->rs_length;\n continue;\n }\n\n dummy.rs_handle = segment->rs_handle;\n dummy.rs_length = min_t(u32, length,\n segment->rs_length) - offset;\n dummy.rs_offset = segment->rs_offset + offset;\n\nFirst, the skip predicate uses '>' instead of '>='. When offset\nequals the segment's full rs_length, the segment is fully consumed\nand should be skipped, but the loop falls through into the body.\nThe resulting dummy.rs_length is min_t(u32, length, rs_length) -\nrs_length, which underflows to a near-UINT_MAX u32 when length is\nsmaller than rs_length, or is zero otherwise.\n\nSecond, the length formula subtracts offset from the min_t() result\nrather than from segment->rs_length before the cap. For offset > 0\nthe segment's residual is rs_length - offset, not rs_length, so the\ncap must be applied to the residual. With the current bracketing,\nwhenever length is smaller than rs_length - offset the per-segment\nlength becomes length - offset instead of length, silently dropping\noffset bytes from the rebuilt chunk. Combined with the boundary\ncase above it also enables the u32 underflow path, which propagates\na huge nr_bvec into svc_rdma_build_read_segment() and a multi-MiB\nkmalloc_array_node() in svc_rdma_get_rw_ctxt().\n\nAdditionally, svc_rdma_read_call_chunk() can invoke this function\nwith length == 0 when the last Read chunk ends exactly at the end\nof the Call chunk. With the corrected >= predicate, every segment\nis skipped and the function returns the initial -EINVAL, rejecting\na valid request. Return success immediately when length is zero.\nAlso break out of the loop once length is fully consumed to avoid\npassing zero-length segments to svc_rdma_build_read_segment().\n\nFix by using '>=' so a fully-consumed segment is skipped, by\nmoving '- offset' inside min_t() so the cap is applied to the\nsegment's residual length, by returning success for zero-length\nrequests, and by stopping iteration when the requested range has\nbeen consumed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00509, EPSS Percentile is 0.42178 |
debian: CVE-2026-89533 was patched at 2026-09-16
1209.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89541) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: SUNRPC: harden gss_unwrap_resp_priv length checks gss_unwrap_resp_priv() validates the RPCSEC_GSS opaque length with offset = (u8 *)(p) - (u8 *)head->iov_base; if (offset + opaque_len > rcv_buf->len) goto unwrap_failed; maj_stat = gss_unwrap(ctx->gc_gss_ctx, offset, offset + opaque_len, rcv_buf); Both operands are u32 and the sum is computed in u32. A reply with opaque_len near 0xffffffff makes offset + opaque_len wrap to a small value that is below rcv_buf->len, so the bound check passes and gss_unwrap() is called with end < begin. The check also lacks a lower bound, so any opaque_len in [0, GSS_KRB5_TOK_HDR_LEN) is accepted and forwarded to gss_krb5_unwrap_v2(), whose pre-decrypt header reads at ptr+4 and ptr+6 then run past the token. A krb5p NFS server returning a crafted RPCSEC_GSS reply can drive the client into out-of-bounds reads in gss_krb5_unwrap_v2() and the rotate_left() loop that follows. Fix by replacing the single combined check with three guards that are safe in u32 arithmetic and that enforce the RFC 4121 minimum outer token length: if (offset > rcv_buf->len) goto unwrap_failed; if (opaque_len > rcv_buf->len - offset) goto unwrap_failed; if (opaque_len < GSS_KRB5_TOK_HDR_LEN) goto unwrap_failed; The first guard makes the subtraction in the second guard unconditionally safe; offset is derived from a successful xdr_inline_decode() in the head kvec, so in practice it already satisfies the bound. The floor mirrors the server-side check added in commit 5b757c2e57a5 ("SUNRPC: svcauth_gss: enforce krb5 token minimum length").', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: harden gss_unwrap_resp_priv length checks\n\ngss_unwrap_resp_priv() validates the RPCSEC_GSS opaque length with\n\n offset = (u8 *)(p) - (u8 *)head->iov_base;\n if (offset + opaque_len > rcv_buf->len)\n goto unwrap_failed;\n maj_stat = gss_unwrap(ctx->gc_gss_ctx, offset,\n offset + opaque_len, rcv_buf);\n\nBoth operands are u32 and the sum is computed in u32. A reply with\nopaque_len near 0xffffffff makes offset + opaque_len wrap to a small\nvalue that is below rcv_buf->len, so the bound check passes and\ngss_unwrap() is called with end < begin. The check also lacks a\nlower bound, so any opaque_len in [0, GSS_KRB5_TOK_HDR_LEN) is\naccepted and forwarded to gss_krb5_unwrap_v2(), whose pre-decrypt\nheader reads at ptr+4 and ptr+6 then run past the token.\n\nA krb5p NFS server returning a crafted RPCSEC_GSS reply can drive\nthe client into out-of-bounds reads in gss_krb5_unwrap_v2() and the\nrotate_left() loop that follows.\n\nFix by replacing the single combined check with three guards that\nare safe in u32 arithmetic and that enforce the RFC 4121 minimum\nouter token length:\n\n if (offset > rcv_buf->len)\n goto unwrap_failed;\n if (opaque_len > rcv_buf->len - offset)\n goto unwrap_failed;\n if (opaque_len < GSS_KRB5_TOK_HDR_LEN)\n goto unwrap_failed;\n\nThe first guard makes the subtraction in the second guard\nunconditionally safe; offset is derived from a successful\nxdr_inline_decode() in the head kvec, so in practice it already\nsatisfies the bound. The floor mirrors the server-side check added\nin commit 5b757c2e57a5 ("SUNRPC: svcauth_gss: enforce krb5 token\nminimum length").', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00521, EPSS Percentile is 0.42957 |
debian: CVE-2026-89541 was patched at 2026-09-16
1210.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89542) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: SUNRPC: harden gss_krb5_unwrap_v2 against short tokens gss_krb5_unwrap_v2() reads the EC and RRC header fields at ptr+4 and ptr+6 before validating that the token is at least GSS_KRB5_TOK_HDR_LEN (16) bytes long, and its rotate_left() helper passes buf->len - base to xdr_buf_subsegment() without verifying that base <= buf->len. When a caller hands in a sub-16-byte token, or a token whose declared len leaves base past the end of the buffer, three distinct failures follow: gss_krb5_unwrap_v2(offset, len, buf) ptr = buf->head[0].iov_base + offset ec = *(ptr + 4) /* OOB read on short head */ rrc = *(ptr + 6) /* OOB read on short head */ rotate_left(offset + 16, buf, rrc) xdr_buf_subsegment(buf, &subbuf, base, buf->len - base) /* u32 wrap when base > len */ _rotate_left(&subbuf, shift) shift %= buf->len /* divide-by-zero when base == len */ After decryption, the cleanup arithmetic has the same shape: movelen = min_t(unsigned int, buf->head[0].iov_len, len); movelen -= offset + GSS_KRB5_TOK_HDR_LEN + headskip; BUG_ON(offset + GSS_KRB5_TOK_HDR_LEN + headskip + movelen > buf->head[0].iov_len); The BUG_ON re-adds the value just subtracted, so it reduces to min(A, B) > A and is permanently false; it cannot catch the unsigned underflow of movelen, which then drives a ~UINT_MAX-byte memmove(). Add four defense-in-depth guards inside the unwrap core so it is safe regardless of what its callers validate: - reject tokens with len - offset < GSS_KRB5_TOK_HDR_LEN before touching ptr+4/ptr+6; - bail from rotate_left() when buf->len <= base, covering both the underflow and zero-length cases; - return early from _rotate_left() when buf->len is zero, so the shift %= buf->len modulo cannot fault; - replace the dead BUG_ON with a live check that returns GSS_S_DEFECTIVE_TOKEN before the movelen subtraction.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: harden gss_krb5_unwrap_v2 against short tokens\n\ngss_krb5_unwrap_v2() reads the EC and RRC header fields at ptr+4 and\nptr+6 before validating that the token is at least GSS_KRB5_TOK_HDR_LEN\n(16) bytes long, and its rotate_left() helper passes buf->len - base\nto xdr_buf_subsegment() without verifying that base <= buf->len. When\na caller hands in a sub-16-byte token, or a token whose declared len\nleaves base past the end of the buffer, three distinct failures follow:\n\n gss_krb5_unwrap_v2(offset, len, buf)\n ptr = buf->head[0].iov_base + offset\n ec = *(ptr + 4) /* OOB read on short head */\n rrc = *(ptr + 6) /* OOB read on short head */\n rotate_left(offset + 16, buf, rrc)\n xdr_buf_subsegment(buf, &subbuf,\n base, buf->len - base) /* u32 wrap when base > len */\n _rotate_left(&subbuf, shift)\n shift %= buf->len /* divide-by-zero when base == len */\n\nAfter decryption, the cleanup arithmetic has the same shape:\n\n movelen = min_t(unsigned int, buf->head[0].iov_len, len);\n movelen -= offset + GSS_KRB5_TOK_HDR_LEN + headskip;\n BUG_ON(offset + GSS_KRB5_TOK_HDR_LEN + headskip + movelen >\n buf->head[0].iov_len);\n\nThe BUG_ON re-adds the value just subtracted, so it reduces to\nmin(A, B) > A and is permanently false; it cannot catch the unsigned\nunderflow of movelen, which then drives a ~UINT_MAX-byte memmove().\n\nAdd four defense-in-depth guards inside the unwrap core so it is safe\nregardless of what its callers validate:\n\n - reject tokens with len - offset < GSS_KRB5_TOK_HDR_LEN before\n touching ptr+4/ptr+6;\n - bail from rotate_left() when buf->len <= base, covering both the\n underflow and zero-length cases;\n - return early from _rotate_left() when buf->len is zero, so the\n shift %= buf->len modulo cannot fault;\n - replace the dead BUG_ON with a live check that returns\n GSS_S_DEFECTIVE_TOKEN before the movelen subtraction.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00521, EPSS Percentile is 0.42956 |
debian: CVE-2026-89542 was patched at 2026-09-16
1211.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89550) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: SUNRPC: svcauth_gss: enforce krb5 token minimum length svcauth_gss_unwrap_priv() validates only an upper bound on the wire-supplied opaque length before handing the buffer to gss_unwrap(): if (len > xdr_stream_remaining(xdr)) goto unwrap_failed; offset = xdr_stream_pos(xdr); ... maj_stat = gss_unwrap(ctx, offset, offset + len, buf); The wire value `len` flows unchanged as the upper bound into the krb5 unwrap path, so a len in [0, 16] passes this check and is handed to gss_unwrap(). For a krb5 v2 context that lands in gss_krb5_unwrap_v2(), which reads the 16-byte RFC 4121 token header fields at ptr+4 and ptr+6 and then calls rotate_left() before any integrity check. With a sub-header length the header reads run past the token, and _rotate_left()'s `shift %= buf->len` path can divide by zero when buf->len has been driven to zero by the truncated token. A header-only token (len == 16) is equally invalid: with a non-zero RRC field and the opaque blob ending at the XDR buffer boundary, rotate_left() builds a zero-length subbuffer, reaching the same division. Reject the token at the server entry point before it reaches the krb5 unwrap core. A valid sealed RFC 4121 token must contain the 16-byte header plus at least some encrypted payload. Fix by adding a minimum-length check immediately after the existing upper-bound check: if (len <= GSS_KRB5_TOK_HDR_LEN) goto unwrap_failed;', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: svcauth_gss: enforce krb5 token minimum length\n\nsvcauth_gss_unwrap_priv() validates only an upper bound on the\nwire-supplied opaque length before handing the buffer to\ngss_unwrap():\n\n if (len > xdr_stream_remaining(xdr))\n goto unwrap_failed;\n offset = xdr_stream_pos(xdr);\n ...\n maj_stat = gss_unwrap(ctx, offset, offset + len, buf);\n\nThe wire value `len` flows unchanged as the upper bound into the\nkrb5 unwrap path, so a len in [0, 16] passes this check and is\nhanded to gss_unwrap(). For a krb5 v2 context that lands in\ngss_krb5_unwrap_v2(), which reads the 16-byte RFC 4121 token\nheader fields at ptr+4 and ptr+6 and then calls rotate_left()\nbefore any integrity check. With a sub-header length the header\nreads run past the token, and _rotate_left()'s `shift %= buf->len`\npath can divide by zero when buf->len has been driven to zero by\nthe truncated token. A header-only token (len == 16) is equally\ninvalid: with a non-zero RRC field and the opaque blob ending at\nthe XDR buffer boundary, rotate_left() builds a zero-length\nsubbuffer, reaching the same division.\n\nReject the token at the server entry point before it reaches the\nkrb5 unwrap core. A valid sealed RFC 4121 token must contain\nthe 16-byte header plus at least some encrypted payload.\n\nFix by adding a minimum-length check immediately after the\nexisting upper-bound check:\n\n if (len <= GSS_KRB5_TOK_HDR_LEN)\n goto unwrap_failed;', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00463, EPSS Percentile is 0.39128 |
debian: CVE-2026-89550 was patched at 2026-09-16
1212.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89551) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow xdr_buf_trim() trims `len` bytes from the tail of an xdr_buf by walking the tail, pages, and head iovecs. Each per-section step uses min_t() so it never removes more bytes than that section holds, but the final accounting at the fix_len label subtracts the total bytes actually consumed from buf->len without any clamp: fix_len: buf->len -= (len - trim); When the caller has set buf->len to a value smaller than the sum of the iov_lens, (len - trim) can exceed buf->len and the unsigned subtraction wraps to near UINT_MAX. gss_krb5_unwrap_v2() reaches xdr_buf_trim() in exactly that state: buf->head[0].iov_len -= GSS_KRB5_TOK_HDR_LEN + headskip; buf->len = len - (GSS_KRB5_TOK_HDR_LEN + headskip); xdr_buf_trim(buf, ec + GSS_KRB5_TOK_HDR_LEN + tailskip); buf->len is a small wire-derived value while the iov_lens are at page scale, so the per-section loops legitimately consume far more bytes than buf->len records. The wrapped buf->len then propagates as the authoritative stream bound into every downstream XDR decoder. Fix by clamping the decrement so buf->len bottoms out at zero: buf->len -= min_t(unsigned int, buf->len, len - trim); On the normal path where the iov_lens sum to buf->len, (len - trim) is always <= buf->len and the result is identical to before. No callers change behavior outside the underflow case.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow\n\nxdr_buf_trim() trims `len` bytes from the tail of an xdr_buf by\nwalking the tail, pages, and head iovecs. Each per-section step\nuses min_t() so it never removes more bytes than that section\nholds, but the final accounting at the fix_len label subtracts the\ntotal bytes actually consumed from buf->len without any clamp:\n\n fix_len:\n buf->len -= (len - trim);\n\nWhen the caller has set buf->len to a value smaller than the sum\nof the iov_lens, (len - trim) can exceed buf->len and the unsigned\nsubtraction wraps to near UINT_MAX. gss_krb5_unwrap_v2() reaches\nxdr_buf_trim() in exactly that state:\n\n buf->head[0].iov_len -= GSS_KRB5_TOK_HDR_LEN + headskip;\n buf->len = len - (GSS_KRB5_TOK_HDR_LEN + headskip);\n xdr_buf_trim(buf, ec + GSS_KRB5_TOK_HDR_LEN + tailskip);\n\nbuf->len is a small wire-derived value while the iov_lens are at\npage scale, so the per-section loops legitimately consume far more\nbytes than buf->len records. The wrapped buf->len then propagates\nas the authoritative stream bound into every downstream XDR\ndecoder.\n\nFix by clamping the decrement so buf->len bottoms out at zero:\n\n buf->len -= min_t(unsigned int, buf->len, len - trim);\n\nOn the normal path where the iov_lens sum to buf->len, (len - trim)\nis always <= buf->len and the result is identical to before. No\ncallers change behavior outside the underflow case.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00521, EPSS Percentile is 0.42956 |
debian: CVE-2026-89551 was patched at 2026-09-16
1213.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89633) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2() coalesce_t2() computes data pointers directly from server-supplied DataOffset fields with no validation against buffer bounds: data_area_of_tgt = (char *)&pSMBt->hdr.Protocol + get_unaligned_le16(&pSMBt->t2_rsp.DataOffset); data_area_of_src = (char *)&pSMBs->hdr.Protocol + get_unaligned_le16(&pSMBs->t2_rsp.DataOffset); data_area_of_tgt += total_in_tgt; ... memcpy(data_area_of_tgt, data_area_of_src, total_in_src); A small DataOffset can push a pointer below the actual byte area, overwriting header fields; a large one can push it past the buffer end, causing out-of-bounds heap reads (source) or writes (target). The BCC overflow guard does not prevent this: BCC reflects how much data is present, while DataOffset controls where in the buffer it starts. The "validate target area" comment present since the function was first written in 2005 was a placeholder that was never implemented. Add lower- and upper-bound checks for both data pointers before the memcpy, and before any target header fields are modified.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()\n\ncoalesce_t2() computes data pointers directly from server-supplied\nDataOffset fields with no validation against buffer bounds:\n\n data_area_of_tgt = (char *)&pSMBt->hdr.Protocol +\n get_unaligned_le16(&pSMBt->t2_rsp.DataOffset);\n data_area_of_src = (char *)&pSMBs->hdr.Protocol +\n get_unaligned_le16(&pSMBs->t2_rsp.DataOffset);\n data_area_of_tgt += total_in_tgt;\n ...\n memcpy(data_area_of_tgt, data_area_of_src, total_in_src);\n\nA small DataOffset can push a pointer below the actual byte area,\noverwriting header fields; a large one can push it past the buffer\nend, causing out-of-bounds heap reads (source) or writes (target).\nThe BCC overflow guard does not prevent this: BCC reflects how much\ndata is present, while DataOffset controls where in the buffer it\nstarts.\n\nThe "validate target area" comment present since the function was\nfirst written in 2005 was a placeholder that was never implemented.\n\nAdd lower- and upper-bound checks for both data pointers before the\nmemcpy, and before any target header fields are modified.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00481, EPSS Percentile is 0.40358 |
debian: CVE-2026-89633 was patched at 2026-09-16
1214.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89634) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: smb: client: fix ALIGN() overflow in symlink_data() error context loop The check added by commit 7d9a7f1f96cd ("smb/client: fix possible infinite loop and oob read in symlink_data()") compared the post-ALIGN length against the remaining buffer, but ALIGN() itself can overflow: for ErrorDataLength near UINT32_MAX (e.g. 0xFFFFFFF9), ALIGN(x, 8) wraps to 0, so the subsequent bounds check passes, and the loop advances by zero bytes leaving 'p' pointing into stale data. Fix by checking the raw ErrorDataLength against the remaining space before applying ALIGN(), then checking again after. Since raw_len is bounded by the buffer, raw_len + 7 cannot overflow, so the second check is an exact post-alignment bounds guard.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix ALIGN() overflow in symlink_data() error context loop\n\nThe check added by commit 7d9a7f1f96cd ("smb/client: fix possible\ninfinite loop and oob read in symlink_data()") compared the post-ALIGN\nlength against the remaining buffer, but ALIGN() itself can overflow:\nfor ErrorDataLength near UINT32_MAX (e.g. 0xFFFFFFF9), ALIGN(x, 8)\nwraps to 0, so the subsequent bounds check passes, and the loop\nadvances by zero bytes leaving 'p' pointing into stale data.\n\nFix by checking the raw ErrorDataLength against the remaining space\nbefore applying ALIGN(), then checking again after. Since raw_len is\nbounded by the buffer, raw_len + 7 cannot overflow, so the second check\nis an exact post-alignment bounds guard.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00702, EPSS Percentile is 0.51536 |
debian: CVE-2026-89634 was patched at 2026-09-16
1215.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89649) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ceph: bound xattr value length in __build_xattrs() __build_xattrs() decodes the MDS-supplied xattr blob one attribute at a time. For each attribute it reads a 32-bit name length, advances past the name bytes, reads a 32-bit value length, records the value pointer, and advances past the value bytes. The two length fields are read with ceph_decode_32_safe(), but the value bytes themselves are advanced over with a bare "p += len" and no ceph_decode_need() check that "len" bytes remain in the blob. For every attribute except the last, the next iteration's ceph_decode_32_safe() on the following name length implicitly verifies that the previous value did not run past the blob end. The final attribute has no successor, so its decoded value length is never checked against the blob bounds. A malicious or compromised metadata server can set the last attribute's value length larger than the bytes actually present in the blob. The blob is a dedicated kvmalloc() allocation sized to the wire length (ceph_buffer_new() in ceph_fill_inode()). __set_xattr() records the oversized length in xattr->val_len verbatim, and a later getxattr(2) runs memcpy(value, xattr->val, xattr->val_len) into a user-supplied buffer, copying bytes past the end of the allocation back to user space. Impact: a malicious metadata server discloses adjacent kernel heap bytes to a local user via getxattr(2) on a CephFS file. Add the missing ceph_decode_need() so an out-of-bounds value length on the final attribute fails the decode and returns -EIO instead of being stored.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nceph: bound xattr value length in __build_xattrs()\n\n__build_xattrs() decodes the MDS-supplied xattr blob one attribute at a\ntime. For each attribute it reads a 32-bit name length, advances past the\nname bytes, reads a 32-bit value length, records the value pointer, and\nadvances past the value bytes. The two length fields are read with\nceph_decode_32_safe(), but the value bytes themselves are advanced over\nwith a bare "p += len" and no ceph_decode_need() check that "len" bytes\nremain in the blob.\n\nFor every attribute except the last, the next iteration's\nceph_decode_32_safe() on the following name length implicitly verifies\nthat the previous value did not run past the blob end. The final\nattribute has no successor, so its decoded value length is never checked\nagainst the blob bounds. A malicious or compromised metadata server can\nset the last attribute's value length larger than the bytes actually\npresent in the blob.\n\nThe blob is a dedicated kvmalloc() allocation sized to the wire length\n(ceph_buffer_new() in ceph_fill_inode()). __set_xattr() records the\noversized length in xattr->val_len verbatim, and a later getxattr(2) runs\nmemcpy(value, xattr->val, xattr->val_len) into a user-supplied buffer,\ncopying bytes past the end of the allocation back to user space.\n\nImpact: a malicious metadata server discloses adjacent kernel heap bytes\nto a local user via getxattr(2) on a CephFS file. Add the missing\nceph_decode_need() so an out-of-bounds value length on the final\nattribute fails the decode and returns -EIO instead of being stored.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00669, EPSS Percentile is 0.50225 |
debian: CVE-2026-89649 was patched at 2026-09-16
1216.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89653) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode MDSMap export_targets entries are monitor controlled. check_new_map() uses each entry as a bit number in a fixed stack bitmap, so a rank outside the protocol namespace can make set_bit() write past the end of the array. Reject ranks outside CEPH_MAX_MDS while decoding the map. Do not validate against possible_max_rank here because maps may legitimately reference ranks beyond a temporarily reduced max_mds.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode\n\nMDSMap export_targets entries are monitor controlled. check_new_map()\nuses each entry as a bit number in a fixed stack bitmap, so a rank\noutside the protocol namespace can make set_bit() write past the end of\nthe array.\n\nReject ranks outside CEPH_MAX_MDS while decoding the map. Do not\nvalidate against possible_max_rank here because maps may legitimately\nreference ranks beyond a temporarily reduced max_mds.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00509, EPSS Percentile is 0.42177 |
debian: CVE-2026-89653 was patched at 2026-09-16
1217.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89656) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: libceph: reject buckets with mismatched CRUSH ids crush_decode() stores bucket data by array slot, and the mapper later derives the per-bucket workspace index from the decoded bucket id. A malformed map can therefore make one bucket reuse another bucket's workspace by encoding an id different from -1 - slot. For uniform buckets, the second replica selection expands the source bucket's permutation into that aliased workspace buffer. If the source bucket is larger than the aliased bucket, the write runs past the smaller permutation array and can escape the kvmalloc'd CRUSH workspace. KASAN reports a slab OOB write of 4 bytes in bucket_perm_choose(). Reject buckets whose encoded id does not match their array slot. Valid CRUSH maps already use the canonical negative id corresponding to the bucket slot, so this restores the invariant expected by work->work[-1 - in->id] without changing valid map behavior.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: reject buckets with mismatched CRUSH ids\n\ncrush_decode() stores bucket data by array slot, and the mapper later\nderives the per-bucket workspace index from the decoded bucket id. A\nmalformed map can therefore make one bucket reuse another bucket's\nworkspace by encoding an id different from -1 - slot.\n\nFor uniform buckets, the second replica selection expands the source\nbucket's permutation into that aliased workspace buffer. If the source\nbucket is larger than the aliased bucket, the write runs past the smaller\npermutation array and can escape the kvmalloc'd CRUSH workspace. KASAN\nreports a slab OOB write of 4 bytes in bucket_perm_choose().\n\nReject buckets whose encoded id does not match their array slot. Valid\nCRUSH maps already use the canonical negative id corresponding to the\nbucket slot, so this restores the invariant expected by\nwork->work[-1 - in->id] without changing valid map behavior.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00521, EPSS Percentile is 0.42954 |
debian: CVE-2026-89656 was patched at 2026-09-16
1218.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89675) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: fix UAF in async copy cancel and shutdown An async copy could be freed or used after free while a teardown caller (OFFLOAD_CANCEL, nfsd4_shutdown_copy, nfsd4_cancel_copy_by_sb) raced the copy kthread: - find_async_copy() bumped copy->refcount but left the copy on clp->async_copies, so the reaper's cleanup_async_copy() could run release_copy_files() concurrently with a cancel/shutdown caller. Both put and NULL nf_src/nf_dst without a common lock, double-putting the nfsd_file and freeing it early. - nfsd4_do_async_copy() set NFSD4_COPY_F_STOPPED before its final uses of the copy (nfsd_update_cmtime_attr() on copy->nf_dst, nfsd4_send_cb_offload()). nfsd4_stop_copy() treats a set STOPPED bit as "kthread done, skip kthread_stop()", so a teardown caller ran release_copy_files() -- which puts and NULLs nf_dst -- while the kthread still dereferenced it (NULL/UAF). - copy->copy_task was never pinned. The one-shot kthread self-reaps on return, so kthread_stop()'s get_task_struct() could touch a freed task_struct. - co_cb is embedded in the copy, but nfsd4_send_cb_offload() held a reference only on the client, so a concurrent teardown could free the copy while the CB_OFFLOAD callback was in flight. Fix the teardown lifetime as a whole: - find_async_copy() unlinks the copy (clear cp_clp, list_del_init) under async_lock; the cancel, shutdown, and sb-cancel paths drop the list-membership reference via nfs4_put_copy() after nfsd4_stop_copy(). Drop the now-redundant list_del fixup from cleanup_async_copy(). - Because unlinking hides the copy from the reaper, its cleanup_async_copy() can no longer remove the copy's s2s_cp_stateids entry; the cancel/shutdown/sb-cancel paths now call nfs4_free_copy_state() themselves (while cp_clp is still valid) so the entry does not dangle at freed memory for the laundromat and manage_cpntf_state() to dereference. - Give the kthread its own reference, taken in nfsd4_copy() before wake_up_process() and dropped at the end of nfsd4_do_async_copy(); call wake_up_process() before list_add(). - Pin the task_struct with get_task_struct() in nfsd4_copy(), released in nfs4_put_copy(), so kthread_stop() is safe whenever the kthread exits. Set NFSD4_COPY_F_STOPPED only in nfsd4_stop_copy(), which now always kthread_stop()s before release_copy_files(); completion is still reported via NFSD4_COPY_F_COMPLETED, so nfsd4_has_active_async_copies() is unaffected. Each teardown caller removes the copy from clp->async_copies first, so kthread_stop() runs exactly once. - Take a copy reference in nfsd4_send_cb_offload(), dropped in nfsd4_cb_offload_release(). The kthread still holds its own reference there, so the refcount_inc() cannot race the final free. - Read cp_clp with smp_load_acquire() to pair with the unordered set_bit()/clear_bit() writers (Documentation/atomic_bitops.rst).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix UAF in async copy cancel and shutdown\n\nAn async copy could be freed or used after free while a teardown caller\n(OFFLOAD_CANCEL, nfsd4_shutdown_copy, nfsd4_cancel_copy_by_sb) raced the\ncopy kthread:\n\n - find_async_copy() bumped copy->refcount but left the copy on\n clp->async_copies, so the reaper's cleanup_async_copy() could run\n release_copy_files() concurrently with a cancel/shutdown caller. Both\n put and NULL nf_src/nf_dst without a common lock, double-putting the\n nfsd_file and freeing it early.\n\n - nfsd4_do_async_copy() set NFSD4_COPY_F_STOPPED before its final uses\n of the copy (nfsd_update_cmtime_attr() on copy->nf_dst,\n nfsd4_send_cb_offload()). nfsd4_stop_copy() treats a set STOPPED bit\n as "kthread done, skip kthread_stop()", so a teardown caller ran\n release_copy_files() -- which puts and NULLs nf_dst -- while the\n kthread still dereferenced it (NULL/UAF).\n\n - copy->copy_task was never pinned. The one-shot kthread self-reaps on\n return, so kthread_stop()'s get_task_struct() could touch a freed\n task_struct.\n\n - co_cb is embedded in the copy, but nfsd4_send_cb_offload() held a\n reference only on the client, so a concurrent teardown could free\n the copy while the CB_OFFLOAD callback was in flight.\n\nFix the teardown lifetime as a whole:\n\n - find_async_copy() unlinks the copy (clear cp_clp, list_del_init)\n under async_lock; the cancel, shutdown, and sb-cancel paths drop the\n list-membership reference via nfs4_put_copy() after nfsd4_stop_copy().\n Drop the now-redundant list_del fixup from cleanup_async_copy().\n\n - Because unlinking hides the copy from the reaper, its\n cleanup_async_copy() can no longer remove the copy's s2s_cp_stateids\n entry; the cancel/shutdown/sb-cancel paths now call\n nfs4_free_copy_state() themselves (while cp_clp is still valid) so\n the entry does not dangle at freed memory for the laundromat and\n manage_cpntf_state() to dereference.\n\n - Give the kthread its own reference, taken in nfsd4_copy() before\n wake_up_process() and dropped at the end of nfsd4_do_async_copy();\n call wake_up_process() before list_add().\n\n - Pin the task_struct with get_task_struct() in nfsd4_copy(), released\n in nfs4_put_copy(), so kthread_stop() is safe whenever the kthread\n exits. Set NFSD4_COPY_F_STOPPED only in nfsd4_stop_copy(), which now\n always kthread_stop()s before release_copy_files(); completion is\n still reported via NFSD4_COPY_F_COMPLETED, so\n nfsd4_has_active_async_copies() is unaffected. Each teardown caller\n removes the copy from clp->async_copies first, so kthread_stop() runs\n exactly once.\n\n - Take a copy reference in nfsd4_send_cb_offload(), dropped in\n nfsd4_cb_offload_release(). The kthread still holds its own reference\n there, so the refcount_inc() cannot race the final free.\n\n - Read cp_clp with smp_load_acquire() to pair with the unordered\n set_bit()/clear_bit() writers (Documentation/atomic_bitops.rst).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00448, EPSS Percentile is 0.38091 |
debian: CVE-2026-89675 was patched at 2026-09-16
1219.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89676) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: fix stale s2s_cp_stateids IDR entry for async COPY For an async COPY, nfsd4_copy() called nfs4_init_copy_state() before dup_copy_fields(), so the s2s_cp_stateids IDR was pointed at &u->copy->cp_stateid -- memory in the per-rqstp COMPOUND buffer that is reused by the next request. dup_copy_fields() copies only the value into async_copy, so the IDR slot dangled at the transient buffer for the whole background copy. Any IDR walker then dereferences reused request memory: the laundromat reads cs_type from it and, if the bytes look like an expired NFS4_COPYNOTIFY_STID, follows into refcount_dec()/idr_remove()/kfree() on garbage; manage_cpntf_state() has the same exposure via idr_find(). Duplicate the fields first, then register the stateid on the stable async_copy. result->cb_stateid is unchanged.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix stale s2s_cp_stateids IDR entry for async COPY\n\nFor an async COPY, nfsd4_copy() called nfs4_init_copy_state() before\ndup_copy_fields(), so the s2s_cp_stateids IDR was pointed at\n&u->copy->cp_stateid -- memory in the per-rqstp COMPOUND buffer that is\nreused by the next request. dup_copy_fields() copies only the value into\nasync_copy, so the IDR slot dangled at the transient buffer for the whole\nbackground copy. Any IDR walker then dereferences reused request memory:\nthe laundromat reads cs_type from it and, if the bytes look like an\nexpired NFS4_COPYNOTIFY_STID, follows into\nrefcount_dec()/idr_remove()/kfree() on garbage; manage_cpntf_state() has\nthe same exposure via idr_find().\n\nDuplicate the fields first, then register the stateid on the stable\nasync_copy. result->cb_stateid is unchanged.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00448, EPSS Percentile is 0.38091 |
debian: CVE-2026-89676 was patched at 2026-09-16
1220.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89697) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() The BOTH_TIME_SET branch calls fh_verify() early so setattr_prepare() can inspect the dentry. This causes nfsd_setattr() to skip fh_want_write(), so notify_change() runs without a mount write reference. Add the missing fh_want_write() call after the early fh_verify().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()\n\nThe BOTH_TIME_SET branch calls fh_verify() early so setattr_prepare()\ncan inspect the dentry. This causes nfsd_setattr() to skip\nfh_want_write(), so notify_change() runs without a mount write\nreference.\n\nAdd the missing fh_want_write() call after the early fh_verify().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00686, EPSS Percentile is 0.50944 |
debian: CVE-2026-89697 was patched at 2026-09-16
1221.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89702) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: size fh_verify server sockaddr slot by xpt_locallen The nfsd_fh_verify and nfsd_fh_verify_err tracepoints declare the server sockaddr slot sized by xpt_remotelen but fill it from xpt_local using xpt_locallen: TP_STRUCT__entry( ... __sockaddr(server, rqstp->rq_xprt->xpt_remotelen) ... ) TP_fast_assign( ... __assign_sockaddr(server, &rqstp->rq_xprt->xpt_local, rqstp->rq_xprt->xpt_locallen); ... ) When xpt_locallen exceeds xpt_remotelen, __assign_sockaddr's memcpy writes past the reserved ring-buffer slot. In the reverse direction (xpt_locallen < xpt_remotelen) the slot is oversized and the unwritten tail leaks prior ring-buffer contents to trace consumers. The write-past-end case is reachable on NFS/UDP. svc_xprt_set_remote() is only called from svc_tcp_accept() (net/sunrpc/svcsock.c) and from the RDMA connect path; svc_create_socket() for UDP calls only svc_xprt_set_local(), so xpt_remotelen stays 0 for the xprt's lifetime. Every fh_verify trace for an NFSv2/v3-over-UDP request then copies 16 or 28 bytes from xpt_local into a zero-byte slot. The other NFSD tracepoints that record the server address (NFSD_TRACE_PROC_CALL_FIELDS, NFSD_TRACE_PROC_RES_FIELDS, SVC_RQST_ENDPOINT_FIELDS) already size the server slot by xpt_locallen; nfsd_fh_verify and nfsd_fh_verify_err were the only exceptions. Fix by sizing the server slot with xpt_locallen so the declared slot matches the copy length. The client slot and its assignment already agree on xpt_remotelen and are left untouched.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: size fh_verify server sockaddr slot by xpt_locallen\n\nThe nfsd_fh_verify and nfsd_fh_verify_err tracepoints declare the\nserver sockaddr slot sized by xpt_remotelen but fill it from\nxpt_local using xpt_locallen:\n\n TP_STRUCT__entry(\n ...\n __sockaddr(server, rqstp->rq_xprt->xpt_remotelen)\n ...\n )\n TP_fast_assign(\n ...\n __assign_sockaddr(server, &rqstp->rq_xprt->xpt_local,\n rqstp->rq_xprt->xpt_locallen);\n ...\n )\n\nWhen xpt_locallen exceeds xpt_remotelen, __assign_sockaddr's memcpy\nwrites past the reserved ring-buffer slot. In the reverse direction\n(xpt_locallen < xpt_remotelen) the slot is oversized and the\nunwritten tail leaks prior ring-buffer contents to trace consumers.\n\nThe write-past-end case is reachable on NFS/UDP. svc_xprt_set_remote()\nis only called from svc_tcp_accept() (net/sunrpc/svcsock.c) and from\nthe RDMA connect path; svc_create_socket() for UDP calls only\nsvc_xprt_set_local(), so xpt_remotelen stays 0 for the xprt's\nlifetime. Every fh_verify trace for an NFSv2/v3-over-UDP request\nthen copies 16 or 28 bytes from xpt_local into a zero-byte slot.\n\nThe other NFSD tracepoints that record the server address\n(NFSD_TRACE_PROC_CALL_FIELDS, NFSD_TRACE_PROC_RES_FIELDS,\nSVC_RQST_ENDPOINT_FIELDS) already size the server slot by\nxpt_locallen; nfsd_fh_verify and nfsd_fh_verify_err were the only\nexceptions.\n\nFix by sizing the server slot with xpt_locallen so the declared slot\nmatches the copy length. The client slot and its assignment already\nagree on xpt_remotelen and are left untouched.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00463, EPSS Percentile is 0.39128 |
debian: CVE-2026-89702 was patched at 2026-09-16
1222.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89713) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: NFSD: check truncate permission under inode lock nfsd_setattr() checks whether a size update needs NFSD_MAY_TRUNC before it takes inode_lock(). The comparison uses the file size sampled by that unlocked read, but the actual ATTR_SIZE update is applied later under inode_lock() by notify_change(). This leaves a TOCTOU window for append-only files. If a client sends a SETATTR that does not shrink the file at the time of the unlocked sample, a concurrent append can extend the file before nfsd_setattr() takes inode_lock(). notify_change() then applies a real truncation without the NFSD_MAY_TRUNC check that rejects IS_APPEND(inode). The VFS truncate syscall paths perform their own append-only checks before calling notify_change(), so NFSD must make this decision against the locked size it is about to change. Split the write-count acquisition from the truncation permission check. Keep get_write_access() before the locked setattr work, then recheck whether the requested size is below i_size_read(inode) after inode_lock() has been acquired and before notify_change(ATTR_SIZE). This also avoids the plain unlocked inode->i_size load.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: check truncate permission under inode lock\n\nnfsd_setattr() checks whether a size update needs NFSD_MAY_TRUNC\nbefore it takes inode_lock(). The comparison uses the file size sampled\nby that unlocked read, but the actual ATTR_SIZE update is applied later\nunder inode_lock() by notify_change().\n\nThis leaves a TOCTOU window for append-only files. If a client sends a\nSETATTR that does not shrink the file at the time of the unlocked\nsample, a concurrent append can extend the file before nfsd_setattr()\ntakes inode_lock(). notify_change() then applies a real truncation\nwithout the NFSD_MAY_TRUNC check that rejects IS_APPEND(inode). The VFS\ntruncate syscall paths perform their own append-only checks before\ncalling notify_change(), so NFSD must make this decision against the\nlocked size it is about to change.\n\nSplit the write-count acquisition from the truncation permission check.\nKeep get_write_access() before the locked setattr work, then recheck\nwhether the requested size is below i_size_read(inode) after inode_lock()\nhas been acquired and before notify_change(ATTR_SIZE). This also avoids\nthe plain unlocked inode->i_size load.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00603, EPSS Percentile is 0.4727 |
debian: CVE-2026-89713 was patched at 2026-09-16
1223.
Denial of Service - Elasticsearch (CVE-2026-56149) - Medium [315]
Description: Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted machine learning request that causes excessive memory consumption, which may render the affected node unavailable.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:elastic:elasticsearch (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 4.9. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.005, EPSS Percentile is 0.41602 |
redos: CVE-2026-56149 was patched at 2026-09-02
1224.
Denial of Service - Hostapd (CVE-2026-58374) - Medium [315]
Description: In hostapd before 2.12, a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) Multi-Link Operation (MLO) association request processing allows an unauthenticated attacker within wireless range to send a crafted management frame containing a malformed Multi-Link Element or Per-STA Profile subelement. In hostapd_process_ml_assoc_req() in src/ap/ieee802_11_eht.c, the received link_id field can be parsed as value 15, but the corresponding links[] storage only has valid entries for lower link IDs (0 through 14). This causes an out-of-bounds write / small memory corruption during association processing before the 4-way handshake. The attack does not require network credentials, prior authentication, or user interaction. The confirmed practical impact is
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:w1.fi:hostapd (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00294, EPSS Percentile is 0.22082 |
altlinux: CVE-2026-58374 was patched at 2026-08-31
1225.
Denial of Service - OpenEXR (CVE-2026-53532) - Medium [315]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | OpenEXR is an open source high-dynamic-range image file format and reference implementation widely used in computer graphics, visual effects, animation, and motion picture production. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.18238 |
debian: CVE-2026-53532 was patched at 2026-09-16
1226.
Denial of Service - OpenEXR (CVE-2026-59981) - Medium [315]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | OpenEXR is an open source high-dynamic-range image file format and reference implementation widely used in computer graphics, visual effects, animation, and motion picture production. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00252, EPSS Percentile is 0.16817 |
debian: CVE-2026-59981 was patched at 2026-09-16
1227.
Denial of Service - OpenEXR (CVE-2026-68516) - Medium [315]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | OpenEXR is an open source high-dynamic-range image file format and reference implementation widely used in computer graphics, visual effects, animation, and motion picture production. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.1618 |
debian: CVE-2026-68516 was patched at 2026-09-16
1228.
Path Traversal - OpenTelemetry (CVE-2026-47256) - Medium [315]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | OpenTelemetry is a collection of APIs, SDKs, and tools. Use it to instrument, generate, collect, and export telemetry data (metrics, logs and traces) to help you analyze your software's performance and behavior | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00416, EPSS Percentile is 0.35358 |
debian: CVE-2026-47256 was patched at 2026-09-16
1229.
Security Feature Bypass - TLS (CVE-2026-63336) - Medium [315]
Description: The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.ConnectionFactory.useSslProtocol() and ConnectionFactory.useSslProtocol(String) configure com.rabbitmq.client.TrustEverythingTrustManager and leave hostname verification disabled, causing arbitrary server certificates, including self-signed certificates, to be accepted. A network attacker able to intercept a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | TLS | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00182, EPSS Percentile is 0.08 |
debian: CVE-2026-63336 was patched at 2026-08-20
1230.
Security Feature Bypass - undici (CVE-2026-18540) - Medium [315]
Description: undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response's status and headers. This happens when an upstream server delivers part of a body without a trustworthy resume checkpoint, for example a non-success response whose headers were already sent or a partial-content response with an unusable content range, then closes the connection and answers the resumed range request with more bytes. As a result the response body can be longer than the Content-Length that the application observes. An application that relays such a response to a downstream HTTP/1.1 peer without normalizing the framing can emit a body that exceeds the forwarded Content-Length, and the excess bytes can be interpreted as the start of a following response, which enables downstream response splitting or desynchronization. Exploitation requires an attacker-controlled upstream server and an application that forwards the response through a framing-sensitive path. This affects undici versions before 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:nodejs:undici (exists in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00239, EPSS Percentile is 0.15138 |
debian: CVE-2026-18540 was patched at 2026-09-16
1231.
Security Feature Bypass - undici (CVE-2026-84947) - Medium [315]
Description: undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares a Content-Length that exceeds the maximum, the interceptor aborts cleanly, but when a response has no Content-Length and is chunked, the interceptor instead signals completion early once the accumulated size reaches the maximum, without pausing or aborting the request. Because the underlying parser keeps delivering body bytes, a second completion signal fires and trips an internal assertion, which aborts the request and tears down the connection. The application is left observing a misleading successful status with an empty or truncated body while the connection has actually been disconnected. This affects undici versions from 7.1.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:nodejs:undici (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00196, EPSS Percentile is 0.09607 |
debian: CVE-2026-84947 was patched at 2026-09-16
1232.
Information Disclosure - GIMP (CVE-2026-78475) - Medium [314]
Description: A flaw was found in the file-pix (ESM) plugin in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | GIMP is an open-source image manipulation program used for photo editing, graphic design, and digital art creation. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00184, EPSS Percentile is 0.08185 |
debian: CVE-2026-78475 was patched at 2026-08-25
1233.
Information Disclosure - GIMP (CVE-2026-82324) - Medium [314]
Description: A flaw was found in the file-iff (IFF/ILBM) plugin in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | GIMP is an open-source image manipulation program used for photo editing, graphic design, and digital art creation. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00185, EPSS Percentile is 0.08342 |
debian: CVE-2026-82324 was patched at 2026-09-16
1234.
Information Disclosure - GIMP (CVE-2026-82328) - Medium [314]
Description: A flaw was found in the file-ico plugin in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | GIMP is an open-source image manipulation program used for photo editing, graphic design, and digital art creation. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00184, EPSS Percentile is 0.08185 |
debian: CVE-2026-82328 was patched at 2026-09-16
1235.
Information Disclosure - GIMP (CVE-2026-82343) - Medium [314]
Description: A flaw was found in the file-psd plugin in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | GIMP is an open-source image manipulation program used for photo editing, graphic design, and digital art creation. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00183, EPSS Percentile is 0.08122 |
debian: CVE-2026-82343 was patched at 2026-09-16
1236.
Information Disclosure - NVIDIA GPU Display Driver (CVE-2026-24198) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | A NVIDIA driver is a software program that enables communication between your computer and the NVIDIA graphics processor installed in your system | |
| 0.6 | 10 | CVSS Base Score is 5.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.05089 |
redos: CVE-2026-24198 was patched at 2026-09-08
1237.
Information Disclosure - TLS (CVE-2026-91992) - Medium [314]
Description: Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | TLS | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00206, EPSS Percentile is 0.1086 |
debian: CVE-2026-91992 was patched at 2026-09-16
1238.
Denial of Service - Envoy (CVE-2026-48521) - Medium [313]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-48521 was patched at 2026-08-28, 2026-08-31
1239.
Denial of Service - Oracle VM VirtualBox (CVE-2026-71125) - Medium [313]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.02244 |
altlinux: CVE-2026-71125 was patched at 2026-08-21
1240.
Denial of Service - qs (CVE-2026-82562) - Medium [313]
Description: ### Summary When `
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | qs is a popular JavaScript library for parsing and serializing URL query strings. It supports nested objects, arrays, custom parsing options, and is widely used in Node.js frameworks and middleware to handle HTTP query parameters and form-encoded data. | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00317, EPSS Percentile is 0.24663 |
debian: CVE-2026-82562 was patched at 2026-09-16
1241.
Elevation of Privilege - GVfs (CVE-2026-88924) - Medium [313]
Description: A flaw was found in the admin backend of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.4 | 14 | GVfs (GNOME Virtual File System) is userspace virtual filesystem software for GNOME that provides backends (including FTP) to access different remote and local file systems transparently. | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00171, EPSS Percentile is 0.06824 |
altlinux: CVE-2026-88924 was patched at 2026-09-12
debian: CVE-2026-88924 was patched at 2026-09-16
1242.
Spoofing - Mozilla Firefox (CVE-2026-92051) - Medium [311]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.03879 |
altlinux: CVE-2026-92051 was patched at 2026-09-16
1243.
Memory Corruption - Linux Kernel (CVE-2025-39729) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00143, EPSS Percentile is 0.03991 |
oraclelinux: CVE-2025-39729 was patched at 2026-09-04
1244.
Cross Site Scripting - DOMPurify (CVE-2026-75838) - Medium [309]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.003, EPSS Percentile is 0.22703 |
debian: CVE-2026-75838 was patched at 2026-08-20
1245.
Cross Site Scripting - Znuny (CVE-2026-77506) - Medium [309]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Znuny/Znuny LTS is a fork of the ((OTRS)) Community Edition, one of the most flexible web-based ticketing systems used for Customer Service, Help Desk, IT Service Management | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00254, EPSS Percentile is 0.17069 |
debian: CVE-2026-77506 was patched at 2026-08-25
1246.
Remote Code Execution - Unknown Product (CVE-2026-42007) - Medium [309]
Description: {'nvd_cve_data_all': 'An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00288, EPSS Percentile is 0.21457 |
debian: CVE-2026-42007 was patched at 2026-09-16
1247.
Remote Code Execution - Unknown Product (CVE-2026-80186) - Medium [309]
Description: {'nvd_cve_data_all': 'A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00406, EPSS Percentile is 0.34418 |
debian: CVE-2026-80186 was patched at 2026-09-16
1248.
Authentication Bypass - JOSE (CVE-2026-75509) - Medium [308]
Description: joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.3 | 14 | JavaScript module for JSON Object Signing and Encryption (JOSE) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00091, EPSS Percentile is 0.00551 |
debian: CVE-2026-75509 was patched at 2026-09-16
1249.
Denial of Service - MongoDB (CVE-2026-18702) - Medium [308]
Description: An issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.6 | 10 | CVSS Base Score is 6.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00209, EPSS Percentile is 0.11292 |
altlinux: CVE-2026-18702 was patched at 2026-08-26
1250.
Denial of Service - MongoDB (CVE-2026-82056) - Medium [308]
Description: A race condition in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00245, EPSS Percentile is 0.15854 |
altlinux: CVE-2026-82056 was patched at 2026-09-09, 2026-09-10
1251.
Denial of Service - MongoDB (CVE-2026-82063) - Medium [308]
Description: A use-after-free security issue in the cursor management component of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.17216 |
altlinux: CVE-2026-82063 was patched at 2026-09-09, 2026-09-10
1252.
Incorrect Calculation - FreeRDP (CVE-2026-63117) - Medium [308]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00389, EPSS Percentile is 0.32642 |
debian: CVE-2026-63117 was patched at 2026-08-25
redos: CVE-2026-63117 was patched at 2026-09-07
1253.
Memory Corruption - FreeRDP (CVE-2026-91947) - Medium [308]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.003, EPSS Percentile is 0.22697 |
debian: CVE-2026-91947 was patched at 2026-09-16
1254.
Memory Corruption - FreeRDP (CVE-2026-91956) - Medium [308]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00346, EPSS Percentile is 0.27988 |
debian: CVE-2026-91956 was patched at 2026-09-16
1255.
Memory Corruption - FreeRDP (CVE-2026-91959) - Medium [308]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00346, EPSS Percentile is 0.27989 |
debian: CVE-2026-91959 was patched at 2026-09-16
1256.
Memory Corruption - strongSwan (CVE-2026-78130) - Medium [308]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | strongSwan is an open source IPsec-based VPN solution that provides secure network connectivity using IKEv1 and IKEv2 protocols, widely used on Linux systems for site-to-site and remote access VPN deployments. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00315, EPSS Percentile is 0.2443 |
altlinux: CVE-2026-78130 was patched at 2026-09-11
debian: CVE-2026-78130 was patched at 2026-09-07, 2026-09-16
1257.
Path Traversal - Rclone (CVE-2026-88046) - Medium [308]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.6 | 14 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers, supporting over 40 cloud storage products including S3, Google Drive, Dropbox, OneDrive, and many more. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00294, EPSS Percentile is 0.22083 |
debian: CVE-2026-88046 was patched at 2026-09-16
1258.
Information Disclosure - Rclone (CVE-2026-79780) - Medium [307]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers, supporting over 40 cloud storage products including S3, Google Drive, Dropbox, OneDrive, and many more. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00095, EPSS Percentile is 0.00764 |
debian: CVE-2026-79780 was patched at 2026-09-16
1259.
Information Disclosure - Rclone (CVE-2026-88013) - Medium [307]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers, supporting over 40 cloud storage products including S3, Google Drive, Dropbox, OneDrive, and many more. | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00182, EPSS Percentile is 0.08041 |
debian: CVE-2026-88013 was patched at 2026-09-16
1260.
Remote Code Execution - libtiff (CVE-2026-52491) - Medium [307]
Description: An issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.2 | 14 | libtiff is a widely used library for reading and writing TIFF (Tagged Image File Format) files, offering tools like tiff2ps. | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0014, EPSS Percentile is 0.03755 |
debian: CVE-2026-52491 was patched at 2026-09-16
1261.
Denial of Service - Chromium (CVE-2026-84358) - Medium [305]
Description: Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.03291 |
altlinux: CVE-2026-84358 was patched at 2026-09-03
debian: CVE-2026-84358 was patched at 2026-09-03, 2026-09-16
1262.
Memory Corruption - CUPS (CVE-2026-87875) - Medium [305]
Description: The cupsUTF32ToUTF8() function in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | CUPS is a modular printing system for Unix-like computer operating systems which allows a computer to act as a print server | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00324, EPSS Percentile is 0.25532 |
debian: CVE-2026-87875 was patched at 2026-09-16
1263.
Memory Corruption - Chromium (CVE-2026-87640) - Medium [305]
Description: Out of bounds read in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10711 |
altlinux: CVE-2026-87640 was patched at 2026-09-17
debian: CVE-2026-87640 was patched at 2026-09-16
1264.
Memory Corruption - Chromium (CVE-2026-91726) - Medium [305]
Description: Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00239, EPSS Percentile is 0.15113 |
altlinux: CVE-2026-91726 was patched at 2026-09-17
debian: CVE-2026-91726 was patched at 2026-09-16
1265.
Path Traversal - gitoxide (CVE-2026-82251) - Medium [305]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.3 | 14 | gitoxide is an idiomatic, lean, fast & safe pure Rust implementation of Git, designed for correctness and performance, available both as a Rust library (gix crate) and command-line interface tools. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00387, EPSS Percentile is 0.32479 |
debian: CVE-2026-82251 was patched at 2026-09-16
1266.
Command Injection - Unknown Product (CVE-2023-54397) - Medium [304]
Description: {'nvd_cve_data_all': 'Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed behind certain proxies.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed behind certain proxies.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00367, EPSS Percentile is 0.30294 |
debian: CVE-2023-54397 was patched at 2026-09-16
1267.
Command Injection - Unknown Product (CVE-2024-14029) - Medium [304]
Description: {'nvd_cve_data_all': 'Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00351, EPSS Percentile is 0.28603 |
debian: CVE-2024-14029 was patched at 2026-09-16
1268.
Command Injection - Unknown Product (CVE-2026-66357) - Medium [304]
Description: {'nvd_cve_data_all': 'httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Every CRLF followed by a non-CRLF octet unconditionally starts a new header. This missing feature became a security concern as the understanding of HTTP request smuggling attacks evolved. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Every CRLF followed by a non-CRLF octet unconditionally starts a new header. This missing feature became a security concern as the understanding of HTTP request smuggling attacks evolved.\n\nThis issue affects OTP from OTP\xa017.0 before OTP\xa027.3.4.17, from OTP\xa028.0 before OTP\xa028.5.0.6, and from OTP\xa029.0 before OTP\xa029.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP\xa017.0, corresponding to inets before 5.10, is affected is unknown.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00328, EPSS Percentile is 0.25886 |
debian: CVE-2026-66357 was patched at 2026-09-16
1269.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-72465) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Sanitize the reply credit grant after parsing The out_norqst exit in rpcrdma_reply_handler() branches away before the credit clamp, so a reply that matches no pending request reaches out_post carrying the raw credit value parsed from the wire. rpcrdma_post_recvs() does not bound its @needed argument: the refill loop allocates and chains Receive WRs until the count is satisfied or allocation fails. A peer that sends a well-formed reply carrying an unknown XID and an inflated credit grant therefore drives rep allocation and Receive posting past re_max_requests on every such reply. Move the clamp to immediately after the credit field is parsed, ahead of the first branch that can reach out_post, so every later consumer sees a sanitized value. The cwnd update stays on the matched-request path.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: Sanitize the reply credit grant after parsing\n\nThe out_norqst exit in rpcrdma_reply_handler() branches away before\nthe credit clamp, so a reply that matches no pending request reaches\nout_post carrying the raw credit value parsed from the wire.\nrpcrdma_post_recvs() does not bound its @needed argument: the refill\nloop allocates and chains Receive WRs until the count is satisfied or\nallocation fails. A peer that sends a well-formed reply carrying an\nunknown XID and an inflated credit grant therefore drives rep\nallocation and Receive posting past re_max_requests on every such\nreply.\n\nMove the clamp to immediately after the credit field is parsed,\nahead of the first branch that can reach out_post, so every later\nconsumer sees a sanitized value. The cwnd update stays on the\nmatched-request path.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00647, EPSS Percentile is 0.49309 |
oraclelinux: CVE-2026-72465 was patched at 2026-09-04
1270.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74723) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: btrfs: lzo: reject inline extents without valid headers [BUG] For a crafted btrfs image, the following KASAN can be triggered when reading an inline lzo compressed file extent: BUG: KASAN: slab-out-of-bounds in lzo_decompress+0x57d/0x700 Read of size 4 at addr ffff888006f2e644 by task btrfs_lzo_inlin/77 Call Trace: <TASK> dump_stack_lvl+0x5b/0x70 print_report+0xd1/0x610 kasan_report+0xe0/0x110 __asan_report_load_n_noabort+0x13/0x20 lzo_decompress+0x57d/0x700 btrfs_decompress+0x140/0x1c0 uncompress_inline+0x147/0x1b0 btrfs_get_extent+0xb23/0x10a0 btrfs_do_readpage.constprop.0+0x538/0x1ac0 btrfs_readahead+0x32f/0x5f0 read_pages+0x16f/0x850 page_cache_ra_unbounded+0x296/0x490 do_page_cache_ra+0xd9/0x130 page_cache_sync_ra+0x3ee/0x6f0 filemap_get_pages+0x306/0x15c0 filemap_read+0x329/0xd00 btrfs_file_read_iter+0x1f8/0x2b0 vfs_read+0x4ef/0x720 ksys_read+0xf8/0x1d0 __x64_sys_read+0x71/0xb0 x64_sys_call+0x1ab0/0x1b70 do_syscall_64+0x61/0x470 entry_SYSCALL_64_after_hwframe+0x4b/0x53 </TASK> [CAUSE] For an inline lzo compressed file extent, there should always be one lzo header, recording the total length of the compressed data, followed by one segment header, recording the compressed lzo payload. But if a crafted inline lzo compressed file extent contains only an lzo header, without the segment header or payload, lzo_decompress() will still try to read the segment header, causing a read beyond the item boundary. Furthermore if the inline lzo compressed file extent is the first item of the leaf, it will be at the extent buffer boundary. The above out-of-boundary read will go beyond the extent buffer boundary, triggering the above KASAN report. [FIX] Validate the total length of the inlined lzo compressed file extent, to make sure there is at least one LZO header and one segment header, and a non-zero payload. [ Rework the commit message to remove slop ]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: lzo: reject inline extents without valid headers\n\n[BUG]\nFor a crafted btrfs image, the following KASAN can be triggered when\nreading an inline lzo compressed file extent:\n\n BUG: KASAN: slab-out-of-bounds in lzo_decompress+0x57d/0x700\n Read of size 4 at addr ffff888006f2e644 by task btrfs_lzo_inlin/77\n\n Call Trace:\n <TASK>\n dump_stack_lvl+0x5b/0x70\n print_report+0xd1/0x610\n kasan_report+0xe0/0x110\n __asan_report_load_n_noabort+0x13/0x20\n lzo_decompress+0x57d/0x700\n btrfs_decompress+0x140/0x1c0\n uncompress_inline+0x147/0x1b0\n btrfs_get_extent+0xb23/0x10a0\n btrfs_do_readpage.constprop.0+0x538/0x1ac0\n btrfs_readahead+0x32f/0x5f0\n read_pages+0x16f/0x850\n page_cache_ra_unbounded+0x296/0x490\n do_page_cache_ra+0xd9/0x130\n page_cache_sync_ra+0x3ee/0x6f0\n filemap_get_pages+0x306/0x15c0\n filemap_read+0x329/0xd00\n btrfs_file_read_iter+0x1f8/0x2b0\n vfs_read+0x4ef/0x720\n ksys_read+0xf8/0x1d0\n __x64_sys_read+0x71/0xb0\n x64_sys_call+0x1ab0/0x1b70\n do_syscall_64+0x61/0x470\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n </TASK>\n\n[CAUSE]\nFor an inline lzo compressed file extent, there should always be one lzo\nheader, recording the total length of the compressed data, followed by\none segment header, recording the compressed lzo payload.\n\nBut if a crafted inline lzo compressed file extent contains only an lzo\nheader, without the segment header or payload, lzo_decompress() will\nstill try to read the segment header, causing a read beyond the item\nboundary.\n\nFurthermore if the inline lzo compressed file extent is the first item\nof the leaf, it will be at the extent buffer boundary. The above\nout-of-boundary read will go beyond the extent buffer boundary,\ntriggering the above KASAN report.\n\n[FIX]\nValidate the total length of the inlined lzo compressed file extent, to\nmake sure there is at least one LZO header and one segment header, and a\nnon-zero payload.\n\n[ Rework the commit message to remove slop ]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0038, EPSS Percentile is 0.31634 |
debian: CVE-2026-74723 was patched at 2026-08-25
1271.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80586) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mptcp: options: reset DSS fields in case of unexpected size A remote peer could send a malformed DSS with a wrong size, followed by another DSS or MPC + Data. In this case, the first suboption will be ignored, but leaving some fields written, which could lead to inconsistency or access uninitialized data. Explicitly reset the fields that could have been modified in case of unexpected size.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: options: reset DSS fields in case of unexpected size\n\nA remote peer could send a malformed DSS with a wrong size, followed by\nanother DSS or MPC + Data. In this case, the first suboption will be\nignored, but leaving some fields written, which could lead to\ninconsistency or access uninitialized data.\n\nExplicitly reset the fields that could have been modified in case of\nunexpected size.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00404, EPSS Percentile is 0.34213 |
debian: CVE-2026-80586 was patched at 2026-09-16
oraclelinux: CVE-2026-80586 was patched at 2026-09-04
1272.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80587) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboptions Some MPTCP suboptions are mutually exclusive according to the RFC8684, but also because in different places, the code doesn't expect some combinations to be present. That's specially true for suboptions that would be present twice, but with different attributes. The new restrictions are the same as the ones applied on the output side, with mptcp_write_options. The same rules can be reused with a small fix: an MP_FASTCLOSE can be used with a DSS when the sender picks this option [1], which is not the case on Linux. Here are the rules: Which options can be used together? X: mutually exclusive O: often used together C: can be used together in some cases P: could be used together but we prefer not to (optimisations) | Opt: | MPC | MPJ | DSS | ADD | RM | PRIO | FAIL | FC | |------|------|------|------|------|------|------|------|------| | MPC |------|------|------|------|------|------|------|------| | MPJ | X |------|------|------|------|------|------|------| | DSS | X | X |------|------|------|------|------|------| | ADD | X | X | P |------|------|------|------|------| | RM | C | C | C | P |------|------|------|------| | PRIO | X | C | C | C | C |------|------|------| | FAIL | X | X | C | X | X | X |------|------| | FC | X | X | P | X | X | X | X |------| | RST | X | X | X | X | X | X | O | O | |------|------|------|------|------|------|------|------|------| The only difference is with the 'P': another stack could send and ADD_ADDR with other suboptions (DSS, RM_ADDR), and this should be allowed. A few points of attention: - In theory, an MP_CAPABLE could be used with a RM_ADDR, but there is no reason to add it with a SYN. Note that even with a 4th ACK, it doesn't seem to be useful, except when IDs are known in advance via another channel. Better not to break that. - Now, combining both an MP_CAPABLE and an MP_JOIN will no longer result to a reject of the two options, but only the second suboption is ignored. That seems OK to do that for this unexpected error. At least now all inconsistent combinations are handled the same way. This could change later in next. This also means the explicit checks for having both MPC + MPJ in subflow.c will now be unreachable. That's fine, they will be removed in a follow-up patch. - In case of conflicting combinations, the extra suboption(s) is/are ignored: having such combinations either means the remote peer is buggy, or is evil. The simplest action is then taken in this case: stop processing the current suboption. - In mp_opt->suboptions, there is also a bit reserved to the checksum, which can be used in an MP_CAPABLE and a DSS. Each time a DSS option can be used in parallel with another option, the checksum can be set, so the verification is combined into a new OPTIONS_MPTCP_DSS macro. - An MP_CAPABLE ACK can carry a Data-Level Length, and an optional Checksum: they are the same as the ones found in a DSS, because a DSS cannot be used in parallel to an MP_CAPABLE. Similarly, even if there is room, a DSS cannot be used with an MP_JOIN.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: avoid combining some incoming suboptions\n\nSome MPTCP suboptions are mutually exclusive according to the RFC8684,\nbut also because in different places, the code doesn't expect some\ncombinations to be present. That's specially true for suboptions that\nwould be present twice, but with different attributes.\n\nThe new restrictions are the same as the ones applied on the output\nside, with mptcp_write_options. The same rules can be reused with a\nsmall fix: an MP_FASTCLOSE can be used with a DSS when the sender picks\nthis option [1], which is not the case on Linux. Here are the rules:\n\n Which options can be used together?\n\n X: mutually exclusive\n O: often used together\n C: can be used together in some cases\n P: could be used together but we prefer not to (optimisations)\n\n | Opt: | MPC | MPJ | DSS | ADD | RM | PRIO | FAIL | FC |\n |------|------|------|------|------|------|------|------|------|\n | MPC |------|------|------|------|------|------|------|------|\n | MPJ | X |------|------|------|------|------|------|------|\n | DSS | X | X |------|------|------|------|------|------|\n | ADD | X | X | P |------|------|------|------|------|\n | RM | C | C | C | P |------|------|------|------|\n | PRIO | X | C | C | C | C |------|------|------|\n | FAIL | X | X | C | X | X | X |------|------|\n | FC | X | X | P | X | X | X | X |------|\n | RST | X | X | X | X | X | X | O | O |\n |------|------|------|------|------|------|------|------|------|\n\nThe only difference is with the 'P': another stack could send and\nADD_ADDR with other suboptions (DSS, RM_ADDR), and this should be\nallowed.\n\nA few points of attention:\n\n - In theory, an MP_CAPABLE could be used with a RM_ADDR, but there is\n no reason to add it with a SYN. Note that even with a 4th ACK, it\n doesn't seem to be useful, except when IDs are known in advance via\n another channel. Better not to break that.\n\n - Now, combining both an MP_CAPABLE and an MP_JOIN will no longer\n result to a reject of the two options, but only the second suboption\n is ignored. That seems OK to do that for this unexpected error. At\n least now all inconsistent combinations are handled the same way.\n This could change later in next. This also means the explicit checks\n for having both MPC + MPJ in subflow.c will now be unreachable.\n That's fine, they will be removed in a follow-up patch.\n\n - In case of conflicting combinations, the extra suboption(s) is/are\n ignored: having such combinations either means the remote peer is\n buggy, or is evil. The simplest action is then taken in this case:\n stop processing the current suboption.\n\n - In mp_opt->suboptions, there is also a bit reserved to the checksum,\n which can be used in an MP_CAPABLE and a DSS. Each time a DSS option\n can be used in parallel with another option, the checksum can be set,\n so the verification is combined into a new OPTIONS_MPTCP_DSS macro.\n\n - An MP_CAPABLE ACK can carry a Data-Level Length, and an optional\n Checksum: they are the same as the ones found in a DSS, because a DSS\n cannot be used in parallel to an MP_CAPABLE. Similarly, even if there\n is room, a DSS cannot be used with an MP_JOIN.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00386, EPSS Percentile is 0.32308 |
debian: CVE-2026-80587 was patched at 2026-09-16
1273.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80634) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag The DEV_PATH_BR_VLAN_UNTAG case post-decrements info->num_encaps inside WARN_ON_ONCE(). num_encaps is u8, so if it's already 0 the decrement still happens and wraps it to 255. The break only leaves the inner switch -- a later path entry can set info->indev back to a real device, and we end up returning with num_encaps == 255. nft_dev_forward_path() then walks info.encap[] (size 2) up to num_encaps, which means an OOB stack read and a bogus count copied into the route descriptor. Should only happen on a malformed bridge path stack, hence the WARN, but worth handling sanely. Move the decrement out of the WARN. [ While at this, remove the WARN_ON_ONCE since this can only happen with a buggy bridge path stack --pablo ].', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag\n\nThe DEV_PATH_BR_VLAN_UNTAG case post-decrements info->num_encaps\ninside WARN_ON_ONCE(). num_encaps is u8, so if it's already 0 the\ndecrement still happens and wraps it to 255. The break only leaves\nthe inner switch -- a later path entry can set info->indev back to\na real device, and we end up returning with num_encaps == 255.\n\nnft_dev_forward_path() then walks info.encap[] (size 2) up to\nnum_encaps, which means an OOB stack read and a bogus count copied\ninto the route descriptor.\n\nShould only happen on a malformed bridge path stack, hence the WARN,\nbut worth handling sanely. Move the decrement out of the WARN.\n\n[ While at this, remove the WARN_ON_ONCE since this can only happen\n with a buggy bridge path stack --pablo ].', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00379, EPSS Percentile is 0.31593 |
debian: CVE-2026-80634 was patched at 2026-09-16
1274.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80668) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use conntrack GC to reap expectations This patch replaces the timer API by GC worker approach for expectations, as it already happened in many other subsystems. Use the existing conntrack GC worker to iterate over the local list of expectations in the master conntrack to reap expired expectations. Check IPS_HELPER_BIT to run GC for expectations, set it on for nft_ct expectation which nevers sets it. Hold the expectation spinlock while iterating over the master conntrack expectation list to synchronize with nf_ct_remove_expectations(). This also performs runtime packet path garbage collection through the expectation insertion and lookup functions while walking over one of the chains of the global expectation hashtables. Unconfirmed conntrack entries are skipped since ct->ext can be reallocated and dying are skipped since those will be gone soon. Set on IPS_HELPER_BIT if the helper ct extension is added, then the new GC worker does not need to bump the ct refcount to check if the ct->ext helper is available. This removes the extra bump on the refcount for expectation timers, this allows to remove several nf_ct_expect_put() calls after the unlink, after this update only refcount remains at 1 while on the expectation hashes. This patch implicitly addresses a race with the existing timer API allowing an expectation to access a stale exp->master pointer which has been already released when expectation removal loses races with an expiring timer, ie. timer_del() reporting false. Add a new NF_CT_EXPECT_DEAD flag to reap this expectation via GC. This is needed by nf_conntrack_unexpect_related() which is called in error paths to invalidate newly created expectations that has been added into the hashes. These expectactions cannot be inmediately released as GC or nf_ct_remove_expectations() could race to make it. On expectation insert, the runtime GC reaps stale expectations before checking the expectation limit set by policy. Set current timestamp in nf_ct_expect_alloc(), then add the expectation policy timeout (or custom timeout specified added on top of this) to specify the expectation lifetime.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_expect: use conntrack GC to reap expectations\n\nThis patch replaces the timer API by GC worker approach for\nexpectations, as it already happened in many other subsystems.\n\nUse the existing conntrack GC worker to iterate over the local list of\nexpectations in the master conntrack to reap expired expectations.\nCheck IPS_HELPER_BIT to run GC for expectations, set it on for nft_ct\nexpectation which nevers sets it. Hold the expectation spinlock while\niterating over the master conntrack expectation list to synchronize with\nnf_ct_remove_expectations(). This also performs runtime packet path\ngarbage collection through the expectation insertion and lookup\nfunctions while walking over one of the chains of the global expectation\nhashtables. Unconfirmed conntrack entries are skipped since ct->ext can\nbe reallocated and dying are skipped since those will be gone soon.\nSet on IPS_HELPER_BIT if the helper ct extension is added, then the new\nGC worker does not need to bump the ct refcount to check if the ct->ext\nhelper is available.\n\nThis removes the extra bump on the refcount for expectation timers, this\nallows to remove several nf_ct_expect_put() calls after the unlink,\nafter this update only refcount remains at 1 while on the expectation\nhashes.\n\nThis patch implicitly addresses a race with the existing timer API\nallowing an expectation to access a stale exp->master pointer which has\nbeen already released when expectation removal loses races with an\nexpiring timer, ie. timer_del() reporting false.\n\nAdd a new NF_CT_EXPECT_DEAD flag to reap this expectation via GC. This\nis needed by nf_conntrack_unexpect_related() which is called in error\npaths to invalidate newly created expectations that has been added into\nthe hashes. These expectactions cannot be inmediately released as GC or\nnf_ct_remove_expectations() could race to make it. On expectation\ninsert, the runtime GC reaps stale expectations before checking the\nexpectation limit set by policy.\n\nSet current timestamp in nf_ct_expect_alloc(), then add the expectation\npolicy timeout (or custom timeout specified added on top of this) to\nspecify the expectation lifetime.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00379, EPSS Percentile is 0.31594 |
debian: CVE-2026-80668 was patched at 2026-09-16
1275.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80670) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: perf tools: Use perf_env__get_cpu_topology() in machine__resolve() machine__resolve() accesses env->cpu[al->cpu].socket_id after checking al->cpu >= 0 and env->cpu != NULL, but without validating al->cpu against env->nr_cpus_avail. Since al->cpu comes from the untrusted perf.data sample, a crafted file with a large CPU index causes an out-of-bounds heap read. Use perf_env__get_cpu_topology() which validates both NULL and bounds. Also bounds-check al->cpu before the cast to struct perf_cpu (int16_t): without this, values like 65536 silently truncate to 0, bypassing the accessor's internal check and returning CPU 0's topology.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nperf tools: Use perf_env__get_cpu_topology() in machine__resolve()\n\nmachine__resolve() accesses env->cpu[al->cpu].socket_id after checking\nal->cpu >= 0 and env->cpu != NULL, but without validating al->cpu\nagainst env->nr_cpus_avail. Since al->cpu comes from the untrusted\nperf.data sample, a crafted file with a large CPU index causes an\nout-of-bounds heap read.\n\nUse perf_env__get_cpu_topology() which validates both NULL and bounds.\nAlso bounds-check al->cpu before the cast to struct perf_cpu (int16_t):\nwithout this, values like 65536 silently truncate to 0, bypassing the\naccessor's internal check and returning CPU 0's topology.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00475, EPSS Percentile is 0.39996 |
debian: CVE-2026-80670 was patched at 2026-09-16
1276.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80945) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - unmap dst before software fallback on decompress On a hardware analytics error, decompress retries through the software fallback, which writes req->dst with the CPU while it is still mapped DMA_FROM_DEVICE. With SWIOTLB active the later dma_unmap_sg() copies the stale bounce buffer over req->dst, corrupting the result. Unmap before the fallback runs. The async path unmaps inline; the sync path signals the retry with -EAGAIN so iaa_comp_adecompress() runs the fallback after unmapping.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: iaa - unmap dst before software fallback on decompress\n\nOn a hardware analytics error, decompress retries through the software\nfallback, which writes req->dst with the CPU while it is still mapped\nDMA_FROM_DEVICE. With SWIOTLB active the later dma_unmap_sg() copies the\nstale bounce buffer over req->dst, corrupting the result.\n\nUnmap before the fallback runs. The async path unmaps inline; the sync\npath signals the retry with -EAGAIN so iaa_comp_adecompress() runs the\nfallback after unmapping.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00471, EPSS Percentile is 0.39637 |
debian: CVE-2026-80945 was patched at 2026-09-16
1277.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80997) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: ipa: fix stalled modem TX queue after runtime resume ipa_start_xmit() unconditionally stops the TX queue before calling pm_runtime_get(), relying on the wake scheduled by runtime resume (ipa_modem_wake_queue_work()) to restart it once power is ACTIVE. But that work is queued from within the runtime resume callback, before the device's power state reaches RPM_ACTIVE, so it can run while the device is still RPM_RESUMING. The wake is then consumed too early: the transmit it restarts stops the queue again, pm_runtime_get() returns -EINPROGRESS without arranging any future wake (deferred_resume exists only for RPM_SUSPENDING), and after the resume completes nothing is left to wake the queue. Transmit stalls permanently: packets pile up in the qdisc behind the stopped queue, the device runtime-suspends, and since the netdev registers no ndo_tx_timeout the watchdog never fires. Observed on SM7635 (Fairphone 6) as the cellular data path going permanently deaf within hours, RX included, since nothing resumes the suspended endpoints. Close the window by making the wake work wait for the resume to complete (pm_runtime_get_sync()) before waking the queue. Every queue stop is then guaranteed a later wake that happens while power is ACTIVE; a transmit racing a new suspend/resume cycle re-schedules the work. If the device could not be resumed, wake the queue anyway so pending packets are dropped by the transmit path rather than stranded. The STARTED power flag used to narrow this window: a wake running before the transmit path's stop suppressed that stop, but only once, as the flag was cleared by the first stop it absorbed. Removing the flag made a single transmit during an in-flight resume sufficient to strand the queue, which is the form observed. With an accelerated reproducer (autosuspend delay shortened to 5 ms, ~20 packets/s of TX), an unpatched kernel stalled three times in 230 s / 4380 packets; with this patch the same test ran 3601 s / 70298 packets without a stall.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ipa: fix stalled modem TX queue after runtime resume\n\nipa_start_xmit() unconditionally stops the TX queue before calling\npm_runtime_get(), relying on the wake scheduled by runtime resume\n(ipa_modem_wake_queue_work()) to restart it once power is ACTIVE.\nBut that work is queued from within the runtime resume callback,\nbefore the device's power state reaches RPM_ACTIVE, so it can run\nwhile the device is still RPM_RESUMING. The wake is then consumed\ntoo early: the transmit it restarts stops the queue again,\npm_runtime_get() returns -EINPROGRESS without arranging any future\nwake (deferred_resume exists only for RPM_SUSPENDING), and after the\nresume completes nothing is left to wake the queue. Transmit stalls\npermanently: packets pile up in the qdisc behind the stopped queue,\nthe device runtime-suspends, and since the netdev registers no\nndo_tx_timeout the watchdog never fires. Observed on SM7635\n(Fairphone 6) as the cellular data path going permanently deaf\nwithin hours, RX included, since nothing resumes the suspended\nendpoints.\n\nClose the window by making the wake work wait for the resume to\ncomplete (pm_runtime_get_sync()) before waking the queue. Every\nqueue stop is then guaranteed a later wake that happens while power\nis ACTIVE; a transmit racing a new suspend/resume cycle re-schedules\nthe work. If the device could not be resumed, wake the queue anyway\nso pending packets are dropped by the transmit path rather than\nstranded.\n\nThe STARTED power flag used to narrow this window: a wake running\nbefore the transmit path's stop suppressed that stop, but only once,\nas the flag was cleared by the first stop it absorbed. Removing the\nflag made a single transmit during an in-flight resume sufficient to\nstrand the queue, which is the form observed.\n\nWith an accelerated reproducer (autosuspend delay shortened to 5 ms,\n~20 packets/s of TX), an unpatched kernel stalled three times in\n230 s / 4380 packets; with this patch the same test ran 3601 s /\n70298 packets without a stall.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00603, EPSS Percentile is 0.4727 |
debian: CVE-2026-80997 was patched at 2026-09-16
1278.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89476) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: sctp: fix stream->outcnt underflow on duplicate RECONF responses A cached RECONF chunk may contain more than one request parameter. A duplicate response can therefore find and process the same ADD_OUT request again while another parameter is still outstanding, rolling back outcnt twice and possibly underflowing it. Track outstanding request types as bits and clear each bit after its first response. Later responses for the same request are then ignored.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix stream->outcnt underflow on duplicate RECONF responses\n\nA cached RECONF chunk may contain more than one request parameter. A\nduplicate response can therefore find and process the same ADD_OUT request\nagain while another parameter is still outstanding, rolling back outcnt\ntwice and possibly underflowing it.\n\nTrack outstanding request types as bits and clear each bit after its first\nresponse. Later responses for the same request are then ignored.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00686, EPSS Percentile is 0.50945 |
debian: CVE-2026-89476 was patched at 2026-09-16
1279.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89537) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2 gss_krb5_verify_mic_v2() reads the token ID at ptr[0..1], the flags byte at ptr[2], and padding at ptr[3..7], then passes ptr + GSS_KRB5_TOK_HDR_LEN and cksum_len to gss_krb5_mic_build_sg(). None of these accesses check read_token->len first. The minimum safe token size is GSS_KRB5_TOK_HDR_LEN (16) plus ctx->krb5e->cksum_len (12-24, depending on the enctype). All callers accept shorter tokens from the wire: - gss_unwrap_resp_integ() enforces only an upper bound (offset + len <= rcv_buf->len) before allocating mic.data = kmalloc(len) and passing it to gss_verify_mic(). A malicious NFS server can therefore supply a short checksum opaque, producing a small slab allocation that the Kerberos MIC verifier reads past. - gss_validate() enforces only len <= RPC_MAX_AUTH_SIZE (400) before passing the wire-supplied length to gss_validate_seqno_mic(), which constructs a mic xdr_netobj and calls gss_verify_mic(). - svcauth_gss_verify_header() enforces only checksum.len >= XDR_UNIT (4 bytes) before dispatching to gss_verify_mic(). - svcauth_gss_unwrap_integ() checks only that the checksum fits in gsd->gsd_scratch. Add a length guard at the top of gss_krb5_verify_mic_v2(), before any ptr[] access or scatterlist construction. Well-formed MIC tokens from gss_krb5_get_mic_v2() already have exactly GSS_KRB5_TOK_HDR_LEN + cksum_len bytes, so valid traffic is unaffected.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2\n\ngss_krb5_verify_mic_v2() reads the token ID at ptr[0..1], the flags\nbyte at ptr[2], and padding at ptr[3..7], then passes\nptr + GSS_KRB5_TOK_HDR_LEN and cksum_len to gss_krb5_mic_build_sg().\nNone of these accesses check read_token->len first.\n\nThe minimum safe token size is GSS_KRB5_TOK_HDR_LEN (16) plus\nctx->krb5e->cksum_len (12-24, depending on the enctype). All callers\naccept shorter tokens from the wire:\n\n - gss_unwrap_resp_integ() enforces only an upper bound\n (offset + len <= rcv_buf->len) before allocating\n mic.data = kmalloc(len) and passing it to gss_verify_mic().\n A malicious NFS server can therefore supply a short checksum\n opaque, producing a small slab allocation that the Kerberos MIC\n verifier reads past.\n\n - gss_validate() enforces only len <= RPC_MAX_AUTH_SIZE (400)\n before passing the wire-supplied length to\n gss_validate_seqno_mic(), which constructs a mic xdr_netobj\n and calls gss_verify_mic().\n\n - svcauth_gss_verify_header() enforces only\n checksum.len >= XDR_UNIT (4 bytes) before dispatching to\n gss_verify_mic().\n\n - svcauth_gss_unwrap_integ() checks only that the checksum fits\n in gsd->gsd_scratch.\n\nAdd a length guard at the top of gss_krb5_verify_mic_v2(), before any\nptr[] access or scatterlist construction. Well-formed MIC tokens from\ngss_krb5_get_mic_v2() already have exactly GSS_KRB5_TOK_HDR_LEN +\ncksum_len bytes, so valid traffic is unaffected.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00516, EPSS Percentile is 0.42645 |
debian: CVE-2026-89537 was patched at 2026-09-16
1280.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89547) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Check svc pool percpu counter allocation __svc_create() initializes three per-pool percpu_counter stats and ignores every return value. On SMP, percpu_counter_init() fails when __alloc_percpu_gfp() cannot satisfy the allocation, leaving the failed counter with fbc->counters == NULL and its embedded raw_spinlock_t, list_head, and count never initialized. __svc_create() returns the half-constructed svc_serv to nfsd, lockd, or the NFS callback service anyway. Once that service is live, the hot-path increments in svc_xprt_enqueue(), svc_handle_xprt(), and svc_pool_wake_idle_thread() reach a counter whose backing pointer is NULL. The pointer is a per-cpu offset, so the access does not fault: it resolves to offset zero of the current CPU's per-cpu area and silently corrupts whatever variable lives there. A /proc/fs/nfsd/pool_stats read walks the same NULL per-cpu storage and returns garbage, and on CONFIG_DEBUG_SPINLOCK or lockdep it splats on the never-initialized lock. Creating the broken service requires a percpu allocation failure during RPC server startup, so it is reachable only by a local administrator under memory pressure or fault injection; a remote peer cannot induce the bad state on its own. Check each percpu_counter_init() return value in __svc_create() and fail when an allocation fails, unwinding the counters already set up in the current pool and in every pool initialized before it. A discrete percpu_counter_destroy() per counter at teardown frees each per-cpu allocation exactly once.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: Check svc pool percpu counter allocation\n\n__svc_create() initializes three per-pool percpu_counter stats and\nignores every return value. On SMP, percpu_counter_init() fails when\n__alloc_percpu_gfp() cannot satisfy the allocation, leaving the failed\ncounter with fbc->counters == NULL and its embedded raw_spinlock_t,\nlist_head, and count never initialized. __svc_create() returns the\nhalf-constructed svc_serv to nfsd, lockd, or the NFS callback service\nanyway.\n\nOnce that service is live, the hot-path increments in\nsvc_xprt_enqueue(), svc_handle_xprt(), and\nsvc_pool_wake_idle_thread() reach a counter whose backing pointer is\nNULL. The pointer is a per-cpu offset, so the access does not fault:\nit resolves to offset zero of the current CPU's per-cpu area and\nsilently corrupts whatever variable lives there. A\n/proc/fs/nfsd/pool_stats read walks the same NULL per-cpu storage and\nreturns garbage, and on CONFIG_DEBUG_SPINLOCK or lockdep it splats on\nthe never-initialized lock.\n\nCreating the broken service requires a percpu allocation failure during\nRPC server startup, so it is reachable only by a local administrator\nunder memory pressure or fault injection; a remote peer cannot induce\nthe bad state on its own.\n\nCheck each percpu_counter_init() return value in __svc_create() and\nfail when an allocation fails, unwinding the counters already set up\nin the current pool and in every pool initialized before it. A\ndiscrete percpu_counter_destroy() per counter at teardown frees each\nper-cpu allocation exactly once.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00568, EPSS Percentile is 0.45577 |
debian: CVE-2026-89547 was patched at 2026-09-16
1281.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89549) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: sunrpc: route to a populated pool in svc_pool_for_cpu() svc_set_num_threads() spreads the requested threads evenly across the service's pools (base = nrservs / sv_nrpools). When a service runs fewer threads than it has pools -- e.g. an nfsd configured with fewer threads than the host has NUMA nodes while running in "pernode" or "percpu" mode -- the trailing pools are left with no threads at all. svc_xprt_enqueue() selects a pool from the CPU servicing the transport, queues the transport on that pool's sp_xprts, and only wakes a thread from the same pool. Each thread services exclusively its own pool, so a transport that lands on a threadless pool is enqueued on sp_xprts and never picked up: the connection hangs indefinitely. Have svc_pool_for_cpu() skip pools that currently have no threads, falling back to the next populated pool. This trades NUMA locality for a guarantee that the work is actually serviced. sp_nrthreads is only updated under the service mutex; the lockless read here is a best-effort routing hint, so annotate it with data_race().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsunrpc: route to a populated pool in svc_pool_for_cpu()\n\nsvc_set_num_threads() spreads the requested threads evenly across the\nservice's pools (base = nrservs / sv_nrpools). When a service runs\nfewer threads than it has pools -- e.g. an nfsd configured with fewer\nthreads than the host has NUMA nodes while running in "pernode" or\n"percpu" mode -- the trailing pools are left with no threads at all.\n\nsvc_xprt_enqueue() selects a pool from the CPU servicing the transport,\nqueues the transport on that pool's sp_xprts, and only wakes a thread\nfrom the same pool. Each thread services exclusively its own pool, so a\ntransport that lands on a threadless pool is enqueued on sp_xprts and\nnever picked up: the connection hangs indefinitely.\n\nHave svc_pool_for_cpu() skip pools that currently have no threads,\nfalling back to the next populated pool. This trades NUMA locality for\na guarantee that the work is actually serviced. sp_nrthreads is only\nupdated under the service mutex; the lockless read here is a best-effort\nrouting hint, so annotate it with data_race().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00716, EPSS Percentile is 0.52057 |
debian: CVE-2026-89549 was patched at 2026-09-16
1282.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89554) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction mptcp_token_join_cookie_init_state() restores remote_nonce, local_nonce, backup, join_id, token and msk from the saved cookie entry when rebuilding the request socket for a MP_JOIN 4th-ACK handled under SYN cookies, but it does not restore local_id, even though the SYN path saved it. subflow_ulp_clone() then reads that uninitialized field and stores it as the joined subflow's address-ID. Because the request-sock slab is SLAB_TYPESAFE_BY_RCU and not zeroed on allocation, the value is the stale byte of a previously freed request socket, which an off-path peer can influence by sending concurrent MP_JOIN SYNs. This corrupts the path manager's id-based subflow bookkeeping for the connection. Restore subflow_req->local_id from the cookie entry, as done for the other fields.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction\n\nmptcp_token_join_cookie_init_state() restores remote_nonce, local_nonce,\nbackup, join_id, token and msk from the saved cookie entry when rebuilding\nthe request socket for a MP_JOIN 4th-ACK handled under SYN cookies, but it\ndoes not restore local_id, even though the SYN path saved it.\nsubflow_ulp_clone() then reads that uninitialized field and stores it as\nthe joined subflow's address-ID. Because the request-sock slab is\nSLAB_TYPESAFE_BY_RCU and not zeroed on allocation, the value is the stale\nbyte of a previously freed request socket, which an off-path peer can\ninfluence by sending concurrent MP_JOIN SYNs. This corrupts the path\nmanager's id-based subflow bookkeeping for the connection.\n\nRestore subflow_req->local_id from the cookie entry, as done for the other\nfields.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00606, EPSS Percentile is 0.47406 |
debian: CVE-2026-89554 was patched at 2026-09-16
1283.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89586) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes ata_scsi_write_same_xlat() translates a SCSI WRITE SAME command with the UNMAP bit set into an ATA DATA SET MANAGEMENT TRIM command. The TRIM descriptor is built by ata_format_dsm_trim_descr() into the 2048-byte ata_scsi_rbuf staging buffer, and the number of bytes copied is compared against the logical sector size by the caller: \tsize = ata_format_dsm_trim_descr(scmd, trmax, block, n_block); \tif (size != len)\t\t/* len == sdp->sector_size */ \t\tgoto invalid_param_len; ata_format_dsm_trim_descr() clamps the copy length to ATA_SCSI_RBUF_SIZE (2048). On a device whose logical sector size exceeds that (e.g. a 4Kn device, where sector_size == 4096) the function can never return more than 2048, while the caller expects it to return sector_size. The comparison therefore always fails, so every TRIM is rejected with "Parameter list length error" and WARN_ON() splats on each attempt. TRIM / discard is thus completely broken on such devices. The descriptor was incorrectly sized from the logical sector size. A DSM TRIM payload is a list of 512-byte pages, each holding up to ATA_MAX_TRIM_RNUM (64) LBA Range Entries, and is independent of the logical sector size. The Block Limits VPD page already advertises a single such page as the maximum WRITE SAME length (65535 * ATA_MAX_TRIM_RNUM logical blocks), so the block layer never sends a request that needs more than one page. Emit exactly one 512-byte page, independent of the logical sector size, and transfer only that page (COUNT == 1). For a 512-byte-sector device this is unchanged; devices with larger logical sectors now work instead of failing every TRIM.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes\n\nata_scsi_write_same_xlat() translates a SCSI WRITE SAME command with the\nUNMAP bit set into an ATA DATA SET MANAGEMENT TRIM command. The TRIM\ndescriptor is built by ata_format_dsm_trim_descr() into the 2048-byte\nata_scsi_rbuf staging buffer, and the number of bytes copied is compared\nagainst the logical sector size by the caller:\n\n\tsize = ata_format_dsm_trim_descr(scmd, trmax, block, n_block);\n\tif (size != len)\t\t/* len == sdp->sector_size */\n\t\tgoto invalid_param_len;\n\nata_format_dsm_trim_descr() clamps the copy length to ATA_SCSI_RBUF_SIZE\n(2048). On a device whose logical sector size exceeds that (e.g. a 4Kn\ndevice, where sector_size == 4096) the function can never return more than\n2048, while the caller expects it to return sector_size. The comparison\ntherefore always fails, so every TRIM is rejected with "Parameter list\nlength error" and WARN_ON() splats on each attempt. TRIM / discard is\nthus completely broken on such devices.\n\nThe descriptor was incorrectly sized from the logical sector size. A DSM\nTRIM payload is a list of 512-byte pages, each holding up to\nATA_MAX_TRIM_RNUM (64) LBA Range Entries, and is independent of the logical\nsector size. The Block Limits VPD page already advertises a single such\npage as the maximum WRITE SAME length (65535 * ATA_MAX_TRIM_RNUM logical\nblocks), so the block layer never sends a request that needs more than one\npage.\n\nEmit exactly one 512-byte page, independent of the logical sector size,\nand transfer only that page (COUNT == 1). For a 512-byte-sector device\nthis is unchanged; devices with larger logical sectors now work instead of\nfailing every TRIM.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00607, EPSS Percentile is 0.47419 |
debian: CVE-2026-89586 was patched at 2026-09-16
1284.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89611) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ntfs: validate non-resident attribute offsets ntfs_attr_update_meta() shifts the attribute name when converting between non-sparse and sparse attributes. Converting to sparse also adds the compressed_size field before the name and mapping pairs, requiring eight additional bytes in the attribute record. However, the validator does not check that name_offset is within safe boundaries for these operations or that the additional space is available. A malicious MFT record could set name_offset such that: 1. The name is positioned at the very end of a non-sparse attribute. Converting to sparse would shift the name forward by 8 bytes, writing beyond the attribute boundary. 2. The name overlaps with the mapping pairs, causing corruption during conversion. Add validation to ensure: - For named attributes, name_offset is within valid bounds - Name does not extend beyond the attribute or overlap with mapping pairs - For non-sparse, non-compressed attributes, eight bytes are available after mapping_pairs_offset for the compressed_size field The space check also covers unnamed attributes, for which name_offset = 0 is valid and no name range needs to be checked.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: validate non-resident attribute offsets\n\nntfs_attr_update_meta() shifts the attribute name when converting between\nnon-sparse and sparse attributes. Converting to sparse also adds the\ncompressed_size field before the name and mapping pairs, requiring eight\nadditional bytes in the attribute record.\n\nHowever, the validator does not check that name_offset is within safe\nboundaries for these operations or that the additional space is available.\nA malicious MFT record could set name_offset such that:\n\n1. The name is positioned at the very end of a non-sparse attribute.\n Converting to sparse would shift the name forward by 8 bytes,\n writing beyond the attribute boundary.\n\n2. The name overlaps with the mapping pairs, causing corruption during\n conversion.\n\nAdd validation to ensure:\n- For named attributes, name_offset is within valid bounds\n- Name does not extend beyond the attribute or overlap with mapping pairs\n- For non-sparse, non-compressed attributes, eight bytes are available\n after mapping_pairs_offset for the compressed_size field\n\nThe space check also covers unnamed attributes, for which name_offset = 0\nis valid and no name range needs to be checked.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00379, EPSS Percentile is 0.31594 |
debian: CVE-2026-89611 was patched at 2026-09-16
1285.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89631) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: smb: client: reject a tree connect response whose byte count is too small CIFSTCon() bounds its strnlen() over the byte area with the server's ByteCount minus two, which for ByteCount 0 or 1 goes negative as an int and converts to a huge size_t. The later subtraction wraps the __u16 bytes_left, and that is what bounds cifs_strndup_from_utf16(): a bound of up to 65535 against a ~16 KB cifs_req_poolp object runs off the end of the slab object, and the bytes reach userspace through tcon->nativeFileSystem in /proc/fs/cifs/DebugData. Reject a byte area too small for what the parser consumes. Two bytes is the least it can consume, and no conformant response carries fewer. The new trace point is the 129th smb_eio_trace entry, which __mode(byte) cannot represent, so the attribute goes with it.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: reject a tree connect response whose byte count is too small\n\nCIFSTCon() bounds its strnlen() over the byte area with the server's\nByteCount minus two, which for ByteCount 0 or 1 goes negative as an int\nand converts to a huge size_t. The later subtraction wraps the __u16\nbytes_left, and that is what bounds cifs_strndup_from_utf16(): a bound of\nup to 65535 against a ~16 KB cifs_req_poolp object runs off the end of the\nslab object, and the bytes reach userspace through tcon->nativeFileSystem\nin /proc/fs/cifs/DebugData.\n\nReject a byte area too small for what the parser consumes. Two bytes is\nthe least it can consume, and no conformant response carries fewer. The\nnew trace point is the 129th smb_eio_trace entry, which __mode(byte)\ncannot represent, so the attribute goes with it.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00448, EPSS Percentile is 0.38092 |
debian: CVE-2026-89631 was patched at 2026-09-16
1286.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89647) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ceph: do not repeat ceph_trim_dentries() if no progress possible ceph_cap_reclaim_work() re-queues itself for as long as ceph_trim_dentries() returns -EAGAIN, which happens whenever a lease walk exhausts its `nr_to_scan` budget. This creates a busy loop that consumes CPU without making any progress when there is nothing to reclaim: with no cap pressure (`count==0`) and every scanned lease still valid, each pass runs the full scan budget down to zero and returns `-EAGAIN`, only to be queued again immediately. The dir-lease walk made this worse. When `expire_dir_lease` is `false` (i.e. we have no intention of reclaiming dir leases), __dir_lease_check() returned `TOUCH` for every valid lease. `TOUCH` moves the dentry to the tail of the list and resets `di->time` via __dentry_dir_lease_touch(), so a walk over N valid leases pointlessly rewrote the list, refreshed the timestamps (preventing them from ever aging out) and always drained `nr_to_scan`, guaranteeing the `-EAGAIN` requeue. Fix this in three steps: - Return `KEEP` instead of `TOUCH` when `expire_dir_lease` is `false`. If we are not going to reclaim the lease, leave it in place instead of churning the list and resetting its timestamp; the walk then terminates naturally (or via `STOP` at the first fresh lease). - Only return `-EAGAIN` from the first (dentry-lease) walk when something was actually freed. A full batch that frees nothing means retrying the same list immediately is futile; fall through to the dir-lease walk instead. - After both walks, bail out with success (0) when nothing was freed and there is no cap pressure (`count==0`). There is no reason to keep retrying when we are not over the cap limit and made no progress. Under real cap pressure (`count>0`) the reclaim path is unchanged and still retries via `-EAGAIN`. Without this patch, I saw 500 ceph_trim_dentries() calls per second on our web servers. This is very visible in `/proc/lock_stat` (5 minute capture): class name con-bounces contentions waittime-min waittime-max waittime-total waittime-avg acq-bounces acquisitions holdtime-min holdtime-max holdtime-total holdtime-avg &mdsc->dentry_list_lock: 126180 128218 0.04 8063.44 15986965.20 124.69 1573354 5296812 0.04 8291.28 74164526.48 14.00 ----------------------- &mdsc->dentry_list_lock 111736 [<000000007b11e319>] __ceph_dentry_dir_lease_touch+0x7c/0xa8 &mdsc->dentry_list_lock 2631 [<0000000050597999>] __dentry_leases_walk+0x64/0x2c8 &mdsc->dentry_list_lock 3878 [<00000000c0022f62>] __ceph_dentry_lease_touch+0x5c/0xa8 &mdsc->dentry_list_lock 9973 [<000000002f27cb6f>] __dentry_lease_unlist+0x50/0xa0 ----------------------- &mdsc->dentry_list_lock 123621 [<0000000050597999>] __dentry_leases_walk+0x64/0x2c8 &mdsc->dentry_list_lock 1822 [<000000007b11e319>] __ceph_dentry_dir_lease_touch+0x7c/0xa8 &mdsc->dentry_list_lock 2720 [<000000002f27cb6f>] __dentry_lease_unlist+0x50/0xa0 &mdsc->dentry_list_lock 55 [<00000000c0022f62>] __ceph_dentry_lease_touch+0x5c/0xa8 With this patch: class name con-bounces contentions waittime-min waittime-max waittime-total waittime-avg acq-bounces acquisitions holdtime-min holdtime-max holdtime-total holdtime-avg &mdsc->dentry_list_lock: 1203 1215 0.16 408.88 33082.88 27.23 4320501 7357389 0.04 500.64 1961578.00 0.27 ----------------------- &mdsc->dentry_list_lock 1029 [<000000003c9aea8a>] __ceph_dentry_dir_lease_touch+0x7c/0xa8 &mdsc->dentry_list_lock 1 ---truncated---', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nceph: do not repeat ceph_trim_dentries() if no progress possible\n\nceph_cap_reclaim_work() re-queues itself for as long as\nceph_trim_dentries() returns -EAGAIN, which happens whenever a lease\nwalk exhausts its `nr_to_scan` budget. This creates a busy loop that\nconsumes CPU without making any progress when there is nothing to\nreclaim: with no cap pressure (`count==0`) and every scanned lease\nstill valid, each pass runs the full scan budget down to zero and\nreturns `-EAGAIN`, only to be queued again immediately.\n\nThe dir-lease walk made this worse. When `expire_dir_lease` is\n`false` (i.e. we have no intention of reclaiming dir leases),\n__dir_lease_check() returned `TOUCH` for every valid lease. `TOUCH`\nmoves the dentry to the tail of the list and resets `di->time` via\n__dentry_dir_lease_touch(), so a walk over N valid leases pointlessly\nrewrote the list, refreshed the timestamps (preventing them from ever\naging out) and always drained `nr_to_scan`, guaranteeing the `-EAGAIN`\nrequeue.\n\nFix this in three steps:\n\n - Return `KEEP` instead of `TOUCH` when `expire_dir_lease` is\n `false`. If we are not going to reclaim the lease, leave it in\n place instead of churning the list and resetting its timestamp; the\n walk then terminates naturally (or via `STOP` at the first fresh\n lease).\n\n - Only return `-EAGAIN` from the first (dentry-lease) walk when something\n was actually freed. A full batch that frees nothing means retrying\n the same list immediately is futile; fall through to the dir-lease\n walk instead.\n\n - After both walks, bail out with success (0) when nothing was freed\n and there is no cap pressure (`count==0`). There is no reason to\n keep retrying when we are not over the cap limit and made no\n progress.\n\nUnder real cap pressure (`count>0`) the reclaim path is unchanged and\nstill retries via `-EAGAIN`.\n\nWithout this patch, I saw 500 ceph_trim_dentries() calls per second on\nour web servers. This is very visible in `/proc/lock_stat` (5 minute\ncapture):\n\n class name con-bounces contentions waittime-min waittime-max waittime-total waittime-avg acq-bounces acquisitions holdtime-min holdtime-max holdtime-total holdtime-avg\n\n &mdsc->dentry_list_lock: 126180 128218 0.04 8063.44 15986965.20 124.69 1573354 5296812 0.04 8291.28 74164526.48 14.00\n -----------------------\n &mdsc->dentry_list_lock 111736 [<000000007b11e319>] __ceph_dentry_dir_lease_touch+0x7c/0xa8\n &mdsc->dentry_list_lock 2631 [<0000000050597999>] __dentry_leases_walk+0x64/0x2c8\n &mdsc->dentry_list_lock 3878 [<00000000c0022f62>] __ceph_dentry_lease_touch+0x5c/0xa8\n &mdsc->dentry_list_lock 9973 [<000000002f27cb6f>] __dentry_lease_unlist+0x50/0xa0\n -----------------------\n &mdsc->dentry_list_lock 123621 [<0000000050597999>] __dentry_leases_walk+0x64/0x2c8\n &mdsc->dentry_list_lock 1822 [<000000007b11e319>] __ceph_dentry_dir_lease_touch+0x7c/0xa8\n &mdsc->dentry_list_lock 2720 [<000000002f27cb6f>] __dentry_lease_unlist+0x50/0xa0\n &mdsc->dentry_list_lock 55 [<00000000c0022f62>] __ceph_dentry_lease_touch+0x5c/0xa8\n\nWith this patch:\n\n class name con-bounces contentions waittime-min waittime-max waittime-total waittime-avg acq-bounces acquisitions holdtime-min holdtime-max holdtime-total holdtime-avg\n\n &mdsc->dentry_list_lock: 1203 1215 0.16 408.88 33082.88 27.23 4320501 7357389 0.04 500.64 1961578.00 0.27\n -----------------------\n &mdsc->dentry_list_lock 1029 [<000000003c9aea8a>] __ceph_dentry_dir_lease_touch+0x7c/0xa8\n &mdsc->dentry_list_lock 1\n---truncated---', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.0063, EPSS Percentile is 0.4852 |
debian: CVE-2026-89647 was patched at 2026-09-16
1287.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89648) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ceph: cap delegated inode count in ceph_parse_deleg_inos() ceph_parse_deleg_inos() decodes interval sets of delegated inode numbers from an MDS create-with-delegation reply. For each set it reads a 64-bit start and a 64-bit len with ceph_decode_64_safe(), which only validates that the eight bytes are present in the message, not the value, and then loops over len while inserting entries into s_delegated_inos. len is fully attacker controlled. A malicious or compromised MDS can send one huge interval, many intervals in one reply, duplicate intervals, or repeated replies that accumulate delegated inodes on the same session. The original code bounded none of these and could spin the insert loop or grow the xarray without limit. Bound both dimensions with a single enforcement point. Track the number of delegated inodes held by each MDS session in an atomic counter and grow it only in ceph_insert_deleg_ino(), which uses atomic_add_unless() to refuse to push the count past CEPH_MAX_DELEG_INOS. Because that helper is the only place the counter grows, the per-session population can never exceed the cap, so no separate per-session pre-check is needed. The counter is decremented when async create consumes a delegated inode or when an insert fails, incremented when a delegated inode is restored, initialized with the session xarray, and reset when reconnect destroys the xarray. A per-session cap alone still lets one reply spin the insert loop on duplicate ranges without growing the counter, so also cap the aggregate interval length accepted from a single reply. Together these bound both the loop trip count per reply and the xarray population across replies. The cap is a fixed, client-chosen constant rather than a value derived from the MDS. mds_client_prealloc_inos is a userspace MDS configuration option; it is never sent to the kernel client on the wire, and a server-supplied bound could not be trusted for a defensive limit in any case. The constant is set well above that option's documented default of 1000 (a generous multiple), so legitimate refill behavior is unaffected while the CPU and xarray memory a malformed delegation stream can consume stays bounded. Impact: a malicious or compromised Ceph MDS can no longer make a client spin through an unbounded delegated-inode interval or grow one session's delegated-inode xarray without limit.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nceph: cap delegated inode count in ceph_parse_deleg_inos()\n\nceph_parse_deleg_inos() decodes interval sets of delegated inode numbers\nfrom an MDS create-with-delegation reply. For each set it reads a 64-bit\nstart and a 64-bit len with ceph_decode_64_safe(), which only validates\nthat the eight bytes are present in the message, not the value, and then\nloops over len while inserting entries into s_delegated_inos.\n\nlen is fully attacker controlled. A malicious or compromised MDS can send\none huge interval, many intervals in one reply, duplicate intervals, or\nrepeated replies that accumulate delegated inodes on the same session.\nThe original code bounded none of these and could spin the insert loop or\ngrow the xarray without limit.\n\nBound both dimensions with a single enforcement point. Track the number\nof delegated inodes held by each MDS session in an atomic counter and\ngrow it only in ceph_insert_deleg_ino(), which uses atomic_add_unless()\nto refuse to push the count past CEPH_MAX_DELEG_INOS. Because that helper\nis the only place the counter grows, the per-session population can never\nexceed the cap, so no separate per-session pre-check is needed. The\ncounter is decremented when async create consumes a delegated inode or\nwhen an insert fails, incremented when a delegated inode is restored,\ninitialized with the session xarray, and reset when reconnect destroys\nthe xarray.\n\nA per-session cap alone still lets one reply spin the insert loop on\nduplicate ranges without growing the counter, so also cap the aggregate\ninterval length accepted from a single reply. Together these bound both\nthe loop trip count per reply and the xarray population across replies.\n\nThe cap is a fixed, client-chosen constant rather than a value derived\nfrom the MDS. mds_client_prealloc_inos is a userspace MDS configuration\noption; it is never sent to the kernel client on the wire, and a\nserver-supplied bound could not be trusted for a defensive limit in any\ncase. The constant is set well above that option's documented default of\n1000 (a generous multiple), so legitimate refill behavior is unaffected\nwhile the CPU and xarray memory a malformed delegation stream can consume\nstays bounded.\n\nImpact: a malicious or compromised Ceph MDS can no longer make a client\nspin through an unbounded delegated-inode interval or grow one session's\ndelegated-inode xarray without limit.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00609, EPSS Percentile is 0.47551 |
debian: CVE-2026-89648 was patched at 2026-09-16
1288.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89654) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ceph: fix UAF in check_new_map() on session freed during unlock check_new_map() iterates mdsc->sessions[] and for each active session drops mdsc->mutex to perform per-session operations. The forced-close path (rank removed from map) correctly takes a reference on s via ceph_get_mds_session() before releasing mdsc->mutex, but three other paths do not: Path A (address changed): mutex_unlock → mutex_lock(&s->s_mutex) Path B (reconnect): mutex_unlock → send_mds_reconnect(mdsc, s) Path C (active transition): mutex_unlock → mutex_lock(&s->s_mutex) Without the extra reference, another thread can acquire mdsc->mutex during the unlock window, call __unregister_session() which drops the last reference on s, and free it. The original thread then accesses freed memory via s->s_mutex. Fix by adding ceph_get_mds_session(s) before each mutex_unlock and ceph_put_mds_session(s) after the corresponding mutex_lock, matching the pattern already used in the forced-close path. Race timeline (Path A): Thread A (check_new_map) Thread B (another map update holds mdsc->mutex or session teardown) -------------------------- -------------------------- s = mdsc->sessions[i] (refcount == 1, held only by sessions[] array) mutex_unlock(&mdsc->mutex) ---> acquires mdsc->mutex __unregister_session(mdsc, s) sessions[i] = NULL ceph_put_mds_session(s) refcount: 1 -> 0 kfree(s) <--- freed! mutex_lock(&s->s_mutex) UAF on freed s->s_mutex', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix UAF in check_new_map() on session freed during unlock\n\ncheck_new_map() iterates mdsc->sessions[] and for each active session\ndrops mdsc->mutex to perform per-session operations. The forced-close\npath (rank removed from map) correctly takes a reference on s via\nceph_get_mds_session() before releasing mdsc->mutex, but three other\npaths do not:\n\n Path A (address changed): mutex_unlock → mutex_lock(&s->s_mutex)\n Path B (reconnect): mutex_unlock → send_mds_reconnect(mdsc, s)\n Path C (active transition): mutex_unlock → mutex_lock(&s->s_mutex)\n\nWithout the extra reference, another thread can acquire mdsc->mutex\nduring the unlock window, call __unregister_session() which drops the\nlast reference on s, and free it. The original thread then accesses\nfreed memory via s->s_mutex.\n\nFix by adding ceph_get_mds_session(s) before each mutex_unlock and\nceph_put_mds_session(s) after the corresponding mutex_lock, matching\nthe pattern already used in the forced-close path.\n\nRace timeline (Path A):\n\n Thread A (check_new_map) Thread B (another map update\n holds mdsc->mutex or session teardown)\n -------------------------- --------------------------\n s = mdsc->sessions[i]\n (refcount == 1, held only by\n sessions[] array)\n\n mutex_unlock(&mdsc->mutex)\n ---> acquires mdsc->mutex\n __unregister_session(mdsc, s)\n sessions[i] = NULL\n ceph_put_mds_session(s)\n refcount: 1 -> 0\n kfree(s) <--- freed!\n\n mutex_lock(&s->s_mutex)\n UAF on freed s->s_mutex', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00407, EPSS Percentile is 0.34483 |
debian: CVE-2026-89654 was patched at 2026-09-16
1289.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89665) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE The NFSv2 sattr decoder converts the wire useconds to nanoseconds in svcxdr_decode_sattr(): \tiap->ia_atime.tv_nsec = tmp2 * NSEC_PER_USEC; tmp2 is a u32 and NSEC_PER_USEC is 1000, so the product is computed in unsigned long. On ILP32 that is 32 bits, and an out-of-range useconds value such as 4294968 wraps to tv_nsec == 704. The corruption therefore happens during decode, before any proc function can inspect the value, and a later range check on tv_nsec would see an in-range result and accept it. Rejecting in the decoder yields an RPC GARBAGE_ARGS reply. NFSv2 defines no NFSERR_INVAL, so there is no NFS-level status to return for a malformed time argument, and the check cannot move to the proc function the way the v3/v4 nsec range checks do. Guard the raw useconds before the multiplication and reject values greater than 1000000. useconds == 1000000 is kept: it is the Sun convention for "set to the current server time", and the in-tree Linux NFSv2 client emits it in both the atime and the mtime field for a plain touch / utimes(file, NULL) (see encode_sattr() and xdr_encode_current_server_time() in fs/nfs/nfs2xdr.c). Rejecting 1000000 would turn that common operation into a hard decode failure for both SETATTR and CREATE. 1000000 * NSEC_PER_USEC is 10^9, which does not wrap on ILP32, so the Sun convention value passes through safely. Only genuinely out-of-range values (> 1000000) are rejected. The atime and mtime guards are therefore symmetric. The decoder only applied the Sun convention in the mtime block, which clears ATTR_ATIME_SET|ATTR_MTIME_SET when mtime useconds == 1000000. If a client puts 1000000 in the atime field but not in the mtime field, the atime block stored an out-of-range tv_nsec (10^9) and left ATTR_ATIME_SET set, so the bogus value reached the filesystem. Apply the convention in the atime block as well, clearing ATTR_ATIME_SET so the server uses its current time and ignores the value. Only ATTR_ATIME_SET is cleared there. The mtime block keeps its existing behavior, where 1000000 means "set both atime and mtime to now". [ cel: various tweaks, addenda, and clean-ups ]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE\n\nThe NFSv2 sattr decoder converts the wire useconds to nanoseconds in\nsvcxdr_decode_sattr():\n\n\tiap->ia_atime.tv_nsec = tmp2 * NSEC_PER_USEC;\n\ntmp2 is a u32 and NSEC_PER_USEC is 1000, so the product is computed in\nunsigned long. On ILP32 that is 32 bits, and an out-of-range useconds\nvalue such as 4294968 wraps to tv_nsec == 704. The corruption therefore\nhappens during decode, before any proc function can inspect the value,\nand a later range check on tv_nsec would see an in-range result and\naccept it. Rejecting in the decoder yields an RPC GARBAGE_ARGS reply.\nNFSv2 defines no NFSERR_INVAL, so there is no NFS-level status to return\nfor a malformed time argument, and the check cannot move to the proc\nfunction the way the v3/v4 nsec range checks do.\n\nGuard the raw useconds before the multiplication and reject values\ngreater than 1000000. useconds == 1000000 is kept: it is the Sun\nconvention for "set to the current server time", and the in-tree Linux\nNFSv2 client emits it in both the atime and the mtime field for a plain\ntouch / utimes(file, NULL) (see encode_sattr() and\nxdr_encode_current_server_time() in fs/nfs/nfs2xdr.c). Rejecting 1000000\nwould turn that common operation into a hard decode failure for both\nSETATTR and CREATE. 1000000 * NSEC_PER_USEC is 10^9, which does not wrap\non ILP32, so the Sun convention value passes through safely. Only\ngenuinely out-of-range values (> 1000000) are rejected. The atime and\nmtime guards are therefore symmetric.\n\nThe decoder only applied the Sun convention in the mtime block, which\nclears ATTR_ATIME_SET|ATTR_MTIME_SET when mtime useconds == 1000000. If a\nclient puts 1000000 in the atime field but not in the mtime field, the\natime block stored an out-of-range tv_nsec (10^9) and left ATTR_ATIME_SET\nset, so the bogus value reached the filesystem. Apply the convention in\nthe atime block as well, clearing ATTR_ATIME_SET so the server uses its\ncurrent time and ignores the value. Only ATTR_ATIME_SET is cleared there.\nThe mtime block keeps its existing behavior, where 1000000 means "set\nboth atime and mtime to now".\n\n[ cel: various tweaks, addenda, and clean-ups ]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.0062, EPSS Percentile is 0.48085 |
debian: CVE-2026-89665 was patched at 2026-09-16
1290.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89672) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: gate nfs2 setacl by argp->mask The NFSACL v2 SETACL path shares the decoder convention used by its v3 sibling: nfsaclsvc_decode_setaclargs() fills in argp->acl_access only when NFS_ACL is set in the request mask and argp->acl_default only when NFS_DFACL is set, leaving the other pointer NULL because the argument buffer is zeroed up to pc_argzero before decode. nfsacld_proc_setacl() then hands both pointers to set_posix_acl() unconditionally. set_posix_acl(idmap, dentry, type, NULL) is the VFS "remove this ACL type" operation, so an omitted arm is indistinguishable from an explicit request to delete that ACL. A SETACL carrying only NFS_ACL silently strips the directory's default ACL; mask=0 strips both. This is the same defect just fixed in nfsd3_proc_setacl(); apply the same remedy. Gate each set_posix_acl() call on its mask bit and initialize error to 0 so that a request with neither bit set leaves the on-disk ACLs untouched and returns success. The out_drop_lock path and the unconditional posix_acl_release() in nfsaclsvc_release_setacl() already tolerate the skipped arms.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: gate nfs2 setacl by argp->mask\n\nThe NFSACL v2 SETACL path shares the decoder convention used by its\nv3 sibling: nfsaclsvc_decode_setaclargs() fills in argp->acl_access\nonly when NFS_ACL is set in the request mask and argp->acl_default\nonly when NFS_DFACL is set, leaving the other pointer NULL because\nthe argument buffer is zeroed up to pc_argzero before decode.\n\nnfsacld_proc_setacl() then hands both pointers to set_posix_acl()\nunconditionally. set_posix_acl(idmap, dentry, type, NULL) is the VFS\n"remove this ACL type" operation, so an omitted arm is\nindistinguishable from an explicit request to delete that ACL. A\nSETACL carrying only NFS_ACL silently strips the directory's default\nACL; mask=0 strips both.\n\nThis is the same defect just fixed in nfsd3_proc_setacl(); apply the\nsame remedy. Gate each set_posix_acl() call on its mask bit and\ninitialize error to 0 so that a request with neither bit set leaves\nthe on-disk ACLs untouched and returns success. The out_drop_lock\npath and the unconditional posix_acl_release() in\nnfsaclsvc_release_setacl() already tolerate the skipped arms.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00522, EPSS Percentile is 0.4305 |
debian: CVE-2026-89672 was patched at 2026-09-16
1291.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89680) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfsd_file leak on inter-server COPY setup failure When nfsd4_setup_inter_ssc() fails, nfsd4_copy() returns nfserr_offload_denied directly, bypassing the out: label where release_copy_files() would drop the nf_dst reference taken by nfs4_preprocess_stateid_op(). Each failed inter-server COPY leaks one nfsd_file, pinning file/inode/dentry/vfsmount. Fix by setting status and jumping to out: instead of returning directly.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix nfsd_file leak on inter-server COPY setup failure\n\nWhen nfsd4_setup_inter_ssc() fails, nfsd4_copy() returns\nnfserr_offload_denied directly, bypassing the out: label where\nrelease_copy_files() would drop the nf_dst reference taken by\nnfs4_preprocess_stateid_op(). Each failed inter-server COPY\nleaks one nfsd_file, pinning file/inode/dentry/vfsmount.\n\nFix by setting status and jumping to out: instead of returning\ndirectly.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00641, EPSS Percentile is 0.4906 |
debian: CVE-2026-89680 was patched at 2026-09-16
1292.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89707) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: release path refs on follow_down() error nfsd_cross_mnt() initializes a local struct path with mntget() and dget() before calling follow_down(). On a negative return the error arm jumps to out without releasing those references: err = follow_down(&path, follow_flags); if (err < 0) goto out; follow_down() never drops the caller's entry-time refs on any error sub-case; for example a pre-cross d_manage() failure leaves path untouched, so the mntget()/dget() taken on entry survive the call. Every other early-exit arm in nfsd_cross_mnt() (other-namespace return, IS_ERR(exp2), and the success tail after the swap) already calls path_put(&path); the err < 0 arm is the lone omission. The leak inflates mnt_count and d_count on each failed cross-mount, blocking umount and pinning dentries against the shrinker, and is reachable by any authenticated NFS client through nfsd_lookup_dentry or the NFSv4 READDIR encode path. Fix by calling path_put(&path) before the goto out in the err < 0 arm so the entry-time refs are released on all follow_down() error returns.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: release path refs on follow_down() error\n\nnfsd_cross_mnt() initializes a local struct path with mntget() and\ndget() before calling follow_down(). On a negative return the error\narm jumps to out without releasing those references:\n\n err = follow_down(&path, follow_flags);\n if (err < 0)\n goto out;\n\nfollow_down() never drops the caller's entry-time refs on any error\nsub-case; for example a pre-cross d_manage() failure leaves path\nuntouched, so the mntget()/dget() taken on entry survive the call.\n\nEvery other early-exit arm in nfsd_cross_mnt() (other-namespace\nreturn, IS_ERR(exp2), and the success tail after the swap) already\ncalls path_put(&path); the err < 0 arm is the lone omission. The\nleak inflates mnt_count and d_count on each failed cross-mount,\nblocking umount and pinning dentries against the shrinker, and is\nreachable by any authenticated NFS client through nfsd_lookup_dentry\nor the NFSv4 READDIR encode path.\n\nFix by calling path_put(&path) before the goto out in the err < 0\narm so the entry-time refs are released on all follow_down() error\nreturns.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00603, EPSS Percentile is 0.47271 |
debian: CVE-2026-89707 was patched at 2026-09-16
1293.
Denial of Service - GPU Display Driver (CVE-2026-24197) - Medium [303]
Description: NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default initialization of memory subsystem routing resources could lead to data corruption or a hang during partition reconfiguration. A successful exploit of this vulnerability might lead to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:nvidia:gpu_display_driver (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0016, EPSS Percentile is 0.05524 |
redos: CVE-2026-24197 was patched at 2026-09-08
1294.
Denial of Service - Suricata (CVE-2026-57227) - Medium [303]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Suricata is an open-source intrusion detection and prevention system (IDS/IPS) and network security monitoring engine that supports deep packet inspection and threat detection. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-57227 was patched at 2026-09-16
1295.
Denial of Service - libmongocrypt (CVE-2026-84971) - Medium [303]
Description: Improper handling of an unexpected value size in the decryption path of a client-side encryption library can cause a failed internal check that terminates the process using the library. A party able to place a suitably formed encrypted value where an application will decrypt it, or able to control the responses the application receives, may cause that application to stop running.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:mongodb:libmongocrypt (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05508 |
debian: CVE-2026-84971 was patched at 2026-09-16
1296.
Denial of Service - undici (CVE-2026-84890) - Medium [303]
Description: undici's decompress interceptor decompresses response bodies according to the untrusted Content-Encoding header. While the number of content-encoding layers is capped, the total decompressed output size is unbounded and there is no configuration option to limit it. A malicious or faulty upstream can therefore return a small compressed payload, a compression bomb, that expands to hundreds of megabytes or more in client memory, an asymmetric resource consumption that can exhaust memory and crash the process. This affects undici versions from 7.15.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:nodejs:undici (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0025, EPSS Percentile is 0.16554 |
debian: CVE-2026-84890 was patched at 2026-09-16
1297.
Memory Corruption - TimescaleDB (CVE-2026-70634) - Medium [303]
Description: TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path uses an assertion compiled out of release builds, leaving the 64-bit Simple8b index unvalidated and the read offset attacker-controlled. Attackers with DML access to a physical compressed relation can store a crafted datum and run a reverse-order scan. With a pass-by-value column type the out-of-bounds Datum is returned to the client as a normal column value, disclosing backend memory including the shared buffer pool, which SQL access control does not cover.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:timescale:timescaledb (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00401, EPSS Percentile is 0.33868 |
altlinux: CVE-2026-70634 was patched at 2026-08-26, 2026-08-28, 2026-08-29, 2026-09-01
1298.
Security Feature Bypass - undici (CVE-2026-85008) - Medium [303]
Description: undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from the set of safe methods, so an unsafe method such as POST, PUT, or DELETE is never placed in the skip list and instead falls through to the full cache-read path. The response-storage gate also lacked a method check, so a response to an unsafe request that is heuristically cacheable or carries an explicit Cache-Control directive is stored and later replayed from cache. Because response headers from a remote origin are untrusted, an origin can answer once with a cacheable status and then have the client's own subsequent state-changing requests to that path served from the stale cache entry without ever reaching the origin, an integrity failure that occurs under the interceptor's default configuration. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:nodejs:undici (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00118, EPSS Percentile is 0.01922 |
debian: CVE-2026-85008 was patched at 2026-09-16
1299.
Memory Corruption - FFmpeg (CVE-2026-75141) - Medium [301]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00137, EPSS Percentile is 0.03489 |
debian: CVE-2026-75141 was patched at 2026-08-20
ubuntu: CVE-2026-75141 was patched at 2026-09-03, 2026-09-16
1300.
Memory Corruption - FFmpeg (CVE-2026-75142) - Medium [301]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00137, EPSS Percentile is 0.0349 |
debian: CVE-2026-75142 was patched at 2026-08-20
ubuntu: CVE-2026-75142 was patched at 2026-09-03, 2026-09-16
1301.
Memory Corruption - FFmpeg (CVE-2026-75144) - Medium [301]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00137, EPSS Percentile is 0.0349 |
debian: CVE-2026-75144 was patched at 2026-08-20
ubuntu: CVE-2026-75144 was patched at 2026-09-03, 2026-09-16
1302.
Information Disclosure - BIND (CVE-2026-72924) - Medium [300]
Description: GitHub CLI (gh) is GitHub's official command line tool. Versions 2.28.0 through 2.97.0
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.2 | 10 | CVSS Base Score is 2.1. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00179, EPSS Percentile is 0.07643 |
debian: CVE-2026-72924 was patched at 2026-09-16
1303.
Unknown Vulnerability Type - RPC (CVE-2026-84445) - Medium [300]
Description: {'nvd_cve_data_all': 'gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header, while RouteAndProcess in internal/xds/server/routing.go assumes that an authority value exists and indexes the empty slice. A remote client that can complete transport connection establishment can trigger an index-out-of-bounds panic that is not recovered by the per-RPC goroutine and terminates the entire server process. In insecure or ordinary TLS deployments the request can be unauthenticated, while strict mTLS or ALTS deployments require valid transport credentials before the malformed RPC can reach the interceptor. This issue is fixed in versions 1.82.2 and 1.83.2.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header, while RouteAndProcess in internal/xds/server/routing.go assumes that an authority value exists and indexes the empty slice. A remote client that can complete transport connection establishment can trigger an index-out-of-bounds panic that is not recovered by the per-RPC goroutine and terminates the entire server process. In insecure or ordinary TLS deployments the request can be unauthenticated, while strict mTLS or ALTS deployments require valid transport credentials before the malformed RPC can reach the interceptor. This issue is fixed in versions 1.82.2 and 1.83.2.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Remote Procedure Call Runtime | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.5 | 10 | EPSS Probability is 0.00685, EPSS Percentile is 0.50906 |
debian: CVE-2026-84445 was patched at 2026-09-16
1304.
Denial of Service - GVfs (CVE-2026-84269) - Medium [298]
Description: A flaw was found in the AFP backend in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | GVfs (GNOME Virtual File System) is userspace virtual filesystem software for GNOME that provides backends (including FTP) to access different remote and local file systems transparently. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00249, EPSS Percentile is 0.16403 |
debian: CVE-2026-84269 was patched at 2026-09-16
1305.
Remote Code Execution - Unknown Product (CVE-2026-19774) - Medium [297]
Description: {'nvd_cve_data_all': 'BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The specific flaw exists within the handling of the stream endpoints. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-29429.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the handling of the stream endpoints. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-29429.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00328, EPSS Percentile is 0.25934 |
debian: CVE-2026-19774 was patched at 2026-09-16
1306.
Denial of Service - ImageMagick (CVE-2026-86423) - Medium [296]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00113, EPSS Percentile is 0.01617 |
altlinux: CVE-2026-86423 was patched at 2026-08-31
debian: CVE-2026-86423 was patched at 2026-09-16
1307.
Denial of Service - ImageMagick (CVE-2026-86425) - Medium [296]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00146, EPSS Percentile is 0.04244 |
altlinux: CVE-2026-86425 was patched at 2026-08-31
debian: CVE-2026-86425 was patched at 2026-09-16
1308.
Denial of Service - Rclone (CVE-2026-79778) - Medium [296]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers, supporting over 40 cloud storage products including S3, Google Drive, Dropbox, OneDrive, and many more. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00233, EPSS Percentile is 0.14355 |
debian: CVE-2026-79778 was patched at 2026-09-16
1309.
Memory Corruption - MongoDB (CVE-2026-82066) - Medium [296]
Description: A heap out-of-bounds read security issue exists in the query planning component of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00215, EPSS Percentile is 0.11983 |
altlinux: CVE-2026-82066 was patched at 2026-09-09, 2026-09-10
1310.
Memory Corruption - MongoDB (CVE-2026-89099) - Medium [296]
Description: A
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00182, EPSS Percentile is 0.07969 |
altlinux: CVE-2026-89099 was patched at 2026-09-12, 2026-09-14
1311.
Memory Corruption - strongSwan (CVE-2026-78126) - Medium [296]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | strongSwan is an open source IPsec-based VPN solution that provides secure network connectivity using IKEv1 and IKEv2 protocols, widely used on Linux systems for site-to-site and remote access VPN deployments. | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00413, EPSS Percentile is 0.34997 |
altlinux: CVE-2026-78126 was patched at 2026-09-11
debian: CVE-2026-78126 was patched at 2026-09-07, 2026-09-16
1312.
Memory Corruption - Chromium (CVE-2026-87602) - Medium [294]
Description: Out of bounds read in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially read memory outside the sandbox via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0017, EPSS Percentile is 0.06695 |
altlinux: CVE-2026-87602 was patched at 2026-09-17
debian: CVE-2026-87602 was patched at 2026-09-16
1313.
Memory Corruption - Mozilla Firefox (CVE-2026-84125) - Medium [294]
Description: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.06052 |
altlinux: CVE-2026-84125 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
1314.
Memory Corruption - OpenSSL (CVE-2026-84964) - Medium [294]
Description: A double free in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00147, EPSS Percentile is 0.04277 |
debian: CVE-2026-84964 was patched at 2026-09-16
1315.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74598) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipv6: fix Route Information option length validation rt6_route_rcv() validates the Route Information option (RFC 4191) length against the prefix length, but both checks are off by one. rinfo->length is the ND option length in units of 8 octets and it *includes* the 8-byte option header, so an option carrying N bytes of prefix has length == 1 + N/8. RFC 4191 section 2.3 requires length 3 when Prefix Length is greater than 64, and 2 or 3 when it is greater than 0. The code accepts length >= 2 and length >= 1 respectively. ipv6_addr_prefix() then copies prefix_len/8 bytes out of rinfo->prefix, so a Router Advertisement with (prefix_len=128, length=2) or (prefix_len=64, length=1) makes the kernel read up to 8 bytes past the end of the option. Those bytes end up in the prefix of the route that gets installed, so they are visible to userspace: # RA with a Route Information option (prefix_len=128, length=2) # followed by a source link-layer address option, 01 01 de ad be ef ca fe $ ip -6 route show 2001:db8:dead:beef:101:dead:beef:cafe via fe80::1234 dev veth0 proto ra ^^^^^^^^^^^^^^^^^^ the next option, read out of bounds When the Route Information option is the last one in the packet, those eight bytes come from the skb tail room instead. Reject the option lengths RFC 4191 does not allow.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix Route Information option length validation\n\nrt6_route_rcv() validates the Route Information option (RFC 4191) length\nagainst the prefix length, but both checks are off by one.\n\nrinfo->length is the ND option length in units of 8 octets and it\n*includes* the 8-byte option header, so an option carrying N bytes of\nprefix has length == 1 + N/8. RFC 4191 section 2.3 requires length 3\nwhen Prefix Length is greater than 64, and 2 or 3 when it is greater\nthan 0. The code accepts length >= 2 and length >= 1 respectively.\n\nipv6_addr_prefix() then copies prefix_len/8 bytes out of rinfo->prefix,\nso a Router Advertisement with (prefix_len=128, length=2) or\n(prefix_len=64, length=1) makes the kernel read up to 8 bytes past the\nend of the option. Those bytes end up in the prefix of the route that\ngets installed, so they are visible to userspace:\n\n # RA with a Route Information option (prefix_len=128, length=2)\n # followed by a source link-layer address option, 01 01 de ad be ef ca fe\n $ ip -6 route show\n 2001:db8:dead:beef:101:dead:beef:cafe via fe80::1234 dev veth0 proto ra\n ^^^^^^^^^^^^^^^^^^ the next option, read out of bounds\n\nWhen the Route Information option is the last one in the packet, those\neight bytes come from the skb tail room instead.\n\nReject the option lengths RFC 4191 does not allow.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00425, EPSS Percentile is 0.36169 |
debian: CVE-2026-74598 was patched at 2026-08-25
oraclelinux: CVE-2026-74598 was patched at 2026-09-04
1316.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74621) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix sk_buff leak when the header checks reject a packet tcf_ct_handle_fragments() runs its header sanity checks before handing anything to the defragmentation engine: \tif (family == NFPROTO_IPV4) \t\terr = tcf_ct_ipv4_is_fragment(skb, &frag); \telse \t\terr = tcf_ct_ipv6_is_fragment(skb, &frag); \tif (err || !frag) \t\treturn err; tcf_ct_ipv4_is_fragment() returns -EINVAL or -ENOMEM; tcf_ct_ipv6_is_fragment() adds -EPROTO when ipv6_find_hdr() fails. None of them frees or queues the skb, so on that path the caller still owns it. tcf_ct_act() however funnels every non-zero return into the ownership-transfer exit: \terr = tcf_ct_handle_fragments(net, skb, family, p->zone, &defrag); \tif (err) \t\tgoto out_frag; \t... out_frag: \tif (err != -EINPROGRESS) \t\ttcf_action_inc_drop_qstats(&c->common); \treturn TC_ACT_CONSUMED; TC_ACT_CONSUMED means the action took ownership of the skb, so no caller frees it - sch_handle_ingress(), sch_handle_egress() and tcf_qevent_handle() all deliberately skip the free for that verdict. The skb is therefore orphaned: one sk_buff plus its data buffer is leaked per malformed packet, unbounded. Note the drop counter is already incremented for these errors, so the statistics claim a drop that never happens. Three different ownership states reach out_frag: today - the skb may be queued by the defrag engine (-EINPROGRESS), already freed by nf_ct_handle_fragments(), or still owned by us. Tell the caller which of those it is, and free the packet ourselves in the last case, which restores the TC_ACT_SHOT behaviour that predated the Fixes: commit. Reproduced on v7.2-rc6 with a 54-byte frame carrying a 40-byte IPv6 header with nexthdr = 0 (hop-by-hop) and nothing after it, on a clsact ingress chain with "action ct". kmemleak reports one leaked 232-byte skbuff_head_cache object plus its 704-byte data buffer per packet; with this patch it reports none.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_ct: fix sk_buff leak when the header checks reject a packet\n\ntcf_ct_handle_fragments() runs its header sanity checks before handing\nanything to the defragmentation engine:\n\n\tif (family == NFPROTO_IPV4)\n\t\terr = tcf_ct_ipv4_is_fragment(skb, &frag);\n\telse\n\t\terr = tcf_ct_ipv6_is_fragment(skb, &frag);\n\tif (err || !frag)\n\t\treturn err;\n\ntcf_ct_ipv4_is_fragment() returns -EINVAL or -ENOMEM;\ntcf_ct_ipv6_is_fragment() adds -EPROTO when ipv6_find_hdr() fails. None of\nthem frees or queues the skb, so on that path the caller still owns it.\n\ntcf_ct_act() however funnels every non-zero return into the\nownership-transfer exit:\n\n\terr = tcf_ct_handle_fragments(net, skb, family, p->zone, &defrag);\n\tif (err)\n\t\tgoto out_frag;\n\t...\nout_frag:\n\tif (err != -EINPROGRESS)\n\t\ttcf_action_inc_drop_qstats(&c->common);\n\treturn TC_ACT_CONSUMED;\n\nTC_ACT_CONSUMED means the action took ownership of the skb, so no caller\nfrees it - sch_handle_ingress(), sch_handle_egress() and\ntcf_qevent_handle() all deliberately skip the free for that verdict. The\nskb is therefore orphaned: one sk_buff plus its data buffer is leaked per\nmalformed packet, unbounded. Note the drop counter is already incremented\nfor these errors, so the statistics claim a drop that never happens.\n\nThree different ownership states reach out_frag: today - the skb may be\nqueued by the defrag engine (-EINPROGRESS), already freed by\nnf_ct_handle_fragments(), or still owned by us. Tell the caller which of\nthose it is, and free the packet ourselves in the last case, which\nrestores the TC_ACT_SHOT behaviour that predated the Fixes: commit.\n\nReproduced on v7.2-rc6 with a 54-byte frame carrying a 40-byte IPv6\nheader with nexthdr = 0 (hop-by-hop) and nothing after it, on a\nclsact ingress chain with "action ct". kmemleak reports one leaked\n232-byte skbuff_head_cache object plus its 704-byte data buffer per\npacket; with this patch it reports none.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0049, EPSS Percentile is 0.40941 |
debian: CVE-2026-74621 was patched at 2026-08-25
oraclelinux: CVE-2026-74621 was patched at 2026-09-04
1317.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74624) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: defer invalid log until after unlock TCP and SCTP conntrack paths can emit invalid-packet logs while ct->lock is still held. When invalid logging is routed to nfnetlink_log and conntrack export is enabled, the log path can re-enter conntrack netlink glue and dump the same conntrack again. Protocol attribute dumping may take ct->lock, so logging while holding that lock can deadlock. Defer the TCP invalid logs by storing only the minimal log context while ct->lock is held and emitting the log after unlocking. Also make the TCP timeout-lowering invalid path return whether a log is needed, then emit that log after unlocking. Do the same for the SCTP invalid state-transition log that can be reached while ct->lock is held. Add a lockdep assertion to nf_ct_l4proto_log_invalid() so future callers that log invalid conntracks while holding ct->lock are caught outside TCP and SCTP as well.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack: defer invalid log until after unlock\n\nTCP and SCTP conntrack paths can emit invalid-packet logs while ct->lock\nis still held.\n\nWhen invalid logging is routed to nfnetlink_log and conntrack export is\nenabled, the log path can re-enter conntrack netlink glue and dump the\nsame conntrack again. Protocol attribute dumping may take ct->lock, so\nlogging while holding that lock can deadlock.\n\nDefer the TCP invalid logs by storing only the minimal log context while\nct->lock is held and emitting the log after unlocking. Also make the TCP\ntimeout-lowering invalid path return whether a log is needed, then emit\nthat log after unlocking.\n\nDo the same for the SCTP invalid state-transition log that can be reached\nwhile ct->lock is held.\n\nAdd a lockdep assertion to nf_ct_l4proto_log_invalid() so future callers\nthat log invalid conntracks while holding ct->lock are caught outside TCP\nand SCTP as well.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00479, EPSS Percentile is 0.40228 |
debian: CVE-2026-74624 was patched at 2026-08-25
oraclelinux: CVE-2026-74624 was patched at 2026-09-04
1318.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74625) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: release template ct on non-IP path A bridge nftables ct zone set rule can attach a conntrack template to an skb before nf_ct_bridge_pre() sees it. For non-IPv4 and non-IPv6 EtherTypes, nf_ct_bridge_pre() currently overwrites skb->_nfct with IP_CT_UNTRACKED without releasing the existing template reference. That makes the per-cpu template, and any temporary templates allocated for concurrent use, unreachable and leaks memory until the host runs out of slab. Reset the skb conntrack state before marking the frame untracked so the existing template reference is dropped on the non-IP path.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: release template ct on non-IP path\n\nA bridge nftables ct zone set rule can attach a conntrack template to\nan skb before nf_ct_bridge_pre() sees it. For non-IPv4 and non-IPv6\nEtherTypes, nf_ct_bridge_pre() currently overwrites skb->_nfct with\nIP_CT_UNTRACKED without releasing the existing template reference.\n\nThat makes the per-cpu template, and any temporary templates allocated\nfor concurrent use, unreachable and leaks memory until the host runs out\nof slab.\n\nReset the skb conntrack state before marking the frame untracked so the\nexisting template reference is dropped on the non-IP path.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00501, EPSS Percentile is 0.41677 |
debian: CVE-2026-74625 was patched at 2026-08-25
oraclelinux: CVE-2026-74625 was patched at 2026-09-04
1319.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74626) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_netdev: Preserve RX queue depth on allocation failure ntb_netdev_rx_handler() hands the received skb to the network stack before allocating its replacement. If the allocation fails, nothing is reposted. Every failure therefore takes one buffer out of the RX queue while the interface remains up, and enough failures eventually stall reception. A retry path could refill the queue later, but ntb_netdev has none. Allocate the replacement first instead. If that fails, drop the packet and repost the same skb. This keeps the queue full and lets packet delivery resume as soon as memory is available again.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nNTB: ntb_netdev: Preserve RX queue depth on allocation failure\n\nntb_netdev_rx_handler() hands the received skb to the network stack\nbefore allocating its replacement. If the allocation fails, nothing is\nreposted. Every failure therefore takes one buffer out of the RX queue\nwhile the interface remains up, and enough failures eventually stall\nreception.\n\nA retry path could refill the queue later, but ntb_netdev has none.\nAllocate the replacement first instead. If that fails, drop the packet\nand repost the same skb. This keeps the queue full and lets packet\ndelivery resume as soon as memory is available again.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00501, EPSS Percentile is 0.41676 |
debian: CVE-2026-74626 was patched at 2026-08-25, 2026-08-29
1320.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74665) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: fix skb length accounting after generic XDP frag adjustment Generic XDP exposes non-linear skb fragments through an xdp_buff. If an XDP program adjusts the fragment area, bpf_prog_run_generic_xdp() copies xdp_frags_size back to skb->data_len but leaves skb->len containing the old fragment contribution. After a fragment shrink, this makes skb_headlen() larger than the actual linear area. In the reproduced UDP receive path, __skb_datagram_iter() copied 1024 bytes past the actual linear tail to userspace, starting at struct skb_shared_info. The copied bytes included the affected skb's nr_frags, xdp_frags_size and a kernel pointer from skb_shinfo(skb)->frags[0]. Real packet data was displaced by the same amount and truncated at the end. Subtract the old data_len before replacing it and add the new data_len afterwards, keeping skb->len and skb->data_len synchronized. A 60000-byte UDP datagram on a veth pair with MTU 64000 was shortened by 1024 bytes from its fragment area. Before the fix, all 10 runs produced corrupted payloads. After the fix, all 10 runs matched the expected payload exactly.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix skb length accounting after generic XDP frag adjustment\n\nGeneric XDP exposes non-linear skb fragments through an xdp_buff. If an\nXDP program adjusts the fragment area, bpf_prog_run_generic_xdp() copies\nxdp_frags_size back to skb->data_len but leaves skb->len containing the\nold fragment contribution.\n\nAfter a fragment shrink, this makes skb_headlen() larger than the actual\nlinear area. In the reproduced UDP receive path, __skb_datagram_iter()\ncopied 1024 bytes past the actual linear tail to userspace, starting at\nstruct skb_shared_info. The copied bytes included the affected skb's\nnr_frags, xdp_frags_size and a kernel pointer from\nskb_shinfo(skb)->frags[0]. Real packet data was displaced by the same\namount and truncated at the end.\n\nSubtract the old data_len before replacing it and add the new data_len\nafterwards, keeping skb->len and skb->data_len synchronized.\n\nA 60000-byte UDP datagram on a veth pair with MTU 64000 was shortened by\n1024 bytes from its fragment area. Before the fix, all 10 runs produced\ncorrupted payloads. After the fix, all 10 runs matched the expected\npayload exactly.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30963 |
debian: CVE-2026-74665 was patched at 2026-08-25
oraclelinux: CVE-2026-74665 was patched at 2026-09-04
1321.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74692) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/smc: fix TOCTOU race between smc_listen_out() and listener close smc_listen_out() reads lsmc->sk.sk_state without the listener lock, then acquires lock_sock_nested() only after the check passes. This opens a window where smc_close_active() can transition the listener to SMC_CLOSED, call smc_close_cleanup_listen() to drain the accept queue, and release the lock, all between the lockless read and the delayed lock acquisition: smc_listen_work (smc_hs_wq) smc_close_active() ------------------------------- ------------------------- release_sock(child) if (sk_state == SMC_LISTEN) TRUE lock_sock(listener) sk_state = SMC_CLOSED smc_close_cleanup_listen() release_sock(listener) flush_work(tcp_listen_work) lock_sock_nested(listener) smc_accept_enqueue(listener, child) /* child enqueued on dead listener */ smc_close_active() flushes only tcp_listen_work. Work items already dispatched onto smc_hs_wq for the CLC handshake continue running unguarded. smc_accept_enqueue() takes a sock_hold() on the child that is never released, so the child smc_sock, its clcsock, and the reference all leak. A remote peer that opens TCP connections while the server calls close() can exhaust kernel memory. Move lock_sock_nested() to before the sk_state check so that the test and the enqueue are atomic under the listener lock.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix TOCTOU race between smc_listen_out() and listener close\n\nsmc_listen_out() reads lsmc->sk.sk_state without the listener lock,\nthen acquires lock_sock_nested() only after the check passes. This\nopens a window where smc_close_active() can transition the listener\nto SMC_CLOSED, call smc_close_cleanup_listen() to drain the accept\nqueue, and release the lock, all between the lockless read and the\ndelayed lock acquisition:\n\n smc_listen_work (smc_hs_wq) smc_close_active()\n ------------------------------- -------------------------\n release_sock(child)\n if (sk_state == SMC_LISTEN) TRUE\n lock_sock(listener)\n sk_state = SMC_CLOSED\n smc_close_cleanup_listen()\n release_sock(listener)\n flush_work(tcp_listen_work)\n lock_sock_nested(listener)\n smc_accept_enqueue(listener, child) /* child enqueued on dead listener */\n\nsmc_close_active() flushes only tcp_listen_work. Work items already\ndispatched onto smc_hs_wq for the CLC handshake continue running\nunguarded. smc_accept_enqueue() takes a sock_hold() on the child that\nis never released, so the child smc_sock, its clcsock, and the\nreference all leak. A remote peer that opens TCP connections while the\nserver calls close() can exhaust kernel memory.\n\nMove lock_sock_nested() to before the sk_state check so that the test\nand the enqueue are atomic under the listener lock.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0049, EPSS Percentile is 0.40941 |
debian: CVE-2026-74692 was patched at 2026-08-25
1322.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74695) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() Incoming skbs passing through netfilter flowtable offload hooks (or XFRM offload path) might already carry a ref-counted dst_entry assigned during earlier RX or routing steps. Calling skb_dst_set_noref() when skb already holds a ref-counted dst overwrites skb->_skb_refdst, leaking the previous dst_entry reference count and triggering a DEBUG_NET_WARN_ON_ONCE assertion in skb_dst_check_unset(): WARNING: at skb_dst_check_unset include/linux/skbuff.h:1170 WARNING: at skb_dst_set_noref include/linux/skbuff.h:1234 WARNING: at nf_flow_offload_ip_hook+0xf6c/0x2b60 net/netfilter/nf_flow_table_ip.c:864 Drop any existing dst_entry reference with skb_dst_drop(skb) before setting the non-referenced flowtable destination.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref()\n\nIncoming skbs passing through netfilter flowtable offload hooks (or XFRM\noffload path) might already carry a ref-counted dst_entry assigned during\nearlier RX or routing steps.\n\nCalling skb_dst_set_noref() when skb already holds a ref-counted dst\noverwrites skb->_skb_refdst, leaking the previous dst_entry reference\ncount and triggering a DEBUG_NET_WARN_ON_ONCE assertion in\nskb_dst_check_unset():\n\n WARNING: at skb_dst_check_unset include/linux/skbuff.h:1170\n WARNING: at skb_dst_set_noref include/linux/skbuff.h:1234\n WARNING: at nf_flow_offload_ip_hook+0xf6c/0x2b60 net/netfilter/nf_flow_table_ip.c:864\n\nDrop any existing dst_entry reference with skb_dst_drop(skb) before\nsetting the non-referenced flowtable destination.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00426, EPSS Percentile is 0.36256 |
debian: CVE-2026-74695 was patched at 2026-08-25
1323.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74696) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: tcp: fix TFO max_qlen accounting across reuseport migration A listener's TCP_FASTOPEN max_qlen stops being accurate and lets through far more pending Fast Open requests than it was configured for. This only shows up with SO_REUSEPORT listener migration, where closing a listener hands its still-pending TFO children over to a surviving one. fastopenq.qlen is charged in tcp_fastopen_create_child() when the child is created and uncharged in reqsk_fastopen_remove() when the handshake completes. The uncharge follows rsk_listener of the request the child points at, and inet_reqsk_clone() has repointed the child at a new request owned by the new listener, so the ++ and the -- land on two different sockets. The new listener's qlen drifts negative and its limit no longer binds. Charge the new listener during migration, like reqsk_queue_migrated() already does for queue->young and queue->qlen.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: fix TFO max_qlen accounting across reuseport migration\n\nA listener's TCP_FASTOPEN max_qlen stops being accurate and lets through\nfar more pending Fast Open requests than it was configured for.\n\nThis only shows up with SO_REUSEPORT listener migration, where closing a\nlistener hands its still-pending TFO children over to a surviving one.\n\nfastopenq.qlen is charged in tcp_fastopen_create_child() when the child\nis created and uncharged in reqsk_fastopen_remove() when the handshake\ncompletes. The uncharge follows rsk_listener of the request the child\npoints at, and inet_reqsk_clone() has repointed the child at a new\nrequest owned by the new listener, so the ++ and the -- land on two\ndifferent sockets. The new listener's qlen drifts negative and its\nlimit no longer binds.\n\nCharge the new listener during migration, like reqsk_queue_migrated()\nalready does for queue->young and queue->qlen.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0049, EPSS Percentile is 0.4094 |
debian: CVE-2026-74696 was patched at 2026-08-25
oraclelinux: CVE-2026-74696 was patched at 2026-09-04
1324.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74697) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Disable EOP for TPA on all chips to prevent data corruption EOP (End of frame padding) on the AGG ring may cause overlapping of zero padding at the end of one segment with the next segment's data. If Relaxed Ordering (RO) is enabled, the zero padding may overwrite valid data in the next segment and corrupt the data. Older chips (P5 and older) do not automatically disable RO when EOP is enabled. On some ARM systems, data corruption was reported on 57508 (P5) chips with RO enabled. Always disable EOP on all chips on the AGG rings when TPA is enabled to fix the data corruption.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Disable EOP for TPA on all chips to prevent data corruption\n\nEOP (End of frame padding) on the AGG ring may cause overlapping of\nzero padding at the end of one segment with the next segment's data.\nIf Relaxed Ordering (RO) is enabled, the zero padding may overwrite\nvalid data in the next segment and corrupt the data. Older chips\n(P5 and older) do not automatically disable RO when EOP is enabled.\nOn some ARM systems, data corruption was reported on 57508 (P5)\nchips with RO enabled.\n\nAlways disable EOP on all chips on the AGG rings when TPA is enabled\nto fix the data corruption.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00433, EPSS Percentile is 0.36845 |
debian: CVE-2026-74697 was patched at 2026-08-25
oraclelinux: CVE-2026-74697 was patched at 2026-09-04
1325.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74704) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter The sch_cake ACK filter parses packets to find the TCP header and filter duplicated ACKs if the flow is backlogged. The parsing code contains a WARN_ON(1) which can be triggered by a malformed IP header in certain cases. Depending on the system configuration, this leads either to either spamming dmesg with warnings, or a panic if panic_on_warn is set. The code already correctly skips the offending packet in the branch that triggers the warning, so the WARN_ON itself doesn't really serve any purpose. So just drop it altogether to avoid the inconvenient side effects.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter\n\nThe sch_cake ACK filter parses packets to find the TCP header and filter\nduplicated ACKs if the flow is backlogged. The parsing code contains a\nWARN_ON(1) which can be triggered by a malformed IP header in certain\ncases. Depending on the system configuration, this leads either to\neither spamming dmesg with warnings, or a panic if panic_on_warn is set.\n\nThe code already correctly skips the offending packet in the branch that\ntriggers the warning, so the WARN_ON itself doesn't really serve any\npurpose. So just drop it altogether to avoid the inconvenient side\neffects.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00443, EPSS Percentile is 0.37697 |
debian: CVE-2026-74704 was patched at 2026-08-25
oraclelinux: CVE-2026-74704 was patched at 2026-09-04
1326.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74717) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fw_tracer, return NULL on create error Tracer creation can fail by returning either NULL or ERR_PTR. The return value is stored without a check on the device, and users treat ERR_PTR and NULL the same way. This also causes a crash in the core dump logic, which is missing the ERR_PTR check and ends up dereferencing it, as shown in the trace below. Switch tracer creation to return NULL on failure only, so callers only need a single NULL check. Internal error: Oops: 0000000096000006 [#1] SMP Modules linked in: mlx5_ib ib_uverbs ib_core ipv6 mlx5_core CPU: 1 UID: 0 PID: 12 Comm: kworker/u16:0 Not tainted 6.19.7 #1 PREEMPT(none) Workqueue: mlx5_health0001:01:00.0 mlx5_fw_reporter_err_work [mlx5_core] pstate: a3400009 (NzCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--) pc : mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core] lr : mlx5_fw_tracer_trigger_core_dump_general+0x40/0xe0 [mlx5_core] sp : ffff800081cf3c40 x29: ffff800081cf3c90 x28: 0000000000000000 x27: 0000000000000000 x26: ffff000080018828 x25: 0000000000000000 x24: ffff000080304a05 x23: ffff800081cf3d80 x22: ffff0000847e01a0 x21: 0000000000000000 x20: ffff0000847e01a0 x19: ffffffffffffffa1 x18: ffff80008310bbf0 x17: ffff800080119650 x16: ffff80008010df54 x15: ffff80008010d4ac x14: ffff800079c202e4 x13: ffff80008002fe60 x12: ffff800080119650 x11: ffff80008010df54 x10: ffff80008010d4ac x9 : ffff800079c203d8 x8 : ffff800081cf3c88 x7 : 0000000000000000 x6 : 0000000000000000 x5 : 0000000000000000 x4 : 0000000000000008 x3 : 0000000000000030 x2 : 0000000000000008 x1 : 0000000000000000 x0 : 00000000c5c4000e Call trace: mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core] (P) mlx5_fw_reporter_dump+0x30/0x2e0 [mlx5_core] devlink_health_do_dump+0x9c/0x160 devlink_health_report+0x1c0/0x288 mlx5_fw_reporter_err_work+0xac/0xc0 [mlx5_core] process_one_work+0x15c/0x3d8 worker_thread+0x18c/0x320 kthread+0x148/0x228 ret_from_fork+0x10/0x20 Code: b9400000 5ac00800 7a401800 540003ca (3940a260) ---[ end trace 0000000000000000 ]--- Kernel panic - not syncing: Oops: Fatal exception SMP: stopping secondary CPUs Kernel Offset: disabled CPU features: 0x000000,00078031,75fce5a1,35fffe67 Memory Limit: none ---[ end Kernel panic - not syncing: Oops: Fatal exception ]---', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: fw_tracer, return NULL on create error\n\nTracer creation can fail by returning either NULL or ERR_PTR.\nThe return value is stored without a check on the device, and users\ntreat ERR_PTR and NULL the same way.\nThis also causes a crash in the core dump logic, which is missing the\nERR_PTR check and ends up dereferencing it, as shown in the trace below.\n\nSwitch tracer creation to return NULL on failure only, so callers only\nneed a single NULL check.\n\n Internal error: Oops: 0000000096000006 [#1] SMP\n Modules linked in: mlx5_ib ib_uverbs ib_core ipv6 mlx5_core\n CPU: 1 UID: 0 PID: 12 Comm: kworker/u16:0 Not tainted 6.19.7 #1 PREEMPT(none)\n Workqueue: mlx5_health0001:01:00.0 mlx5_fw_reporter_err_work [mlx5_core]\n pstate: a3400009 (NzCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\n pc : mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core]\n lr : mlx5_fw_tracer_trigger_core_dump_general+0x40/0xe0 [mlx5_core]\n sp : ffff800081cf3c40\n x29: ffff800081cf3c90 x28: 0000000000000000 x27: 0000000000000000\n x26: ffff000080018828 x25: 0000000000000000 x24: ffff000080304a05\n x23: ffff800081cf3d80 x22: ffff0000847e01a0 x21: 0000000000000000\n x20: ffff0000847e01a0 x19: ffffffffffffffa1 x18: ffff80008310bbf0\n x17: ffff800080119650 x16: ffff80008010df54 x15: ffff80008010d4ac\n x14: ffff800079c202e4 x13: ffff80008002fe60 x12: ffff800080119650\n x11: ffff80008010df54 x10: ffff80008010d4ac x9 : ffff800079c203d8\n x8 : ffff800081cf3c88 x7 : 0000000000000000 x6 : 0000000000000000\n x5 : 0000000000000000 x4 : 0000000000000008 x3 : 0000000000000030\n x2 : 0000000000000008 x1 : 0000000000000000 x0 : 00000000c5c4000e\n Call trace:\n mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core] (P)\n mlx5_fw_reporter_dump+0x30/0x2e0 [mlx5_core]\n devlink_health_do_dump+0x9c/0x160\n devlink_health_report+0x1c0/0x288\n mlx5_fw_reporter_err_work+0xac/0xc0 [mlx5_core]\n process_one_work+0x15c/0x3d8\n worker_thread+0x18c/0x320\n kthread+0x148/0x228\n ret_from_fork+0x10/0x20\n Code: b9400000 5ac00800 7a401800 540003ca (3940a260)\n ---[ end trace 0000000000000000 ]---\n Kernel panic - not syncing: Oops: Fatal exception\n SMP: stopping secondary CPUs\n Kernel Offset: disabled\n CPU features: 0x000000,00078031,75fce5a1,35fffe67\n Memory Limit: none\n ---[ end Kernel panic - not syncing: Oops: Fatal exception ]---', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00501, EPSS Percentile is 0.41679 |
debian: CVE-2026-74717 was patched at 2026-08-25
oraclelinux: CVE-2026-74717 was patched at 2026-09-04
1327.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74742) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: veth: fix queue index used to wake the peer txq in veth_poll veth_poll() derives the index of the peer TX queue to wake from rq->xdp_rxq.queue_index. That field is only initialized by xdp_rxq_info_reg() in veth_enable_xdp_range(), which runs only when an XDP program is attached. On the plain GRO/NAPI path (veth_napi_enable_range()) xdp_rxq_info_reg() is never called, so queue_index stays 0 for every queue, as priv->rq is zero-allocated. So in a multi-queue setup with GRO enabled and no XDP program attached, every NAPI instance looks at the peer's TX queue 0. If veth_xmit() stops peer TX queue 1 because the ptr_ring is full (NETDEV_TX_BUSY), nothing ever wakes it again: the poller draining queue 1 wakes queue 0 instead. veth implements no ndo_tx_timeout, so the netdev watchdog does not kick in either, and the queue stays stopped indefinitely. Derive the index from the position of the rq within priv->rq instead, which is correct regardless of whether XDP was ever enabled. Scripts to reproduce the stall are available at https://github.com/netoptimizer/veth-backpressure-performance-testing', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nveth: fix queue index used to wake the peer txq in veth_poll\n\nveth_poll() derives the index of the peer TX queue to wake from\nrq->xdp_rxq.queue_index. That field is only initialized by\nxdp_rxq_info_reg() in veth_enable_xdp_range(), which runs only when an\nXDP program is attached. On the plain GRO/NAPI path\n(veth_napi_enable_range()) xdp_rxq_info_reg() is never called, so\nqueue_index stays 0 for every queue, as priv->rq is zero-allocated.\n\nSo in a multi-queue setup with GRO enabled and no XDP program attached,\nevery NAPI instance looks at the peer's TX queue 0. If veth_xmit() stops\npeer TX queue 1 because the ptr_ring is full (NETDEV_TX_BUSY), nothing\never wakes it again: the poller draining queue 1 wakes queue 0 instead.\nveth implements no ndo_tx_timeout, so the netdev watchdog does not kick\nin either, and the queue stays stopped indefinitely.\n\nDerive the index from the position of the rq within priv->rq instead,\nwhich is correct regardless of whether XDP was ever enabled.\n\nScripts to reproduce the stall are available at\nhttps://github.com/netoptimizer/veth-backpressure-performance-testing', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00466, EPSS Percentile is 0.39301 |
debian: CVE-2026-74742 was patched at 2026-09-16
1328.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80527) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ceph: fix hanging __ceph_get_caps() with stale mds_wanted A reader can hang forever in __ceph_get_caps() when the client no longer holds `FILE_RD`, but local cap state still says that the capability is already wanted (via `mds_wanted`). One way to trigger this is through MDS cap revocation. If another client performs a conflicting operation, the MDS can revoke `FILE_RD` from the reader; the next read then has to reacquire `FILE_RD`. If the cap update that should request `FILE_RD` never reaches the MDS after `cap->mds_wanted` was raised, the reader is left holding only non-file caps while local `mds_wanted` still includes the file read caps. In that state, try_get_cap_refs() sees `need <= mds_wanted` and returns 0, so __ceph_get_caps() just waits on `i_cap_wq`. If the cap update that was supposed to request `FILE_RD never reaches the MDS after `cap->mds_wanted was` raised, no further request is sent and the waiter can sleep indefinitely until unrelated cap traffic happens to wake it up. The ordering issue is that `cap->mds_wanted` is updated in __prep_cap() before the `CEPH_MSG_CLIENT_CAPS message` is actually queued for send. That makes one field serve two different meanings at once: what this client wants, and what the client believes the MDS already knows it wants. A proper fix would be to split those states and track whether a cap update is actually in flight or has been observed by the MDS. However, simply moving the `cap->mds_wanted assignment` later would not be sufficient: queueing the message in the messenger does not guarantee that the MDS processed that specific wanted set, and reconnect or message loss can still invalidate that assumption. Fixing that properly would require a larger rework of the cap state machine. To allow simpler backports to stable kernels, this patch implements a simpler workaround: - stop waiting forever in __ceph_get_caps(); after a bounded wait, fall back to the renew path - make ceph_renew_caps() issue a synchronous `OPEN` request whenever the inode still does not actually hold the wanted caps, instead of only calling ceph_check_caps() The extra issued-vs-wanted check in ceph_renew_caps() is necessary because the previous test only checked whether the inode still had any real caps at all. That is not enough after revocation: the client can still hold something like `pLs` and yet be missing `FILE_RD` completely. In that case, falling back to ceph_check_caps() is not sufficient, because it still trusts `cap->mds_wanted` and may resend nothing. By requiring `(issued & wanted) == wanted` before taking the asynchronous path, the code only uses ceph_check_caps() when the `wanted caps` are already actually issued. Otherwise, it sends the synchronous `OPEN` renew. This preserves the existing asynchronous fast path when the wanted caps are already issued, avoids changing cap-state semantics, and fixes the hang by guaranteeing that a stalled waiter eventually retries through a path that does not rely on the stale `mds_wanted` state. [ idryomov: move CEPH_GET_CAPS_WAIT_TIMEOUT from libceph.h to mds_client.h, formatting ]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix hanging __ceph_get_caps() with stale mds_wanted\n\nA reader can hang forever in __ceph_get_caps() when the client no\nlonger holds `FILE_RD`, but local cap state still says that the\ncapability is already wanted (via `mds_wanted`).\n\nOne way to trigger this is through MDS cap revocation. If another\nclient performs a conflicting operation, the MDS can revoke `FILE_RD`\nfrom the reader; the next read then has to reacquire `FILE_RD`. If\nthe cap update that should request `FILE_RD` never reaches the MDS\nafter `cap->mds_wanted` was raised, the reader is left holding only\nnon-file caps while local `mds_wanted` still includes the file read\ncaps.\n\nIn that state, try_get_cap_refs() sees `need <= mds_wanted` and\nreturns 0, so __ceph_get_caps() just waits on `i_cap_wq`. If the cap\nupdate that was supposed to request `FILE_RD never reaches the MDS\nafter `cap->mds_wanted was` raised, no further request is sent and the\nwaiter can sleep indefinitely until unrelated cap traffic happens to\nwake it up.\n\nThe ordering issue is that `cap->mds_wanted` is updated in\n__prep_cap() before the `CEPH_MSG_CLIENT_CAPS message` is actually\nqueued for send. That makes one field serve two different meanings at\nonce: what this client wants, and what the client believes the MDS\nalready knows it wants.\n\nA proper fix would be to split those states and track whether a cap\nupdate is actually in flight or has been observed by the MDS.\nHowever, simply moving the `cap->mds_wanted assignment` later would\nnot be sufficient: queueing the message in the messenger does not\nguarantee that the MDS processed that specific wanted set, and\nreconnect or message loss can still invalidate that assumption.\nFixing that properly would require a larger rework of the cap state\nmachine.\n\nTo allow simpler backports to stable kernels, this patch implements a\nsimpler workaround:\n\n- stop waiting forever in __ceph_get_caps(); after a bounded wait,\n fall back to the renew path\n\n- make ceph_renew_caps() issue a synchronous `OPEN` request whenever\n the inode still does not actually hold the wanted caps, instead of\n only calling ceph_check_caps()\n\nThe extra issued-vs-wanted check in ceph_renew_caps() is necessary\nbecause the previous test only checked whether the inode still had any\nreal caps at all. That is not enough after revocation: the client can\nstill hold something like `pLs` and yet be missing `FILE_RD`\ncompletely. In that case, falling back to ceph_check_caps() is not\nsufficient, because it still trusts `cap->mds_wanted` and may resend\nnothing. By requiring `(issued & wanted) == wanted` before taking the\nasynchronous path, the code only uses ceph_check_caps() when the\n`wanted caps` are already actually issued. Otherwise, it sends the\nsynchronous `OPEN` renew.\n\nThis preserves the existing asynchronous fast path when the wanted\ncaps are already issued, avoids changing cap-state semantics, and\nfixes the hang by guaranteeing that a stalled waiter eventually\nretries through a path that does not rely on the stale `mds_wanted`\nstate.\n\n[ idryomov: move CEPH_GET_CAPS_WAIT_TIMEOUT from libceph.h to\n mds_client.h, formatting ]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00508, EPSS Percentile is 0.42107 |
debian: CVE-2026-80527 was patched at 2026-09-16
oraclelinux: CVE-2026-80527 was patched at 2026-09-04
1329.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80637) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: fix unaligned memory access in timestamp adjustment Use get_unaligned_be32() and put_unaligned_be32() to safely read and write the timestamp fields. This prevents performance degradation due to unaligned memory access or even a crash on strict alignment architectures. This follows the implementation of timestamp parsing in the networking stack at tcp_parse_options() and synproxy_parse_options().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: synproxy: fix unaligned memory access in timestamp adjustment\n\nUse get_unaligned_be32() and put_unaligned_be32() to safely read and\nwrite the timestamp fields. This prevents performance degradation due to\nunaligned memory access or even a crash on strict alignment\narchitectures.\n\nThis follows the implementation of timestamp parsing in the networking\nstack at tcp_parse_options() and synproxy_parse_options().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00446, EPSS Percentile is 0.37943 |
debian: CVE-2026-80637 was patched at 2026-09-16
1330.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80646) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipv6: guard against possible NULL deref in __in6_dev_stats_get() dev_get_by_index_rcu() could return NULL if the original physical device is unregistered. Found by Sashiko.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: guard against possible NULL deref in __in6_dev_stats_get()\n\ndev_get_by_index_rcu() could return NULL if the original physical\ndevice is unregistered.\n\nFound by Sashiko.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00508, EPSS Percentile is 0.42107 |
debian: CVE-2026-80646 was patched at 2026-09-16
oraclelinux: CVE-2026-80646 was patched at 2026-09-04
redos: CVE-2026-80646 was patched at 2026-09-16
1331.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80691) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE In the iblock_execute_pr_out() function, PRO_PREEMPT, PRO_PREEMPT_AND_ABORT, and PRO_RELEASE all perform callback capability checks through ops->pr_clear. The error check allows unimplemented hooks to pass through the gate, resulting dereferencing a NULL function pointer. Check whether the hooks that need to be called are supported.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE\n\nIn the iblock_execute_pr_out() function, PRO_PREEMPT,\nPRO_PREEMPT_AND_ABORT, and PRO_RELEASE all perform callback capability\nchecks through ops->pr_clear. The error check allows unimplemented hooks\nto pass through the gate, resulting dereferencing a NULL function\npointer.\n\nCheck whether the hooks that need to be called are supported.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00446, EPSS Percentile is 0.37943 |
debian: CVE-2026-80691 was patched at 2026-09-16
1332.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80987) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_transport: Reject oversized TX buffers ntb_process_tx() handles an oversized buffer by calling tx_handler() with a NULL data pointer and returning success. ntb_netdev therefore neither frees the skb in its completion callback nor takes its enqueue error path, leaking it. Reject oversized buffers in ntb_transport_tx_enqueue() before acquiring a queue entry and return -EMSGSIZE. The caller retains ownership of the buffer, and the preceding netdev patch frees the skb when enqueue returns this permanent error.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nNTB: ntb_transport: Reject oversized TX buffers\n\nntb_process_tx() handles an oversized buffer by calling tx_handler()\nwith a NULL data pointer and returning success. ntb_netdev therefore\nneither frees the skb in its completion callback nor takes its enqueue\nerror path, leaking it.\n\nReject oversized buffers in ntb_transport_tx_enqueue() before acquiring\na queue entry and return -EMSGSIZE. The caller retains ownership of the\nbuffer, and the preceding netdev patch frees the skb when enqueue\nreturns this permanent error.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00508, EPSS Percentile is 0.42108 |
debian: CVE-2026-80987 was patched at 2026-09-16
1333.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80989) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Mark the connection down when bringing it up fails Every failure path in tbnet_connected_work() undoes its own work and returns without clearing login_sent, so the connection still looks established. The next tbnet_tear_down() therefore takes its main branch and repeats a teardown that already happened: it stops rings that are already stopped, which is a dev_WARN() and fatal under panic_on_warn, and it releases net->remote_transmit_path even on the HopID mismatch path, where this connection never owned that id, silently freeing one that someone else is still using. Clear login_sent on those paths. That is enough for tbnet_tear_down() to leave the unwound state alone, and login_received has to stay set: it records that the peer has logged in and carries the transmit path it gave us, which nothing on this side can make the peer send again. Two things change beyond keeping the teardown out of the way: the logout request in that block is no longer sent, and the peer's next login request now re-queues our login work rather than connected_work, giving the connection a fresh login instead of a retry on stale state.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: thunderbolt: Mark the connection down when bringing it up fails\n\nEvery failure path in tbnet_connected_work() undoes its own work and\nreturns without clearing login_sent, so the connection still looks\nestablished. The next tbnet_tear_down() therefore takes its main branch\nand repeats a teardown that already happened: it stops rings that are\nalready stopped, which is a dev_WARN() and fatal under panic_on_warn,\nand it releases net->remote_transmit_path even on the HopID mismatch\npath, where this connection never owned that id, silently freeing one\nthat someone else is still using.\n\nClear login_sent on those paths. That is enough for tbnet_tear_down() to\nleave the unwound state alone, and login_received has to stay set: it\nrecords that the peer has logged in and carries the transmit path it gave\nus, which nothing on this side can make the peer send again. Two things\nchange beyond keeping the teardown out of the way: the logout request in\nthat block is no longer sent, and the peer's next login request now\nre-queues our login work rather than connected_work, giving the\nconnection a fresh login instead of a retry on stale state.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00338, EPSS Percentile is 0.2706 |
debian: CVE-2026-80989 was patched at 2026-09-16
1334.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89477) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: sctp: fix NULL deref on untransmitted RECONF completion sctp_process_strreset_outreq(), sctp_process_strreset_addstrm_out() and sctp_process_strreset_resp() complete a pending stream reconfiguration request by stopping the reconf timer on the transport it was sent on: \tt = asoc->strreset_chunk->transport; \tif (timer_delete(&t->reconf_timer)) \t\tsctp_transport_put(t); chunk->transport is assigned by __sctp_packet_append_chunk() when the chunk is appended to an outbound packet, and sctp_outq_flush_ctrl() arms the reconf timer at that same point. A request already published in asoc->strreset_chunk but not yet transmitted has neither, so completing it dereferences NULL. Two ways to get there. sctp_send_asconf_del_ip() sets asoc->src_out_of_asoc_ok without sending anything when the address being removed is the association's last one, and sctp_outq_flush_ctrl() then leaves every non-ASCONF control chunk queued; as only sctp_process_asconf_ack() clears that flag, it persists. An unprivileged process that removes such an address and then asks for a stream reset panics the kernel from softirq. A peer needs neither ASCONF nor local help: sctp_cmd_interpreter() uncorks the outqueue only once the whole packet has been processed, so a reply built while walking a RECONF chunk stays untransmitted for the rest of that walk, and one RECONF chunk carrying [Incoming SSN Reset Request, Outgoing SSN Reset Request, Response] -- or two RECONF chunks in one packet -- reaches the same dereference. KASAN: null-ptr-deref in range [0x00000000000001e8-0x00000000000001ef] RIP: 0010:timer_delete+0x67/0x110 Call Trace: <IRQ> sctp_process_strreset_addstrm_out (net/sctp/stream.c:832) sctp_sf_do_reconf (net/sctp/sm_statefuns.c:4212) sctp_do_sm (net/sctp/sm_sideeffect.c:1172) sctp_assoc_bh_rcv (net/sctp/associola.c:1044) sctp_rcv (net/sctp/input.c:243) ip_local_deliver (net/ipv4/ip_input.c:262) process_backlog (net/core/dev.c:6680) </IRQ> A response can only acknowledge a request that was actually sent, so do not match asoc->strreset_chunk while chunk->transport is NULL. Guarding the lookup covers all three completion sites.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix NULL deref on untransmitted RECONF completion\n\nsctp_process_strreset_outreq(), sctp_process_strreset_addstrm_out() and\nsctp_process_strreset_resp() complete a pending stream reconfiguration\nrequest by stopping the reconf timer on the transport it was sent on:\n\n\tt = asoc->strreset_chunk->transport;\n\tif (timer_delete(&t->reconf_timer))\n\t\tsctp_transport_put(t);\n\nchunk->transport is assigned by __sctp_packet_append_chunk() when the\nchunk is appended to an outbound packet, and sctp_outq_flush_ctrl() arms\nthe reconf timer at that same point. A request already published in\nasoc->strreset_chunk but not yet transmitted has neither, so completing\nit dereferences NULL.\n\nTwo ways to get there. sctp_send_asconf_del_ip() sets\nasoc->src_out_of_asoc_ok without sending anything when the address being\nremoved is the association's last one, and sctp_outq_flush_ctrl() then\nleaves every non-ASCONF control chunk queued; as only\nsctp_process_asconf_ack() clears that flag, it persists. An unprivileged\nprocess that removes such an address and then asks for a stream reset\npanics the kernel from softirq. A peer needs neither ASCONF nor local\nhelp: sctp_cmd_interpreter() uncorks the outqueue only once the whole\npacket has been processed, so a reply built while walking a RECONF chunk\nstays untransmitted for the rest of that walk, and one RECONF chunk\ncarrying [Incoming SSN Reset Request, Outgoing SSN Reset Request,\nResponse] -- or two RECONF chunks in one packet -- reaches the same\ndereference.\n\n KASAN: null-ptr-deref in range [0x00000000000001e8-0x00000000000001ef]\n RIP: 0010:timer_delete+0x67/0x110\n Call Trace:\n <IRQ>\n sctp_process_strreset_addstrm_out (net/sctp/stream.c:832)\n sctp_sf_do_reconf (net/sctp/sm_statefuns.c:4212)\n sctp_do_sm (net/sctp/sm_sideeffect.c:1172)\n sctp_assoc_bh_rcv (net/sctp/associola.c:1044)\n sctp_rcv (net/sctp/input.c:243)\n ip_local_deliver (net/ipv4/ip_input.c:262)\n process_backlog (net/core/dev.c:6680)\n </IRQ>\n\nA response can only acknowledge a request that was actually sent, so do\nnot match asoc->strreset_chunk while chunk->transport is NULL. Guarding\nthe lookup covers all three completion sites.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00508, EPSS Percentile is 0.42108 |
debian: CVE-2026-89477 was patched at 2026-09-16
1335.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89480) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: reject a read that transferred too few bytes nvme_tcp_recv_data() completes a request once the current C2HData PDU has been consumed. Nothing compares the total bytes received against the length the command asked for: struct nvme_tcp_request has no receive-side counter, queue->data_remaining is per queue, and blk_mq_end_request() completes for blk_rq_bytes(rq) unconditionally with no residual concept anywhere above. A controller can therefore answer a 4096-byte read with 512 bytes and have it reported as a complete read; user space then gets 4096 bytes of which 3584 are whatever was already in the page. I reproduced that with a test target. Count the bytes received and refuse to complete a successful read whose count does not match, at the two NVME_TCP_F_DATA_SUCCESS paths and in nvme_tcp_process_nvme_cqe(). The success test shifts req->status right by one, because the driver keeps the wire value there and shifts it on completion, so the check must see what the completion path will see. Only REQ_OP_READ is checked, because there the length comes from the sectors the request covers; a passthrough command is built by its submitter, which picks both command and buffer, so the kernel has nothing to compare against.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-tcp: reject a read that transferred too few bytes\n\nnvme_tcp_recv_data() completes a request once the current C2HData PDU\nhas been consumed. Nothing compares the total bytes received against\nthe length the command asked for: struct nvme_tcp_request has no\nreceive-side counter, queue->data_remaining is per queue, and\nblk_mq_end_request() completes for blk_rq_bytes(rq) unconditionally\nwith no residual concept anywhere above.\n\nA controller can therefore answer a 4096-byte read with 512 bytes and\nhave it reported as a complete read; user space then gets 4096 bytes of\nwhich 3584 are whatever was already in the page. I reproduced that with\na test target.\n\nCount the bytes received and refuse to complete a successful read whose\ncount does not match, at the two NVME_TCP_F_DATA_SUCCESS paths and in\nnvme_tcp_process_nvme_cqe(). The success test shifts req->status right\nby one, because the driver keeps the wire value there and shifts it on\ncompletion, so the check must see what the completion path will see.\nOnly REQ_OP_READ is checked, because there the length comes from the\nsectors the request covers; a passthrough command is built by its\nsubmitter, which picks both command and buffer, so the kernel has\nnothing to compare against.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00415, EPSS Percentile is 0.35227 |
debian: CVE-2026-89480 was patched at 2026-09-16
1336.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89483) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nvme: zero the discard fallback page nvme_setup_discard() always maps sizeof(struct nvme_dsm_range) * NVME_DSM_MAX_RANGES = 4096 bytes as the DSM payload however many ranges the command declares, because some devices ignore the 'Number of Ranges' field - the Fixes: commit records two that read past the declared ranges. A single-range discard fills only the first 16 bytes. Normally the buffer comes from kzalloc() and the other 4080 bytes are zero. When that allocation fails the code falls back to the per-controller ctrl->discard_page, which nvme_init_ctrl() obtains with alloc_page(GFP_KERNEL) and nothing ever zeroes, so those 4080 bytes are whatever the page last held and are handed to the controller. Reaching it requires the kzalloc(GFP_ATOMIC | __GFP_NOWARN) to fail, that is memory pressure; it is not remotely triggerable. Failing the allocation under KMSAN reproduces it, with the leaked tail full of vmemmap struct page pointers. The extent in the report is a partial transfer of the payload, not the whole 4096 bytes; the 16-byte boundary in it is the one declared range: [ 11.991601] BUG: KMSAN: uninit-value in dma_map_phys+0x14c8/0x1900 [ 11.991969] dma_map_phys+0x14c8/0x1900 [ 11.992220] dma_map_page_attrs+0xcf/0x130 [ 11.992485] e1000_xmit_frame+0x4099/0x6d10 [ 11.992768] dev_hard_start_xmit+0x22f/0xa80 [ 11.993068] sch_direct_xmit+0x35c/0xcb0 [ 11.993315] __dev_queue_xmit+0x1ee5/0x5eb0 [ 11.993608] ip_finish_output2+0x1903/0x1c30 [ 11.993881] ip_finish_output+0x288/0x870 [ 11.994125] ip_output+0x15e/0x400 [ 11.994365] __ip_queue_xmit+0x1e85/0x1fb0 [ 11.994639] ip_queue_xmit+0x60/0x80 [ 11.994899] __tcp_transmit_skb+0x4e71/0x5fa0 [ 11.995210] tcp_write_xmit+0x3a36/0x9160 [ 11.995533] __tcp_push_pending_frames+0xc5/0x3c0 [ 11.995854] tcp_push+0x7dc/0x840 [ 11.996076] tcp_sendmsg_locked+0x766c/0x8400 [ 11.996371] tcp_sendmsg+0x4b/0x90 [ 11.996572] inet_sendmsg+0x134/0x2a0 [ 11.996823] __sock_sendmsg+0x265/0x360 [ 11.997076] sock_sendmsg+0x100/0x1e0 [ 11.997293] nvme_tcp_try_send+0x196f/0x6370 [ 11.997605] nvme_tcp_queue_rq+0x1d54/0x20b0 [ 11.997882] blk_mq_dispatch_rq_list+0x5ee/0x2e50 [ 11.998175] __blk_mq_sched_dispatch_requests+0x16dc/0x24a0 [ 11.998539] blk_mq_sched_dispatch_requests+0x11b/0x2c0 [ 11.998865] blk_mq_run_work_fn+0x13b/0x280 [ 11.999146] process_scheduled_works+0x966/0x1ad0 [ 11.999465] worker_thread+0xe44/0x1480 [ 11.999709] kthread+0x53b/0x600 [ 11.999927] ret_from_fork+0x29f/0x7c0 [ 12.000191] ret_from_fork_asm+0x1a/0x30 [ 12.000460] [ 12.000558] Uninit was created at: [ 12.000788] __alloc_frozen_pages_noprof+0x8bf/0xd30 [ 12.001096] alloc_pages_mpol+0x1d0/0x5f0 [ 12.001326] alloc_pages_noprof+0x102/0x290 [ 12.001627] nvme_init_ctrl+0x5a3/0x9f0 [ 12.001891] nvme_tcp_create_ctrl+0xd75/0x19b0 [ 12.002170] nvmf_dev_write+0x4c68/0x4fd0 [ 12.002426] vfs_write+0x587/0x1a10 [ 12.002636] __x64_sys_write+0x207/0x4f0 [ 12.002874] x64_sys_call+0x2ff0/0x3ea0 [ 12.003123] do_syscall_64+0x147/0x3b0 [ 12.003400] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 12.003680] [ 12.003777] Bytes 16-2843 of 2844 are uninitialized [ 12.004068] Memory access of size 2844 starts at ffff888109f82000 [ 12.004412] [ 12.004530] CPU: 0 UID: 0 PID: 101 Comm: kworker/0:1H Not tainted 7.2.0-rc5-NVMECTL-gf5098b6bae76 #1 PREEMPT(lazy) [ 12.005127] Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 12.005762] Workqueue: kblockd blk_mq_run_work_fn [ 12.006073] ===================================================== Allocate the page with __GFP_ZERO. The single allocation site covers every use of it: bytes no discard has written stay zero, and bytes one did write hold that controller's own range list, which it has already been sent.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: zero the discard fallback page\n\nnvme_setup_discard() always maps sizeof(struct nvme_dsm_range) *\nNVME_DSM_MAX_RANGES = 4096 bytes as the DSM payload however many ranges\nthe command declares, because some devices ignore the 'Number of Ranges'\nfield - the Fixes: commit records two that read past the declared ranges.\nA single-range discard fills only the first 16 bytes.\n\nNormally the buffer comes from kzalloc() and the other 4080 bytes are\nzero. When that allocation fails the code falls back to the\nper-controller ctrl->discard_page, which nvme_init_ctrl() obtains with\nalloc_page(GFP_KERNEL) and nothing ever zeroes, so those 4080 bytes are\nwhatever the page last held and are handed to the controller. Reaching\nit requires the kzalloc(GFP_ATOMIC | __GFP_NOWARN) to fail, that is\nmemory pressure; it is not remotely triggerable. Failing the allocation\nunder KMSAN reproduces it, with the leaked tail full of vmemmap struct\npage pointers. The extent in the report is a partial transfer of the\npayload, not the whole 4096 bytes; the 16-byte boundary in it is the one\ndeclared range:\n\n[ 11.991601] BUG: KMSAN: uninit-value in dma_map_phys+0x14c8/0x1900\n[ 11.991969] dma_map_phys+0x14c8/0x1900\n[ 11.992220] dma_map_page_attrs+0xcf/0x130\n[ 11.992485] e1000_xmit_frame+0x4099/0x6d10\n[ 11.992768] dev_hard_start_xmit+0x22f/0xa80\n[ 11.993068] sch_direct_xmit+0x35c/0xcb0\n[ 11.993315] __dev_queue_xmit+0x1ee5/0x5eb0\n[ 11.993608] ip_finish_output2+0x1903/0x1c30\n[ 11.993881] ip_finish_output+0x288/0x870\n[ 11.994125] ip_output+0x15e/0x400\n[ 11.994365] __ip_queue_xmit+0x1e85/0x1fb0\n[ 11.994639] ip_queue_xmit+0x60/0x80\n[ 11.994899] __tcp_transmit_skb+0x4e71/0x5fa0\n[ 11.995210] tcp_write_xmit+0x3a36/0x9160\n[ 11.995533] __tcp_push_pending_frames+0xc5/0x3c0\n[ 11.995854] tcp_push+0x7dc/0x840\n[ 11.996076] tcp_sendmsg_locked+0x766c/0x8400\n[ 11.996371] tcp_sendmsg+0x4b/0x90\n[ 11.996572] inet_sendmsg+0x134/0x2a0\n[ 11.996823] __sock_sendmsg+0x265/0x360\n[ 11.997076] sock_sendmsg+0x100/0x1e0\n[ 11.997293] nvme_tcp_try_send+0x196f/0x6370\n[ 11.997605] nvme_tcp_queue_rq+0x1d54/0x20b0\n[ 11.997882] blk_mq_dispatch_rq_list+0x5ee/0x2e50\n[ 11.998175] __blk_mq_sched_dispatch_requests+0x16dc/0x24a0\n[ 11.998539] blk_mq_sched_dispatch_requests+0x11b/0x2c0\n[ 11.998865] blk_mq_run_work_fn+0x13b/0x280\n[ 11.999146] process_scheduled_works+0x966/0x1ad0\n[ 11.999465] worker_thread+0xe44/0x1480\n[ 11.999709] kthread+0x53b/0x600\n[ 11.999927] ret_from_fork+0x29f/0x7c0\n[ 12.000191] ret_from_fork_asm+0x1a/0x30\n[ 12.000460]\n[ 12.000558] Uninit was created at:\n[ 12.000788] __alloc_frozen_pages_noprof+0x8bf/0xd30\n[ 12.001096] alloc_pages_mpol+0x1d0/0x5f0\n[ 12.001326] alloc_pages_noprof+0x102/0x290\n[ 12.001627] nvme_init_ctrl+0x5a3/0x9f0\n[ 12.001891] nvme_tcp_create_ctrl+0xd75/0x19b0\n[ 12.002170] nvmf_dev_write+0x4c68/0x4fd0\n[ 12.002426] vfs_write+0x587/0x1a10\n[ 12.002636] __x64_sys_write+0x207/0x4f0\n[ 12.002874] x64_sys_call+0x2ff0/0x3ea0\n[ 12.003123] do_syscall_64+0x147/0x3b0\n[ 12.003400] entry_SYSCALL_64_after_hwframe+0x77/0x7f\n[ 12.003680]\n[ 12.003777] Bytes 16-2843 of 2844 are uninitialized\n[ 12.004068] Memory access of size 2844 starts at ffff888109f82000\n[ 12.004412]\n[ 12.004530] CPU: 0 UID: 0 PID: 101 Comm: kworker/0:1H Not tainted 7.2.0-rc5-NVMECTL-gf5098b6bae76 #1 PREEMPT(lazy)\n[ 12.005127] Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n[ 12.005762] Workqueue: kblockd blk_mq_run_work_fn\n[ 12.006073] =====================================================\n\nAllocate the page with __GFP_ZERO. The single allocation site covers\nevery use of it: bytes no discard has written stay zero, and bytes one\ndid write hold that controller's own range list, which it has already\nbeen sent.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00555, EPSS Percentile is 0.44885 |
debian: CVE-2026-89483 was patched at 2026-09-16
1337.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89535) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id svc_rdma_free() caches rdma->sc_cm_id->device before teardown, then calls rdma_destroy_id(sc_cm_id) which frees the cm_id. rpcrdma_rn_unregister() follows, but between those two calls the transport's sc_rn entry is still installed in the device's rd_xa. A concurrent ib_unregister_device walk can dispatch svc_rdma_xprt_done() against the now-freed sc_cm_id. Move rpcrdma_rn_unregister() before rdma_destroy_id() so the transport's notification entry is removed from the xarray before the cm_id it references is destroyed. Also guard the sc_cm_id dereference with a NULL check: the following patches introduce paths that reach svc_rdma_free() with sc_cm_id == NULL (listener create failure, ADDR_CHANGE replacement failure).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id\n\nsvc_rdma_free() caches rdma->sc_cm_id->device before teardown,\nthen calls rdma_destroy_id(sc_cm_id) which frees the cm_id.\nrpcrdma_rn_unregister() follows, but between those two calls\nthe transport's sc_rn entry is still installed in the device's\nrd_xa. A concurrent ib_unregister_device walk can dispatch\nsvc_rdma_xprt_done() against the now-freed sc_cm_id.\n\nMove rpcrdma_rn_unregister() before rdma_destroy_id() so the\ntransport's notification entry is removed from the xarray before\nthe cm_id it references is destroyed.\n\nAlso guard the sc_cm_id dereference with a NULL check: the\nfollowing patches introduce paths that reach svc_rdma_free()\nwith sc_cm_id == NULL (listener create failure, ADDR_CHANGE\nreplacement failure).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00512, EPSS Percentile is 0.42401 |
debian: CVE-2026-89535 was patched at 2026-09-16
1338.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89561) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv() ipv6_rpl_srh_rcv() dereferences idev from __in6_dev_get() without a NULL check when reading idev->cnf.rpl_seg_enabled. When the device's MTU drops below IPV6_MIN_MTU, addrconf_ifdown() clears dev->ip6_ptr through RCU_INIT_POINTER(). A packet that passed the idev check in ip6_rcv_core() can then reach ipv6_rpl_srh_rcv() with dev->ip6_ptr already NULL. Reproduced by flooding the receiving interface with ping6 traffic while flapping its MTU between 1500 and 1200: BUG: KASAN: null-ptr-deref in ipv6_rpl_srh_rcv+0xb3/0x1070 Read of size 4 at addr 00000000000006b4 by task ping6/394 CPU: 2 UID: 0 PID: 394 Comm: ping6 Not tainted 7.2.0-rc7-micro-vm-dev-00095-g24ef02f934ee #240 PREEMPT(full) Call Trace: <IRQ> kasan_report+0xc6/0x100 ipv6_rpl_srh_rcv+0xb3/0x1070 ip6_protocol_deliver_rcu+0x759/0x9a0 ip6_input_finish+0xa8/0x1b0 ip6_input+0xe1/0x490 ipv6_rcv+0x33d/0x460 __netif_receive_skb_one_core+0xd6/0x130 process_backlog+0x2cc/0xa00 __napi_poll.constprop.0+0x56/0x270 net_rx_action+0x327/0x730 handle_softirqs+0x11e/0x630 do_softirq+0xb3/0xf0 </IRQ> Both ipv6_rpl_srh_rcv() and ipv6_srh_rcv() are called only from ipv6_rthdr_rcv(), which already has an idev lookup. Fix the NULL dereference on the RPL path by checking idev in ipv6_rthdr_rcv(), before it calls either function. The callees take idev as an argument and no longer call __in6_dev_get(), so the packet is now dropped in one place, with SKB_DROP_REASON_IPV6DISABLED on both paths.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()\n\nipv6_rpl_srh_rcv() dereferences idev from __in6_dev_get() without a NULL\ncheck when reading idev->cnf.rpl_seg_enabled.\n\nWhen the device's MTU drops below IPV6_MIN_MTU, addrconf_ifdown() clears\ndev->ip6_ptr through RCU_INIT_POINTER(). A packet that passed the idev\ncheck in ip6_rcv_core() can then reach ipv6_rpl_srh_rcv() with\ndev->ip6_ptr already NULL.\n\nReproduced by flooding the receiving interface with ping6 traffic while\nflapping its MTU between 1500 and 1200:\n\n BUG: KASAN: null-ptr-deref in ipv6_rpl_srh_rcv+0xb3/0x1070\n Read of size 4 at addr 00000000000006b4 by task ping6/394\n\n CPU: 2 UID: 0 PID: 394 Comm: ping6 Not tainted 7.2.0-rc7-micro-vm-dev-00095-g24ef02f934ee #240 PREEMPT(full)\n Call Trace:\n <IRQ>\n kasan_report+0xc6/0x100\n ipv6_rpl_srh_rcv+0xb3/0x1070\n ip6_protocol_deliver_rcu+0x759/0x9a0\n ip6_input_finish+0xa8/0x1b0\n ip6_input+0xe1/0x490\n ipv6_rcv+0x33d/0x460\n __netif_receive_skb_one_core+0xd6/0x130\n process_backlog+0x2cc/0xa00\n __napi_poll.constprop.0+0x56/0x270\n net_rx_action+0x327/0x730\n handle_softirqs+0x11e/0x630\n do_softirq+0xb3/0xf0\n </IRQ>\n\nBoth ipv6_rpl_srh_rcv() and ipv6_srh_rcv() are called only from\nipv6_rthdr_rcv(), which already has an idev lookup.\n\nFix the NULL dereference on the RPL path by checking idev in\nipv6_rthdr_rcv(), before it calls either function. The callees take idev as\nan argument and no longer call __in6_dev_get(), so the packet is now\ndropped in one place, with SKB_DROP_REASON_IPV6DISABLED on both paths.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00432, EPSS Percentile is 0.36729 |
debian: CVE-2026-89561 was patched at 2026-09-16
1339.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89601) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ext2: Fix lost inode updates for IS_SYNC inodes ext2_setsize() and ext2_xattr_set2() had a construct like: \tif (IS_SYNC(inode)) { \t\tsync_inode_metadata(inode, 1); \t} else { \t\tmark_inode_dirty(inode); \t} which leads to lost inode updates for IS_SYNC inodes because sync_inode_metadata() does anything only if the inode is already dirty and hence inode updates may be simply lost. Fix the problem by unconditionally marking the inode dirty and *then* call sync_inode_metadata().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\next2: Fix lost inode updates for IS_SYNC inodes\n\next2_setsize() and ext2_xattr_set2() had a construct like:\n\n\tif (IS_SYNC(inode)) {\n\t\tsync_inode_metadata(inode, 1);\n\t} else {\n\t\tmark_inode_dirty(inode);\n\t}\n\nwhich leads to lost inode updates for IS_SYNC inodes because\nsync_inode_metadata() does anything only if the inode is already dirty\nand hence inode updates may be simply lost. Fix the problem by\nunconditionally marking the inode dirty and *then* call\nsync_inode_metadata().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00348, EPSS Percentile is 0.2825 |
debian: CVE-2026-89601 was patched at 2026-09-16
1340.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89616) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame() ni_read_frame() decompresses an LZNT $DATA frame into the vmapped target pages and then trusts decompress_lznt()'s return value: unc_size = decompress_lznt(frame_ondisk, ondisk_size, frame_mem, frame_size); if ((ssize_t)unc_size < 0) err = unc_size; else if (!unc_size || unc_size > frame_size) err = -EINVAL; decompress_lznt() stops as soon as the compressed stream is exhausted (e.g. a zero chunk header) and returns the number of bytes it actually wrote, which may be far less than frame_size. The bytes between unc_size and frame_size are never written. The only memset() that follows zeroes the region beyond i_valid; when the frame lies entirely within the file's valid size that memset() does not run, so the gap retains whatever was in the just-vmapped pages. All pages are then marked uptodate and returned to userspace, disclosing uninitialized (recently-freed) kernel page memory. A crafted compressed file whose stream decompresses to only a few bytes leaks the remainder of every frame on a plain read(2), which is enough to recover kernel pointers and defeat KASLR. Zero the [unc_size, frame_size) tail immediately after a successful LZNT decompress so the remainder reads back as zero.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()\n\nni_read_frame() decompresses an LZNT $DATA frame into the vmapped target\npages and then trusts decompress_lznt()'s return value:\n\n unc_size = decompress_lznt(frame_ondisk, ondisk_size, frame_mem,\n frame_size);\n if ((ssize_t)unc_size < 0) err = unc_size;\n else if (!unc_size || unc_size > frame_size) err = -EINVAL;\n\ndecompress_lznt() stops as soon as the compressed stream is exhausted\n(e.g. a zero chunk header) and returns the number of bytes it actually\nwrote, which may be far less than frame_size. The bytes between unc_size\nand frame_size are never written. The only memset() that follows zeroes\nthe region beyond i_valid; when the frame lies entirely within the file's\nvalid size that memset() does not run, so the gap retains whatever was in\nthe just-vmapped pages. All pages are then marked uptodate and returned\nto userspace, disclosing uninitialized (recently-freed) kernel page\nmemory. A crafted compressed file whose stream decompresses to only a few\nbytes leaks the remainder of every frame on a plain read(2), which is\nenough to recover kernel pointers and defeat KASLR.\n\nZero the [unc_size, frame_size) tail immediately after a successful LZNT\ndecompress so the remainder reads back as zero.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00415, EPSS Percentile is 0.35226 |
debian: CVE-2026-89616 was patched at 2026-09-16
1341.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89626) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: HID: sensor: custom: Fix field sysfs group cleanup on failure hid_sensor_custom_add_attributes() creates one sysfs group for each custom sensor field. If sysfs_create_group() fails after some groups have already been created, the function returns the error without removing the previously created groups. Add a local unwind path to remove the groups that were already created. With enable_sensor exposed only after the field attributes are ready, this path can free sensor_inst->fields without leaving enable_sensor able to access pointers into that array.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nHID: sensor: custom: Fix field sysfs group cleanup on failure\n\nhid_sensor_custom_add_attributes() creates one sysfs group for each\ncustom sensor field. If sysfs_create_group() fails after some groups\nhave already been created, the function returns the error without\nremoving the previously created groups.\n\nAdd a local unwind path to remove the groups that were already created.\nWith enable_sensor exposed only after the field attributes are ready,\nthis path can free sensor_inst->fields without leaving enable_sensor\nable to access pointers into that array.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00349, EPSS Percentile is 0.28382 |
debian: CVE-2026-89626 was patched at 2026-09-16
1342.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89667) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache The shrinker, GC worker, and fsnotify/lease callbacks can unhash an nfsd_file from the rhashtable and then call nfsd_file_dispose_list_delayed() to move it to the per-net dispose list. If nfsd_file_cache_shutdown_net() runs concurrently, its rhashtable walk misses the already-unhashed file, and its drain of the per-net dispose list can run before the file has been queued. The file then sits on the per-net list with no thread to drain it, leaking both the file and its associated state. The GC worker and shrinker already hold nfsd_gc_lock while walking the LRU, but in the original code they release it before calling nfsd_file_dispose_list_delayed(). The fsnotify/lease path (nfsd_file_close_inode) has no synchronization at all. Fix this by: 1. Widening nfsd_gc_lock in both nfsd_file_gc() and nfsd_file_lru_scan() to cover the nfsd_file_dispose_list_delayed() call. 2. Wrapping nfsd_file_close_inode() in nfsd_gc_lock so that all three callers of nfsd_file_dispose_list_delayed() hold the lock. 3. Adding a spin_lock/unlock(nfsd_gc_lock) barrier in nfsd_file_cache_shutdown_net() after the purge, so that any in-progress disposal has fully completed before the per-net list is drained. All operations inside the lock are non-sleeping (rhashtable lookups, atomic bit/refcount ops, list moves, svc_wake_up), so the spinlock is appropriate.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache\n\nThe shrinker, GC worker, and fsnotify/lease callbacks can unhash an\nnfsd_file from the rhashtable and then call\nnfsd_file_dispose_list_delayed() to move it to the per-net dispose list.\nIf nfsd_file_cache_shutdown_net() runs concurrently, its rhashtable walk\nmisses the already-unhashed file, and its drain of the per-net dispose\nlist can run before the file has been queued. The file then sits on\nthe per-net list with no thread to drain it, leaking both the file and\nits associated state.\n\nThe GC worker and shrinker already hold nfsd_gc_lock while walking the\nLRU, but in the original code they release it before calling\nnfsd_file_dispose_list_delayed(). The fsnotify/lease path\n(nfsd_file_close_inode) has no synchronization at all.\n\nFix this by:\n\n 1. Widening nfsd_gc_lock in both nfsd_file_gc() and nfsd_file_lru_scan()\n to cover the nfsd_file_dispose_list_delayed() call.\n\n 2. Wrapping nfsd_file_close_inode() in nfsd_gc_lock so that all three\n callers of nfsd_file_dispose_list_delayed() hold the lock.\n\n 3. Adding a spin_lock/unlock(nfsd_gc_lock) barrier in\n nfsd_file_cache_shutdown_net() after the purge, so that any\n in-progress disposal has fully completed before the per-net list\n is drained.\n\nAll operations inside the lock are non-sleeping (rhashtable lookups,\natomic bit/refcount ops, list moves, svc_wake_up), so the spinlock is\nappropriate.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00512, EPSS Percentile is 0.42402 |
debian: CVE-2026-89667 was patched at 2026-09-16
1343.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89684) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: fix cpntf publish race in nfs4_init_cp_state nfs4_alloc_init_cpntf_state() published the new cpntf entry into the s2s_cp_stateids IDR (with cs_type set) in one s2s_cp_lock section, then took the lock again to list_add() it onto p_stid->sc_cp_list. In the gap the entry is reachable by so_id but cp_list is still {NULL,NULL} from kzalloc. A racing OFFLOAD_CANCEL (so_id is echoed to the client as cnr_stateid, so any NFSv4.2 client can drive it) reaches manage_cpntf_state() -> _free_cpntf_state_locked() and does list_del() on the zeroed list_head, oopsing the server. Fold the cs_type assignment and the list_add() into the same critical section as idr_alloc_cyclic(), so a concurrent lookup either misses the entry or sees a fully linked cp_list. INIT_LIST_HEAD() the entry after allocation and switch _free_cpntf_state_locked() to list_del_init() so a stale unlink is a no-op. nfs4_init_copy_state() passes NULL p_stid and skips the list_add, preserving NFS4_COPY_STID semantics.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix cpntf publish race in nfs4_init_cp_state\n\nnfs4_alloc_init_cpntf_state() published the new cpntf entry into the\ns2s_cp_stateids IDR (with cs_type set) in one s2s_cp_lock section, then\ntook the lock again to list_add() it onto p_stid->sc_cp_list. In the gap\nthe entry is reachable by so_id but cp_list is still {NULL,NULL} from\nkzalloc. A racing OFFLOAD_CANCEL (so_id is echoed to the client as\ncnr_stateid, so any NFSv4.2 client can drive it) reaches\nmanage_cpntf_state() -> _free_cpntf_state_locked() and does list_del() on\nthe zeroed list_head, oopsing the server.\n\nFold the cs_type assignment and the list_add() into the same critical\nsection as idr_alloc_cyclic(), so a concurrent lookup either misses the\nentry or sees a fully linked cp_list. INIT_LIST_HEAD() the entry after\nallocation and switch _free_cpntf_state_locked() to list_del_init() so a\nstale unlink is a no-op. nfs4_init_copy_state() passes NULL p_stid and\nskips the list_add, preserving NFS4_COPY_STID semantics.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00508, EPSS Percentile is 0.42108 |
debian: CVE-2026-89684 was patched at 2026-09-16
1344.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89685) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: fix clock domain mismatch in clients_still_reclaiming() clients_still_reclaiming() computes a deadline from nn->boot_time (CLOCK_REALTIME, ~1.7 billion) but compares it against ktime_get_boottime_seconds() (CLOCK_BOOTTIME, seconds since boot). The comparison is always false — it would take ~54 years of uptime for BOOTTIME to exceed the REALTIME-derived deadline. This means any client can hold the server in grace indefinitely by sending CLAIM_PREVIOUS OPEN requests, blocking all non-reclaim operations for all other clients. Add boot_time_bt (CLOCK_BOOTTIME) alongside the existing boot_time and use it for the deadline computation. boot_time (CLOCK_REALTIME) is preserved for its cl_boot clientid-nonce role.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix clock domain mismatch in clients_still_reclaiming()\n\nclients_still_reclaiming() computes a deadline from nn->boot_time\n(CLOCK_REALTIME, ~1.7 billion) but compares it against\nktime_get_boottime_seconds() (CLOCK_BOOTTIME, seconds since boot).\nThe comparison is always false — it would take ~54 years of uptime\nfor BOOTTIME to exceed the REALTIME-derived deadline.\n\nThis means any client can hold the server in grace indefinitely by\nsending CLAIM_PREVIOUS OPEN requests, blocking all non-reclaim\noperations for all other clients.\n\nAdd boot_time_bt (CLOCK_BOOTTIME) alongside the existing boot_time\nand use it for the deadline computation. boot_time (CLOCK_REALTIME)\nis preserved for its cl_boot clientid-nonce role.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00432, EPSS Percentile is 0.36729 |
debian: CVE-2026-89685 was patched at 2026-09-16
1345.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89699) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: validate symlink target length in NFSv4 CREATE nfsd4_decode_create() accepts an unbounded cr_datalen from the wire for NF4LNK symlink targets, allowing a client to force a kmalloc of up to the maximum RPC payload size (several MiB) per COMPOUND op that persists until compound teardown. The VFS rejects oversized targets with ENAMETOOLONG, but the allocation has already occurred. Reject cr_datalen == 0 early with nfserr_inval and cr_datalen greater than NFS4_MAXPATHLEN (PATH_MAX) with nfserr_nametoolong to bound the allocation.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: validate symlink target length in NFSv4 CREATE\n\nnfsd4_decode_create() accepts an unbounded cr_datalen from the wire for\nNF4LNK symlink targets, allowing a client to force a kmalloc of up to\nthe maximum RPC payload size (several MiB) per COMPOUND op that persists\nuntil compound teardown. The VFS rejects oversized targets with\nENAMETOOLONG, but the allocation has already occurred.\n\nReject cr_datalen == 0 early with nfserr_inval and cr_datalen greater\nthan NFS4_MAXPATHLEN (PATH_MAX) with nfserr_nametoolong to bound the\nallocation.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00508, EPSS Percentile is 0.42107 |
debian: CVE-2026-89699 was patched at 2026-09-16
1346.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89704) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: sample writeback error cursor before async COPY loop _nfsd_copy_file_range() samples dst->f_wb_err into "since" after the copy loop, then uses it to detect writeback errors via filemap_check_wb_err() once vfs_fsync_range() returns. Because the nfsd_file cache reuses a single struct file across requests targeting the same inode, a concurrent COMMIT or stable WRITE on dst advances dst->f_wb_err to the current mapping->wb_err via file_check_and_advance_wb_err() during its own vfs_fsync_range(). If that advancement lands between the writeback error appearing in mapping->wb_err and the COPY worker sampling "since", the worker captures the already-advanced cursor, errseq_check() sees cur == since and returns zero, and NFSD4_COPY_F_COMMITTED is set even though writeback failed. CB_OFFLOAD then encodes wr_stable_how = FILE_SYNC4, the client treats the copied data as durable, and the failure becomes silent data loss. Sample since once at the start of the function. The cursor then reflects state in effect before this COPY issues any writes, and filemap_check_wb_err() detects any error that occurs during the copy regardless of which thread first observes it. This matches the pattern used by nfsd_vfs_write() and nfsd4_clone_file_range().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: sample writeback error cursor before async COPY loop\n\n_nfsd_copy_file_range() samples dst->f_wb_err into "since"\nafter the copy loop, then uses it to detect writeback errors\nvia filemap_check_wb_err() once vfs_fsync_range() returns.\nBecause the nfsd_file cache reuses a single struct file\nacross requests targeting the same inode, a concurrent\nCOMMIT or stable WRITE on dst advances dst->f_wb_err to the\ncurrent mapping->wb_err via file_check_and_advance_wb_err()\nduring its own vfs_fsync_range(). If that advancement lands\nbetween the writeback error appearing in mapping->wb_err\nand the COPY worker sampling "since", the worker captures\nthe already-advanced cursor, errseq_check() sees cur ==\nsince and returns zero, and NFSD4_COPY_F_COMMITTED is set\neven though writeback failed. CB_OFFLOAD then encodes\nwr_stable_how = FILE_SYNC4, the client treats the copied\ndata as durable, and the failure becomes silent data loss.\n\nSample since once at the start of the function. The cursor\nthen reflects state in effect before this COPY issues any\nwrites, and filemap_check_wb_err() detects any error that\noccurs during the copy regardless of which thread first\nobserves it. This matches the pattern used by\nnfsd_vfs_write() and nfsd4_clone_file_range().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00511, EPSS Percentile is 0.42354 |
debian: CVE-2026-89704 was patched at 2026-09-16
1347.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89706) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: Reset write verifier when async COPY writeback fails Async COPY captures nn->writeverf at request time and reports it to the client via CB_OFFLOAD after the worker kthread completes. When the post-copy vfs_fsync_range() or filemap_check_wb_err() in _nfsd_copy_file_range() reports an error, the worker correctly leaves NFSD4_COPY_F_COMMITTED clear so that CB_OFFLOAD encodes wr_stable_how as NFS_UNSTABLE, but the server's write verifier is not rotated. A client that receives NFS_UNSTABLE in CB_OFFLOAD follows up with COMMIT to make the copied data durable. With the verifier unchanged, COMMIT returns the same value the client just received via CB_OFFLOAD, and the client concludes the copy is durable -- silently dropping the data whose writeback in fact failed. This violates the UNSTABLE+COMMIT durability contract (RFC 7862 section 15.1, RFC 8881 section 18.32) and matches the bug just fixed in nfsd_vfs_write() and nfsd_commit(). Rotate nn->writeverf at the writeback-failure site. The async COPY worker has no svc_rqst, so commit_reset_write_verifier() is not available here; calling nfsd_reset_write_verifier() directly mirrors the trace-less reset already used by nfsd_file_check_write_error() for the same purpose. Filter out -EAGAIN and -ESTALE, matching commit_reset_write_verifier(), since neither indicates a durable-storage failure.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: Reset write verifier when async COPY writeback fails\n\nAsync COPY captures nn->writeverf at request time and reports it to\nthe client via CB_OFFLOAD after the worker kthread completes. When\nthe post-copy vfs_fsync_range() or filemap_check_wb_err() in\n_nfsd_copy_file_range() reports an error, the worker correctly\nleaves NFSD4_COPY_F_COMMITTED clear so that CB_OFFLOAD encodes\nwr_stable_how as NFS_UNSTABLE, but the server's write verifier is\nnot rotated.\n\nA client that receives NFS_UNSTABLE in CB_OFFLOAD follows up with\nCOMMIT to make the copied data durable. With the verifier\nunchanged, COMMIT returns the same value the client just received\nvia CB_OFFLOAD, and the client concludes the copy is durable --\nsilently dropping the data whose writeback in fact failed. This\nviolates the UNSTABLE+COMMIT durability contract (RFC 7862 section\n15.1, RFC 8881 section 18.32) and matches the bug just fixed in\nnfsd_vfs_write() and nfsd_commit().\n\nRotate nn->writeverf at the writeback-failure site. The async COPY\nworker has no svc_rqst, so commit_reset_write_verifier() is not\navailable here; calling nfsd_reset_write_verifier() directly\nmirrors the trace-less reset already used by\nnfsd_file_check_write_error() for the same purpose. Filter out\n-EAGAIN and -ESTALE, matching commit_reset_write_verifier(), since\nneither indicates a durable-storage failure.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00511, EPSS Percentile is 0.42354 |
debian: CVE-2026-89706 was patched at 2026-09-16
1348.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89711) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check The header for commit e75b23f9e323 ("nfsd: check d_can_lookup in fh_verify of directories") details the assumption that justified adding the WARN_ON_ONCE to nfsd_mode_check(), that assumption is invalid (in the case of NFS reexport). When NFSD exports an NFS filesystem it is very possible for nfsd_mode_check() to encounter a @dentry that doesn't have i_op->lookup (see nfs_fhget()'s NFS_ATTR_FATTR_MOUNTPOINT and NFS_ATTR_FATTR_V4_REFERRAL handling, and d_flags_for_inode()). So remove nfsd_mode_check()'s WARN_ON_ONCE(). The nfserr_notdir return on that branch must stay. It guards the subsequent lookup_one_unlocked() -> __lookup_slow() path, which calls inode->i_op->lookup() with no NULL check, so returning nfserr_notdir is what keeps a client LOOKUP into such a @dentry from dereferencing a NULL method pointer.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check\n\nThe header for commit e75b23f9e323 ("nfsd: check d_can_lookup in\nfh_verify of directories") details the assumption that justified\nadding the WARN_ON_ONCE to nfsd_mode_check(), that assumption is\ninvalid (in the case of NFS reexport).\n\nWhen NFSD exports an NFS filesystem it is very possible for\nnfsd_mode_check() to encounter a @dentry that doesn't have\ni_op->lookup (see nfs_fhget()'s NFS_ATTR_FATTR_MOUNTPOINT and\nNFS_ATTR_FATTR_V4_REFERRAL handling, and d_flags_for_inode()).\n\nSo remove nfsd_mode_check()'s WARN_ON_ONCE(). The nfserr_notdir\nreturn on that branch must stay. It guards the subsequent\nlookup_one_unlocked() -> __lookup_slow() path, which calls\ninode->i_op->lookup() with no NULL check, so returning nfserr_notdir\nis what keeps a client LOOKUP into such a @dentry from dereferencing\na NULL method pointer.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00449, EPSS Percentile is 0.38152 |
debian: CVE-2026-89711 was patched at 2026-09-16
1349.
XXE Injection - Unknown Product (CVE-2026-17615) - Medium [292]
Description: {'nvd_cve_data_all': 'A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitive file contents in the HTTP response. This is due to the SourceProvider.writeTo() method creating a SAXParser without disabling external entity resolution, leading to an XML External Entity (XXE) vulnerability.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitive file contents in the HTTP response. This is due to the SourceProvider.writeTo() method creating a SAXParser without disabling external entity resolution, leading to an XML External Entity (XXE) vulnerability.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | XXE Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0032, EPSS Percentile is 0.2497 |
debian: CVE-2026-17615 was patched at 2026-09-16
1350.
Denial of Service - GPU Display Driver (CVE-2026-24182) - Medium [291]
Description: NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could leak held driver locks. A successful exploit of this vulnerability might lead to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:nvidia:gpu_display_driver (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02573 |
redos: CVE-2026-24182 was patched at 2026-09-08
1351.
Denial of Service - Nodemailer (CVE-2024-58379) - Medium [291]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Nodemailer is a Node.js module for sending email, supporting SMTP, message composition, attachments, and multiple transport mechanisms. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00304, EPSS Percentile is 0.23167 |
debian: CVE-2024-58379 was patched at 2026-09-16
1352.
Denial of Service - Suricata (CVE-2026-57224) - Medium [291]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Suricata is an open-source intrusion detection and prevention system (IDS/IPS) and network security monitoring engine that supports deep packet inspection and threat detection. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-57224 was patched at 2026-09-16
1353.
Denial of Service - Traefik (CVE-2026-88012) - Medium [291]
Description: Traefik is an open source HTTP reverse proxy and load balancer. From 2.8.2 until 2.11.56 and 3.7.12, HTTP/3 entrypoints do not apply entryPoints..transport.respondingTimeouts.readTimeout because the timeout is enforced on a TCP connection and the HTTP/3 server has no corresponding QUIC stream deadline. An unauthenticated client can use a slow request body, trickling data indefinitely while holding a request and an upstream connection open and exhausting backends with bounded connection pools. This issue is fixed in 2.11.56 and 3.7.12.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:traefik:traefik (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00297, EPSS Percentile is 0.22373 |
altlinux: CVE-2026-88012 was patched at 2026-09-15, 2026-09-16
1354.
Denial of Service - Traefik (CVE-2026-88878) - Medium [291]
Description: Traefik is an HTTP reverse proxy and load balancer. In versions >= v2.8.2 through <= v2.11.55 and >= v3.0.0 through <= v3.7.11, the entryPoints.<name>.transport.respondingTimeouts settings — notably readTimeout, which is enabled by default at 60s — are not applied to the HTTP/3 request path. readTimeout is enforced as a deadline on the underlying TCP connection, which cannot be applied to a QUIC stream, and Traefik's HTTP/3 server is constructed without any timeout. As a result, on entry points with HTTP/3 enabled, an unauthenticated remote client that trickles request body bytes can hold a request open indefinitely and, with it, one upstream connection per request, exhausting bounded backend connection pools and causing denial of service. The issue was introduced in v2.8.2 when a quic-go API change removed the embedded http.Server that carried these timeouts. Fixed in v2.11.56 and v3.7.12.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:traefik:traefik (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00304, EPSS Percentile is 0.23167 |
altlinux: CVE-2026-88878 was patched at 2026-09-15, 2026-09-16
1355.
Denial of Service - nokogiri (CVE-2026-79771) - Medium [291]
Description: Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings containing null bytes. Attackers can exploit this by passing attacker-controlled input with null bytes to transform parameters, causing heap allocations to leak and enabling
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:nokogiri:nokogiri (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00304, EPSS Percentile is 0.23167 |
debian: CVE-2026-79771 was patched at 2026-09-16
1356.
Information Disclosure - Unknown Product (CVE-2026-58419) - Medium [291]
Description: {'nvd_cve_data_all': 'Notification API leaks private issue metadata after access revocation', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Notification API leaks private issue metadata after access revocation', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00508, EPSS Percentile is 0.42153 |
altlinux: CVE-2026-58419 was patched at 2026-08-27, 2026-08-29, 2026-09-04
1357.
Information Disclosure - Xeon Bronze 3408U (CVE-2026-20705) - Medium [291]
Description: Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0: Trust Domain may allow
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Product detected by h:intel:xeon_bronze_3408u (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00105, EPSS Percentile is 0.01188 |
oraclelinux: CVE-2026-20705 was patched at 2026-09-02, 2026-09-16
1358.
Memory Corruption - TLS (CVE-2026-86098) - Medium [291]
Description: ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network packet data including
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | TLS | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00353, EPSS Percentile is 0.28774 |
debian: CVE-2026-86098 was patched at 2026-09-16
1359.
Memory Corruption - Thunderbird (CVE-2026-84641) - Medium [291]
Description: A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:mozilla:thunderbird (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00267, EPSS Percentile is 0.18986 |
altlinux: CVE-2026-84641 was patched at 2026-09-03, 2026-09-09
debian: CVE-2026-84641 was patched at 2026-09-04, 2026-09-16
1360.
Security Feature Bypass - TLS (CVE-2026-68554) - Medium [291]
Description: Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an on-path attacker can append attributes after MESSAGE-INTEGRITY to an authenticated STUN request on plain UDP or TCP, adjust the STUN header length, and recompute the unkeyed FINGERPRINT while the original HMAC remains valid because it covers only the message prefix. Server-side parsing in src/server/ns_turn_server.c continues past MESSAGE-INTEGRITY through handle_turn_allocate(), handle_turn_create_permission(), handle_turn_refresh(), and handle_turn_command(), allowing trailing LIFETIME, XOR-PEER-ADDRESS, or ORIGIN attributes to override allocation lifetime, inject a permission, or bypass the origin check.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | TLS | |
| 0.2 | 10 | CVSS Base Score is 2.3. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00248, EPSS Percentile is 0.16327 |
debian: CVE-2026-68554 was patched at 2026-08-25
1361.
Security Feature Bypass - Unknown Product (CVE-2026-73276) - Medium [291]
Description: {'nvd_cve_data_all': 'Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities. This issue affects OTP from OTP 22.2 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 7.1.2 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities.\n\nThis issue affects OTP from OTP\xa022.2 before OTP\xa027.3.4.17, from OTP\xa028.0 before OTP\xa028.5.0.6, and from OTP\xa029.0 before OTP\xa029.0.6, corresponding to inets from 7.1.2 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00328, EPSS Percentile is 0.25887 |
debian: CVE-2026-73276 was patched at 2026-09-16
1362.
Security Feature Bypass - Unknown Product (CVE-2026-86145) - Medium [291]
Description: {'nvd_cve_data_all': 'PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30921 |
debian: CVE-2026-86145 was patched at 2026-09-04, 2026-09-16
1363.
Server-Side Request Forgery - WeasyPrint (CVE-2026-55073) - Medium [288]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.3 | 14 | Python library to generate PDF documents from HTML/CSS | |
| 0.6 | 10 | CVSS Base Score is 6.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0019, EPSS Percentile is 0.08863 |
altlinux: CVE-2026-55073 was patched at 2026-09-09
debian: CVE-2026-55073 was patched at 2026-09-16
1364.
Spoofing - Chromium (CVE-2026-78912) - Medium [288]
Description: UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0025, EPSS Percentile is 0.16486 |
altlinux: CVE-2026-78912 was patched at 2026-08-28
debian: CVE-2026-78912 was patched at 2026-09-03, 2026-09-16
1365.
Spoofing - Chromium (CVE-2026-79173) - Medium [288]
Description: UI misrepresentation in WebAppInstalls in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0025, EPSS Percentile is 0.16486 |
altlinux: CVE-2026-79173 was patched at 2026-08-28
debian: CVE-2026-79173 was patched at 2026-09-03, 2026-09-16
1366.
Spoofing - Chromium (CVE-2026-79204) - Medium [288]
Description: UI misrepresentation in Input in Google Chrome on on Mac prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0025, EPSS Percentile is 0.16485 |
altlinux: CVE-2026-79204 was patched at 2026-08-28
debian: CVE-2026-79204 was patched at 2026-09-03, 2026-09-16
1367.
Spoofing - Chromium (CVE-2026-79250) - Medium [288]
Description: UI misrepresentation in Navigation in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0025, EPSS Percentile is 0.16485 |
altlinux: CVE-2026-79250 was patched at 2026-08-28
debian: CVE-2026-79250 was patched at 2026-09-03, 2026-09-16
1368.
Unknown Vulnerability Type - Windows Resilient File System (ReFS) (CVE-2026-27775) - Medium [288]
Description: {'nvd_cve_data_all': 'Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allowing a per-branch maintainer-edit grant to be reused for other refs and escalate to full repository write access.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allowing a per-branch maintainer-edit grant to be reused for other refs and escalate to full repository write access.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00523, EPSS Percentile is 0.4312 |
altlinux: CVE-2026-27775 was patched at 2026-08-27, 2026-08-29, 2026-09-04
1369.
Denial of Service - Linux Kernel (CVE-2026-74734) - Medium [286]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.07027 |
debian: CVE-2026-74734 was patched at 2026-09-16
1370.
Denial of Service - Linux Kernel (CVE-2026-80636) - Medium [286]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06417 |
debian: CVE-2026-80636 was patched at 2026-09-16
1371.
Denial of Service - Linux Kernel (CVE-2026-80655) - Medium [286]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.05061 |
debian: CVE-2026-80655 was patched at 2026-09-16
1372.
Denial of Service - Linux Kernel (CVE-2026-80765) - Medium [286]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09462 |
debian: CVE-2026-80765 was patched at 2026-09-16
1373.
Denial of Service - Linux Kernel (CVE-2026-80823) - Medium [286]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09456 |
debian: CVE-2026-80823 was patched at 2026-09-16
1374.
Denial of Service - Linux Kernel (CVE-2026-80864) - Medium [286]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05201 |
debian: CVE-2026-80864 was patched at 2026-09-16
1375.
Denial of Service - Linux Kernel (CVE-2026-80870) - Medium [286]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00161, EPSS Percentile is 0.05703 |
debian: CVE-2026-80870 was patched at 2026-09-16
redos: CVE-2026-80870 was patched at 2026-09-16
1376.
Memory Corruption - Spring Framework (CVE-2026-47888) - Medium [286]
Description: A Spring RSocket application is exposed to a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.4 | 14 | The Spring Framework is an application framework and inversion of control container for the Java platform | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00324, EPSS Percentile is 0.25515 |
debian: CVE-2026-47888 was patched at 2026-09-16
1377.
Server-Side Request Forgery - Unknown Product (CVE-2026-71198) - Medium [286]
Description: {'nvd_cve_data_all': 'In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import path, the location API only checks the URL scheme and does not apply the import_filtering_opts host restrictions. An authenticated user can add a location pointing to internal endpoints such as the cloud metadata service (169.254.169.254), and retrieve the response by downloading the image data. This affects both the new POST /v2/images/{id}/locations API and the old PATCH API when show_multiple_locations is enabled. Deployments with the HTTP store backend enabled are affected.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import path, the location API only checks the URL scheme and does not apply the import_filtering_opts host restrictions. An authenticated user can add a location pointing to internal endpoints such as the cloud metadata service (169.254.169.254), and retrieve the response by downloading the image data. This affects both the new POST /v2/images/{id}/locations API and the old PATCH API when show_multiple_locations is enabled. Deployments with the HTTP store backend enabled are affected.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00449, EPSS Percentile is 0.38186 |
debian: CVE-2026-71198 was patched at 2026-09-16
1378.
Remote Code Execution - Unknown Product (CVE-2026-55588) - Medium [285]
Description: {'nvd_cve_data_all': 'ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to and including 1.3.2, the recursive referrer traversal does not track visited descriptors, so a malicious OCI registry that returns a cyclic referrer graph causes unbounded recursion and memory growth. This affects oras discover, whose recursive traversal is enabled by default because the --depth option defaults to 0 (unlimited), as well as the recursive referrer counting used by the oras backup and oras restore workflows. A cyclic graph can be as simple as A referring to B and B referring back to A. A malicious registry can use this to cause a client-side denial of service, exhausting CPU and memory and hanging automation or CI/CD pipelines that run ORAS against untrusted registry metadata. The vulnerability does not extend to code execution, artifact substitution, or integrity bypass. This issue has been fixed in version 1.3.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to and including 1.3.2, the recursive referrer traversal does not track visited descriptors, so a malicious OCI registry that returns a cyclic referrer graph causes unbounded recursion and memory growth. This affects oras discover, whose recursive traversal is enabled by default because the --depth option defaults to 0 (unlimited), as well as the recursive referrer counting used by the oras backup and oras restore workflows. A cyclic graph can be as simple as A referring to B and B referring back to A. A malicious registry can use this to cause a client-side denial of service, exhausting CPU and memory and hanging automation or CI/CD pipelines that run ORAS against untrusted registry metadata. The vulnerability does not extend to code execution, artifact substitution, or integrity bypass. This issue has been fixed in version 1.3.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00302, EPSS Percentile is 0.22901 |
debian: CVE-2026-55588 was patched at 2026-09-16
1379.
Remote Code Execution - Unknown Product (CVE-2026-68766) - Medium [285]
Description: {'nvd_cve_data_all': 'hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append attacker-controlled content to arbitrary files, enabling code execution when targeting shell startup files.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append attacker-controlled content to arbitrary files, enabling code execution when targeting shell startup files.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00162, EPSS Percentile is 0.05781 |
debian: CVE-2026-68766 was patched at 2026-08-25
1380.
Remote Code Execution - Unknown Product (CVE-2026-69242) - Medium [285]
Description: {'nvd_cve_data_all': 'libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoadTiff can evade scanline validation in libvips/iofuncs/image.c and cause an integer overflow in vips_image_sanity. The resulting buffer-region calculation can access attacker-controlled negative offsets in mmap-resident allocations, allowing reads or writes of other image data, possible data disclosure through uncompressed .v output, and likely process crashes. Remote code execution has not been demonstrated but cannot be ruled out. This issue is fixed in version 8.18.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoadTiff can evade scanline validation in libvips/iofuncs/image.c and cause an integer overflow in vips_image_sanity. The resulting buffer-region calculation can access attacker-controlled negative offsets in mmap-resident allocations, allowing reads or writes of other image data, possible data disclosure through uncompressed .v output, and likely process crashes. Remote code execution has not been demonstrated but cannot be ruled out. This issue is fixed in version 8.18.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00206, EPSS Percentile is 0.10879 |
debian: CVE-2026-69242 was patched at 2026-08-25
1381.
Denial of Service - Python (CVE-2026-15310) - Medium [284]
Description: When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.2 | 10 | CVSS Base Score is 2.1. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00346, EPSS Percentile is 0.27998 |
debian: CVE-2026-15310 was patched at 2026-09-16
1382.
Incorrect Calculation - FreeRDP (CVE-2026-91962) - Medium [284]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00244, EPSS Percentile is 0.15726 |
debian: CVE-2026-91962 was patched at 2026-09-16
1383.
Incorrect Calculation - libxml2 (CVE-2026-86138) - Medium [284]
Description: In
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.6 | 14 | libxml2 is an XML toolkit implemented in C, originally developed for the GNOME Project | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02535 |
altlinux: CVE-2026-86138 was patched at 2026-09-09
debian: CVE-2026-86138 was patched at 2026-09-16
1384.
Incorrect Calculation - libxml2 (CVE-2026-86139) - Medium [284]
Description: In
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.6 | 14 | libxml2 is an XML toolkit implemented in C, originally developed for the GNOME Project | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00113, EPSS Percentile is 0.01629 |
debian: CVE-2026-86139 was patched at 2026-09-16
1385.
Memory Corruption - FreeRDP (CVE-2026-91958) - Medium [284]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.7 | 10 | CVSS Base Score is 6.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00199, EPSS Percentile is 0.10001 |
debian: CVE-2026-91958 was patched at 2026-09-16
1386.
Memory Corruption - MongoDB (CVE-2026-88032) - Medium [284]
Description: A use-after-free in the reactive client-side encryption component of the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04772 |
debian: CVE-2026-88032 was patched at 2026-09-16
1387.
Memory Corruption - libxml2 (CVE-2026-86140) - Medium [284]
Description: In
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | libxml2 is an XML toolkit implemented in C, originally developed for the GNOME Project | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00149, EPSS Percentile is 0.04456 |
debian: CVE-2026-86140 was patched at 2026-09-16
1388.
Memory Corruption - libxml2 (CVE-2026-86142) - Medium [284]
Description: In
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | libxml2 is an XML toolkit implemented in C, originally developed for the GNOME Project | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0015, EPSS Percentile is 0.0458 |
debian: CVE-2026-86142 was patched at 2026-09-16
1389.
Memory Corruption - Vim (CVE-2026-73071) - Medium [283]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.95 | 14 | Highly configurable command-line text editor used in development and system administration. | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0011, EPSS Percentile is 0.01416 |
ubuntu: CVE-2026-73071 was patched at 2026-08-20, 2026-08-25
1390.
Open Redirect - Spring Framework (CVE-2026-47887) - Medium [283]
Description: A
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.75 | 15 | Open Redirect | |
| 0.4 | 14 | The Spring Framework is an application framework and inversion of control container for the Java platform | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06858 |
debian: CVE-2026-47887 was patched at 2026-09-16
1391.
Denial of Service - JOSE (CVE-2026-53938) - Medium [282]
Description: OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.3 | 14 | JavaScript module for JSON Object Signing and Encryption (JOSE) | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00236, EPSS Percentile is 0.14783 |
debian: CVE-2026-53938 was patched at 2026-09-15, 2026-09-16
1392.
Incorrect Calculation - Chromium (CVE-2026-87630) - Medium [282]
Description: Integer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00226, EPSS Percentile is 0.1341 |
altlinux: CVE-2026-87630 was patched at 2026-09-17
debian: CVE-2026-87630 was patched at 2026-09-16
1393.
Incorrect Calculation - Chromium (CVE-2026-91746) - Medium [282]
Description: Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00201, EPSS Percentile is 0.10235 |
altlinux: CVE-2026-91746 was patched at 2026-09-17
debian: CVE-2026-91746 was patched at 2026-09-16
1394.
Memory Corruption - Binutils (CVE-2026-90801) - Medium [282]
Description: A security flaw has been discovered in GNU
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00133, EPSS Percentile is 0.03207 |
debian: CVE-2026-90801 was patched at 2026-09-16
1395.
Memory Corruption - Binutils (CVE-2026-90803) - Medium [282]
Description: A security vulnerability has been detected in GNU
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.02471 |
debian: CVE-2026-90803 was patched at 2026-09-16
1396.
Memory Corruption - Binutils (CVE-2026-90804) - Medium [282]
Description: A vulnerability was detected in GNU
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.0186 |
debian: CVE-2026-90804 was patched at 2026-09-16
1397.
Memory Corruption - Binutils (CVE-2026-90828) - Medium [282]
Description: A security flaw has been discovered in GNU
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04712 |
debian: CVE-2026-90828 was patched at 2026-09-16
1398.
Memory Corruption - Binutils (CVE-2026-90830) - Medium [282]
Description: A security vulnerability has been detected in GNU
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04711 |
debian: CVE-2026-90830 was patched at 2026-09-16
1399.
Memory Corruption - Binutils (CVE-2026-90831) - Medium [282]
Description: A vulnerability was detected in GNU
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04712 |
debian: CVE-2026-90831 was patched at 2026-09-16
1400.
Memory Corruption - Chromium (CVE-2026-79004) - Medium [282]
Description: Out of bounds read in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00253, EPSS Percentile is 0.16984 |
altlinux: CVE-2026-79004 was patched at 2026-08-28
debian: CVE-2026-79004 was patched at 2026-09-03, 2026-09-16
1401.
Memory Corruption - Chromium (CVE-2026-87592) - Medium [282]
Description: Out of bounds read in Tint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00201, EPSS Percentile is 0.10227 |
altlinux: CVE-2026-87592 was patched at 2026-09-17
debian: CVE-2026-87592 was patched at 2026-09-16
1402.
Memory Corruption - GNU C Library (CVE-2026-18374) - Medium [282]
Description: Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | The GNU C Library, commonly known as glibc, is the GNU Project's implementation of the C standard library | |
| 0.5 | 10 | CVSS Base Score is 4.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0015, EPSS Percentile is 0.04522 |
debian: CVE-2026-18374 was patched at 2026-09-16
1403.
Memory Corruption - Mozilla Firefox (CVE-2026-84126) - Medium [282]
Description: Incorrect boundary conditions in the Layout: Grid component. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00179, EPSS Percentile is 0.07687 |
altlinux: CVE-2026-84126 was patched at 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
1404.
Security Feature Bypass - JOSE (CVE-2026-84185) - Medium [282]
Description: A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.3 | 14 | JavaScript module for JSON Object Signing and Encryption (JOSE) | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00087, EPSS Percentile is 0.00409 |
altlinux: CVE-2026-84185 was patched at 2026-09-02, 2026-09-07
debian: CVE-2026-84185 was patched at 2026-09-16
1405.
Code Injection - Unknown Product (CVE-2026-40018) - Medium [280]
Description: {'nvd_cve_data_all': 'None None None No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'None None None No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0027, EPSS Percentile is 0.19272 |
debian: CVE-2026-40018 was patched at 2026-09-16
1406.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74425) - Medium [280]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: afs: handle CB.InitCallBackState3 requests without a server record The cache manager callback path now attaches the server record to an incoming call through the rxrpc peer's app data. That association is not guaranteed to exist for every callback request, and most callback handlers already tolerate that case. Make CB.InitCallBackState3 follow the same pattern by checking whether a server record was attached before using it. If the peer is not mapped to a server record, trace the request and ignore it, matching the existing behaviour for other unmatched callback requests. This keeps the callback handler consistent with the rest of the cache manager service and avoids depending on peer state that may not be available for a given request.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nafs: handle CB.InitCallBackState3 requests without a server record\n\nThe cache manager callback path now attaches the server record to an\nincoming call through the rxrpc peer's app data. That association is\nnot guaranteed to exist for every callback request, and most callback\nhandlers already tolerate that case.\n\nMake CB.InitCallBackState3 follow the same pattern by checking whether a\nserver record was attached before using it. If the peer is not mapped\nto a server record, trace the request and ignore it, matching the\nexisting behaviour for other unmatched callback requests.\n\nThis keeps the callback handler consistent with the rest of the cache\nmanager service and avoids depending on peer state that may not be\navailable for a given request.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00346, EPSS Percentile is 0.27992 |
oraclelinux: CVE-2026-74425 was patched at 2026-09-04
1407.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74592) - Medium [280]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ima: Instantiate file_truncate and path_truncate hooks Instantiate the file_truncate and path_truncate LSM hooks to reset the action cache flags (IMA_DONE_MASK) as soon as truncation is requested, so the file, based on policy, is re-collected, re-measured, re-audited, and re-appraised on next access.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nima: Instantiate file_truncate and path_truncate hooks\n\nInstantiate the file_truncate and path_truncate LSM hooks to reset the\naction cache flags (IMA_DONE_MASK) as soon as truncation is requested,\nso the file, based on policy, is re-collected, re-measured, re-audited,\nand re-appraised on next access.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00341, EPSS Percentile is 0.27494 |
debian: CVE-2026-74592 was patched at 2026-08-25
oraclelinux: CVE-2026-74592 was patched at 2026-09-04
1408.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74649) - Medium [280]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix missing shared-key auth challenge length check The WEP shared-key authentication handler uses the challenge-text element's attacker-controlled length without checking it against the fixed 128-byte chg_txt buffer. In OnAuthClient() the length from rtw_get_ie() - up to 255 - is used to perform memcpy() into the 128-byte pmlmeinfo->chg_txt, so a malicious AP sending a malformed WLAN_EID_CHALLENGE element can overflow/underfill chg_txt by up to 127 bytes. It is reachable over the air, before association, during shared-key authentication. In the case of an overflow, the driver can write out of bounds. In the case of an underfill, the driver can echo stale buffer memory. The challenge text is defined to be exactly 128 octets, which is already provided as the WLAN_AUTH_CHALLENGE_LEN define; require the element to be exactly that length before use.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix missing shared-key auth challenge length check\n\nThe WEP shared-key authentication handler uses the challenge-text\nelement's attacker-controlled length without checking it against the\nfixed 128-byte chg_txt buffer.\n\nIn OnAuthClient() the length from rtw_get_ie() - up to 255 - is used\nto perform memcpy() into the 128-byte pmlmeinfo->chg_txt, so a\nmalicious AP sending a malformed WLAN_EID_CHALLENGE element can\noverflow/underfill chg_txt by up to 127 bytes. It is reachable over the\nair, before association, during shared-key authentication. In the case\nof an overflow, the driver can write out of bounds. In the case of an\nunderfill, the driver can echo stale buffer memory.\n\nThe challenge text is defined to be exactly 128 octets, which is\nalready provided as the WLAN_AUTH_CHALLENGE_LEN define; require the\nelement to be exactly that length before use.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00288, EPSS Percentile is 0.21431 |
debian: CVE-2026-74649 was patched at 2026-08-25
oraclelinux: CVE-2026-74649 was patched at 2026-09-04
1409.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74691) - Medium [280]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Tear down DMA paths before stopping the rings tbnet_tear_down() stops both rings and frees their frame buffers before calling tb_xdomain_disable_paths(). tb_ring_stop() zeroes the ring's descriptor base and tbnet_free_buffers() unmaps and frees the pages the frames sit in, so by the time __tb_path_deactivate_hop() polls the hop's 'pending' bit, anything still in flight has nowhere to drain to. The teardown sequence has been in this order since the driver was added. The setup path has not: commit ff7cd07f3064 ("net: thunderbolt: Enable DMA paths only after rings are enabled") moved the path enable to the end of tbnet_connected_work() and documented why: \t/* Both logins successful so enable the rings, high-speed DMA \t * paths and start the network device queue. \t * \t * Note we enable the DMA paths last to make sure we have primed \t * the Rx ring before any incoming packets are allowed to \t * arrive. \t */ Teardown was never updated to match, so the rings and the paths now come down in the same order they go up instead of in reverse. On an ASMedia ASM4242 host router the 'pending' bit then never clears: every teardown burns the full 500 ms timeout and __tb_path_deactivate_hop() returns -ETIMEDOUT. Raising the timeout to 5 s does not help, so the hop is not slow to drain, it never drains at all. The failure is invisible above the thunderbolt core. __tb_path_deactivate_hops() is void and only calls tb_port_warn(); tb_path_deactivate(), tb_tunnel_deactivate() and __tb_disconnect_xdomain_paths() are void as well, and tb_disconnect_xdomain_paths() ends in an unconditional "return 0". So tb_xdomain_disable_paths() reports success and the netdev_warn() below it never fires. Repeated teardowns eventually take the XDomain control channel down, after which the peer node is gone and only a power cycle brings the controller back. Deactivating the paths first fixes it. Measured with kretprobes on a stock v6.17 tree with no other patches applied, on a link that was up and had just carried traffic: before: __tb_path_deactivate_hop() returns 0 for the first hop, then -ETIMEDOUT for the second 500335 us later after: 0 for both, 525 us apart Alternating the two orderings ABBA over three load levels, four teardowns per arm: every teardown failed before the change (21 of 21 that ran), none failed after (0 of 24). The before arms ran short because the link died partway through. The same split shows up when the interface is enslaved to a bond instead of just brought down, which is how I ran into this in the first place. Throughput and latency after the change are unchanged. Hosts whose routers drain the hop despite the stale descriptor base see no functional difference, since the paths end up deactivated either way.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: thunderbolt: Tear down DMA paths before stopping the rings\n\ntbnet_tear_down() stops both rings and frees their frame buffers before\ncalling tb_xdomain_disable_paths(). tb_ring_stop() zeroes the ring's\ndescriptor base and tbnet_free_buffers() unmaps and frees the pages the\nframes sit in, so by the time __tb_path_deactivate_hop() polls the hop's\n'pending' bit, anything still in flight has nowhere to drain to.\n\nThe teardown sequence has been in this order since the driver was added.\nThe setup path has not: commit ff7cd07f3064 ("net: thunderbolt: Enable\nDMA paths only after rings are enabled") moved the path enable to the end\nof tbnet_connected_work() and documented why:\n\n\t/* Both logins successful so enable the rings, high-speed DMA\n\t * paths and start the network device queue.\n\t *\n\t * Note we enable the DMA paths last to make sure we have primed\n\t * the Rx ring before any incoming packets are allowed to\n\t * arrive.\n\t */\n\nTeardown was never updated to match, so the rings and the paths now come\ndown in the same order they go up instead of in reverse.\n\nOn an ASMedia ASM4242 host router the 'pending' bit then never clears:\nevery teardown burns the full 500 ms timeout and\n__tb_path_deactivate_hop() returns -ETIMEDOUT. Raising the timeout to\n5 s does not help, so the hop is not slow to drain, it never drains\nat all.\n\nThe failure is invisible above the thunderbolt core.\n__tb_path_deactivate_hops() is void and only calls tb_port_warn();\ntb_path_deactivate(), tb_tunnel_deactivate() and\n__tb_disconnect_xdomain_paths() are void as well, and\ntb_disconnect_xdomain_paths() ends in an unconditional "return 0". So\ntb_xdomain_disable_paths() reports success and the netdev_warn() below\nit never fires. Repeated teardowns eventually take the XDomain control\nchannel down, after which the peer node is gone and only a power cycle\nbrings the controller back.\n\nDeactivating the paths first fixes it. Measured with kretprobes on a\nstock v6.17 tree with no other patches applied, on a link that was up\nand had just carried traffic:\n\n before: __tb_path_deactivate_hop() returns 0 for the first hop, then\n -ETIMEDOUT for the second 500335 us later\n after: 0 for both, 525 us apart\n\nAlternating the two orderings ABBA over three load levels, four\nteardowns per arm: every teardown failed before the change (21 of 21\nthat ran), none failed after (0 of 24). The before arms ran short\nbecause the link died partway through. The same split shows up when\nthe interface is enslaved to a bond instead of just brought down, which\nis how I ran into this in the first place. Throughput and latency after\nthe change are unchanged.\n\nHosts whose routers drain the hop despite the stale descriptor base see\nno functional difference, since the paths end up deactivated either way.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00256, EPSS Percentile is 0.17472 |
debian: CVE-2026-74691 was patched at 2026-08-25
oraclelinux: CVE-2026-74691 was patched at 2026-09-04
1410.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80585) - Medium [280]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with SYN data Passive TCP Fast Open accepts a valid-cookie SYN even when it carries no data. In that case the child socket's receive queue is intentionally left empty. mptcp_fastopen_subflow_synack_set_params() set is_mptfo before checking for queued SYN data. That made data-less TFO SYNs hit a WARN and, if the warning was non-fatal, left stale MPTFO state behind. The stale flag could later trigger a state-confusion bug in check_fully_established(). Only mark the subflow as MPTFO after confirming that an SKB was queued. Return quietly when the receive queue is empty. Note that mptcp_subflow_context's is_mptfo field is now not just about subflows where the TFO was present, but about MPTFO subflow that consumed SYN data. Only having a valid cookie but not carrying data is not really "doing TFO".', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: fastopen: only mark MPTFO subflows with SYN data\n\nPassive TCP Fast Open accepts a valid-cookie SYN even when it carries\nno data. In that case the child socket's receive queue is intentionally\nleft empty.\n\nmptcp_fastopen_subflow_synack_set_params() set is_mptfo before checking\nfor queued SYN data. That made data-less TFO SYNs hit a WARN and, if\nthe warning was non-fatal, left stale MPTFO state behind. The stale\nflag could later trigger a state-confusion bug in\ncheck_fully_established().\n\nOnly mark the subflow as MPTFO after confirming that an SKB was queued.\nReturn quietly when the receive queue is empty.\n\nNote that mptcp_subflow_context's is_mptfo field is now not just about\nsubflows where the TFO was present, but about MPTFO subflow that\nconsumed SYN data. Only having a valid cookie but not carrying data is\nnot really "doing TFO".', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00317, EPSS Percentile is 0.24619 |
debian: CVE-2026-80585 was patched at 2026-09-16
1411.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80631) - Medium [280]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: btrfs: lzo: reject compressed segment that overflows the compressed input lzo_decompress_bio() validates each on-disk segment length seg_len only against the workspace cbuf size, not against the compressed input size (compressed_len, the total folio bytes of the bio). A crafted extent can carry a segment whose seg_len passes the cbuf check but runs past the end of the bio, so copy_compressed_segment() walks off the last folio: get_current_folio() then returns the NULL folio from bio_next_folio(), and with CONFIG_BTRFS_ASSERT disabled (default) folio_size(NULL) faults. BUG: KASAN: null-ptr-deref in lzo_decompress_bio (fs/btrfs/lzo.c:383) Read of size 8 at addr 0000000000000000 by task kworker/u8:1/29 Workqueue: btrfs-endio simple_end_io_work kasan_report (mm/kasan/report.c:590) lzo_decompress_bio (fs/btrfs/lzo.c:383) end_bbio_compressed_read (fs/btrfs/compression.c:1065) btrfs_bio_end_io (fs/btrfs/bio.c:135) btrfs_check_read_bio (fs/btrfs/bio.c:180 fs/btrfs/bio.c:285) simple_end_io_work process_one_work worker_thread Reject any segment whose payload would extend beyond compressed_len before copying it, treating it as corruption like the other on-disk validation failures in this function.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: lzo: reject compressed segment that overflows the compressed input\n\nlzo_decompress_bio() validates each on-disk segment length seg_len only\nagainst the workspace cbuf size, not against the compressed input size\n(compressed_len, the total folio bytes of the bio). A crafted extent can\ncarry a segment whose seg_len passes the cbuf check but runs past the end\nof the bio, so copy_compressed_segment() walks off the last folio:\nget_current_folio() then returns the NULL folio from bio_next_folio(), and\nwith CONFIG_BTRFS_ASSERT disabled (default) folio_size(NULL) faults.\n\n BUG: KASAN: null-ptr-deref in lzo_decompress_bio (fs/btrfs/lzo.c:383)\n Read of size 8 at addr 0000000000000000 by task kworker/u8:1/29\n Workqueue: btrfs-endio simple_end_io_work\n kasan_report (mm/kasan/report.c:590)\n lzo_decompress_bio (fs/btrfs/lzo.c:383)\n end_bbio_compressed_read (fs/btrfs/compression.c:1065)\n btrfs_bio_end_io (fs/btrfs/bio.c:135)\n btrfs_check_read_bio (fs/btrfs/bio.c:180 fs/btrfs/bio.c:285)\n simple_end_io_work\n process_one_work\n worker_thread\n\nReject any segment whose payload would extend beyond compressed_len before\ncopying it, treating it as corruption like the other on-disk validation\nfailures in this function.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00343, EPSS Percentile is 0.27723 |
debian: CVE-2026-80631 was patched at 2026-09-16
1412.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80707) - Medium [280]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer Zero the allocated buffer in j1939_session_fresh_new() to ensure it contains no residual data. While there is a potential performance impact if users allocate maximum sized ETP buffers, most real-world use cases are not noticeably affected since the maximum known buffer size is typically around 65K. [mkl: add Message-ID]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncan: j1939: transport: j1939_session_fresh_new(): initialize receive buffer\n\nZero the allocated buffer in j1939_session_fresh_new() to ensure it\ncontains no residual data.\n\nWhile there is a potential performance impact if users allocate maximum\nsized ETP buffers, most real-world use cases are not noticeably affected\nsince the maximum known buffer size is typically around 65K.\n\n[mkl: add Message-ID]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00329, EPSS Percentile is 0.26007 |
debian: CVE-2026-80707 was patched at 2026-09-16
oraclelinux: CVE-2026-80707 was patched at 2026-09-04
1413.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80717) - Medium [280]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: sctp: validate Adaptation Indication parameter length The Adaptation Layer Indication parameter contains a fixed 32-bit Adaptation Code Point after its parameter header. However, sctp_verify_param() accepts a header-only parameter because the generic parameter walker only requires the header to be present. sctp_process_param() then reads adaptation_ind beyond the declared parameter. When the malformed parameter is last in an INIT, the read starts at the receive skb tail, and the value is copied into the state cookie returned in the INIT ACK. This may disclose four receive-buffer tail bytes. Require the declared parameter length to match the fixed structure size and abort the association through the existing invalid parameter length path otherwise.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: validate Adaptation Indication parameter length\n\nThe Adaptation Layer Indication parameter contains a fixed 32-bit\nAdaptation Code Point after its parameter header. However,\nsctp_verify_param() accepts a header-only parameter because the generic\nparameter walker only requires the header to be present.\n\nsctp_process_param() then reads adaptation_ind beyond the declared\nparameter. When the malformed parameter is last in an INIT, the read\nstarts at the receive skb tail, and the value is copied into the state\ncookie returned in the INIT ACK. This may disclose four receive-buffer\ntail bytes.\n\nRequire the declared parameter length to match the fixed structure size\nand abort the association through the existing invalid parameter length\npath otherwise.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00329, EPSS Percentile is 0.26007 |
debian: CVE-2026-80717 was patched at 2026-09-16
oraclelinux: CVE-2026-80717 was patched at 2026-09-04
1414.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80722) - Medium [280]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate individual TWT params before driver setup ieee80211_process_rx_twt_action() only partially validates a received S1G TWT setup frame before queueing it. An individual agreement can therefore reach ieee80211_s1g_rx_twt_setup() with twt->length too short for the full struct ieee80211_twt_params. The individual path passes twt to drv_add_twt_setup(). Both the tracepoint and the driver callback consume the complete parameters block, not merely req_type. Do not pass a short individual agreement to the driver. Broadcast agreements remain unchanged because they are rejected locally after accessing only req_type. [edit commit message to not overclaim lack of validation nor understate driver impact]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: validate individual TWT params before driver setup\n\nieee80211_process_rx_twt_action() only partially validates a received\nS1G TWT setup frame before queueing it.\n\nAn individual agreement can therefore reach ieee80211_s1g_rx_twt_setup()\nwith twt->length too short for the full struct ieee80211_twt_params.\n\nThe individual path passes twt to drv_add_twt_setup(). Both the tracepoint\nand the driver callback consume the complete parameters block, not merely\nreq_type. Do not pass a short individual agreement to the driver.\nBroadcast agreements remain unchanged because they are rejected locally\nafter accessing only req_type.\n\n[edit commit message to not overclaim lack of validation nor\n understate driver impact]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00242, EPSS Percentile is 0.15526 |
debian: CVE-2026-80722 was patched at 2026-09-16
oraclelinux: CVE-2026-80722 was patched at 2026-09-04
1415.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89481) - Medium [280]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix host memory disclosure on R2T for a read command nvme_tcp_handle_r2t() does not check the direction of the request the R2T refers to. A malicious controller can send an R2T for a READ and the host will answer it: nvme_tcp_setup_h2c_data_pdu() builds the H2CData header and nvme_tcp_try_send_data() sends the request's data buffer. That buffer is the READ destination, so its contents go to the controller. The command then completes normally and nothing is logged. Against a test controller that answers every READ with an R2T, a 4096 byte buffered read returned all 4096 bytes, split over two R2Ts. The pages contained stale kernel data, including an array of struct page pointers. Reject an R2T for a request that is not a write.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-tcp: fix host memory disclosure on R2T for a read command\n\nnvme_tcp_handle_r2t() does not check the direction of the request the\nR2T refers to. A malicious controller can send an R2T for a READ and\nthe host will answer it: nvme_tcp_setup_h2c_data_pdu() builds the\nH2CData header and nvme_tcp_try_send_data() sends the request's data\nbuffer. That buffer is the READ destination, so its contents go to the\ncontroller.\n\nThe command then completes normally and nothing is logged.\n\nAgainst a test controller that answers every READ with an R2T, a 4096\nbyte buffered read returned all 4096 bytes, split over two R2Ts. The\npages contained stale kernel data, including an array of struct page\npointers.\n\nReject an R2T for a request that is not a write.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00413, EPSS Percentile is 0.3499 |
debian: CVE-2026-89481 was patched at 2026-09-16
1416.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89778) - Medium [280]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: isofs: fix out-of-bounds page array access on empty zisofs block zisofs_uncompress_block()'s empty-block fast path returns pcount << PAGE_SHIFT, ignoring the incoming poffset, unlike the decompression path which returns bytes produced relative to poffset. zisofs_fill_pages() uses that return to advance its page cursor, so when the zisofs block size is below PAGE_SIZE and a sub-page block leaves poffset partway into a page, a following empty block over-counts and advances pages[] one element past its end, after which "if (poffset && *pages)" reads pages[1] out of bounds. rock.c only rejects a block-size shift > 17, so a crafted "ZF" Rock Ridge record can set it below PAGE_SHIFT; the bug is reached by an ordinary read() of a compressed file on such a mounted ISO9660 image. Return the byte count relative to poffset and zero only [poffset, PAGE_SIZE) of the first page, matching the decompression path. The page-aligned case (poffset == 0) is unaffected. BUG: KASAN: slab-out-of-bounds in zisofs_read_folio (fs/isofs/compress.c:290) Read of size 8 at addr ffff88800f5eac48 by task exploit/142 zisofs_read_folio (fs/isofs/compress.c:290) read_pages (mm/readahead.c:184) ... filemap_read (mm/filemap.c:2814) vfs_read (fs/read_write.c:574) __x64_sys_pread64 (fs/read_write.c:769) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) The buggy address is located 0 bytes to the right of the allocated 8-byte region in the kmalloc-8 cache', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nisofs: fix out-of-bounds page array access on empty zisofs block\n\nzisofs_uncompress_block()'s empty-block fast path returns\npcount << PAGE_SHIFT, ignoring the incoming poffset, unlike the\ndecompression path which returns bytes produced relative to poffset.\nzisofs_fill_pages() uses that return to advance its page cursor, so when\nthe zisofs block size is below PAGE_SIZE and a sub-page block leaves\npoffset partway into a page, a following empty block over-counts and\nadvances pages[] one element past its end, after which\n"if (poffset && *pages)" reads pages[1] out of bounds. rock.c only\nrejects a block-size shift > 17, so a crafted "ZF" Rock Ridge record can\nset it below PAGE_SHIFT; the bug is reached by an ordinary read() of a\ncompressed file on such a mounted ISO9660 image.\n\nReturn the byte count relative to poffset and zero only\n[poffset, PAGE_SIZE) of the first page, matching the decompression path.\nThe page-aligned case (poffset == 0) is unaffected.\n\n BUG: KASAN: slab-out-of-bounds in zisofs_read_folio (fs/isofs/compress.c:290)\n Read of size 8 at addr ffff88800f5eac48 by task exploit/142\n zisofs_read_folio (fs/isofs/compress.c:290)\n read_pages (mm/readahead.c:184)\n ...\n filemap_read (mm/filemap.c:2814)\n vfs_read (fs/read_write.c:574)\n __x64_sys_pread64 (fs/read_write.c:769)\n do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n The buggy address is located 0 bytes to the right of the\n allocated 8-byte region in the kmalloc-8 cache', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10807 |
debian: CVE-2026-89778 was patched at 2026-09-16
1417.
Denial of Service - OpenTelemetry (CVE-2026-45404) - Medium [279]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | OpenTelemetry is a collection of APIs, SDKs, and tools. Use it to instrument, generate, collect, and export telemetry data (metrics, logs and traces) to help you analyze your software's performance and behavior | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00131, EPSS Percentile is 0.03102 |
debian: CVE-2026-45404 was patched at 2026-09-16
1418.
Denial of Service - TLS (CVE-2026-33263) - Medium [279]
Description: When mail_max_userip_connections is set (default 10) and reached, submission-login
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | TLS | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0029, EPSS Percentile is 0.21622 |
altlinux: CVE-2026-33263 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-33263 was patched at 2026-09-16
1419.
Denial of Service - Unknown Product (CVE-2026-69219) - Medium [279]
Description: {'nvd_cve_data_all': 'The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to accept a wire-declared contentLength below Integer.MAX_VALUE and allocate a byte array before checking the bytes available in the frame. A malicious AMQP peer can send a LongString or byte-array field with type tag S and a declared length such as 0x7FFFFFFE during the pre-authentication connection.start server-properties table, causing an approximately 2 GB allocation and OutOfMemoryError before readFully consumes data. The resulting memory exhaustion can terminate the JVM and cause denial of service. This issue is fixed in version 5.33.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to accept a wire-declared contentLength below Integer.MAX_VALUE and allocate a byte array before checking the bytes available in the frame. A malicious AMQP peer can send a LongString or byte-array field with type tag S and a declared length such as 0x7FFFFFFE during the pre-authentication connection.start server-properties table, causing an approximately 2 GB allocation and OutOfMemoryError before readFully consumes data. The resulting memory exhaustion can terminate the JVM and cause denial of service. This issue is fixed in version 5.33.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00422, EPSS Percentile is 0.35919 |
debian: CVE-2026-69219 was patched at 2026-08-20
1420.
Denial of Service - Unknown Product (CVE-2026-78002) - Medium [279]
Description: {'nvd_cve_data_all': 'A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, causing memory corruption. Successful exploitation can lead to a denial of service (DoS) for the affected system.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, causing memory corruption. Successful exploitation can lead to a denial of service (DoS) for the affected system.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00612, EPSS Percentile is 0.47697 |
debian: CVE-2026-78002 was patched at 2026-09-16
1421.
Denial of Service - Unknown Product (CVE-2026-84732) - Medium [279]
Description: {'nvd_cve_data_all': 'Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00544, EPSS Percentile is 0.44333 |
debian: CVE-2026-84732 was patched at 2026-09-16
1422.
Memory Corruption - Suricata (CVE-2026-57228) - Medium [279]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Suricata is an open-source intrusion detection and prevention system (IDS/IPS) and network security monitoring engine that supports deep packet inspection and threat detection. | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-57228 was patched at 2026-09-16
1423.
Memory Corruption - TimescaleDB (CVE-2026-70635) - Medium [279]
Description: TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated attackers to cause query-result integrity failures or backend crashes by supplying a crafted Simple8b selector-11 value, which is stored in the signed int16 Arrow dictionary-index type and bypasses index validation checks in bulk text dictionary decompression. Attackers with direct DML access to a non-frozen physical compressed hypertable relation can trigger an out-of-bounds read before the base of the live offsets array through the VectorAgg single-text hashing strategy, resulting in incorrect aggregation output, backend SIGSEGV, or PostgreSQL crash recovery depending on build configuration.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:timescale:timescaledb (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00311, EPSS Percentile is 0.23965 |
altlinux: CVE-2026-70635 was patched at 2026-08-26, 2026-08-28, 2026-08-29, 2026-09-01
1424.
Path Traversal - Unknown Product (CVE-2026-82481) - Medium [279]
Description: {'nvd_cve_data_all': 'The cohttp package before 6.3.0 for OCaml allows directory traversal.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The cohttp package before 6.3.0 for OCaml allows directory traversal.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00504, EPSS Percentile is 0.4189 |
debian: CVE-2026-82481 was patched at 2026-09-16
1425.
Security Feature Bypass - Unknown Product (CVE-2026-20715) - Medium [279]
Description: {'nvd_cve_data_all': 'Improper input validation in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(R) Standard Manageability may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via network access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Improper input validation in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(R) Standard Manageability may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via network access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00316, EPSS Percentile is 0.24574 |
oraclelinux: CVE-2026-20715 was patched at 2026-09-02, 2026-09-16
1426.
Security Feature Bypass - Unknown Product (CVE-2026-39944) - Medium [279]
Description: {'nvd_cve_data_all': 'Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the RADOS Gateway (RGW) protects STS session tokens with an AES-128-CBC handler that provides no message authentication, allowing an attacker who holds any valid STS token to tamper with it undetected and escalate to full RGW administrative access. Because the ciphertext is unauthenticated, the attacker can perform a CBC bit-flip on the acct_type, perm_type, and is_admin fields of their own token, and a forged is_admin value triggers a global administrative override that bypasses all capability checks. The attack is reachable remotely over the RGW S3 endpoint and is a self-contained modification of a token the attacker already possesses, requiring no encryption oracle and no network observation. It requires only a single valid STS token, which need not carry any elevated privileges, with STS enabled. This issue is fixed in versions 20.2.4 and 19.2.6.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the RADOS Gateway (RGW) protects STS session tokens with an AES-128-CBC handler that provides no message authentication, allowing an attacker who holds any valid STS token to tamper with it undetected and escalate to full RGW administrative access. Because the ciphertext is unauthenticated, the attacker can perform a CBC bit-flip on the acct_type, perm_type, and is_admin fields of their own token, and a forged is_admin value triggers a global administrative override that bypasses all capability checks. The attack is reachable remotely over the RGW S3 endpoint and is a self-contained modification of a token the attacker already possesses, requiring no encryption oracle and no network observation. It requires only a single valid STS token, which need not carry any elevated privileges, with STS enabled. This issue is fixed in versions 20.2.4 and 19.2.6.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0017, EPSS Percentile is 0.06739 |
debian: CVE-2026-39944 was patched at 2026-08-25
1427.
Security Feature Bypass - Unknown Product (CVE-2026-73812) - Medium [279]
Description: {'nvd_cve_data_all': 'httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 identifies as a probable smuggling attempt. handle_body/3 frames by chunked and silently discards Content-Length. A CL-preferring front-end paired with chunked-preferring inets creates a classic CL.TE front-end/back-end desync. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 identifies as a probable smuggling attempt. handle_body/3 frames by chunked and silently discards Content-Length. A CL-preferring front-end paired with chunked-preferring inets creates a classic CL.TE front-end/back-end desync.\n\nThis issue affects OTP from OTP\xa017.0 before OTP\xa027.3.4.17, from OTP\xa028.0 before OTP\xa028.5.0.6, and from OTP\xa029.0 before OTP\xa029.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP\xa017.0, corresponding to inets before 5.10, is affected is unknown.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00301, EPSS Percentile is 0.2282 |
debian: CVE-2026-73812 was patched at 2026-09-16
1428.
Memory Corruption - Envoy (CVE-2026-50572) - Medium [277]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-50572 was patched at 2026-08-28, 2026-08-31
1429.
Spoofing - Chromium (CVE-2026-79283) - Medium [276]
Description: UI misrepresentation in Geometry in Google Chrome prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00198, EPSS Percentile is 0.09823 |
altlinux: CVE-2026-79283 was patched at 2026-08-28
debian: CVE-2026-79283 was patched at 2026-09-03, 2026-09-16
1430.
Spoofing - Chromium (CVE-2026-84330) - Medium [276]
Description: UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00158, EPSS Percentile is 0.05401 |
altlinux: CVE-2026-84330 was patched at 2026-09-03
debian: CVE-2026-84330 was patched at 2026-09-03, 2026-09-16
1431.
Spoofing - Chromium (CVE-2026-87463) - Medium [276]
Description: Incorrect authorization in Certificate in Google Chrome on on Android prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00158, EPSS Percentile is 0.05382 |
altlinux: CVE-2026-87463 was patched at 2026-09-17
debian: CVE-2026-87463 was patched at 2026-09-16
1432.
Spoofing - Chromium (CVE-2026-87562) - Medium [276]
Description: Incorrect reference resolution in Accessibility in Google Chrome on on Mac prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00185, EPSS Percentile is 0.08284 |
altlinux: CVE-2026-87562 was patched at 2026-09-17
debian: CVE-2026-87562 was patched at 2026-09-16
1433.
Spoofing - Chromium (CVE-2026-87583) - Medium [276]
Description: UI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06116 |
altlinux: CVE-2026-87583 was patched at 2026-09-17
debian: CVE-2026-87583 was patched at 2026-09-16
1434.
Spoofing - Chromium (CVE-2026-87597) - Medium [276]
Description: UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00208, EPSS Percentile is 0.11206 |
altlinux: CVE-2026-87597 was patched at 2026-09-17
debian: CVE-2026-87597 was patched at 2026-09-16
1435.
Spoofing - Chromium (CVE-2026-87635) - Medium [276]
Description: UI misrepresentation in Payments in Google Chrome prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00224, EPSS Percentile is 0.13165 |
altlinux: CVE-2026-87635 was patched at 2026-09-17
debian: CVE-2026-87635 was patched at 2026-09-16
1436.
Spoofing - Chromium (CVE-2026-87653) - Medium [276]
Description: UI misrepresentation in FullScreen in Google Chrome on on Windows prior to 153.0.8010.36
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00185, EPSS Percentile is 0.08328 |
altlinux: CVE-2026-87653 was patched at 2026-09-17
debian: CVE-2026-87653 was patched at 2026-09-16
1437.
Unknown Vulnerability Type - Chromium (CVE-2026-79011) - Medium [276]
Description: {'nvd_cve_data_all': 'UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00444, EPSS Percentile is 0.37783 |
altlinux: CVE-2026-79011 was patched at 2026-08-28
debian: CVE-2026-79011 was patched at 2026-09-03, 2026-09-16
1438.
Unknown Vulnerability Type - Chromium (CVE-2026-79045) - Medium [276]
Description: {'nvd_cve_data_all': 'Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00322, EPSS Percentile is 0.25224 |
altlinux: CVE-2026-79045 was patched at 2026-08-28
debian: CVE-2026-79045 was patched at 2026-09-03, 2026-09-16
1439.
Unknown Vulnerability Type - Chromium (CVE-2026-79058) - Medium [276]
Description: {'nvd_cve_data_all': 'Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00321, EPSS Percentile is 0.2511 |
altlinux: CVE-2026-79058 was patched at 2026-08-28
debian: CVE-2026-79058 was patched at 2026-09-03, 2026-09-16
1440.
Unknown Vulnerability Type - Chromium (CVE-2026-79152) - Medium [276]
Description: {'nvd_cve_data_all': 'Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00239, EPSS Percentile is 0.15146 |
altlinux: CVE-2026-79152 was patched at 2026-08-28
debian: CVE-2026-79152 was patched at 2026-09-03, 2026-09-16
1441.
Unknown Vulnerability Type - Netty (CVE-2026-75596) - Medium [276]
Description: {'nvd_cve_data_all': 'Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/main/java/io/netty/handler/ssl/SslClientHelloHandler.java at io.netty.handler.ssl.SslClientHelloHandler#decode, where handshakeBuffer.clear() and writeBytes() recopy all previously received body bytes for every additional TLS record. An unauthenticated remote peer can advertise a large ClientHello and deliver its body in thousands of tiny records, causing quadratic CPU work on the event loop before the TLS handshake completes and degrading TLS handling for other clients. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/main/java/io/netty/handler/ssl/SslClientHelloHandler.java at io.netty.handler.ssl.SslClientHelloHandler#decode, where handshakeBuffer.clear() and writeBytes() recopy all previously received body bytes for every additional TLS record. An unauthenticated remote peer can advertise a large ClientHello and deliver its body in thousands of tiny records, causing quadratic CPU work on the event loop before the TLS handshake completes and degrading TLS handling for other clients. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Netty is a non-blocking I/O client-server framework for the development of Java network applications such as protocol servers and clients | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00351, EPSS Percentile is 0.28533 |
debian: CVE-2026-75596 was patched at 2026-08-25
1442.
Server-Side Request Forgery - Unknown Product (CVE-2026-76177) - Medium [274]
Description: {'nvd_cve_data_all': 'Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate endpoint due to insufficient validation of the HTTPS_SERV and FILE_SERV parameters. An authenticated user with operator privileges can provide arbitrary values for these parameters, causing the OCS Inventory server to make HTTP/HTTPS requests to external systems or internal resources, which could allow access to internal network services or metadata resources of cloud services.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate endpoint due to insufficient validation of the HTTPS_SERV and FILE_SERV parameters. An authenticated user with operator privileges can provide arbitrary values for these parameters, causing the OCS Inventory server to make HTTP/HTTPS requests to external systems or internal resources, which could allow access to internal network services or metadata resources of cloud services.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00336, EPSS Percentile is 0.26822 |
debian: CVE-2026-76177 was patched at 2026-09-16
1443.
Cross Site Scripting - Unknown Product (CVE-2026-76178) - Medium [273]
Description: {'nvd_cve_data_all': 'A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification. A user with administrator privileges can input malicious HTML content which is subsequently stored and displayed without proper sanitisation when other administrators access the template customisation view, allowing JavaScript code to be executed within the application’s security context and potentially compromising the sessions of other users with administrative privileges.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification. A user with administrator privileges can input malicious HTML content which is subsequently stored and displayed without proper sanitisation when other administrators access the template customisation view, allowing JavaScript code to be executed within the application’s security context and potentially compromising the sessions of other users with administrative privileges.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.2. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00269, EPSS Percentile is 0.19197 |
debian: CVE-2026-76178 was patched at 2026-09-16
1444.
Incorrect Calculation - zstd-jni (CVE-2026-87823) - Medium [273]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.25 | 14 | zstd-jni provides Java Native Interface bindings for the Zstandard lossless compression library, enabling high-performance compression and decompression from Java, Android, and other JVM languages. | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00432, EPSS Percentile is 0.36803 |
debian: CVE-2026-87823 was patched at 2026-09-16
1445.
Remote Code Execution - Unknown Product (CVE-2026-38821) - Medium [273]
Description: {'nvd_cve_data_all': 'A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00201, EPSS Percentile is 0.10195 |
debian: CVE-2026-38821 was patched at 2026-09-16
1446.
Remote Code Execution - Unknown Product (CVE-2026-40013) - Medium [273]
Description: {'nvd_cve_data_all': 'An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an out-of-bounds write when the ManageSieve service compiles the script. This causes memory corruption and an observed crash of the ManageSieve process, resulting in denial of service for script management. This might be able to be used for remote code execution. Disable the ManageSieve service if users do not need remote Sieve script management. Update to non-vulnerable version. No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an out-of-bounds write when the ManageSieve service compiles the script. This causes memory corruption and an observed crash of the ManageSieve process, resulting in denial of service for script management. This might be able to be used for remote code execution. Disable the ManageSieve service if users do not need remote Sieve script management. Update to non-vulnerable version. No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00455, EPSS Percentile is 0.38562 |
debian: CVE-2026-40013 was patched at 2026-09-16
1447.
Remote Code Execution - Unknown Product (CVE-2026-56704) - Medium [273]
Description: {'nvd_cve_data_all': 'Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafted version strings that break out of the JavaScript context and execute arbitrary code, bypassing Content Security Policy protections.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafted version strings that break out of the JavaScript context and execute arbitrary code, bypassing Content Security Policy protections.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00241, EPSS Percentile is 0.15458 |
debian: CVE-2026-56704 was patched at 2026-09-16
1448.
Remote Code Execution - Unknown Product (CVE-2026-75131) - Medium [273]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains a privilege escalation vulnerability that allows local users with permission to create VPN connections to execute arbitrary code as root by injecting pppd options through a crafted VPN username. Attackers can embed a double-quote character or whitespace in the username to break out of the pppd options file quoting context and include the pppd plugin directive, causing the privileged pppd process to load an attacker-controlled shared object.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.5. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-75131 was patched at 2026-09-14, 2026-09-16
1449.
Remote Code Execution - Unknown Product (CVE-2026-79992) - Medium [273]
Description: {'nvd_cve_data_all': 'A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00135, EPSS Percentile is 0.03355 |
debian: CVE-2026-79992 was patched at 2026-09-16
1450.
Memory Corruption - GNU Screen (CVE-2026-77219) - Medium [272]
Description: GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color index. The image loader multiplies image dimensions and channel count using signed integer arithmetic; for sufficiently large values, the result wraps to a negative number, bypassing the bounds check and causing the pixel reader to access heap memory past the end of the allocated buffer. The over-read contents are interpreted as pixel color values and rendered on
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | GNU Screen is a terminal multiplexer that allows multiple virtual terminal sessions to be accessed and controlled from a single physical terminal. It supports session detaching/reattaching, multiple windows, logging, and scripting — and historically is distributed as part of the GNU Project for use on Unix-like systems. When run with setuid-root privileges (as in CVE-2025-23395), Screen may perform privileged file operations on user-supplied paths without dropping elevated privileges, enabling unprivileged users to create root-owned files and potentially escalate to root. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02838 |
debian: CVE-2026-77219 was patched at 2026-08-25
1451.
Memory Corruption - Binutils (CVE-2026-90802) - Medium [270]
Description: A weakness has been identified in GNU
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.4 | 10 | CVSS Base Score is 4.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.01563 |
debian: CVE-2026-90802 was patched at 2026-09-16
1452.
Memory Corruption - Chromium (CVE-2026-85052) - Medium [270]
Description: Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00182, EPSS Percentile is 0.0801 |
altlinux: CVE-2026-85052 was patched at 2026-09-05
debian: CVE-2026-85052 was patched at 2026-09-05, 2026-09-16
1453.
Memory Corruption - Chromium (CVE-2026-87657) - Medium [270]
Description: Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.07 |
altlinux: CVE-2026-87657 was patched at 2026-09-17
debian: CVE-2026-87657 was patched at 2026-09-16
1454.
Memory Corruption - Chromium (CVE-2026-91747) - Medium [270]
Description: Use after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.13991 |
altlinux: CVE-2026-91747 was patched at 2026-09-17
debian: CVE-2026-91747 was patched at 2026-09-16
1455.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80599) - Medium [269]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: ensure accessible eth_hdr proto field When batadv_get_vid() accesses the proto field of the ethernet header, it is not checking if the data itself is accessible. The caller is responsible for it. But in contrast to other call sites, batadv_dat_get_vid() and its caller didn't make sure this is true. This could have caused an out-of-bounds access.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: dat: ensure accessible eth_hdr proto field\n\nWhen batadv_get_vid() accesses the proto field of the ethernet header, it\nis not checking if the data itself is accessible. The caller is responsible\nfor it. But in contrast to other call sites, batadv_dat_get_vid() and its\ncaller didn't make sure this is true. This could have caused an\nout-of-bounds access.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00277, EPSS Percentile is 0.20244 |
debian: CVE-2026-80599 was patched at 2026-09-16
oraclelinux: CVE-2026-80599 was patched at 2026-09-04
redos: CVE-2026-80599 was patched at 2026-09-16
1456.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80645) - Medium [269]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() With a list_for_each() loop, if we don't find the item we are looking for in the list, then the loop exits with the iterator, which is "dbell" in this loop, pointing to invalid memory. This code uses the "found" variable to determine if we have found the doorbell we are looking for or not. However, the problem that the "found" variable needs to be set to false at the start of each iteration, otherwise after the first correct doorbell, then everything is marked as found. Reset the "found" to false at the start of the iteration and move the variable inside the loop.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nrapidio/tsi721: prevent a bad dereference in tsi721_db_dpc()\n\nWith a list_for_each() loop, if we don't find the item we are looking for\nin the list, then the loop exits with the iterator, which is "dbell" in\nthis loop, pointing to invalid memory.\n\nThis code uses the "found" variable to determine if we have found the\ndoorbell we are looking for or not. However, the problem that the "found"\nvariable needs to be set to false at the start of each iteration,\notherwise after the first correct doorbell, then everything is marked as\nfound.\n\nReset the "found" to false at the start of the iteration and move the\nvariable inside the loop.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00259, EPSS Percentile is 0.17772 |
debian: CVE-2026-80645 was patched at 2026-09-16
redos: CVE-2026-80645 was patched at 2026-09-16
1457.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80692) - Medium [269]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks There is theoretical UAF if the conn is freed while the hci_sync task is running. Hold refcount to avoid that.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks\n\nThere is theoretical UAF if the conn is freed while the hci_sync task\nis running.\n\nHold refcount to avoid that.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00218, EPSS Percentile is 0.12421 |
debian: CVE-2026-80692 was patched at 2026-09-16
1458.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80721) - Medium [269]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: ensure no dangling hcon references in iso_conn After iso_conn_del(), ISO sockets should not dereference the hcon any more. Currently, clearing iso_conn::hcon relies on iso_conn_del() releasing the last reference to the iso_conn. Simplify this by explicitly clearing conn->hcon in iso_conn_del(), to avoid more complex reasoning on races about who holds the last reference.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: ensure no dangling hcon references in iso_conn\n\nAfter iso_conn_del(), ISO sockets should not dereference the hcon any\nmore. Currently, clearing iso_conn::hcon relies on iso_conn_del()\nreleasing the last reference to the iso_conn.\n\nSimplify this by explicitly clearing conn->hcon in iso_conn_del(), to\navoid more complex reasoning on races about who holds the last\nreference.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00225, EPSS Percentile is 0.1336 |
debian: CVE-2026-80721 was patched at 2026-09-16
1459.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80943) - Medium [269]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids rtl92du_tx_fill_desc() uses ieee80211_get_tid() to read the QoS TID from the 802.11 header and then uses it as an index into sta_entry->tids[]. ieee80211_get_tid() returns the low 4-bit QoS TID value, so the result can be in the range 0..15. rtlwifi only allocates MAX_TID_COUNT entries for sta_entry->tids[], and MAX_TID_COUNT is 9. A QoS TID greater than 8 therefore indexes past the aggregation state array. Keep the default RTL_AGG_STOP state for out-of-range TIDs, matching rtl92cu_tx_fill_desc(). This issue was detected by our static analysis tool and confirmed by manual audit. UBSAN validation for the same bug pattern reports an array-index-out-of-bounds access with index 10 for type 'rtl_tid_data [9]'.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtlwifi: rtl8192du: check QoS TID before indexing tids\n\nrtl92du_tx_fill_desc() uses ieee80211_get_tid() to read the QoS TID\nfrom the 802.11 header and then uses it as an index into\nsta_entry->tids[]. ieee80211_get_tid() returns the low 4-bit QoS TID\nvalue, so the result can be in the range 0..15.\n\nrtlwifi only allocates MAX_TID_COUNT entries for sta_entry->tids[], and\nMAX_TID_COUNT is 9. A QoS TID greater than 8 therefore indexes past the\naggregation state array. Keep the default RTL_AGG_STOP state for\nout-of-range TIDs, matching rtl92cu_tx_fill_desc().\n\nThis issue was detected by our static analysis tool and confirmed by\nmanual audit. UBSAN validation for the same bug pattern reports an\narray-index-out-of-bounds access with index 10 for type\n'rtl_tid_data [9]'.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16156 |
debian: CVE-2026-80943 was patched at 2026-09-16
1460.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89445) - Medium [269]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix UAF in selftest IOPF reporting IOMMUFD selftest TRIGGER_IOPF borrows an attach handle from group->pasid_array without synchronizing against PASID detach, then a concurrent iommu_report_device_fault() can dereference that borrowed handle's domain pointer after the detach erases the handle and frees the backing struct iommufd_attach_handle. TRIGGER_IOPF then dereferences the freed handle, causing a UAF. Fix by adding a iopf_rwsem in mock_dev to follow the expected design of a real driver. Hold its read side across the whole iommu_report_device_fault() call, and its write side around every path that attaches, detaches, or replaces a device domain. This can block new reports and drains in-flight reports before an old attach handle or the IOPF fault parameter can be removed. Also take the write side while registering a mock device, since it can invoke the mock driver's default-domain attach callback.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Fix UAF in selftest IOPF reporting\n\nIOMMUFD selftest TRIGGER_IOPF borrows an attach handle from\ngroup->pasid_array without synchronizing against PASID detach,\nthen a concurrent iommu_report_device_fault() can dereference\nthat borrowed handle's domain pointer after the detach erases\nthe handle and frees the backing struct iommufd_attach_handle.\nTRIGGER_IOPF then dereferences the freed handle, causing a UAF.\n\nFix by adding a iopf_rwsem in mock_dev to follow the expected design\nof a real driver. Hold its read side across the whole\niommu_report_device_fault() call, and its write side around every\npath that attaches, detaches, or replaces a device domain.\nThis can block new reports and drains in-flight reports before an old\nattach handle or the IOPF fault parameter can be removed.\nAlso take the write side while registering a mock device, since\nit can invoke the mock driver's default-domain attach callback.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00161, EPSS Percentile is 0.05731 |
debian: CVE-2026-89445 was patched at 2026-09-16
1461.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89524) - Medium [269]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets ath6kl_cfg80211_connect_event() subtracts fixed IE offsets from assoc_req_len (-= 4) and assoc_resp_len (-= 6), both u8, with no lower bound. The aggregate check recently added to ath6kl_wmi_connect_event_rx() bounds the declared lengths from above (their sum must fit the received event), but an assoc request/response shorter than its fixed offset still underflows here: the u8 wraps to ~250, and cfg80211_connect_result() / cfg80211_roamed() then treat that wrapped value as the IE length and copy that many bytes out of the small assoc_info buffer to user space via nl80211, disclosing adjacent slab memory. Clamp both lengths to their offsets before subtracting. Found by 0sec (https://0sec.ai) using automated source analysis; the missing lower bound is evident from source. Compile-tested.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets\n\nath6kl_cfg80211_connect_event() subtracts fixed IE offsets from\nassoc_req_len (-= 4) and assoc_resp_len (-= 6), both u8, with no lower\nbound. The aggregate check recently added to ath6kl_wmi_connect_event_rx()\nbounds the declared lengths from above (their sum must fit the received\nevent), but an assoc request/response shorter than its fixed offset still\nunderflows here: the u8 wraps to ~250, and cfg80211_connect_result() /\ncfg80211_roamed() then treat that wrapped value as the IE length and copy\nthat many bytes out of the small assoc_info buffer to user space via\nnl80211, disclosing adjacent slab memory.\n\nClamp both lengths to their offsets before subtracting.\n\nFound by 0sec (https://0sec.ai) using automated source analysis; the\nmissing lower bound is evident from source. Compile-tested.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00277, EPSS Percentile is 0.20244 |
debian: CVE-2026-89524 was patched at 2026-09-16
1462.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89583) - Medium [269]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix OOB read in eir_get_service_data() eir_get_service_data() walks the advertising data for a Service Data field with a matching UUID. On a mismatch it advances: eir += dlen; eir_len -= dlen; eir_get_data() reports dlen as the field's data length, but the field spans dlen + 2 bytes once its length and type bytes count, and more when non-Service-Data fields were skipped to reach it. The pointer lands correctly on the next field. eir_len does not, and the shortfall compounds across fields until eir_get_data() reads the length and type bytes of a "field" past the end of the buffer. For an ISO broadcast sink that buffer is hcon->le_per_adv_data[], filled from the periodic advertising reports of a remote broadcaster. A PA payload packed with mismatching Service Data fields walks off the array into the rest of struct hci_conn. A drifted field that matches the BAA UUID puts those bytes in iso_pi(sk)->base, where user space reads them back with getsockopt(BT_ISO_BASE). Recompute eir_len from the end of the buffer each iteration.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: eir: Fix OOB read in eir_get_service_data()\n\neir_get_service_data() walks the advertising data for a Service Data\nfield with a matching UUID. On a mismatch it advances:\n\n eir += dlen;\n eir_len -= dlen;\n\neir_get_data() reports dlen as the field's data length, but the field\nspans dlen + 2 bytes once its length and type bytes count, and more\nwhen non-Service-Data fields were skipped to reach it. The pointer\nlands correctly on the next field. eir_len does not, and the shortfall\ncompounds across fields until eir_get_data() reads the length and type\nbytes of a "field" past the end of the buffer.\n\nFor an ISO broadcast sink that buffer is hcon->le_per_adv_data[], filled\nfrom the periodic advertising reports of a remote broadcaster. A PA\npayload packed with mismatching Service Data fields walks off the array\ninto the rest of struct hci_conn. A drifted field that matches the BAA\nUUID puts those bytes in iso_pi(sk)->base, where user space reads them\nback with getsockopt(BT_ISO_BASE).\n\nRecompute eir_len from the end of the buffer each iteration.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00271, EPSS Percentile is 0.19415 |
debian: CVE-2026-89583 was patched at 2026-09-16
1463.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89774) - Medium [269]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: hold sk properly in sco_conn_ready sk deref in sco_conn_ready must be done either under conn->lock, or holding a refcount, to avoid concurrent close. conn->sk and parent sk is currently accessed without either, and without checking parent->sk_state: [Task 1] [Task 2] sco_sock_release sco_conn_ready sk = conn->sk lock_sock(sk) conn->sk = NULL lock_sock(sk) release_sock(sk) sco_sock_kill(sk) UAF on sk deref and similarly for access to sco_get_sock_listen() return value. Fix possible UAF by holding sk refcount in sco_conn_ready() and making sco_get_sock_listen() increase refcount. Also recheck after lock_sock that the socket is still valid. Adjust conn->sk locking so it's protected also by lock_sock() of the associated socket if any.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: SCO: hold sk properly in sco_conn_ready\n\nsk deref in sco_conn_ready must be done either under conn->lock, or\nholding a refcount, to avoid concurrent close. conn->sk and parent sk is\ncurrently accessed without either, and without checking parent->sk_state:\n\n [Task 1] [Task 2]\n sco_sock_release\n sco_conn_ready\n sk = conn->sk\n lock_sock(sk)\n conn->sk = NULL\n lock_sock(sk)\n release_sock(sk)\n sco_sock_kill(sk)\n UAF on sk deref\n\nand similarly for access to sco_get_sock_listen() return value.\n\nFix possible UAF by holding sk refcount in sco_conn_ready() and making\nsco_get_sock_listen() increase refcount. Also recheck after lock_sock\nthat the socket is still valid. Adjust conn->sk locking so it's\nprotected also by lock_sock() of the associated socket if any.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00191, EPSS Percentile is 0.09043 |
debian: CVE-2026-89774 was patched at 2026-09-16
1464.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89779) - Medium [269]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate ef->size covers the record's name and value When an EA record has a non-zero ef->size, ntfs_read_ea() only checks that the record fits in the remaining buffer (ea_size > bytes), not that ef->size is large enough to hold the record's own name_len + 1 + elength. A crafted image can pass validation with, e.g., ef->size = 24 but elength = 0xffff. ntfs_get_ea() then trusts elength and copies it out of the undersized record, reading past the kmalloc(info->size) allocation and leaking heap memory to userspace via getxattr(): BUG: KASAN: slab-out-of-bounds in ntfs_get_ea (fs/ntfs3/xattr.c:302) Read of size 65535 at addr ffff888100794550 by task exploit __asan_memcpy (mm/kasan/shadow.c:105) ntfs_get_ea (fs/ntfs3/xattr.c:302) ntfs_getxattr (fs/ntfs3/xattr.c:848) __vfs_getxattr (fs/xattr.c:441) vfs_getxattr (fs/xattr.c:474) do_getxattr (fs/xattr.c:800) path_getxattrat (fs/xattr.c:868) do_syscall_64 (arch/x86/entry/syscall_64.c:94) The buggy address is located 80 bytes inside of allocated 84-byte region in cache kmalloc-96 Compute the size the record needs and require ef->size to cover it.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: validate ef->size covers the record's name and value\n\nWhen an EA record has a non-zero ef->size, ntfs_read_ea() only checks\nthat the record fits in the remaining buffer (ea_size > bytes), not that\nef->size is large enough to hold the record's own name_len + 1 + elength.\n\nA crafted image can pass validation with, e.g., ef->size = 24 but\nelength = 0xffff. ntfs_get_ea() then trusts elength and copies it out of\nthe undersized record, reading past the kmalloc(info->size) allocation\nand leaking heap memory to userspace via getxattr():\n\n BUG: KASAN: slab-out-of-bounds in ntfs_get_ea (fs/ntfs3/xattr.c:302)\n Read of size 65535 at addr ffff888100794550 by task exploit\n __asan_memcpy (mm/kasan/shadow.c:105)\n ntfs_get_ea (fs/ntfs3/xattr.c:302)\n ntfs_getxattr (fs/ntfs3/xattr.c:848)\n __vfs_getxattr (fs/xattr.c:441)\n vfs_getxattr (fs/xattr.c:474)\n do_getxattr (fs/xattr.c:800)\n path_getxattrat (fs/xattr.c:868)\n do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n\n The buggy address is located 80 bytes inside of\n allocated 84-byte region in cache kmalloc-96\n\nCompute the size the record needs and require ef->size to cover it.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10806 |
debian: CVE-2026-89779 was patched at 2026-09-16
1465.
Denial of Service - GPU Display Driver (CVE-2026-24199) - Medium [267]
Description: NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where a user could cause a race condition by reordering compiler or processor memory instructions. A successful exploit of this vulnerability might lead to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:nvidia:gpu_display_driver (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00092, EPSS Percentile is 0.00609 |
redos: CVE-2026-24199 was patched at 2026-09-08
1466.
Denial of Service - Unknown Product (CVE-2026-50161) - Medium [267]
Description: {'nvd_cve_data_all': 'libre is a generic library for real-time communications with asynchronous input and output support. Prior to 4.8.1, the websock_decode() function in src/websock/websock.c contains an integer overflow when validating a masked WebSocket frame that uses the 64-bit extended length encoding. The expression 4 + hdr->len can wrap when hdr->len is close to UINT64_MAX, causing the mbuf_get_left() bounds check to pass. The subsequent XOR unmasking loop then writes beyond the heap buffer. Applications using websock_accept() or websock_accept_proto() to implement a WebSocket server are affected, and exploitation can cause attacker-controlled heap corruption or denial of service after the HTTP WebSocket upgrade handshake. This issue is fixed in version 4.8.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'libre is a generic library for real-time communications with asynchronous input and output support. Prior to 4.8.1, the websock_decode() function in src/websock/websock.c contains an integer overflow when validating a masked WebSocket frame that uses the 64-bit extended length encoding. The expression 4 + hdr->len can wrap when hdr->len is close to UINT64_MAX, causing the mbuf_get_left() bounds check to pass. The subsequent XOR unmasking loop then writes beyond the heap buffer. Applications using websock_accept() or websock_accept_proto() to implement a WebSocket server are affected, and exploitation can cause attacker-controlled heap corruption or denial of service after the HTTP WebSocket upgrade handshake. This issue is fixed in version 4.8.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00384, EPSS Percentile is 0.32109 |
debian: CVE-2026-50161 was patched at 2026-08-25
1467.
Denial of Service - Unknown Product (CVE-2026-61666) - Medium [267]
Description: {'nvd_cve_data_all': 'websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing a remote client to crash a TCP-backed WebSocket server when the application does not catch the error from parse(). This issue is fixed in version 0.8.2.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, allowing a remote client to crash a TCP-backed WebSocket server when the application does not catch the error from parse(). This issue is fixed in version 0.8.2.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.9. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00338, EPSS Percentile is 0.27117 |
debian: CVE-2026-61666 was patched at 2026-08-25
1468.
Denial of Service - Unknown Product (CVE-2026-69220) - Medium [267]
Description: {'nvd_cve_data_all': 'The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call ValueReader.readFieldValue recursively for AMQP table type F and AMQP array type A values without a nesting-depth limit. A malicious AMQP server or network intermediary can send approximately 580 nested table levels in the pre-authentication connection.start frame, fitting within the default 131072-byte frame maximum, to trigger StackOverflowError. The error terminates the client input processing thread and causes denial of service. This issue is fixed in version 5.33.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call ValueReader.readFieldValue recursively for AMQP table type F and AMQP array type A values without a nesting-depth limit. A malicious AMQP server or network intermediary can send approximately 580 nested table levels in the pre-authentication connection.start frame, fitting within the default 131072-byte frame maximum, to trigger StackOverflowError. The error terminates the client input processing thread and causes denial of service. This issue is fixed in version 5.33.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00399, EPSS Percentile is 0.33749 |
debian: CVE-2026-69220 was patched at 2026-08-20
1469.
Denial of Service - Unknown Product (CVE-2026-74835) - Medium [267]
Description: {'nvd_cve_data_all': 'The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request.\n\nThis issue affects OTP from OTP\xa017.0 before OTP\xa027.3.4.17, from OTP\xa028.0 before OTP\xa028.5.0.6, and from OTP\xa029.0 before OTP\xa029.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP\xa017.0, corresponding to inets before 5.10, is affected is unknown.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00328, EPSS Percentile is 0.25886 |
debian: CVE-2026-74835 was patched at 2026-09-16
1470.
Denial of Service - Unknown Product (CVE-2026-75140) - Medium [267]
Description: {'nvd_cve_data_all': 'jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced elements. The builder copies the entire inherited namespace map on every start element, causing quadratic time and memory complexity, which attackers can exploit to trigger an OutOfMemoryError and terminate the application.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced elements. The builder copies the entire inherited namespace map on every start element, causing quadratic time and memory complexity, which attackers can exploit to trigger an OutOfMemoryError and terminate the application.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00525, EPSS Percentile is 0.43227 |
debian: CVE-2026-75140 was patched at 2026-08-25
1471.
Denial of Service - Unknown Product (CVE-2026-85150) - Medium [267]
Description: {'nvd_cve_data_all': 'A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00519, EPSS Percentile is 0.42825 |
almalinux: CVE-2026-85150 was patched at 2026-09-10, 2026-09-14
altlinux: CVE-2026-85150 was patched at 2026-09-08
debian: CVE-2026-85150 was patched at 2026-09-16
oraclelinux: CVE-2026-85150 was patched at 2026-09-11, 2026-09-14
1472.
Denial of Service - Unknown Product (CVE-2026-85234) - Medium [267]
Description: {'nvd_cve_data_all': 'A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a non-empty custom error message, it can pass invalid match offsets to the `genmatchstring()` function. This leads to out-of-bounds read/write operations. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted request, causing the daemon to crash and resulting in a denial of service.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a non-empty custom error message, it can pass invalid match offsets to the `genmatchstring()` function. This leads to out-of-bounds read/write operations. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted request, causing the daemon to crash and resulting in a denial of service.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0044, EPSS Percentile is 0.374 |
debian: CVE-2026-85234 was patched at 2026-09-16
1473.
Denial of Service - Xeon Bronze 3408U (CVE-2026-20775) - Medium [267]
Description: Uncaught exception for some Intel(R) TDX modules within Ring 0: Trust Domain may allow a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by h:intel:xeon_bronze_3408u (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00099, EPSS Percentile is 0.00892 |
oraclelinux: CVE-2026-20775 was patched at 2026-09-02, 2026-09-16
1474.
Incorrect Calculation - Pcre2 (CVE-2026-89158) - Medium [267]
Description: PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:pcre:pcre2 (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00221, EPSS Percentile is 0.12822 |
debian: CVE-2026-89158 was patched at 2026-09-16
1475.
Memory Corruption - IMAP (CVE-2026-61908) - Medium [267]
Description: An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H<emailid>-<index>, which could read past the end of the internal blob_headers array during download, exposing adjacent heap memory.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:cyrus:imap (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.1071 |
debian: CVE-2026-61908 was patched at 2026-09-16
1476.
Memory Corruption - IMAP (CVE-2026-61915) - Medium [267]
Description: An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The memory holding the selector would be freed once on each iteration over the properties.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:cyrus:imap (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00217, EPSS Percentile is 0.12326 |
debian: CVE-2026-61915 was patched at 2026-09-16
1477.
Memory Corruption - Kamailio (CVE-2026-82608) - Medium [267]
Description: A vulnerability was determined in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Kamailio is an open-source SIP server used for building scalable VoIP, instant messaging, and real-time communications systems. | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00234, EPSS Percentile is 0.14432 |
debian: CVE-2026-82608 was patched at 2026-09-11, 2026-09-16
1478.
Memory Corruption - OpenEXR (CVE-2026-59184) - Medium [267]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | OpenEXR is an open source high-dynamic-range image file format and reference implementation widely used in computer graphics, visual effects, animation, and motion picture production. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00218, EPSS Percentile is 0.12362 |
debian: CVE-2026-59184 was patched at 2026-09-16
1479.
Memory Corruption - OpenEXR (CVE-2026-59186) - Medium [267]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | OpenEXR is an open source high-dynamic-range image file format and reference implementation widely used in computer graphics, visual effects, animation, and motion picture production. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00224, EPSS Percentile is 0.13168 |
debian: CVE-2026-59186 was patched at 2026-09-16
1480.
Memory Corruption - OpenEXR (CVE-2026-59187) - Medium [267]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | OpenEXR is an open source high-dynamic-range image file format and reference implementation widely used in computer graphics, visual effects, animation, and motion picture production. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00217, EPSS Percentile is 0.12252 |
debian: CVE-2026-59187 was patched at 2026-09-16
1481.
Memory Corruption - libexpat (CVE-2026-76957) - Medium [267]
Description: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:libexpat_project:libexpat (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00107, EPSS Percentile is 0.01264 |
debian: CVE-2026-76957 was patched at 2026-08-25
1482.
Security Feature Bypass - Unknown Product (CVE-2025-30156) - Medium [267]
Description: {'nvd_cve_data_all': 'Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol encrypts tickets with AES-128-CBC in an unauthenticated mode that uses a hard-coded initialization vector and no message authentication, allowing an attacker to forge credentials and gain cluster-wide access. Because the ciphertext is malleable and the monitor will encrypt attacker-chosen entity names, an attacker holding one low-privilege key and able to observe CephX traffic can use the monitor as an encryption oracle and splice ciphertext blocks into valid tickets for privileged entities such as Manager, MDS, and OSD. The same lack of authentication also lets an attacker with CephX permissions escalate privileges by flipping a single bit in a service ticket to set its allow_all field to true. This issue is fixed in versions 20.2.4 and 19.2.6.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol encrypts tickets with AES-128-CBC in an unauthenticated mode that uses a hard-coded initialization vector and no message authentication, allowing an attacker to forge credentials and gain cluster-wide access. Because the ciphertext is malleable and the monitor will encrypt attacker-chosen entity names, an attacker holding one low-privilege key and able to observe CephX traffic can use the monitor as an encryption oracle and splice ciphertext blocks into valid tickets for privileged entities such as Manager, MDS, and OSD. The same lack of authentication also lets an attacker with CephX permissions escalate privileges by flipping a single bit in a service ticket to set its allow_all field to true. This issue is fixed in versions 20.2.4 and 19.2.6.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00093, EPSS Percentile is 0.00636 |
debian: CVE-2025-30156 was patched at 2026-08-25
1483.
Security Feature Bypass - Unknown Product (CVE-2026-54330) - Medium [267]
Description: {'nvd_cve_data_all': 'Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) SigV4 handler does not reject requests that carry x-amz-* headers absent from the signed header set, allowing anyone holding a presigned URL to attach arbitrary unsigned x-amz-* headers that RGW will honor. AWS S3 requires every x-amz-* header on a SigV4 request to be signed and rejects requests bearing additional unsigned headers, but RGW validates only the headers listed in X-Amz-SignedHeaders and ignores any extra ones, so they take effect without being covered by the signature. By adding such headers to a presigned PUT URL, an attacker can grant themselves more capabilities than the URL's signer intended and escalate their privileges. This issue is fixed in versions 20.2.4 and 19.2.6.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) SigV4 handler does not reject requests that carry x-amz-* headers absent from the signed header set, allowing anyone holding a presigned URL to attach arbitrary unsigned x-amz-* headers that RGW will honor. AWS S3 requires every x-amz-* header on a SigV4 request to be signed and rejects requests bearing additional unsigned headers, but RGW validates only the headers listed in X-Amz-SignedHeaders and ignores any extra ones, so they take effect without being covered by the signature. By adding such headers to a presigned PUT URL, an attacker can grant themselves more capabilities than the URL's signer intended and escalate their privileges. This issue is fixed in versions 20.2.4 and 19.2.6.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00181, EPSS Percentile is 0.07954 |
debian: CVE-2026-54330 was patched at 2026-08-25
1484.
Security Feature Bypass - Unknown Product (CVE-2026-63335) - Medium [267]
Description: {'nvd_cve_data_all': 'The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly in src/main/java/com/rabbitmq/client/impl/CommandAssembler.java processes a content-bearing method and header whose remainingBodyBytes value is smaller than a following AMQP.FRAME_BODY payload. CommandAssembler.consumeBodyFrame subtracts the peer-controlled payload length before validating that it fits, drives remainingBodyBytes negative, and throws a raw UnsupportedOperationException instead of MalformedFrameException. A malicious or compromised broker peer can send this malformed sequence on an open nonzero channel to terminate frame processing and close the client connection, causing denial of service for work using that connection. This issue is fixed in version 5.31.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly in src/main/java/com/rabbitmq/client/impl/CommandAssembler.java processes a content-bearing method and header whose remainingBodyBytes value is smaller than a following AMQP.FRAME_BODY payload. CommandAssembler.consumeBodyFrame subtracts the peer-controlled payload length before validating that it fits, drives remainingBodyBytes negative, and throws a raw UnsupportedOperationException instead of MalformedFrameException. A malicious or compromised broker peer can send this malformed sequence on an open nonzero channel to terminate frame processing and close the client connection, causing denial of service for work using that connection. This issue is fixed in version 5.31.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00372, EPSS Percentile is 0.30897 |
debian: CVE-2026-63335 was patched at 2026-08-20
1485.
Unknown Vulnerability Type - xmldom (CVE-2026-83608) - Medium [267]
Description: {'nvd_cve_data_all': 'xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, the DOCUMENT_TYPE_NODE branch in lib/dom.js validates publicId, systemId, and internalSubset under requireWellFormed: true but emits DocumentType.name verbatim. A name containing > or whitespace can terminate the <!DOCTYPE ...> declaration and inject sibling markup; the value can be supplied through createDocumentType() on the 0.8.x and unscoped lines or through a direct DocumentType.name property write on every affected line. The default path and legacy creation-time behavior remain permissive, while the vulnerable strict path fails to enforce an XML Name. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, the DOCUMENT_TYPE_NODE branch in lib/dom.js validates publicId, systemId, and internalSubset under requireWellFormed: true but emits DocumentType.name verbatim. A name containing > or whitespace can terminate the <!DOCTYPE ...> declaration and inject sibling markup; the value can be supplied through createDocumentType() on the 0.8.x and unscoped lines or through a direct DocumentType.name property write on every affected line. The default path and legacy creation-time behavior remain permissive, while the vulnerable strict path fails to enforce an XML Name. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.75 | 14 | JavaScript XML parser and serializer implementing W3C DOM standards. | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00348, EPSS Percentile is 0.28242 |
debian: CVE-2026-83608 was patched at 2026-09-16
1486.
Memory Corruption - Open Asset Import Library Assimp (CVE-2026-82591) - Medium [265]
Description: A security vulnerability has been detected in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | Open Asset Import Library is a library that loads various 3D file formats into a shared, in-memory format | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.02495 |
debian: CVE-2026-82591 was patched at 2026-09-16
1487.
Spoofing - Chromium (CVE-2026-79233) - Medium [264]
Description: UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0019, EPSS Percentile is 0.0892 |
altlinux: CVE-2026-79233 was patched at 2026-08-28
debian: CVE-2026-79233 was patched at 2026-09-03, 2026-09-16
1488.
Spoofing - Chromium (CVE-2026-91723) - Medium [264]
Description: Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06866 |
altlinux: CVE-2026-91723 was patched at 2026-09-17
debian: CVE-2026-91723 was patched at 2026-09-16
1489.
Spoofing - Mozilla Firefox (CVE-2026-74975) - Medium [264]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00154, EPSS Percentile is 0.04969 |
altlinux: CVE-2026-74975 was patched at 2026-08-20, 2026-08-28
1490.
Spoofing - Mozilla Firefox (CVE-2026-92069) - Medium [264]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04023 |
altlinux: CVE-2026-92069 was patched at 2026-09-16
1491.
Unknown Vulnerability Type - Chromium (CVE-2026-76019) - Medium [264]
Description: {'nvd_cve_data_all': 'Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00359, EPSS Percentile is 0.29478 |
altlinux: CVE-2026-76019 was patched at 2026-08-21
debian: CVE-2026-76019 was patched at 2026-08-25, 2026-08-27
1492.
Unknown Vulnerability Type - Chromium (CVE-2026-87569) - Medium [264]
Description: {'nvd_cve_data_all': 'Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00245, EPSS Percentile is 0.15934 |
altlinux: CVE-2026-87569 was patched at 2026-09-17
debian: CVE-2026-87569 was patched at 2026-09-16
1493.
Unknown Vulnerability Type - GNU C Library (CVE-2026-19499) - Medium [264]
Description: {'nvd_cve_data_all': 'Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller. At the time of publication, no network-facing application impact is known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | The GNU C Library, commonly known as glibc, is the GNU Project's implementation of the C standard library | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00376, EPSS Percentile is 0.31279 |
debian: CVE-2026-19499 was patched at 2026-09-16
ubuntu: CVE-2026-19499 was patched at 2026-09-08, 2026-09-16
1494.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-74956) - Medium [264]
Description: {'nvd_cve_data_all': 'Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00283, EPSS Percentile is 0.20859 |
altlinux: CVE-2026-74956 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
1495.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92018) - Medium [264]
Description: {'nvd_cve_data_all': 'Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.0518 |
altlinux: CVE-2026-92018 was patched at 2026-09-16
debian: CVE-2026-92018 was patched at 2026-09-16, 2026-09-17
1496.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92032) - Medium [264]
Description: {'nvd_cve_data_all': 'Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.0518 |
altlinux: CVE-2026-92032 was patched at 2026-09-16
debian: CVE-2026-92032 was patched at 2026-09-16, 2026-09-17
1497.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92052) - Medium [264]
Description: {'nvd_cve_data_all': 'Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.17263 |
altlinux: CVE-2026-92052 was patched at 2026-09-16
1498.
Unknown Vulnerability Type - Netty (CVE-2026-75595) - Medium [264]
Description: {'nvd_cve_data_all': 'Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a ClientHello whose handshake header spans records can cause an IndexOutOfBoundsException and invoke select(ctx, null). This selects the default SslContext instead of the SNI-specific context. In deployments where per-SNI clientAuth=REQUIRE is the sole mutual TLS gate, the default SslContext uses clientAuth=NONE or clientAuth=OPTIONAL, and no application-layer certificate verification exists, an unauthenticated remote attacker can bypass the protected route's mutual TLS requirement. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a ClientHello whose handshake header spans records can cause an IndexOutOfBoundsException and invoke select(ctx, null). This selects the default SslContext instead of the SNI-specific context. In deployments where per-SNI clientAuth=REQUIRE is the sole mutual TLS gate, the default SslContext uses clientAuth=NONE or clientAuth=OPTIONAL, and no application-layer certificate verification exists, an unauthenticated remote attacker can bypass the protected route's mutual TLS requirement. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Netty is a non-blocking I/O client-server framework for the development of Java network applications such as protocol servers and clients | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00317, EPSS Percentile is 0.24693 |
debian: CVE-2026-75595 was patched at 2026-08-25
1499.
Unknown Vulnerability Type - Node.js (CVE-2026-87776) - Medium [264]
Description: {'nvd_cve_data_all': 'compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never destroyed, so each aborted compressed response leaks its native zlib memory. A remote unauthenticated attacker can repeatedly open requests and disconnect early, exhausting the available memory and crashing the server. All applications using compression are affected. The issue is fixed in compression 1.8.2, and users should upgrade to 1.8.2 or later.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never destroyed, so each aborted compressed response leaks its native zlib memory. A remote unauthenticated attacker can repeatedly open requests and disconnect early, exhausting the available memory and crashing the server. All applications using compression are affected. The issue is fixed in compression 1.8.2, and users should upgrade to 1.8.2 or later.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00363, EPSS Percentile is 0.29896 |
debian: CVE-2026-87776 was patched at 2026-09-16
1500.
Server-Side Request Forgery - Unknown Product (CVE-2026-10582) - Medium [262]
Description: {'nvd_cve_data_all': 'Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the configured pattern list and then re-checks a canonicalised form of an integer, hex or octal IPv4 host, but it never resolves the hostname and never inspects the address the HTTP client actually connects to. The client constructed in resources/resource_factories/create/create.go installs no dial-time hook, so no check occurs at connection time either. A hostname that resolves to a loopback, private or cloud-metadata address therefore satisfies the policy, and the response body is embedded in the generated site. An attacker who can supply a URL through content, for example a front-matter field or a CMS field, can make the build fetch an internal endpoint and publish the response in the static output, so the build artifact itself carries the data out.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the configured pattern list and then re-checks a canonicalised form of an integer, hex or octal IPv4 host, but it never resolves the hostname and never inspects the address the HTTP client actually connects to. The client constructed in resources/resource_factories/create/create.go installs no dial-time hook, so no check occurs at connection time either. A hostname that resolves to a loopback, private or cloud-metadata address therefore satisfies the policy, and the response body is embedded in the generated site. An attacker who can supply a URL through content, for example a front-matter field or a CMS field, can make the build fetch an internal endpoint and publish the response in the static output, so the build artifact itself carries the data out.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00315, EPSS Percentile is 0.24427 |
debian: CVE-2026-10582 was patched at 2026-09-16
1501.
Memory Corruption - zstd-jni (CVE-2026-90560) - Medium [261]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.25 | 14 | zstd-jni provides Java Native Interface bindings for the Zstandard lossless compression library, enabling high-performance compression and decompression from Java, Android, and other JVM languages. | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00336, EPSS Percentile is 0.26848 |
debian: CVE-2026-90560 was patched at 2026-09-16
1502.
Remote Code Execution - Unknown Product (CVE-2026-55893) - Medium [261]
Description: {'nvd_cve_data_all': 'Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() using sh_info.op.op_count without checking the fixed-size operands[] array. Repeated crafted instructions processed through cs_disasm_iter() or cs_disasm() with CS_ARCH_SH, CS_MODE_SH2A or CS_MODE_SH4A, CS_MODE_SHFPU, and CS_OPT_DETAIL can increment the operand count beyond the 176-byte sh_info allocation and perform a four-byte heap buffer overflow write. The corruption can crash the process and may enable code execution depending on heap layout. This issue is fixed in version 6.0.0-Alpha10.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() using sh_info.op.op_count without checking the fixed-size operands[] array. Repeated crafted instructions processed through cs_disasm_iter() or cs_disasm() with CS_ARCH_SH, CS_MODE_SH2A or CS_MODE_SH4A, CS_MODE_SHFPU, and CS_OPT_DETAIL can increment the operand count beyond the 176-byte sh_info allocation and perform a four-byte heap buffer overflow write. The corruption can crash the process and may enable code execution depending on heap layout. This issue is fixed in version 6.0.0-Alpha10.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.0014, EPSS Percentile is 0.03752 |
debian: CVE-2026-55893 was patched at 2026-08-25
1503.
Remote Code Execution - Unknown Product (CVE-2026-55894) - Medium [261]
Description: {'nvd_cve_data_all': 'Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value from a raw 16-bit instruction without ensuring it is within the active mode-specific decode[] function-pointer table. An application using CS_ARCH_SH with CS_MODE_SH2A or CS_MODE_SH4A and CS_MODE_SHFPU can pass crafted bytecode through cs_disasm_iter() or cs_disasm(), causing the decode[idx] test to read outside the table and terminate the process with a segmentation fault. No code execution or information disclosure was demonstrated. This issue is fixed in version 6.0.0-Alpha10.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value from a raw 16-bit instruction without ensuring it is within the active mode-specific decode[] function-pointer table. An application using CS_ARCH_SH with CS_MODE_SH2A or CS_MODE_SH4A and CS_MODE_SHFPU can pass crafted bytecode through cs_disasm_iter() or cs_disasm(), causing the decode[idx] test to read outside the table and terminate the process with a segmentation fault. No code execution or information disclosure was demonstrated. This issue is fixed in version 6.0.0-Alpha10.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.03287 |
debian: CVE-2026-55894 was patched at 2026-08-25
1504.
Remote Code Execution - Unknown Product (CVE-2026-56711) - Medium [261]
Description: {'nvd_cve_data_all': 'VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00106, EPSS Percentile is 0.01222 |
debian: CVE-2026-56711 was patched at 2026-09-16
1505.
Remote Code Execution - Unknown Product (CVE-2026-71220) - Medium [261]
Description: {'nvd_cve_data_all': 'A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00135, EPSS Percentile is 0.03367 |
debian: CVE-2026-71220 was patched at 2026-09-16
1506.
Remote Code Execution - Unknown Product (CVE-2026-71221) - Medium [261]
Description: {'nvd_cve_data_all': 'A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00135, EPSS Percentile is 0.03367 |
debian: CVE-2026-71221 was patched at 2026-09-16
1507.
Spoofing - Traefik (CVE-2026-88004) - Medium [261]
Description: Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint defenses aliasHeadersStrategy, underscoreHeadersStrategy, and forwardedHeaders inspect req.Header but not req.Trailer, allowing an unauthenticated client to submit an aliasing or trusted header name in an HTTP/1.1 chunked trailer or an HTTP/2 trailer. When the retry or buffering middleware reads the body before the reverse proxy clones the request, the attacker-controlled trailer value reaches a backend that merges trailers into the header namespace, bypassing the documented delete or reject behavior and potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Product detected by a:traefik:traefik (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00273, EPSS Percentile is 0.19744 |
altlinux: CVE-2026-88004 was patched at 2026-09-15, 2026-09-16
1508.
Unknown Vulnerability Type - FreeMarker (CVE-2026-84939) - Medium [261]
Description: {'nvd_cve_data_all': 'Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default enabled). This issue affects Apache FreeMarker from 2.2.0 through 2.3.34. Users are recommended to upgrade to version 2.3.35. Disabling localized lookup in previous versions also mitigates this. Note that even in versions affected by this vulnerability, the files that can be loaded remain restricted by the TemplateLoader that FreeMarker is configured to use. In particular, FileTemplateLoader prevents attempts to traverse outside the baseDir specified in its constructor. Other TemplateLoader implementations may allow access outside their designated base directory, but they are still constrained by the underlying storage mechanism—for example, a loader wrapping a Java class loader can only access resources that the class loader can load, while one wrapping a web application context can only access resources available through that context.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default enabled).\n\nThis issue affects Apache FreeMarker from 2.2.0 through 2.3.34.\n\nUsers are recommended to upgrade to version 2.3.35. Disabling localized lookup in previous versions also mitigates this.\n\nNote that even in versions affected by this vulnerability, the files that can be loaded remain restricted by the TemplateLoader that FreeMarker is configured to use. In particular, FileTemplateLoader prevents attempts to traverse outside the baseDir specified in its constructor. Other TemplateLoader implementations may allow access outside their designated base directory, but they are still constrained by the underlying storage mechanism—for example, a loader wrapping a Java class loader can only access resources that the class loader can load, while one wrapping a web application context can only access resources available through that context.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:apache:freemarker (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.0083, EPSS Percentile is 0.55767 |
debian: CVE-2026-84939 was patched at 2026-09-16
1509.
Incorrect Calculation - MongoDB (CVE-2026-88035) - Medium [260]
Description: A size check in the client-side authentication path of the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00103, EPSS Percentile is 0.01098 |
debian: CVE-2026-88035 was patched at 2026-09-16
1510.
Memory Corruption - MongoDB (CVE-2026-84968) - Medium [260]
Description: An out-of-bounds read in the BSON decoding component of the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00197, EPSS Percentile is 0.09738 |
debian: CVE-2026-84968 was patched at 2026-09-16
1511.
Unknown Vulnerability Type - Apache Tomcat (CVE-2026-65183) - Medium [259]
Description: {'nvd_cve_data_all': 'Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120.\n\n\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00452, EPSS Percentile is 0.38409 |
altlinux: CVE-2026-65183 was patched at 2026-08-26, 2026-08-27, 2026-09-11, 2026-09-16
debian: CVE-2026-65183 was patched at 2026-09-16
1512.
Authentication Bypass - Unknown Product (CVE-2026-40205) - Medium [258]
Description: {'nvd_cve_data_all': 'An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is required in the configuration, the remote token validation paths accept a token that carries only one of them, while the local token validation path correctly requires all of them. The configured authorization policy is not enforced, so a token that was granted only part of the required permissions is accepted where it should have been rejected. Use local token validation where tokens can be validated locally. Update to non-vulnerable version. No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is required in the configuration, the remote token validation paths accept a token that carries only one of them, while the local token validation path correctly requires all of them. The configured authorization policy is not enforced, so a token that was granted only part of the required permissions is accepted where it should have been rejected. Use local token validation where tokens can be validated locally. Update to non-vulnerable version. No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00179, EPSS Percentile is 0.07708 |
altlinux: CVE-2026-40205 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-40205 was patched at 2026-09-16
1513.
Memory Corruption - Binutils (CVE-2026-91779) - Medium [258]
Description: A security flaw has been discovered in GNU
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.01563 |
debian: CVE-2026-91779 was patched at 2026-09-16
1514.
Memory Corruption - Binutils (CVE-2026-91780) - Medium [258]
Description: A weakness has been identified in GNU
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.01562 |
debian: CVE-2026-91780 was patched at 2026-09-16
1515.
Memory Corruption - Chromium (CVE-2026-87525) - Medium [258]
Description: Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read memory outside the sandbox via a local program. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 2.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00103, EPSS Percentile is 0.01075 |
altlinux: CVE-2026-87525 was patched at 2026-09-17
debian: CVE-2026-87525 was patched at 2026-09-16
1516.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63813) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Revert "f2fs: remove non-uptodate folio from the page cache in move_data_block" This reverts commit 9609dd704725a40cd63d915f2ab6c44248a44598. The kernel panics are keeping to be reported especially when the f2fs partition get almost full. By investigation, we find that the reason is one f2fs page got freed to buddy without being deleted from LRU and the root cause is the race happened in [2] which is enrolled by this commit. There are 3 race processes in this scenario, please find below for their main activities. The changed code in move_data_block() lets the GC path evict the tail-end folio from the page cache through folio_end_dropbehind(). Once folio_unmap_invalidate() removes the folio from mapping->i_pages, the page-cache references for all pages in the folio are dropped. The folio is then kept alive only by temporary external references, which allows a later split to operate on a folio whose subpages are no longer protected by page-cache references. After the page-cache references are gone, split_folio_to_order() can split the big folio into individual pages and put the resulting subpages back on the LRU. For tail pages beyond EOF, split removes them from the page cache and drops their page-cache references. A tail page can then remain on the LRU with PG_lru set while holding only the split caller's temporary reference. When free_folio_and_swap_cache() drops that final reference, the page enters the final folio_put() release path. In parallel, folio_isolate_lru() can observe the same tail page with a non-zero refcount and PG_lru set. It clears PG_lru before taking its own reference. If this races with the final folio_put() from the split path, __folio_put() sees PG_lru already cleared and skips lruvec_del_folio(). The page is then freed back to the allocator while its lru links are still present in the LRU list. A later LRU operation on a neighboring page detects the stale link and reports list corruption. [1] [ 22.486082] list_del corruption. next->prev should be fffffffec10e0ac8, but was dead000000000122. (next=fffffffec10e0a88) [ 22.486130] ------------[ cut here ]------------ [ 22.486134] kernel BUG at lib/list_debug.c:67! [ 22.486141] Internal error: Oops - BUG: 00000000f2000800 [#1] SMP [ 22.488502] Tainted: [W]=WARN, [O]=OOT_MODULE [ 22.488506] Hardware name: Spreadtrum UMS9230 1H10 SoC (DT) [ 22.488511] pstate: 604000c5 (nZCv daIF +PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 22.488517] pc : __list_del_entry_valid_or_report+0x14c/0x154 [ 22.488531] lr : __list_del_entry_valid_or_report+0x14c/0x154 [ 22.488539] sp : ffffffc08006b830 [ 22.488542] x29: ffffffc08006b868 x28: 0000000000003020 x27: 0000000000000000 [ 22.488553] x26: 0000000000000000 x25: 0000000000000004 x24: fffffffec10e0ac0 [ 22.488564] x23: 00000000000000e8 x22: 0000000000000024 x21: dead000000000122 [ 22.488574] x20: fffffffec10e0a88 x19: fffffffec10e0ac8 x18: ffffffc080061060 [ 22.488585] x17: 20747562202c3863 x16: 6130653031636566 x15: 0000000000000058 [ 22.488595] x14: 0000000000000004 x13: ffffff80f91e0000 x12: 0000000000000003 [ 22.488605] x11: 0000000000000003 x10: 0000000000000001 x9 : ffe85721f0e25f00 [ 22.488615] x8 : ffe85721f0e25f00 x7 : 0000000000000000 x6 : 6c65645f7473696c [ 22.488625] x5 : ffffffed39b23026 x4 : 0000000000000000 x3 : 0000000000000010 [ 22.488636] x2 : 0000000000000000 x1 : 0000000000000000 x0 : 000000000000006d [ 22.488647] Call trace: [ 22.488651] __list_del_entry_valid_or_report+0x14c/0x154 (P) [ 22.488661] __folio_put+0x2bc/0x434 [ 22.488670] folio_put+0x28/0x58 [ 22.488678] do_garbage_collect+0x1a34/0x2584 [ 22.488689] f2fs_gc+0x230/0x9b4 [ 22.488697] f2fs_fallocate+0xb90/0xdf4 [ 22.488706] vfs_fallocate+0x1b4/0x2bc [ 22.488716] __arm64_sys_fallocate+0x44/0x78 [ 22.488725] invoke_syscall+0x58/0xe4 [ 22.488732] do_el0_svc+0x48/0xdc [ 22.488739] el0 ---truncated---', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRevert "f2fs: remove non-uptodate folio from the page cache in move_data_block"\n\nThis reverts commit 9609dd704725a40cd63d915f2ab6c44248a44598.\n\nThe kernel panics are keeping to be reported especially when the f2fs\npartition get almost full. By investigation, we find that the reason is\none f2fs page got freed to buddy without being deleted from LRU and the\nroot cause is the race happened in [2] which is enrolled by this commit.\n\nThere are 3 race processes in this scenario, please find below for their\nmain activities.\n\nThe changed code in move_data_block() lets the GC path evict the tail-end\nfolio from the page cache through folio_end_dropbehind(). Once\nfolio_unmap_invalidate() removes the folio from mapping->i_pages, the\npage-cache references for all pages in the folio are dropped. The folio\nis then kept alive only by temporary external references, which allows a\nlater split to operate on a folio whose subpages are no longer protected\nby page-cache references.\n\nAfter the page-cache references are gone, split_folio_to_order() can\nsplit the big folio into individual pages and put the resulting subpages\nback on the LRU. For tail pages beyond EOF, split removes them from the\npage cache and drops their page-cache references. A tail page can then\nremain on the LRU with PG_lru set while holding only the split caller's\ntemporary reference. When free_folio_and_swap_cache() drops that final\nreference, the page enters the final folio_put() release path.\n\nIn parallel, folio_isolate_lru() can observe the same tail page with a\nnon-zero refcount and PG_lru set. It clears PG_lru before taking its own\nreference. If this races with the final folio_put() from the split path,\n__folio_put() sees PG_lru already cleared and skips lruvec_del_folio().\nThe page is then freed back to the allocator while its lru links are\nstill present in the LRU list. A later LRU operation on a neighboring\npage detects the stale link and reports list corruption.\n\n[1]\n[ 22.486082] list_del corruption. next->prev should be fffffffec10e0ac8, but was dead000000000122. (next=fffffffec10e0a88)\n[ 22.486130] ------------[ cut here ]------------\n[ 22.486134] kernel BUG at lib/list_debug.c:67!\n[ 22.486141] Internal error: Oops - BUG: 00000000f2000800 [#1] SMP\n[ 22.488502] Tainted: [W]=WARN, [O]=OOT_MODULE\n[ 22.488506] Hardware name: Spreadtrum UMS9230 1H10 SoC (DT)\n[ 22.488511] pstate: 604000c5 (nZCv daIF +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 22.488517] pc : __list_del_entry_valid_or_report+0x14c/0x154\n[ 22.488531] lr : __list_del_entry_valid_or_report+0x14c/0x154\n[ 22.488539] sp : ffffffc08006b830\n[ 22.488542] x29: ffffffc08006b868 x28: 0000000000003020 x27: 0000000000000000\n[ 22.488553] x26: 0000000000000000 x25: 0000000000000004 x24: fffffffec10e0ac0\n[ 22.488564] x23: 00000000000000e8 x22: 0000000000000024 x21: dead000000000122\n[ 22.488574] x20: fffffffec10e0a88 x19: fffffffec10e0ac8 x18: ffffffc080061060\n[ 22.488585] x17: 20747562202c3863 x16: 6130653031636566 x15: 0000000000000058\n[ 22.488595] x14: 0000000000000004 x13: ffffff80f91e0000 x12: 0000000000000003\n[ 22.488605] x11: 0000000000000003 x10: 0000000000000001 x9 : ffe85721f0e25f00\n[ 22.488615] x8 : ffe85721f0e25f00 x7 : 0000000000000000 x6 : 6c65645f7473696c\n[ 22.488625] x5 : ffffffed39b23026 x4 : 0000000000000000 x3 : 0000000000000010\n[ 22.488636] x2 : 0000000000000000 x1 : 0000000000000000 x0 : 000000000000006d\n[ 22.488647] Call trace:\n[ 22.488651] __list_del_entry_valid_or_report+0x14c/0x154 (P)\n[ 22.488661] __folio_put+0x2bc/0x434\n[ 22.488670] folio_put+0x28/0x58\n[ 22.488678] do_garbage_collect+0x1a34/0x2584\n[ 22.488689] f2fs_gc+0x230/0x9b4\n[ 22.488697] f2fs_fallocate+0xb90/0xdf4\n[ 22.488706] vfs_fallocate+0x1b4/0x2bc\n[ 22.488716] __arm64_sys_fallocate+0x44/0x78\n[ 22.488725] invoke_syscall+0x58/0xe4\n[ 22.488732] do_el0_svc+0x48/0xdc\n[ 22.488739] el0\n---truncated---', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.07026 |
ubuntu: CVE-2026-63813 was patched at 2026-09-07, 2026-09-16
1517.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63874) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: mctp: usb: fix race between urb completion and rx_retry cancellation It's possible that sequencing between setting ->stopped and cancelling the rx_retry work (in ndo_stop) could leave us with an urb queued: T1: ndo_stop T2: rx_retry_work ------------ ---------------- LD: ->stopped => false ST: ->stopped <= true usb_kill_urb() mctp_usb_rx_queue() usb_submit_urb() cancel_delayed_work_sync() That urb completion can then re-schedule rx_retry_work. Strenghen the sequencing between the stop (preventing another requeue) and the cancel by updating both atomically under a new rx lock. After setting ->rx_stopped, and cancelling pending work, we know that the requeue cannot occur, so all that's left is killing any pending urb.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mctp: usb: fix race between urb completion and rx_retry cancellation\n\nIt's possible that sequencing between setting ->stopped and cancelling\nthe rx_retry work (in ndo_stop) could leave us with an urb queued:\n\n T1: ndo_stop T2: rx_retry_work\n ------------ ----------------\n LD: ->stopped => false\n ST: ->stopped <= true\n usb_kill_urb()\n mctp_usb_rx_queue()\n usb_submit_urb()\n cancel_delayed_work_sync()\n\nThat urb completion can then re-schedule rx_retry_work.\n\nStrenghen the sequencing between the stop (preventing another requeue)\nand the cancel by updating both atomically under a new rx lock. After\nsetting ->rx_stopped, and cancelling pending work, we know that the\nrequeue cannot occur, so all that's left is killing any pending urb.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.07027 |
ubuntu: CVE-2026-63874 was patched at 2026-09-07, 2026-09-16
1518.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64467) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: rust_binder: use a u64 stride when cleaning up the offsets array Allocation's Drop walks the offsets array (binder_size_t = u64 entries), cleaning up the objects, but it used usize instead of u64 for both the stride and the per-entry read. On 64-bit kernels (usize == u64) this is harmless, but on 32-bit kernels it walks the 8-byte entries in 4-byte steps, iterating an N-entry array 2N times, and reads the always-zero high word as offset 0, cleaning up the object at offset 0 N extra times. As a result the referenced node or handle ends up with a lower reference count than it actually has (a refcount over-decrement), and binder's reference accounting is corrupted; for example, the owner can be notified of a strong reference release (BR_RELEASE) even though references still remain. Change the stride to u64, and read each entry as a u64, narrowing it to usize with try_into(). On 32-bit ARM, when this over-decrement would drive a count below zero, the driver's existing refcount guard refuses it and fires: rust_binder: Failure: refcount underflow!', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nrust_binder: use a u64 stride when cleaning up the offsets array\n\nAllocation's Drop walks the offsets array (binder_size_t = u64 entries),\ncleaning up the objects, but it used usize instead of u64 for both the\nstride and the per-entry read.\n\nOn 64-bit kernels (usize == u64) this is harmless, but on 32-bit kernels\nit walks the 8-byte entries in 4-byte steps, iterating an N-entry array\n2N times, and reads the always-zero high word as offset 0, cleaning up\nthe object at offset 0 N extra times. As a result the referenced node or\nhandle ends up with a lower reference count than it actually has (a\nrefcount over-decrement), and binder's reference accounting is corrupted;\nfor example, the owner can be notified of a strong reference release\n(BR_RELEASE) even though references still remain.\n\nChange the stride to u64, and read each entry as a u64, narrowing it to\nusize with try_into().\n\nOn 32-bit ARM, when this over-decrement would drive a count below zero,\nthe driver's existing refcount guard refuses it and fires:\n\n rust_binder: Failure: refcount underflow!', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00137, EPSS Percentile is 0.03441 |
ubuntu: CVE-2026-64467 was patched at 2026-09-07, 2026-09-16
1519.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74580) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: vhost: reset the vring metadata cache on vring reconfiguration vq->meta_iotlb[] caches the vhost_iotlb_map that backs each vring metadata region, and iotlb_access_ok() returns early on a cache hit, taking the hit as proof that the region has already been validated: \tif (vhost_vq_meta_fetch(vq, addr, len, type)) \t\treturn true; The cache is reset on VHOST_IOTLB_UPDATE and VHOST_IOTLB_INVALIDATE, on device IOTLB (re)initialisation and on vq reset, but not when VHOST_SET_VRING_ADDR replaces vq->desc, vq->avail and vq->used, nor when VHOST_SET_VRING_NUM changes the region sizes. With a device IOTLB attached both ioctls are accepted while the vq is live, and neither validates the addresses at ioctl time: vq_access_ok() and vq_log_used_access_ok() return true early because the addresses are GIOVAs, deferring validation to prefetch time. Once the cache has been populated that deferred validation no longer runs -- vq_meta_prefetch() hits the stale entry and returns true -- and vhost_vq_meta_fetch() keeps translating through the old mapping as \tmap->addr + addr - map->start for an address the mapping no longer covers. vhost_copy_to_user() and vhost_copy_from_user() consume the result with __copy_to_user() and __copy_from_user(), which do not check it either, so a subsequent used ring update or descriptor fetch accesses memory outside the region the IOTLB actually maps. Reset the metadata cache whenever the vring is reconfigured, so the new addresses are pushed back through iotlb_access_ok()'s slow path.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvhost: reset the vring metadata cache on vring reconfiguration\n\nvq->meta_iotlb[] caches the vhost_iotlb_map that backs each vring\nmetadata region, and iotlb_access_ok() returns early on a cache hit,\ntaking the hit as proof that the region has already been validated:\n\n\tif (vhost_vq_meta_fetch(vq, addr, len, type))\n\t\treturn true;\n\nThe cache is reset on VHOST_IOTLB_UPDATE and VHOST_IOTLB_INVALIDATE, on\ndevice IOTLB (re)initialisation and on vq reset, but not when\nVHOST_SET_VRING_ADDR replaces vq->desc, vq->avail and vq->used, nor when\nVHOST_SET_VRING_NUM changes the region sizes.\n\nWith a device IOTLB attached both ioctls are accepted while the vq is\nlive, and neither validates the addresses at ioctl time: vq_access_ok()\nand vq_log_used_access_ok() return true early because the addresses are\nGIOVAs, deferring validation to prefetch time. Once the cache has been\npopulated that deferred validation no longer runs -- vq_meta_prefetch()\nhits the stale entry and returns true -- and vhost_vq_meta_fetch() keeps\ntranslating through the old mapping as\n\n\tmap->addr + addr - map->start\n\nfor an address the mapping no longer covers. vhost_copy_to_user() and\nvhost_copy_from_user() consume the result with __copy_to_user() and\n__copy_from_user(), which do not check it either, so a subsequent used\nring update or descriptor fetch accesses memory outside the region the\nIOTLB actually maps.\n\nReset the metadata cache whenever the vring is reconfigured, so the new\naddresses are pushed back through iotlb_access_ok()'s slow path.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02189 |
debian: CVE-2026-74580 was patched at 2026-08-25
oraclelinux: CVE-2026-74580 was patched at 2026-09-04
redhat: CVE-2026-74580 was patched at 2026-09-02
1520.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74607) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Serialize accesses to the owner and mirror list with separate lock Interaction between KVM_CAP_VM_MOVE_ENC_CONTEXT_FROM and KVM_CAP_VM_COPY_ENC_CONTEXT_FROM can cause two separate issues: - in sev_migrate_from(), when the destination KVM is a mirror, the mirror entry is moved from the source's list to the owner's mirror_vms list, without holding the owner's lock unlike other writers of the owner's mirror list (sev_vm_copy_enc_context_from(), sev_vm_destroy()). A concurrent COPY or destroy can race with sev_migrate_from() and corrupt the list. - In sev_vm_destroy(), the *owner* is still active and could receive concurrently a KVM_CAP_VM_MOVE_ENC_CONTEXT_FROM that causes sev->enc_context_owner to change. In this case the incorrect VM receives kvm_put_kvm(). The second issue needs particular care because the owner could disappear altogether (even though the race window is impossibly small) between reading it and locking it. There is thus no way to perform the checks under the owner lock without putting struct kvm under SLAB_TYPESAFE_BY_RCU (which would allow kvm_get_kvm_safe() under RCU critical section). It is much simpler to just use a global lock, since the critical sections are so small and the new lock is always a leaf lock.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: Serialize accesses to the owner and mirror list with separate lock\n\nInteraction between KVM_CAP_VM_MOVE_ENC_CONTEXT_FROM and\nKVM_CAP_VM_COPY_ENC_CONTEXT_FROM can cause two separate issues:\n\n- in sev_migrate_from(), when the destination KVM is a mirror, the mirror\n entry is moved from the source's list to the owner's mirror_vms list,\n without holding the owner's lock unlike other writers of the owner's\n mirror list (sev_vm_copy_enc_context_from(), sev_vm_destroy()).\n A concurrent COPY or destroy can race with sev_migrate_from() and\n corrupt the list.\n\n- In sev_vm_destroy(), the *owner* is still active and could receive\n concurrently a KVM_CAP_VM_MOVE_ENC_CONTEXT_FROM that causes\n sev->enc_context_owner to change. In this case the incorrect VM\n receives kvm_put_kvm().\n\nThe second issue needs particular care because the owner could disappear\naltogether (even though the race window is impossibly small) between\nreading it and locking it. There is thus no way to perform the checks\nunder the owner lock without putting struct kvm under SLAB_TYPESAFE_BY_RCU\n(which would allow kvm_get_kvm_safe() under RCU critical section).\n\nIt is much simpler to just use a global lock, since the critical\nsections are so small and the new lock is always a leaf lock.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.0293 |
debian: CVE-2026-74607 was patched at 2026-08-25
oraclelinux: CVE-2026-74607 was patched at 2026-09-04
1521.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74655) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: serial: qcom-geni: fix TX DMA buffer flush When transmit flushing a qcom-geni UART during an ongoing TX DMA, the UART gets stuck infinitely repeating corrupted TX DMA frames. The DMA-mode uart_ops does not provide a flush_buffer callback, so an in-flight transfer can complete after serial core has reset the transmit kfifo, underflowing its length and resubmitting page-sized transfers indefinitely. Add one that stops the transfer and clears tx_remaining and tx_queued. The stop path was also broken: it unmapped the buffer while the serial engine could still read it, and never reset the TX DMA state machine. Cancel the main sequencer command first, then reset the state machine and wait for it before unmapping. Drop the early return so a pending mapping is also cleaned up when the main command is inactive. The bug can be triggered from userspace with a large write immediately followed by TCOFLUSH. A following tcdrain will hang forever. The bug was reproduced and this fix was validated on Arduino Uno Q (QRB2210) using /dev/ttyHS1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nserial: qcom-geni: fix TX DMA buffer flush\n\nWhen transmit flushing a qcom-geni UART during an ongoing TX DMA, the\nUART gets stuck infinitely repeating corrupted TX DMA frames.\n\nThe DMA-mode uart_ops does not provide a flush_buffer callback, so an\nin-flight transfer can complete after serial core has reset the transmit\nkfifo, underflowing its length and resubmitting page-sized transfers\nindefinitely. Add one that stops the transfer and clears tx_remaining\nand tx_queued.\n\nThe stop path was also broken: it unmapped the buffer while the serial\nengine could still read it, and never reset the TX DMA state machine.\nCancel the main sequencer command first, then reset the state machine\nand wait for it before unmapping. Drop the early return so a pending\nmapping is also cleaned up when the main command is inactive.\n\nThe bug can be triggered from userspace with a large write immediately\nfollowed by TCOFLUSH. A following tcdrain will hang forever. The bug was\nreproduced and this fix was validated on Arduino Uno Q (QRB2210)\nusing /dev/ttyHS1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02862 |
debian: CVE-2026-74655 was patched at 2026-08-25
1522.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74712) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: Fix buffer length in create_direct_keys() We have seen in our CI the following KASAN message: BUG: KASAN: slab-out-of-bounds in cmd_exec+0x550/0xca0 [mlx5_core] Read of size 272 at addr 0000000176795020 by task qemu-system-s39/82764 [...] [<000011388ab3a7a0>] cmd_exec+0x550/0xca0 [mlx5_core] [<000011388ab3b61c>] mlx5_cmd_exec_cb+0x25c/0x4f0 [mlx5_core] [<000011388b21e82e>] mlx5_vdpa_exec_async_cmds+0x22e/0x5e0 [mlx5_vdpa] [<000011388b21fd44>] create_direct_keys+0x954/0xef0 [mlx5_vdpa] [...] The buggy address is located 4128 bytes inside of allocated 4384-byte region [0000000176794000, 0000000176795120) So in essence we read 16 bytes beyond 4384-byte allocation. create_direct_keys calculates the pointer and length for in and out buffers. The size calculation for in includes the entire structure size (out + in + mtt[]) but the pointer passed to cmd_exec points only to the 'in' field, skipping the 'out' field. This causes mlx5_copy_to_msg() to read beyond the allocated buffer by sizeof(out) bytes when copying command data. Properly calculate the input size to match the pointer and allocation size.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvdpa/mlx5: Fix buffer length in create_direct_keys()\n\nWe have seen in our CI the following KASAN message:\nBUG: KASAN: slab-out-of-bounds in cmd_exec+0x550/0xca0 [mlx5_core]\nRead of size 272 at addr 0000000176795020 by task qemu-system-s39/82764\n[...]\n[<000011388ab3a7a0>] cmd_exec+0x550/0xca0 [mlx5_core]\n[<000011388ab3b61c>] mlx5_cmd_exec_cb+0x25c/0x4f0 [mlx5_core]\n[<000011388b21e82e>] mlx5_vdpa_exec_async_cmds+0x22e/0x5e0 [mlx5_vdpa]\n[<000011388b21fd44>] create_direct_keys+0x954/0xef0 [mlx5_vdpa]\n[...]\nThe buggy address is located 4128 bytes inside of\nallocated 4384-byte region [0000000176794000, 0000000176795120)\n\nSo in essence we read 16 bytes beyond 4384-byte allocation.\ncreate_direct_keys calculates the pointer and length for in and out\nbuffers.\nThe size calculation for in includes the entire structure\nsize (out + in + mtt[]) but the pointer passed to cmd_exec points only\nto the 'in' field, skipping the 'out' field.\n\nThis causes mlx5_copy_to_msg() to read beyond the allocated buffer\nby sizeof(out) bytes when copying command data.\n\nProperly calculate the input size to match the pointer and allocation size.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.03851 |
debian: CVE-2026-74712 was patched at 2026-08-25
oraclelinux: CVE-2026-74712 was patched at 2026-09-04
1523.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80547) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Implement a crw lock Unlike the channel_program struct, which covers synchronous I/O submissions and asynchronous interrupts, the CRW region relies exclusively on asynchronous events coming from hardware. Implement a lock to manage the list of those payloads, to ensure they are read cohesively.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Implement a crw lock\n\nUnlike the channel_program struct, which covers synchronous I/O\nsubmissions and asynchronous interrupts, the CRW region relies\nexclusively on asynchronous events coming from hardware.\n\nImplement a lock to manage the list of those payloads, to ensure\nthey are read cohesively.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02911 |
debian: CVE-2026-80547 was patched at 2026-09-16
1524.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80548) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Selectively expand io_mutex The io_mutex was defined to serialize the io_regions, but then has also sort of been associated with the I/O themselves because of the close relationship they share. With the handful of races that are possible, the choices are either to: A) expand the scope of io_mutex to close these remaining windows, or B) reduce the scope of io_mutex to just io_region, and introduce a new lock mechanism for the remaining I/O resources This patch implements A, since B brings with it a lot more interactions that would need to be tracked and kept in a correct hierarchy. It also takes advantage of the workqueue element for cp_free() that now gets called out of fsm_notoper(), which could be invoked out of an interrupt context and thus cannot acquire a mutex itself.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Selectively expand io_mutex\n\nThe io_mutex was defined to serialize the io_regions, but then has\nalso sort of been associated with the I/O themselves because of\nthe close relationship they share.\n\nWith the handful of races that are possible, the choices are either to:\n A) expand the scope of io_mutex to close these remaining windows, or\n B) reduce the scope of io_mutex to just io_region, and introduce a new\n lock mechanism for the remaining I/O resources\n\nThis patch implements A, since B brings with it a lot more interactions\nthat would need to be tracked and kept in a correct hierarchy. It also\ntakes advantage of the workqueue element for cp_free() that now gets\ncalled out of fsm_notoper(), which could be invoked out of an interrupt\ncontext and thus cannot acquire a mutex itself.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02912 |
debian: CVE-2026-80548 was patched at 2026-09-16
1525.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80551) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Ensure first IDAW remains constant The first IDAW in a list does not need to be on a 2K/4K boundary like all others, and so is read separately to accurately calculate the size of the buffer needed to read the full IDAL. Verify that the address found in the first IDAW is unchanged between reads, to ensure a consistent set of IDAWs being worked with.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Ensure first IDAW remains constant\n\nThe first IDAW in a list does not need to be on a 2K/4K boundary\nlike all others, and so is read separately to accurately calculate\nthe size of the buffer needed to read the full IDAL.\n\nVerify that the address found in the first IDAW is unchanged between\nreads, to ensure a consistent set of IDAWs being worked with.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04026 |
debian: CVE-2026-80551 was patched at 2026-09-16
1526.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80552) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Ensure index for read/write regions are within range The introduction of the capability chain rightly clamped the region indexes to the range of the capabilities itself, but neglected to do so for the existing read/write regions which should also be enforced.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Ensure index for read/write regions are within range\n\nThe introduction of the capability chain rightly clamped the\nregion indexes to the range of the capabilities itself, but\nneglected to do so for the existing read/write regions which\nshould also be enforced.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02907 |
debian: CVE-2026-80552 was patched at 2026-09-16
1527.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80553) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Cancel existing workqueues The initialization of the io_work and crw_work workqueues begs the question of whether they should be un-initialized. Add the corresponding cleanup tags in _release_dev to ensure work isn't dispatched after the private struct is free'd.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Cancel existing workqueues\n\nThe initialization of the io_work and crw_work workqueues begs the\nquestion of whether they should be un-initialized. Add the corresponding\ncleanup tags in _release_dev to ensure work isn't dispatched after\nthe private struct is free'd.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02907 |
debian: CVE-2026-80553 was patched at 2026-09-16
1528.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80554) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Limit the number of channel program segments The processing of channel programs, and the CCWs within them, is done recursively. As such, there is an arbitrary (but not architectural) limit to the number of CCWs that can exist in a single channel program. The vfio-ccw logic breaks these channel programs into segments whenever it encounters a Transfer-In-Channel (TIC) CCW, and the combined number of segments count towards the global limit. Impose an equivalent limit to the number of segments until such logic can be made non-recursive.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Limit the number of channel program segments\n\nThe processing of channel programs, and the CCWs within them, is done\nrecursively. As such, there is an arbitrary (but not architectural)\nlimit to the number of CCWs that can exist in a single channel program.\n\nThe vfio-ccw logic breaks these channel programs into segments whenever\nit encounters a Transfer-In-Channel (TIC) CCW, and the combined number\nof segments count towards the global limit. Impose an equivalent limit\nto the number of segments until such logic can be made non-recursive.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04026 |
debian: CVE-2026-80554 was patched at 2026-09-16
1529.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80576) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject oversized IBs with per-ring packet limits On GFX rings, amdgpu_cs_p2_ib() passed user-supplied ib_bytes through to ib->length_dw without a limit, while ring_emit_ib() encodes length into packet fields. Oversized values can corrupt adjacent control bits and destabilize command submission. Add a per-ring IB packet size limit helper and reject command submissions exceeding the corresponding dword limit before IB allocation. Use the documented 20-bit limit for GFX/compute/SDMA/VPE, and apply the MM fallback limit for other ring types. (cherry picked from commit 7f48fa2cf62e3fa6c9c3870aa74988f773247e52)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: reject oversized IBs with per-ring packet limits\n\nOn GFX rings, amdgpu_cs_p2_ib() passed user-supplied ib_bytes through\nto ib->length_dw without a limit, while ring_emit_ib() encodes length\ninto packet fields. Oversized values can corrupt adjacent control bits\nand destabilize command submission.\n\nAdd a per-ring IB packet size limit helper and reject command\nsubmissions exceeding the corresponding dword limit before IB\nallocation. Use the documented 20-bit limit for GFX/compute/SDMA/VPE,\nand apply the MM fallback limit for other ring types.\n\n(cherry picked from commit 7f48fa2cf62e3fa6c9c3870aa74988f773247e52)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02058 |
debian: CVE-2026-80576 was patched at 2026-09-16
1530.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80684) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix NULL dereference on AIBV allocation failure The airq_iv_create() can return NULL on failure, but the return value was never checked. If it fails, zdev->aibv will be NULL and fail when dereferenced in kvm_zpci_set_airq(). Add a NULL check and free the previously allocated AISB bit and zdev->aisb on failure.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: pci: Fix NULL dereference on AIBV allocation failure\n\nThe airq_iv_create() can return NULL on failure, but the return value was\nnever checked. If it fails, zdev->aibv will be NULL and fail when\ndereferenced in kvm_zpci_set_airq(). Add a NULL check and free the\npreviously allocated AISB bit and zdev->aisb on failure.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04027 |
debian: CVE-2026-80684 was patched at 2026-09-16
1531.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80736) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Fix bandwidth group reservation indexing Valid bandwidth group IDs range from 1 through MAX_GROUPS, while Group ID 0 is reserved. tb_consumed_dp_bandwidth() uses the Group ID directly to index its local group_reserved[] array. The array currently has MAX_GROUPS entries, so its valid indices are 0 through MAX_GROUPS - 1. Group ID MAX_GROUPS therefore accesses one element past the end, and the final group's reserved bandwidth is not included when the array is summed. Give group_reserved[] MAX_GROUPS + 1 entries so direct Group ID indexing covers the reserved ID 0 and valid IDs 1 through MAX_GROUPS.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: Fix bandwidth group reservation indexing\n\nValid bandwidth group IDs range from 1 through MAX_GROUPS, while Group\nID 0 is reserved. tb_consumed_dp_bandwidth() uses the Group ID directly\nto index its local group_reserved[] array.\n\nThe array currently has MAX_GROUPS entries, so its valid indices are 0\nthrough MAX_GROUPS - 1. Group ID MAX_GROUPS therefore accesses one\nelement past the end, and the final group's reserved bandwidth is not\nincluded when the array is summed.\n\nGive group_reserved[] MAX_GROUPS + 1 entries so direct Group ID\nindexing covers the reserved ID 0 and valid IDs 1 through MAX_GROUPS.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00163, EPSS Percentile is 0.05915 |
debian: CVE-2026-80736 was patched at 2026-09-16
1532.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80737) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: serial: amba-pl011: synchronize DMA teardown dmaengine_terminate_all() does not wait for a running callback, so the TX callback can still touch the TX buffer after it is freed. The RX poll timer reads the RX buffers without the port lock. Switch to dmaengine_terminate_sync() and delete the RX timer before freeing the buffers.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nserial: amba-pl011: synchronize DMA teardown\n\ndmaengine_terminate_all() does not wait for a running callback, so the TX\ncallback can still touch the TX buffer after it is freed. The RX poll\ntimer reads the RX buffers without the port lock.\n\nSwitch to dmaengine_terminate_sync() and delete the RX timer before\nfreeing the buffers.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.05996 |
debian: CVE-2026-80737 was patched at 2026-09-16
1533.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80747) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add bounds check for CRAT subtype length The CRAT parser validates that the subtype header fits within the image, but does not verify that the advertised subtype length fits. A malformed CRAT table with an oversized length field causes out-of-bounds reads when kfd_parse_subtype() casts the header to specific subtype structures. Add validation that sub_type_hdr + length does not exceed the image boundary before parsing the subtype contents. (cherry picked from commit 48e1d1e6e8798aef0312e68d8e586021b5b3cf4d)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Add bounds check for CRAT subtype length\n\nThe CRAT parser validates that the subtype header fits within the image,\nbut does not verify that the advertised subtype length fits. A malformed\nCRAT table with an oversized length field causes out-of-bounds reads when\nkfd_parse_subtype() casts the header to specific subtype structures.\n\nAdd validation that sub_type_hdr + length does not exceed the image\nboundary before parsing the subtype contents.\n\n(cherry picked from commit 48e1d1e6e8798aef0312e68d8e586021b5b3cf4d)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.05967 |
debian: CVE-2026-80747 was patched at 2026-09-16
1534.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80754) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - fix F55 transmitter electrode count typo During F55 sensor detection, the transmitter (TX) electrode count was incorrectly assigned the value of the receiver (RX) electrode count due to copy-paste typos. This incorrect value was then propagated to the driver data and used by F54 to determine the diagnostics report size. On devices with more RX than TX electrodes, this inflated the perceived TX count, leading to incorrect report size calculations and potential out-of-bounds buffer accesses. Fix the typos by correctly assigning the TX electrode counts.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - fix F55 transmitter electrode count typo\n\nDuring F55 sensor detection, the transmitter (TX) electrode count was\nincorrectly assigned the value of the receiver (RX) electrode count\ndue to copy-paste typos.\n\nThis incorrect value was then propagated to the driver data and used\nby F54 to determine the diagnostics report size. On devices with more\nRX than TX electrodes, this inflated the perceived TX count, leading\nto incorrect report size calculations and potential out-of-bounds\nbuffer accesses.\n\nFix the typos by correctly assigning the TX electrode counts.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.05989 |
debian: CVE-2026-80754 was patched at 2026-09-16
oraclelinux: CVE-2026-80754 was patched at 2026-09-04
1535.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80921) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale crypto bits When shadowing crypto access bits from a format0 apcb (crycb 0 or 1), the bits 64..255 are unchanged from whatever is in the vsie page in the crycb and thus in the apcb. This gives a nested guest potential access to a device no longer available. Zero out the remaining bits.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: vsie: zero stale crypto bits\n\nWhen shadowing crypto access bits from a format0 apcb (crycb 0 or 1),\nthe bits 64..255 are unchanged from whatever is in the vsie page in the\ncrycb and thus in the apcb. This gives a nested guest potential access\nto a device no longer available. Zero out the remaining bits.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02608 |
debian: CVE-2026-80921 was patched at 2026-09-16
1536.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80967) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: pcxhr: initialize mutexes before requesting threaded IRQ pcxhr_probe() requests pcxhr_threaded_irq() before initializing mgr->lock, even though the threaded handler takes that mutex. Initialize the manager locks before request_threaded_irq() so an early interrupt cannot run against uninitialized mutex state during probe.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcxhr: initialize mutexes before requesting threaded IRQ\n\npcxhr_probe() requests pcxhr_threaded_irq() before initializing\nmgr->lock, even though the threaded handler takes that mutex.\n\nInitialize the manager locks before request_threaded_irq() so an\nearly interrupt cannot run against uninitialized mutex state during\nprobe.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00182, EPSS Percentile is 0.0806 |
debian: CVE-2026-80967 was patched at 2026-09-16
1537.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-81016) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Propagate SMU errors and validate S2D address amd_stb_s2d_init() discards the return value of several S2D SMU commands. When the SMU refuses a command (e.g. "SMU cmd failed. err: 0xff") the failure is only noticed indirectly - if at all - and reported as -EIO, masking the real error. More seriously, the S2D_PHYS_ADDR_LOW/HIGH return values are ignored, so on failure phys_addr_low/hi are left uninitialised and the assembled address is passed straight to devm_ioremap(). When the SMU leaves them at zero this maps physical address 0 and trips the ioremap-on-RAM warning: amd_pmc AMDI000B:00: SMU cmd failed. err: 0xff ioremap on RAM at 0x0000000000000000 - 0x0000000000ffffff WARNING: CPU: 13 PID: 4592 at arch/x86/mm/ioremap.c:... Check the return value of each SMU command and propagate it, and reject a zero physical address before calling devm_ioremap().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86/amd/pmc: Propagate SMU errors and validate S2D address\n\namd_stb_s2d_init() discards the return value of several S2D SMU commands.\nWhen the SMU refuses a command (e.g. "SMU cmd failed. err: 0xff") the\nfailure is only noticed indirectly - if at all - and reported as -EIO,\nmasking the real error.\n\nMore seriously, the S2D_PHYS_ADDR_LOW/HIGH return values are ignored, so\non failure phys_addr_low/hi are left uninitialised and the assembled\naddress is passed straight to devm_ioremap(). When the SMU leaves them at\nzero this maps physical address 0 and trips the ioremap-on-RAM warning:\n\n amd_pmc AMDI000B:00: SMU cmd failed. err: 0xff\n ioremap on RAM at 0x0000000000000000 - 0x0000000000ffffff\n WARNING: CPU: 13 PID: 4592 at arch/x86/mm/ioremap.c:...\n\nCheck the return value of each SMU command and propagate it, and reject a\nzero physical address before calling devm_ioremap().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07869 |
debian: CVE-2026-81016 was patched at 2026-09-16
1538.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89440) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mmc: via-sdmmc: stop card-detect handling on probe failure request_irq() registers the SD card-detect interrupt and the probe enables it before mmc_add_host() runs. If mmc_add_host() fails, the error path only unmaps the registers and returns: the interrupt stays registered, so the handler keeps running against the host once it is freed. via_sdc_isr() dereferences sdhost and its MMIO base and schedules carddet_work, which via_sdc_card_detect() also runs against freed memory through its container_of() dereference. Add a probe-error path that disables and frees the interrupt and cancels carddet_work before unmapping. carddet_work can re-enable the device interrupt via via_reset_pcictrl(), which restores PCIINTCTRL, so mask it again after cancelling the work. This issue was found by an in-house static analysis tool and confirmed by manual code review.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: via-sdmmc: stop card-detect handling on probe failure\n\nrequest_irq() registers the SD card-detect interrupt and the probe enables\nit before mmc_add_host() runs. If mmc_add_host() fails, the error path only\nunmaps the registers and returns: the interrupt stays registered, so the\nhandler keeps running against the host once it is freed. via_sdc_isr()\ndereferences sdhost and its MMIO base and schedules carddet_work, which\nvia_sdc_card_detect() also runs against freed memory through its\ncontainer_of() dereference.\n\nAdd a probe-error path that disables and frees the interrupt and cancels\ncarddet_work before unmapping. carddet_work can re-enable the device\ninterrupt via via_reset_pcictrl(), which restores PCIINTCTRL, so mask it\nagain after cancelling the work.\n\nThis issue was found by an in-house static analysis tool and confirmed by\nmanual code review.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.05993 |
debian: CVE-2026-89440 was patched at 2026-09-16
1539.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89448) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Force requesting ACS when tboot is enabled Currently the conditions of requesting ACS in detect_intel_iommu() don't include tboot, leading to a possible misconfiguration with ACS disabled (e.g. due to user opts) while iommu is later forced on by tboot_force_iommu(). Fix it by checking tboot in detect_intel_iommu().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Force requesting ACS when tboot is enabled\n\nCurrently the conditions of requesting ACS in detect_intel_iommu()\ndon't include tboot, leading to a possible misconfiguration with ACS\ndisabled (e.g. due to user opts) while iommu is later forced on by\ntboot_force_iommu().\n\nFix it by checking tboot in detect_intel_iommu().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04029 |
debian: CVE-2026-89448 was patched at 2026-09-16
1540.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89452) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: iommu/msm: Unwind probe state on registration failure msm_iommu_probe() adds its devm-managed IOMMU object to qcom_iommu_devices before adding the IOMMU sysfs device and registering it with the IOMMU core. If iommu_device_sysfs_add() fails, probe returns with the object still on qcom_iommu_devices. The driver core then releases the devm allocation, leaving a dangling list entry that later list walks may dereference. If iommu_device_register() fails, the same dangling list entry remains and the sysfs device is left registered as well. Unwind the sysfs device and global list entry in reverse setup order on the corresponding failure paths.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\niommu/msm: Unwind probe state on registration failure\n\nmsm_iommu_probe() adds its devm-managed IOMMU object to\nqcom_iommu_devices before adding the IOMMU sysfs device and registering\nit with the IOMMU core.\n\nIf iommu_device_sysfs_add() fails, probe returns with the object still on\nqcom_iommu_devices. The driver core then releases the devm allocation,\nleaving a dangling list entry that later list walks may dereference.\n\nIf iommu_device_register() fails, the same dangling list entry remains\nand the sysfs device is left registered as well.\n\nUnwind the sysfs device and global list entry in reverse setup order on\nthe corresponding failure paths.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07868 |
debian: CVE-2026-89452 was patched at 2026-09-16
1541.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89500) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page Discarding a cached reader page after a concurrent ring buffer resize uses the new global subbuf_order for the free_pages() call. This mismatched order may crashes the kernel or leaks memory because the cached page was allocated under the old size. Save the actual free_page order alongside the page address to ensure we always refer to the correct value and do not rely on the potentially stalled cpu_buffer->subbuf_order value. The simplest is to make free_page a buffer_data_read_page which already covers exactly what we need: a page address and a page order.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Make cpu_buffer::free_page a buffer_data_read_page\n\nDiscarding a cached reader page after a concurrent ring buffer resize\nuses the new global subbuf_order for the free_pages() call. This\nmismatched order may crashes the kernel or leaks memory because the cached\npage was allocated under the old size.\n\nSave the actual free_page order alongside the page address to ensure we\nalways refer to the correct value and do not rely on the potentially\nstalled cpu_buffer->subbuf_order value. The simplest is to make\nfree_page a buffer_data_read_page which already covers exactly what we\nneed: a page address and a page order.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00161, EPSS Percentile is 0.05732 |
debian: CVE-2026-89500 was patched at 2026-09-16
1542.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89501) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Hold cpu_buffer::lock when resizing a subbuf Because, ring_buffer_subbuf_order_set() can clear cpu_buffer->free_page, hold cpu_buffer->lock to prevent races with ring_buffer_alloc_read_page() and ring_buffer_free_read_page().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Hold cpu_buffer::lock when resizing a subbuf\n\nBecause, ring_buffer_subbuf_order_set() can clear cpu_buffer->free_page,\nhold cpu_buffer->lock to prevent races with\nring_buffer_alloc_read_page() and ring_buffer_free_read_page().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00163, EPSS Percentile is 0.05915 |
debian: CVE-2026-89501 was patched at 2026-09-16
1543.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89503) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page() ring_buffer_alloc_read_page() is racy with ring_buffer_subbuf_order_set, it can allocate a reader page with an outdated order. This isn't a big issue, the user can still re-allocate a new reader page and try again. However, what is more problematic is if the value of subbuf_order changes in the middle of ring_buffer_alloc_read_page(). In that case, bpage->order might not match the actual allocated memory. Use bpage->order for the allocation to prevent this race.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page()\n\nring_buffer_alloc_read_page() is racy with ring_buffer_subbuf_order_set,\nit can allocate a reader page with an outdated order. This isn't a big\nissue, the user can still re-allocate a new reader page and try again.\n\nHowever, what is more problematic is if the value of subbuf_order\nchanges in the middle of ring_buffer_alloc_read_page(). In that case,\nbpage->order might not match the actual allocated memory.\n\nUse bpage->order for the allocation to prevent this race.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00161, EPSS Percentile is 0.05732 |
debian: CVE-2026-89503 was patched at 2026-09-16
1544.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89510) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Cancel reg_work before freeing device on remove c4iw_uld_state_change() queues reg_work to register the RDMA device. c4iw_remove() can free ctx->dev while this work is pending or running, leaving c4iw_register_device() accessing the freed device. Cancel reg_work before removing the device. The registration work can tear down ctx->dev when registration fails, so do not unregister or deallocate it again in that case. This issue was found by an in-house static analysis tool.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/cxgb4: Cancel reg_work before freeing device on remove\n\nc4iw_uld_state_change() queues reg_work to register the RDMA device.\nc4iw_remove() can free ctx->dev while this work is pending or running,\nleaving c4iw_register_device() accessing the freed device.\n\nCancel reg_work before removing the device. The registration work can\ntear down ctx->dev when registration fails, so do not unregister or\ndeallocate it again in that case.\n\nThis issue was found by an in-house static analysis tool.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07357 |
debian: CVE-2026-89510 was patched at 2026-09-16
1545.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89520) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: sched/core: Make core-sched flips wait for in-flight selections Core scheduling's pick_next_task() operates on all sibling rqs under one acquisition of the shared core-wide lock. A ->pick_task() that releases the rq lock leaves every sibling __lock momentarily free, letting __sched_core_flip(false) complete mid-selection and rebind rq_lockp() under it. The selection resumes on the split locks, touching sibling state it no longer protects, and __schedule() finally releases a lock that was never taken while leaking the one that was. Count in-flight core-wide selections in the leader's rq->core_pick_in_flight and make __sched_core_flip() wait for the count to drain. The count only changes under the shared lock, which the flip holds while sampling, so no other ordering is needed. The wait can repeat while selections overlap, but the flip backs off between samples and flips are rare cookie-lifetime events. sched_core_cpu_deactivate() moves the count to the new leader - a stale copy left behind would bias it forever if that CPU later returns as its own leader.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsched/core: Make core-sched flips wait for in-flight selections\n\nCore scheduling's pick_next_task() operates on all sibling rqs under one\nacquisition of the shared core-wide lock. A ->pick_task() that releases the\nrq lock leaves every sibling __lock momentarily free, letting\n__sched_core_flip(false) complete mid-selection and rebind rq_lockp() under\nit. The selection resumes on the split locks, touching sibling state it no\nlonger protects, and __schedule() finally releases a lock that was never\ntaken while leaking the one that was.\n\nCount in-flight core-wide selections in the leader's rq->core_pick_in_flight\nand make __sched_core_flip() wait for the count to drain. The count only\nchanges under the shared lock, which the flip holds while sampling, so no\nother ordering is needed. The wait can repeat while selections overlap, but\nthe flip backs off between samples and flips are rare cookie-lifetime\nevents.\n\nsched_core_cpu_deactivate() moves the count to the new leader - a stale copy\nleft behind would bias it forever if that CPU later returns as its own\nleader.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00161, EPSS Percentile is 0.05732 |
debian: CVE-2026-89520 was patched at 2026-09-16
1546.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89557) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: md: do overflow check for sb->bblog_shift in super_1_load() In super_1_load(), sb->bblog_shift is an __u8 type value loaded from on- disk superblock. It is used for badblocks API badblocks_set() by the following sequence, 1930 rdev->badblocks.shift = sb->bblog_shift; 1931 for (i = 0 ; i < (sectors << (9-3)) ; i++, bbp++) { 1932 u64 bb = le64_to_cpu(*bbp); 1933 int count = bb & (0x3ff); 1934 u64 sector = bb >> 10; 1935 sector <<= sb->bblog_shift; 1936 count <<= sb->bblog_shift; 1937 if (bb + 1 == 0) 1938 break; 1939 if (!badblocks_set(&rdev->badblocks, sector, count, 1)) 1940 return -EINVAL; 1941 } bb->bblog_shit is in range of 0-255, variable sector is 64bit width, for an invalid bb->bblog_shit, it is possible to make sector be overflowed by the following calculation, 1935 sector <<= sb->bblog_shift; Then in turn when call badblocks_set() at line 1939 with the invalid rdev->badblocks.shift set at line 1930, may result an overflow inside _badblocks_clear() in block/badblocks.c. Although there are many places to call badblocks APIs, the non-zero shift value is only used in super_1_load(), other places always use 0 as the shift value. Therefore it is unnecessary to do a general shift value overflow check inside badblock API, and just check here as the caller. This may avoid unnecessary check, make the badblocks API code more simple and elegant.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmd: do overflow check for sb->bblog_shift in super_1_load()\n\nIn super_1_load(), sb->bblog_shift is an __u8 type value loaded from on-\ndisk superblock. It is used for badblocks API badblocks_set() by the\nfollowing sequence,\n\n 1930 rdev->badblocks.shift = sb->bblog_shift;\n 1931 for (i = 0 ; i < (sectors << (9-3)) ; i++, bbp++) {\n 1932 u64 bb = le64_to_cpu(*bbp);\n 1933 int count = bb & (0x3ff);\n 1934 u64 sector = bb >> 10;\n 1935 sector <<= sb->bblog_shift;\n 1936 count <<= sb->bblog_shift;\n 1937 if (bb + 1 == 0)\n 1938 break;\n 1939 if (!badblocks_set(&rdev->badblocks, sector, count, 1))\n 1940 return -EINVAL;\n 1941 }\n\nbb->bblog_shit is in range of 0-255, variable sector is 64bit width, for\nan invalid bb->bblog_shit, it is possible to make sector be overflowed\nby the following calculation,\n 1935 sector <<= sb->bblog_shift;\nThen in turn when call badblocks_set() at line 1939 with the invalid\nrdev->badblocks.shift set at line 1930, may result an overflow inside\n_badblocks_clear() in block/badblocks.c.\n\nAlthough there are many places to call badblocks APIs, the non-zero\nshift value is only used in super_1_load(), other places always use 0 as\nthe shift value. Therefore it is unnecessary to do a general shift value\noverflow check inside badblock API, and just check here as the caller.\n\nThis may avoid unnecessary check, make the badblocks API code more simple\nand elegant.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.05995 |
debian: CVE-2026-89557 was patched at 2026-09-16
1547.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89574) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: dm array: validate array block headers on read array_block_check() validates blocknr and csum and nothing else, while node_check(), next to it, has bounded the structural fields since both were written. dm_array_cursor_next() takes its loop bound from the on-disk nr_entries and element_at() is unguarded pointer arithmetic, so a count larger than the block holds keeps the cursor in one block while the index grows past it and the read walks off the dm-bufio buffer -- dm_cache_load_mappings() drives it once per cache block at activation. Check the header against itself: reject a zero value_size, require max_entries to equal calc_max_entries() for that value_size and block size, and require nr_entries to fit. Equality rather than an upper bound, since a count below the real capacity trips BUG_ON() in fill_ablock() and trim_ablock(). Metadata dm-array writes satisfies all three.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndm array: validate array block headers on read\n\narray_block_check() validates blocknr and csum and nothing else, while\nnode_check(), next to it, has bounded the structural fields since both\nwere written. dm_array_cursor_next() takes its loop bound from the\non-disk nr_entries and element_at() is unguarded pointer arithmetic, so\na count larger than the block holds keeps the cursor in one block while\nthe index grows past it and the read walks off the dm-bufio buffer --\ndm_cache_load_mappings() drives it once per cache block at activation.\n\nCheck the header against itself: reject a zero value_size, require\nmax_entries to equal calc_max_entries() for that value_size and block\nsize, and require nr_entries to fit. Equality rather than an upper bound,\nsince a count below the real capacity trips BUG_ON() in fill_ablock() and\ntrim_ablock(). Metadata dm-array writes satisfies all three.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00163, EPSS Percentile is 0.05916 |
debian: CVE-2026-89574 was patched at 2026-09-16
1548.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89585) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: auxdisplay: charlcd: cancel backlight work on registration failure With CONFIG_CHARLCD_BL_FLASH, charlcd_init() schedules bl_work before charlcd_register() calls misc_register(). If registration fails, the caller frees the charlcd object while delayed work still contains its address. Add charlcd_deinit() to cancel the delayed work and turn the backlight off. Use it for both registration rollback and normal unregistration.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nauxdisplay: charlcd: cancel backlight work on registration failure\n\nWith CONFIG_CHARLCD_BL_FLASH, charlcd_init() schedules bl_work before\ncharlcd_register() calls misc_register(). If registration fails, the\ncaller frees the charlcd object while delayed work still contains its\naddress.\n\nAdd charlcd_deinit() to cancel the delayed work and turn the backlight\noff. Use it for both registration rollback and normal unregistration.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.05991 |
debian: CVE-2026-89585 was patched at 2026-09-16
1549.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89588) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ACPI: APEI: GHES: fix ARM section length accounting after header In ghes_handle_arm_hw_error(), after skipping the cper_sec_proc_arm header with (err + 1), the remaining length was reduced by sizeof(err) (pointer size) instead of sizeof(*err) (structure size). That overestimates the bytes left for cper_arm_err_info records and can let the parser read past the CPER section when err_info_num is large enough relative to error_data_length. Use sizeof(*err) so the length accounting matches the pointer advance and the earlier sizeof(*err) size check.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: APEI: GHES: fix ARM section length accounting after header\n\nIn ghes_handle_arm_hw_error(), after skipping the cper_sec_proc_arm\nheader with (err + 1), the remaining length was reduced by sizeof(err)\n(pointer size) instead of sizeof(*err) (structure size).\n\nThat overestimates the bytes left for cper_arm_err_info records and can\nlet the parser read past the CPER section when err_info_num is large\nenough relative to error_data_length.\n\nUse sizeof(*err) so the length accounting matches the pointer advance\nand the earlier sizeof(*err) size check.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00182, EPSS Percentile is 0.08059 |
debian: CVE-2026-89588 was patched at 2026-09-16
1550.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89594) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device The OMAP SSI driver uses a synthetic HSI controller device allocated via hsi_alloc_controller(), which does not go through the normal OF/platform device initialization path. As a result, the embedded struct device does not have a DMA mask initialized by default. After recent DMA API hardening changes, dma_map_sg() and related helpers now require a valid dma_mask to be present, otherwise the driver may crash or trigger warnings when attempting DMA mapping operations. Fix this by explicitly initializing the DMA mask for the SSI controller device and setting a 32-bit DMA mask, which matches the hardware capabilities.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device\n\nThe OMAP SSI driver uses a synthetic HSI controller device allocated via\nhsi_alloc_controller(), which does not go through the normal OF/platform\ndevice initialization path.\n\nAs a result, the embedded struct device does not have a DMA mask\ninitialized by default.\n\nAfter recent DMA API hardening changes, dma_map_sg() and related helpers\nnow require a valid dma_mask to be present, otherwise the driver may\ncrash or trigger warnings when attempting DMA mapping operations.\n\nFix this by explicitly initializing the DMA mask for the SSI controller\ndevice and setting a 32-bit DMA mask, which matches the hardware\ncapabilities.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.05994 |
debian: CVE-2026-89594 was patched at 2026-09-16
1551.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89597) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fbdev: uvesafb: unregister connector callback on init failure uvesafb_init() registers the v86d connector callback before registering the platform driver. If platform_driver_register() fails, the function returns the error directly and leaves the connector callback registered. The later platform-device failure path already unregisters the callback. Add the same cleanup before the final return when platform-driver registration fails. This issue was identified during our ongoing static-analysis research while reviewing kernel code.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: uvesafb: unregister connector callback on init failure\n\nuvesafb_init() registers the v86d connector callback before registering\nthe platform driver. If platform_driver_register() fails, the function\nreturns the error directly and leaves the connector callback registered.\n\nThe later platform-device failure path already unregisters the callback.\nAdd the same cleanup before the final return when platform-driver\nregistration fails.\n\nThis issue was identified during our ongoing static-analysis research while\nreviewing kernel code.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.0599 |
debian: CVE-2026-89597 was patched at 2026-09-16
1552.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89602) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: erofs: skip sufficiently large global buffers when resizing z_erofs_gbuf_nrpages is advanced only after every global buffer has been grown. If a resize fails after some buffers were enlarged, a retry revisits those enlarged buffers. Retrying the same size then returns -ENOMEM because alloc_pages_bulk() has no pages to add and the unchanged return value is treated as a failure. Retrying an intermediate size allocates a temporary pointer array smaller than gbuf->nrpages and copies more existing pointers than the array can hold. Skip buffers that already satisfy the request. Once all remaining buffers have caught up, advancing z_erofs_gbuf_nrpages again describes the guaranteed minimum size across the pool.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: skip sufficiently large global buffers when resizing\n\nz_erofs_gbuf_nrpages is advanced only after every global buffer has been\ngrown. If a resize fails after some buffers were enlarged, a retry\nrevisits those enlarged buffers.\n\nRetrying the same size then returns -ENOMEM because alloc_pages_bulk()\nhas no pages to add and the unchanged return value is treated as a\nfailure. Retrying an intermediate size allocates a temporary pointer\narray smaller than gbuf->nrpages and copies more existing pointers than\nthe array can hold.\n\nSkip buffers that already satisfy the request. Once all remaining\nbuffers have caught up, advancing z_erofs_gbuf_nrpages again describes\nthe guaranteed minimum size across the pool.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06863 |
debian: CVE-2026-89602 was patched at 2026-09-16
1553.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89605) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ecryptfs: release message context on send failure ecryptfs_send_message_locked() moves a message context from the free list to the allocated list before sending the request to the userspace daemon. If ecryptfs_send_miscdev() fails, the context is left on the allocated list and cannot be reused. Move it back to the free list on failure and clear the caller's pointer.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\necryptfs: release message context on send failure\n\necryptfs_send_message_locked() moves a message context from the free\nlist to the allocated list before sending the request to the userspace\ndaemon.\n\nIf ecryptfs_send_miscdev() fails, the context is left on the\nallocated list and cannot be reused. Move it back to the free list on\nfailure and clear the caller's pointer.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.0599 |
debian: CVE-2026-89605 was patched at 2026-09-16
1554.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89607) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet parse_tag_3_packet() set encrypted_key_size from the Tag 3 packet body without bounding it against ECRYPTFS_MAX_KEY_BYTES (64). When encrypted_key_size > 64, decrypt_passphrase_encrypted_session_key() sets decrypted_key_size = encrypted_key_size and performs two out-of-bounds writes: 1. crypto_skcipher_decrypt() writes encrypted_key_size bytes into decrypted_key[64] via scatterlist, overflowing into the parent ecryptfs_auth_tok struct. 2. memcpy(crypt_stat->key, decrypted_key, decrypted_key_size) writes into crypt_stat->key[64], corrupting root_iv, keysig_list, and mutexes in ecryptfs_crypt_stat. Only AES-192 (cipher code 0x08) enables this because it sets crypt_stat->key_size = 24 independently of encrypted_key_size, allowing crypto_skcipher_setkey() to succeed while encrypted_key_size exceeds ECRYPTFS_MAX_KEY_BYTES. The PKI decryption path (parse_tag_65_packet) already validates decrypted_key_size <= ECRYPTFS_MAX_KEY_BYTES; the passphrase path omits this check. Bound encrypted_key_size against ECRYPTFS_MAX_KEY_BYTES (64) rather than ECRYPTFS_MAX_ENCRYPTED_KEY_BYTES (512). The 64-byte limit also protects the 512-byte encrypted_key[] buffer, so the former 512-byte check is removed as redundant. [tyhicks: Adjust the code comment to refer to macros representing the buffer sizes rather than mentioning the buffer size values since they may change in the future]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\necryptfs: reject oversized encrypted_key_size in parse_tag_3_packet\n\nparse_tag_3_packet() set encrypted_key_size from the Tag 3 packet body\nwithout bounding it against ECRYPTFS_MAX_KEY_BYTES (64). When\nencrypted_key_size > 64, decrypt_passphrase_encrypted_session_key()\nsets decrypted_key_size = encrypted_key_size and performs two\nout-of-bounds writes:\n\n1. crypto_skcipher_decrypt() writes encrypted_key_size bytes into\n decrypted_key[64] via scatterlist, overflowing into the parent\n ecryptfs_auth_tok struct.\n2. memcpy(crypt_stat->key, decrypted_key, decrypted_key_size) writes\n into crypt_stat->key[64], corrupting root_iv, keysig_list, and\n mutexes in ecryptfs_crypt_stat.\n\nOnly AES-192 (cipher code 0x08) enables this because it sets\ncrypt_stat->key_size = 24 independently of encrypted_key_size,\nallowing crypto_skcipher_setkey() to succeed while encrypted_key_size\nexceeds ECRYPTFS_MAX_KEY_BYTES.\n\nThe PKI decryption path (parse_tag_65_packet) already validates\ndecrypted_key_size <= ECRYPTFS_MAX_KEY_BYTES; the passphrase path\nomits this check.\n\nBound encrypted_key_size against ECRYPTFS_MAX_KEY_BYTES (64) rather\nthan ECRYPTFS_MAX_ENCRYPTED_KEY_BYTES (512). The 64-byte limit also\nprotects the 512-byte encrypted_key[] buffer, so the former 512-byte\ncheck is removed as redundant.\n\n[tyhicks: Adjust the code comment to refer to macros representing the\n buffer sizes rather than mentioning the buffer size values since they\n may change in the future]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.0599 |
debian: CVE-2026-89607 was patched at 2026-09-16
1555.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89609) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ecryptfs: hold msg ctx list lock when cleaning daemon queue ecryptfs_exorcise_daemon() drops queued messages from a dying daemon without holding ecryptfs_msg_ctx_lists_mux, but ecryptfs_msg_ctx_alloc_to_free() requires that lock. Take the list lock while moving the queued contexts back to the free list to avoid racing with other global msg ctx list users.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\necryptfs: hold msg ctx list lock when cleaning daemon queue\n\necryptfs_exorcise_daemon() drops queued messages from a dying daemon\nwithout holding ecryptfs_msg_ctx_lists_mux, but\necryptfs_msg_ctx_alloc_to_free() requires that lock.\n\nTake the list lock while moving the queued contexts back to the free\nlist to avoid racing with other global msg ctx list users.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07358 |
debian: CVE-2026-89609 was patched at 2026-09-16
1556.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89723) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation Shuangpeng Bai reported that KASAN detected a slab-out-of-bounds error in nilfs_direct_propagate() during testing. Analysis revealed that after truncating a file, a node block immediately below the B-tree root was not deleted. Instead, it remained in the B-tree node cache in a dirty state. The log writer subsequently detected this block and incorrectly invoked nilfs_direct_propagate() on it, which is designed to handle only data blocks in direct mapping. B-tree nodes in the cache are managed by virtual block numbers, and their logical keys typically exceed the range expected by direct mapping. Consequently, processing such a node as a direct mapping entry triggers a slab-out-of-bounds access. The root cause is that when a B-tree mapping collapses into a direct mapping during truncation, an intermediate node block pointed to by the root node is left behind as garbage instead of being explicitly deleted. This resolves the issue by adding a nilfs_btree_discard() operation to delete the remaining intermediate node block during the conversion. A 'deform' flag is added to the bop_delete interface to explicitly signal that the deletion is part of a mapping transformation. This allows the B-tree mapping implementation to perform the necessary cleanup and discarding of the residual node structure that would be otherwise be left orphaned after the transition.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation\n\nShuangpeng Bai reported that KASAN detected a slab-out-of-bounds error\nin nilfs_direct_propagate() during testing.\n\nAnalysis revealed that after truncating a file, a node block immediately\nbelow the B-tree root was not deleted. Instead, it remained in the B-tree\nnode cache in a dirty state. The log writer subsequently detected this\nblock and incorrectly invoked nilfs_direct_propagate() on it, which is\ndesigned to handle only data blocks in direct mapping.\n\nB-tree nodes in the cache are managed by virtual block numbers, and their\nlogical keys typically exceed the range expected by direct mapping.\nConsequently, processing such a node as a direct mapping entry triggers\na slab-out-of-bounds access.\n\nThe root cause is that when a B-tree mapping collapses into a direct\nmapping during truncation, an intermediate node block pointed to by the\nroot node is left behind as garbage instead of being explicitly deleted.\n\nThis resolves the issue by adding a nilfs_btree_discard() operation\nto delete the remaining intermediate node block during the conversion.\nA 'deform' flag is added to the bop_delete interface to explicitly signal\nthat the deletion is part of a mapping transformation. This allows the\nB-tree mapping implementation to perform the necessary cleanup and\ndiscarding of the residual node structure that would be otherwise be left\norphaned after the transition.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.05992 |
debian: CVE-2026-89723 was patched at 2026-09-16
1557.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89733) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() In uvc_function_bind() error path, we use usb_ep_free_request which uses uvc->control_req but does not set it to NULL afterwards. Thus, uvc->control_req is a dangling pointer causing a UAF. Also we do not set the uvc->control_buf pointer to NULL after freeing it, which is another dangling pointer. Fix it by setting uvc->control_req to NULL after we run usb_ep_free_request() and uvc->control_buf to NULL after kfree. Do the same for uvc_function_unbind().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind()\n\nIn uvc_function_bind() error path, we use usb_ep_free_request which\nuses uvc->control_req but does not set it to NULL afterwards. Thus,\nuvc->control_req is a dangling pointer causing a UAF. Also we do not set\nthe uvc->control_buf pointer to NULL after freeing it, which is another\ndangling pointer. Fix it by setting uvc->control_req to NULL after we run\nusb_ep_free_request() and uvc->control_buf to NULL after kfree. Do the\nsame for uvc_function_unbind().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.06052 |
debian: CVE-2026-89733 was patched at 2026-09-16
1558.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89738) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed In polled-VBUS mode (board.vbus_pin && board.vbus_polled), probe arms a self-restarting cycle: at91_vbus_timer() schedules vbus_timer_work, and at91_vbus_timer_work() calls at91_vbus_update() and re-arms the timer via mod_timer(). Both recover the same udc through container_of and dereference it on every iteration. Neither teardown path cancels this cycle. udc is devm-allocated, so it is freed after at91udc_remove() returns, and is likewise freed when probe fails and devres runs. A timer callback or work item that is pending or running at either point dereferences the freed udc. Add at91_udc_shutdown_vbus_timer() and call it from at91udc_remove() and from the usb_add_gadget_udc() failure path in probe; the remaining probe error paths fail before the timer is armed. timer_shutdown_sync() waits for a running callback and clears timer->function, which makes the work handler's mod_timer() a permanent no-op; cancel_work_sync() then drains any pending or running work whose re-arm attempt now does nothing. The timer must be shut down first, since cancelling the work alone would let the timer re-queue it. The guard mirrors probe: in IRQ mode the timer and work_struct are never initialized. This does not require a fault; a normal driver unbind can interleave with an already queued work item. This issue was found by an in-house static analysis tool.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed\n\nIn polled-VBUS mode (board.vbus_pin && board.vbus_polled), probe arms a\nself-restarting cycle: at91_vbus_timer() schedules vbus_timer_work, and\nat91_vbus_timer_work() calls at91_vbus_update() and re-arms the timer via\nmod_timer(). Both recover the same udc through container_of and dereference\nit on every iteration.\n\nNeither teardown path cancels this cycle. udc is devm-allocated, so it is\nfreed after at91udc_remove() returns, and is likewise freed when probe\nfails and devres runs. A timer callback or work item that is pending or\nrunning at either point dereferences the freed udc.\n\nAdd at91_udc_shutdown_vbus_timer() and call it from at91udc_remove() and\nfrom the usb_add_gadget_udc() failure path in probe; the remaining probe\nerror paths fail before the timer is armed. timer_shutdown_sync() waits\nfor a running callback and clears timer->function, which makes the work\nhandler's mod_timer() a permanent no-op; cancel_work_sync() then drains\nany pending or running work whose re-arm attempt now does nothing. The\ntimer must be shut down first, since cancelling the work alone would let\nthe timer re-queue it. The guard mirrors probe: in IRQ mode the timer and\nwork_struct are never initialized.\n\nThis does not require a fault; a normal driver unbind can interleave with\nan already queued work item.\n\nThis issue was found by an in-house static analysis tool.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.05978 |
debian: CVE-2026-89738 was patched at 2026-09-16
1559.
Arbitrary File Reading - Unknown Product (CVE-2026-78679) - Medium [255]
Description: {'nvd_cve_data_all': 'GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=<path> to read arbitrary files, with contents returned in the annotated tag message.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=<path> to read arbitrary files, with contents returned in the annotated tag message.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00241, EPSS Percentile is 0.15463 |
debian: CVE-2026-78679 was patched at 2026-08-25
1560.
Denial of Service - Unknown Product (CVE-2026-27852) - Medium [255]
Description: {'nvd_cve_data_all': 'An attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresses or MIME parameters, which causes excessive memory usage when the message is later parsed. The message is still delivered, but reading it over IMAP can exhaust the memory limit of the process and terminate it, causing denial of service for the affected user. Update to non-vulnerable version. No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresses or MIME parameters, which causes excessive memory usage when the message is later parsed. The message is still delivered, but reading it over IMAP can exhaust the memory limit of the process and terminate it, causing denial of service for the affected user. Update to non-vulnerable version. No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00359, EPSS Percentile is 0.29497 |
altlinux: CVE-2026-27852 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-27852 was patched at 2026-09-16
1561.
Denial of Service - Unknown Product (CVE-2026-33605) - Medium [255]
Description: {'nvd_cve_data_all': 'An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community releases), only the attacker's own connection is terminated. If running in high-performance mode (default for Pro releases), all connections handled by the same managesieve-login process are terminated. Repeating the attack can cause denial of service for Sieve script management. Restrict network access to the ManageSieve service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community releases), only the attacker's own connection is terminated. If running in high-performance mode (default for Pro releases), all connections handled by the same managesieve-login process are terminated. Repeating the attack can cause denial of service for Sieve script management. Restrict network access to the ManageSieve service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00375, EPSS Percentile is 0.31197 |
debian: CVE-2026-33605 was patched at 2026-09-16
1562.
Denial of Service - Unknown Product (CVE-2026-42391) - Medium [255]
Description: {'nvd_cve_data_all': 'An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage to grow disproportionately. The login process can be terminated by the out-of-memory handling, which also terminates all other connections handled by the same process. This can cause degradation or denial of service for IMAP logins. Limit the number of connections handled by a single imap-login process. This has a performance impact though. Update to non-vulnerable version. No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage to grow disproportionately. The login process can be terminated by the out-of-memory handling, which also terminates all other connections handled by the same process. This can cause degradation or denial of service for IMAP logins. Limit the number of connections handled by a single imap-login process. This has a performance impact though. Update to non-vulnerable version. No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00375, EPSS Percentile is 0.31197 |
altlinux: CVE-2026-42391 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-42391 was patched at 2026-09-16
1563.
Denial of Service - Unknown Product (CVE-2026-68005) - Medium [255]
Description: {'nvd_cve_data_all': 'An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in the handle_request() function', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in the handle_request() function', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0041, EPSS Percentile is 0.34735 |
debian: CVE-2026-68005 was patched at 2026-08-20
1564.
Denial of Service - Unknown Product (CVE-2026-79921) - Medium [255]
Description: {'nvd_cve_data_all': 'amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to unexpected memory consumption or application-layer denial of service (DoS), bypassing the protocol's built-in framing constraints. Version 1.13.0 contains a fix. No known workarounds are available.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to unexpected memory consumption or application-layer denial of service (DoS), bypassing the protocol's built-in framing constraints. Version 1.13.0 contains a fix. No known workarounds are available.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.9. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00316, EPSS Percentile is 0.24552 |
debian: CVE-2026-79921 was patched at 2026-09-16
1565.
Denial of Service - Unknown Product (CVE-2026-84375) - Medium [255]
Description: {'nvd_cve_data_all': 'js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. An attacker can alias a large sequence of empty mappings into many merge targets, causing O(N * K) processing while totalMergeKeys remains unchanged and the configured resource limit is never reached. A relatively small YAML document can therefore cause prolonged CPU consumption in applications that parse untrusted YAML, and merge processing is enabled by default on these release lines. This issue is fixed in versions 3.15.2 and 4.3.2.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2, 4.3.2, and 5.4.1, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. An attacker can alias a large sequence of empty mappings into many merge targets, causing O(N * K) processing while totalMergeKeys remains unchanged and the configured resource limit is never reached. A relatively small YAML document can therefore cause prolonged CPU consumption in applications that parse untrusted YAML, and merge processing is enabled by default on these release lines. In v3 & v4, merge is enabled by default so the severity score is higher. This issue is fixed in versions 3.15.2, 4.3.2, and 5.4.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00385, EPSS Percentile is 0.32173 |
debian: CVE-2026-84375 was patched at 2026-09-16
1566.
Denial of Service - Unknown Product (CVE-2026-91752) - Medium [255]
Description: {'nvd_cve_data_all': 'GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. Attackers can craft malicious StarOffice documents that allocate up to 4 MB on the stack, causing stack overflow and crashing any application extracting metadata from the document.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. Attackers can craft malicious StarOffice documents that allocate up to 4 MB on the stack, causing stack overflow and crashing any application extracting metadata from the document.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00387, EPSS Percentile is 0.32407 |
debian: CVE-2026-91752 was patched at 2026-09-16
1567.
Denial of Service - Unknown Product (CVE-2026-91990) - Medium [255]
Description: {'nvd_cve_data_all': 'Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transient lists, exhausting server memory and causing denial of service.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transient lists, exhausting server memory and causing denial of service.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00412, EPSS Percentile is 0.34969 |
debian: CVE-2026-91990 was patched at 2026-09-16
1568.
Incorrect Calculation - OpenEXR (CVE-2026-59183) - Medium [255]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | OpenEXR is an open source high-dynamic-range image file format and reference implementation widely used in computer graphics, visual effects, animation, and motion picture production. | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06425 |
debian: CVE-2026-59183 was patched at 2026-09-16
1569.
Incorrect Calculation - TLS (CVE-2026-68552) - Medium [255]
Description: Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an unauthenticated remote client can send a STUN message over TCP or
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | TLS | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00315, EPSS Percentile is 0.24435 |
debian: CVE-2026-68552 was patched at 2026-08-25
1570.
Memory Corruption - OpenEXR (CVE-2026-68515) - Medium [255]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | OpenEXR is an open source high-dynamic-range image file format and reference implementation widely used in computer graphics, visual effects, animation, and motion picture production. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00127, EPSS Percentile is 0.02695 |
debian: CVE-2026-68515 was patched at 2026-09-16
1571.
Path Traversal - Unknown Product (CVE-2026-85396) - Medium [255]
Description: {'nvd_cve_data_all': 'rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like ../upload_backup/owned.sh to write files outside the intended extraction directory into sibling paths sharing the destination prefix.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like ../upload_backup/owned.sh to write files outside the intended extraction directory into sibling paths sharing the destination prefix.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00383, EPSS Percentile is 0.32024 |
debian: CVE-2026-85396 was patched at 2026-09-16
1572.
Path Traversal - nltk (CVE-2026-71514) - Medium [255]
Description: NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus root with crubadan_code, the column-0 value read from the corpus table.txt mapping file, and opens the result with the builtin open() rather than the pathsec-validated opener, so os.path.join discards the root when that value is absolute and the read escapes the corpus directory without the containment check nltk.pathsec applies when ENFORCE is set. An attacker who controls a corpus package can disclose file contents outside the corpus root through lang_freq, limited to paths ending in -3grams.txt whose contents parse as token count lines.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00162, EPSS Percentile is 0.05793 |
debian: CVE-2026-71514 was patched at 2026-08-25
1573.
Security Feature Bypass - Unknown Product (CVE-2026-48549) - Medium [255]
Description: {'nvd_cve_data_all': 'Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi. When no Cookie header is present, the double-submit cookie protection can be bypassed by supplying matching NagFormId and nagFormId values in the POST body, allowing a cross-site request to execute Nagios commands as a currently authenticated user.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi. When no Cookie header is present, the double-submit cookie protection can be bypassed by supplying matching NagFormId and nagFormId values in the POST body, allowing a cross-site request to execute Nagios commands as a currently authenticated user.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06399 |
debian: CVE-2026-48549 was patched at 2026-09-16
1574.
Security Feature Bypass - Unknown Product (CVE-2026-53499) - Medium [255]
Description: {'nvd_cve_data_all': 'FORT Validator is a Resource Public Key Infrastructure (RPKI) relying-party validator that produces validated route-origin data. FORT Validator versions through 1.6.7 contain an origin-validation error in their RRDP processing: a delegated CA under the same Trust Anchor Locator (TAL) can reference a victim CA’s public RRDP notification and snapshot URLs, causing FORT’s URL-based download cache to report success after deleting the victim’s local snapshot. Following a routine victim publication, this can silently remove the victim’s VRPs and other signed objects from FORT’s output, potentially enabling route hijacking or loss of reachability. Version 1.6.8 contains a patch that rejects cross-origin RRDP snapshot and delta URLs; as a workaround, administrators can disable HTTP/RRDP with --http.enabled=false while keeping rsync enabled, although this can leave data unavailable or stale where rsync is not supported.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'FORT Validator is a Resource Public Key Infrastructure (RPKI) relying-party validator that produces validated route-origin data. FORT Validator versions through 1.6.7 contain an origin-validation error in their RRDP processing: a delegated CA under the same Trust Anchor Locator (TAL) can reference a victim CA’s public RRDP notification and snapshot URLs, causing FORT’s URL-based download cache to report success after deleting the victim’s local snapshot. Following a routine victim publication, this can silently remove the victim’s VRPs and other signed objects from FORT’s output, potentially enabling route hijacking or loss of reachability. Version 1.6.8 contains a patch that rejects cross-origin RRDP snapshot and delta URLs; as a workaround, administrators can disable HTTP/RRDP with \xa0--http.enabled=false\xa0 while keeping rsync enabled, although this can leave data unavailable or stale where rsync is not supported.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00158, EPSS Percentile is 0.05405 |
debian: CVE-2026-53499 was patched at 2026-08-25, 2026-09-08
1575.
Security Feature Bypass - Unknown Product (CVE-2026-61711) - Medium [255]
Description: {'nvd_cve_data_all': 'BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom frontend could place an invalid SecurityMode value in a crafted build request, and executor/oci/spec_linux.go treated the unsupported value as a non-sandbox mode without requiring the security.insecure entitlement. This disabled Seccomp and AppArmor protections for the build container even though Linux capabilities remained restricted. This issue is fixed in version 0.31.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom frontend could place an invalid SecurityMode value in a crafted build request, and executor/oci/spec_linux.go treated the unsupported value as a non-sandbox mode without requiring the security.insecure entitlement. This disabled Seccomp and AppArmor protections for the build container even though Linux capabilities remained restricted. This issue is fixed in version 0.31.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00357, EPSS Percentile is 0.29235 |
redos: CVE-2026-61711 was patched at 2026-09-07
1576.
Unknown Vulnerability Type - Perl (CVE-2026-16028) - Medium [254]
Description: {'nvd_cve_data_all': 'Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table. When a stream reaches the CLOSED state, stream_state returns the concurrency slot and clears most of the stream's keys, but the entry itself stays in the connection stream table and nothing in the distribution removes it. Stream identifiers increase monotonically, so a peer can open and close streams on one connection indefinitely, each close leaving a residual entry that is retained for the life of the connection. SETTINGS_MAX_CONCURRENT_STREAMS does not bound this. That setting caps how many streams are live at once and is enforced, while the growth is made of streams the cap has already released, so it accumulates with concurrency never exceeding one. The client keeps the same table and grows the same way against a hostile server. Measured against a server built on this module, roughly 920 bytes are retained per closed stream for about 19 bytes on the wire, so 100,000 sequential streams on one connection grow server resident memory by about 88 MiB. The streams are ordinary requests that the application accepts and completes.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table.\n\nWhen a stream reaches the CLOSED state, stream_state returns the concurrency slot and clears most of the stream's keys, but the entry itself stays in the connection stream table and nothing in the distribution removes it. Stream identifiers increase monotonically, so a peer can open and close streams on one connection indefinitely, each close leaving a residual entry that is retained for the life of the connection.\n\nSETTINGS_MAX_CONCURRENT_STREAMS does not bound this. That setting caps how many streams are live at once and is enforced, while the growth is made of streams the cap has already released, so it accumulates with concurrency never exceeding one. The client keeps the same table and grows the same way against a hostile server.\n\nMeasured against a server built on this module, roughly 920 bytes are retained per closed stream for about 19 bytes on the wire, so 100,000 sequential streams on one connection grow server resident memory by about 88 MiB. The streams are ordinary requests that the application accepts and completes.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.0063, EPSS Percentile is 0.48517 |
debian: CVE-2026-16028 was patched at 2026-09-16
1577.
Unknown Vulnerability Type - Perl (CVE-2026-77781) - Medium [254]
Description: {'nvd_cve_data_all': 'Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys. The FETCH, EXISTS and DELETE methods throw an exception when on malformed regular expressions. Each method falls back to a regex match when the key is not already stored in the hash, compiling the caller's key with a bare qr// and no eval guard. A key that is not a valid regular expression pattern, such as a single unmatched bracket, dies. An application that looks up externally supplied strings in a tied hash will die on an invalid key.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys.\n\nThe FETCH, EXISTS and DELETE methods throw an exception when on malformed regular expressions.\n\nEach method falls back to a regex match when the key is not already stored in the hash, compiling the caller's key with a bare qr// and no eval guard. A key that is not a valid regular expression pattern, such as a single unmatched bracket, dies.\n\nAn application that looks up externally supplied strings in a tied hash will die on an invalid key.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00583, EPSS Percentile is 0.46313 |
debian: CVE-2026-77781 was patched at 2026-08-25
1578.
Spoofing - Chromium (CVE-2026-84356) - Medium [252]
Description: UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00154, EPSS Percentile is 0.04951 |
altlinux: CVE-2026-84356 was patched at 2026-09-03
debian: CVE-2026-84356 was patched at 2026-09-03, 2026-09-16
1579.
Unknown Vulnerability Type - Chromium (CVE-2026-78907) - Medium [252]
Description: {'nvd_cve_data_all': 'Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0037, EPSS Percentile is 0.30686 |
altlinux: CVE-2026-78907 was patched at 2026-08-28
debian: CVE-2026-78907 was patched at 2026-09-03, 2026-09-16
1580.
Unknown Vulnerability Type - Chromium (CVE-2026-78959) - Medium [252]
Description: {'nvd_cve_data_all': 'Improper handling of case sensitivity in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Improper handling of case sensitivity in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00391, EPSS Percentile is 0.32844 |
altlinux: CVE-2026-78959 was patched at 2026-08-28
debian: CVE-2026-78959 was patched at 2026-09-03, 2026-09-16
1581.
Unknown Vulnerability Type - Chromium (CVE-2026-78967) - Medium [252]
Description: {'nvd_cve_data_all': 'Missing authorization in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00386, EPSS Percentile is 0.32358 |
altlinux: CVE-2026-78967 was patched at 2026-08-28
debian: CVE-2026-78967 was patched at 2026-09-03, 2026-09-16
1582.
Unknown Vulnerability Type - Chromium (CVE-2026-78969) - Medium [252]
Description: {'nvd_cve_data_all': 'Uninitialized resource in Video in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in Video in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00397, EPSS Percentile is 0.33486 |
altlinux: CVE-2026-78969 was patched at 2026-08-28
debian: CVE-2026-78969 was patched at 2026-09-03, 2026-09-16
1583.
Unknown Vulnerability Type - Chromium (CVE-2026-78977) - Medium [252]
Description: {'nvd_cve_data_all': 'Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00381, EPSS Percentile is 0.31792 |
altlinux: CVE-2026-78977 was patched at 2026-08-28
debian: CVE-2026-78977 was patched at 2026-09-03, 2026-09-16
1584.
Unknown Vulnerability Type - Chromium (CVE-2026-79072) - Medium [252]
Description: {'nvd_cve_data_all': 'Improper state validation in Performance in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Improper state validation in Performance in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00312, EPSS Percentile is 0.24038 |
altlinux: CVE-2026-79072 was patched at 2026-08-28
debian: CVE-2026-79072 was patched at 2026-09-03, 2026-09-16
1585.
Unknown Vulnerability Type - Chromium (CVE-2026-79120) - Medium [252]
Description: {'nvd_cve_data_all': 'Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0034, EPSS Percentile is 0.27325 |
altlinux: CVE-2026-79120 was patched at 2026-08-28
debian: CVE-2026-79120 was patched at 2026-09-03, 2026-09-16
1586.
Unknown Vulnerability Type - Chromium (CVE-2026-79229) - Medium [252]
Description: {'nvd_cve_data_all': 'Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00411, EPSS Percentile is 0.34879 |
altlinux: CVE-2026-79229 was patched at 2026-08-28
debian: CVE-2026-79229 was patched at 2026-09-03, 2026-09-16
1587.
Unknown Vulnerability Type - Chromium (CVE-2026-79270) - Medium [252]
Description: {'nvd_cve_data_all': 'Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00411, EPSS Percentile is 0.34879 |
altlinux: CVE-2026-79270 was patched at 2026-08-28
debian: CVE-2026-79270 was patched at 2026-09-03, 2026-09-16
1588.
Unknown Vulnerability Type - Chromium (CVE-2026-79285) - Medium [252]
Description: {'nvd_cve_data_all': 'Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00411, EPSS Percentile is 0.34879 |
altlinux: CVE-2026-79285 was patched at 2026-08-28
debian: CVE-2026-79285 was patched at 2026-09-03, 2026-09-16
1589.
Unknown Vulnerability Type - Chromium (CVE-2026-87436) - Medium [252]
Description: {'nvd_cve_data_all': 'Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00331, EPSS Percentile is 0.26269 |
altlinux: CVE-2026-87436 was patched at 2026-09-17
debian: CVE-2026-87436 was patched at 2026-09-16
1590.
Unknown Vulnerability Type - Chromium (CVE-2026-87446) - Medium [252]
Description: {'nvd_cve_data_all': 'Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00331, EPSS Percentile is 0.26269 |
altlinux: CVE-2026-87446 was patched at 2026-09-17
debian: CVE-2026-87446 was patched at 2026-09-16
1591.
Unknown Vulnerability Type - Chromium (CVE-2026-87549) - Medium [252]
Description: {'nvd_cve_data_all': 'Incomplete cleanup in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incomplete cleanup in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.25376 |
altlinux: CVE-2026-87549 was patched at 2026-09-17
debian: CVE-2026-87549 was patched at 2026-09-16
1592.
Unknown Vulnerability Type - Chromium (CVE-2026-91732) - Medium [252]
Description: {'nvd_cve_data_all': 'Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00249, EPSS Percentile is 0.1647 |
altlinux: CVE-2026-91732 was patched at 2026-09-17
debian: CVE-2026-91732 was patched at 2026-09-16
1593.
Unknown Vulnerability Type - Chromium (CVE-2026-91733) - Medium [252]
Description: {'nvd_cve_data_all': 'Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00293, EPSS Percentile is 0.2199 |
altlinux: CVE-2026-91733 was patched at 2026-09-17
debian: CVE-2026-91733 was patched at 2026-09-16
1594.
Unknown Vulnerability Type - Keycloak (CVE-2026-15571) - Medium [252]
Description: {'nvd_cve_data_all': 'A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a hash that can be predicted by a malicious OIDC client. By tricking a user into authenticating, an attacker-controlled client can forge a valid linking URL to connect the victim's account to an attacker's external identity. This results in a full account takeover, allowing the attacker to log in as the victim.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a hash that can be predicted by a malicious OIDC client. By tricking a user into authenticating, an attacker-controlled client can forge a valid linking URL to connect the victim's account to an attacker's external identity. This results in a full account takeover, allowing the attacker to log in as the victim.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00329, EPSS Percentile is 0.2603 |
altlinux: CVE-2026-15571 was patched at 2026-08-20, 2026-08-26, 2026-08-28
1595.
Unknown Vulnerability Type - Keycloak (CVE-2026-17059) - Medium [252]
Description: {'nvd_cve_data_all': 'A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when listing members of a role. This allows a restricted administrator to see private information, such as names and email addresses, for users they should not be able to access.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when listing members of a role. This allows a restricted administrator to see private information, such as names and email addresses, for users they should not be able to access.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00404, EPSS Percentile is 0.34253 |
altlinux: CVE-2026-17059 was patched at 2026-09-01, 2026-09-04, 2026-09-07
1596.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-74966) - Medium [252]
Description: {'nvd_cve_data_all': 'Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00256, EPSS Percentile is 0.17432 |
altlinux: CVE-2026-74966 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
1597.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92016) - Medium [252]
Description: {'nvd_cve_data_all': 'Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05182 |
altlinux: CVE-2026-92016 was patched at 2026-09-16
debian: CVE-2026-92016 was patched at 2026-09-16, 2026-09-17
1598.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92022) - Medium [252]
Description: {'nvd_cve_data_all': 'Use-after-free in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Use-after-free in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05182 |
altlinux: CVE-2026-92022 was patched at 2026-09-16
debian: CVE-2026-92022 was patched at 2026-09-16, 2026-09-17
1599.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92023) - Medium [252]
Description: {'nvd_cve_data_all': 'Use-after-free in the XML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Use-after-free in the XML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05181 |
altlinux: CVE-2026-92023 was patched at 2026-09-16
debian: CVE-2026-92023 was patched at 2026-09-16, 2026-09-17
1600.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92024) - Medium [252]
Description: {'nvd_cve_data_all': 'Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05181 |
altlinux: CVE-2026-92024 was patched at 2026-09-16
debian: CVE-2026-92024 was patched at 2026-09-16, 2026-09-17
1601.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92025) - Medium [252]
Description: {'nvd_cve_data_all': 'Use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05181 |
altlinux: CVE-2026-92025 was patched at 2026-09-16
debian: CVE-2026-92025 was patched at 2026-09-16, 2026-09-17
1602.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92026) - Medium [252]
Description: {'nvd_cve_data_all': 'Use-after-free in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Use-after-free in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05182 |
altlinux: CVE-2026-92026 was patched at 2026-09-16
debian: CVE-2026-92026 was patched at 2026-09-16, 2026-09-17
1603.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92027) - Medium [252]
Description: {'nvd_cve_data_all': 'Use-after-free in the DOM: Streams component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Use-after-free in the DOM: Streams component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05179 |
altlinux: CVE-2026-92027 was patched at 2026-09-16
debian: CVE-2026-92027 was patched at 2026-09-16, 2026-09-17
1604.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92028) - Medium [252]
Description: {'nvd_cve_data_all': 'Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.0518 |
altlinux: CVE-2026-92028 was patched at 2026-09-16
debian: CVE-2026-92028 was patched at 2026-09-16, 2026-09-17
1605.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92029) - Medium [252]
Description: {'nvd_cve_data_all': 'Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05179 |
altlinux: CVE-2026-92029 was patched at 2026-09-16
debian: CVE-2026-92029 was patched at 2026-09-16, 2026-09-17
1606.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92035) - Medium [252]
Description: {'nvd_cve_data_all': 'Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Thunderbird 140.17, Firefox 156, Firefox ESR 153.3, Thunderbird 156, Thunderbird 153.3, Firefox ESR 115.42, and Firefox ESR 140.17.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04707 |
altlinux: CVE-2026-92035 was patched at 2026-09-16
1607.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92036) - Medium [252]
Description: {'nvd_cve_data_all': 'Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.0015, EPSS Percentile is 0.04567 |
altlinux: CVE-2026-92036 was patched at 2026-09-16
1608.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92037) - Medium [252]
Description: {'nvd_cve_data_all': 'Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.0015, EPSS Percentile is 0.04568 |
altlinux: CVE-2026-92037 was patched at 2026-09-16
1609.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92038) - Medium [252]
Description: {'nvd_cve_data_all': 'Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.055 |
altlinux: CVE-2026-92038 was patched at 2026-09-16
1610.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92041) - Medium [252]
Description: {'nvd_cve_data_all': 'Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.055 |
altlinux: CVE-2026-92041 was patched at 2026-09-16
1611.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92045) - Medium [252]
Description: {'nvd_cve_data_all': 'Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04709 |
altlinux: CVE-2026-92045 was patched at 2026-09-16
1612.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92061) - Medium [252]
Description: {'nvd_cve_data_all': 'Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.03878 |
altlinux: CVE-2026-92061 was patched at 2026-09-16
1613.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92066) - Medium [252]
Description: {'nvd_cve_data_all': 'Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.03879 |
altlinux: CVE-2026-92066 was patched at 2026-09-16
1614.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92071) - Medium [252]
Description: {'nvd_cve_data_all': 'Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04021 |
altlinux: CVE-2026-92071 was patched at 2026-09-16
1615.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92074) - Medium [252]
Description: {'nvd_cve_data_all': 'Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05499 |
altlinux: CVE-2026-92074 was patched at 2026-09-16
1616.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92075) - Medium [252]
Description: {'nvd_cve_data_all': 'Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05499 |
altlinux: CVE-2026-92075 was patched at 2026-09-16
1617.
Unknown Vulnerability Type - Netty (CVE-2026-48480) - Medium [252]
Description: {'nvd_cve_data_all': 'The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp implementation of draft-ietf-ohai-chunked-ohttp does not verify that a cryptographically-signed final chunk was received before the outer HTTP body terminates. An on-path adversary (the OHTTP relay itself, or any MITM on the relay↔gateway or relay↔client transport) can forward a prefix of a legitimate chunked-OHTTP message—cut at a non-final chunk boundary—and close the outer body cleanly, producing no decryption error and no exception in the receiving application. Version 0.0.22.Final fixes the issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp implementation of draft-ietf-ohai-chunked-ohttp does not verify that a cryptographically-signed final chunk was received before the outer HTTP body terminates. An on-path adversary (the OHTTP relay itself, or any MITM on the relay↔gateway or relay↔client transport) can forward a prefix of a legitimate chunked-OHTTP message—cut at a non-final chunk boundary—and close the outer body cleanly, producing no decryption error and no exception in the receiving application. Version 0.0.22.Final fixes the issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Netty is a non-blocking I/O client-server framework for the development of Java network applications such as protocol servers and clients | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00167, EPSS Percentile is 0.0634 |
redos: CVE-2026-48480 was patched at 2026-09-04
1618.
Unknown Vulnerability Type - jackson-databind (CVE-2026-59889) - Medium [252]
Description: {'nvd_cve_data_all': 'jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and calls prop.deserializeAndSet() without a prop.visibleInView(ctxt.getActiveView()) guard, allowing a property annotated with both @JsonView and @JsonUnwrapped to be written from attacker JSON under a less-privileged active view. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and calls prop.deserializeAndSet() without a prop.visibleInView(ctxt.getActiveView()) guard, allowing a property annotated with both @JsonView and @JsonUnwrapped to be written from attacker JSON under a less-privileged active view. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Jackson Databind is a widely used Java library for converting JSON data to and from Java objects, providing data-binding functionality within the Jackson JSON processing ecosystem. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00346, EPSS Percentile is 0.28004 |
altlinux: CVE-2026-59889 was patched at 2026-08-20, 2026-08-26, 2026-08-28
1619.
Incorrect Calculation - Linux Kernel (CVE-2026-80605) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07427 |
debian: CVE-2026-80605 was patched at 2026-09-16
oraclelinux: CVE-2026-80605 was patched at 2026-09-04
redos: CVE-2026-80605 was patched at 2026-09-16
1620.
Memory Corruption - Linux Kernel (CVE-2026-64466) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.07052 |
ubuntu: CVE-2026-64466 was patched at 2026-09-07, 2026-09-16
1621.
Memory Corruption - Linux Kernel (CVE-2026-68378) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10078 |
oraclelinux: CVE-2026-68378 was patched at 2026-09-04
1622.
Memory Corruption - Linux Kernel (CVE-2026-74352) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06451 |
oraclelinux: CVE-2026-74352 was patched at 2026-09-04
1623.
Memory Corruption - Linux Kernel (CVE-2026-74599) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06961 |
debian: CVE-2026-74599 was patched at 2026-08-25
oraclelinux: CVE-2026-74599 was patched at 2026-09-04
1624.
Memory Corruption - Linux Kernel (CVE-2026-74623) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07468 |
debian: CVE-2026-74623 was patched at 2026-08-25
oraclelinux: CVE-2026-74623 was patched at 2026-09-04
1625.
Memory Corruption - Linux Kernel (CVE-2026-74650) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07468 |
debian: CVE-2026-74650 was patched at 2026-08-25
oraclelinux: CVE-2026-74650 was patched at 2026-09-04
1626.
Memory Corruption - Linux Kernel (CVE-2026-74671) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07458 |
debian: CVE-2026-74671 was patched at 2026-08-25
oraclelinux: CVE-2026-74671 was patched at 2026-09-04
1627.
Memory Corruption - Linux Kernel (CVE-2026-74672) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06962 |
debian: CVE-2026-74672 was patched at 2026-08-25
1628.
Memory Corruption - Linux Kernel (CVE-2026-74677) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06438 |
debian: CVE-2026-74677 was patched at 2026-08-25
oraclelinux: CVE-2026-74677 was patched at 2026-09-04
1629.
Memory Corruption - Linux Kernel (CVE-2026-74679) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00185, EPSS Percentile is 0.08374 |
debian: CVE-2026-74679 was patched at 2026-08-25
oraclelinux: CVE-2026-74679 was patched at 2026-09-04
1630.
Memory Corruption - Linux Kernel (CVE-2026-74722) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06962 |
debian: CVE-2026-74722 was patched at 2026-08-25
oraclelinux: CVE-2026-74722 was patched at 2026-09-04
1631.
Memory Corruption - Linux Kernel (CVE-2026-74732) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00183, EPSS Percentile is 0.08156 |
debian: CVE-2026-74732 was patched at 2026-08-25
oraclelinux: CVE-2026-74732 was patched at 2026-09-04
1632.
Memory Corruption - Linux Kernel (CVE-2026-80563) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06409 |
debian: CVE-2026-80563 was patched at 2026-09-16
1633.
Memory Corruption - Linux Kernel (CVE-2026-80577) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05187 |
debian: CVE-2026-80577 was patched at 2026-09-16
1634.
Memory Corruption - Linux Kernel (CVE-2026-80597) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07429 |
debian: CVE-2026-80597 was patched at 2026-09-16
redos: CVE-2026-80597 was patched at 2026-09-16
1635.
Memory Corruption - Linux Kernel (CVE-2026-80620) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06935 |
debian: CVE-2026-80620 was patched at 2026-09-16
redos: CVE-2026-80620 was patched at 2026-09-16
1636.
Memory Corruption - Linux Kernel (CVE-2026-80624) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06419 |
debian: CVE-2026-80624 was patched at 2026-09-16
1637.
Memory Corruption - Linux Kernel (CVE-2026-80627) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07427 |
debian: CVE-2026-80627 was patched at 2026-09-16
redos: CVE-2026-80627 was patched at 2026-09-16
1638.
Memory Corruption - Linux Kernel (CVE-2026-80650) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06417 |
debian: CVE-2026-80650 was patched at 2026-09-16
1639.
Memory Corruption - Linux Kernel (CVE-2026-80679) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07429 |
debian: CVE-2026-80679 was patched at 2026-09-16
1640.
Memory Corruption - Linux Kernel (CVE-2026-80689) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.0743 |
debian: CVE-2026-80689 was patched at 2026-09-16
1641.
Memory Corruption - Linux Kernel (CVE-2026-80704) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05508 |
debian: CVE-2026-80704 was patched at 2026-09-16
1642.
Memory Corruption - Linux Kernel (CVE-2026-80730) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10809 |
debian: CVE-2026-80730 was patched at 2026-09-16
1643.
Memory Corruption - Linux Kernel (CVE-2026-80743) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11444 |
debian: CVE-2026-80743 was patched at 2026-09-16
1644.
Memory Corruption - Linux Kernel (CVE-2026-80762) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06963 |
debian: CVE-2026-80762 was patched at 2026-09-16
1645.
Memory Corruption - Linux Kernel (CVE-2026-80764) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06963 |
debian: CVE-2026-80764 was patched at 2026-09-16
1646.
Memory Corruption - Linux Kernel (CVE-2026-80766) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07457 |
debian: CVE-2026-80766 was patched at 2026-09-16
1647.
Memory Corruption - Linux Kernel (CVE-2026-80767) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09464 |
debian: CVE-2026-80767 was patched at 2026-09-16
1648.
Memory Corruption - Linux Kernel (CVE-2026-80770) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06959 |
debian: CVE-2026-80770 was patched at 2026-09-16
1649.
Memory Corruption - Linux Kernel (CVE-2026-80772) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06959 |
debian: CVE-2026-80772 was patched at 2026-09-16
1650.
Memory Corruption - Linux Kernel (CVE-2026-80780) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00181, EPSS Percentile is 0.07935 |
debian: CVE-2026-80780 was patched at 2026-09-16
1651.
Memory Corruption - Linux Kernel (CVE-2026-80781) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09463 |
debian: CVE-2026-80781 was patched at 2026-09-16
1652.
Memory Corruption - Linux Kernel (CVE-2026-80783) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09445 |
debian: CVE-2026-80783 was patched at 2026-09-16
1653.
Memory Corruption - Linux Kernel (CVE-2026-80784) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06965 |
debian: CVE-2026-80784 was patched at 2026-09-16
1654.
Memory Corruption - Linux Kernel (CVE-2026-80792) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09463 |
debian: CVE-2026-80792 was patched at 2026-09-16
1655.
Memory Corruption - Linux Kernel (CVE-2026-80795) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09464 |
debian: CVE-2026-80795 was patched at 2026-09-16
1656.
Memory Corruption - Linux Kernel (CVE-2026-80796) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09458 |
debian: CVE-2026-80796 was patched at 2026-09-16
1657.
Memory Corruption - Linux Kernel (CVE-2026-80798) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00234, EPSS Percentile is 0.14471 |
debian: CVE-2026-80798 was patched at 2026-09-16
1658.
Memory Corruption - Linux Kernel (CVE-2026-80802) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09457 |
debian: CVE-2026-80802 was patched at 2026-09-16
1659.
Memory Corruption - Linux Kernel (CVE-2026-80824) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09461 |
debian: CVE-2026-80824 was patched at 2026-09-16
1660.
Memory Corruption - Linux Kernel (CVE-2026-80826) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.0946 |
debian: CVE-2026-80826 was patched at 2026-09-16
1661.
Memory Corruption - Linux Kernel (CVE-2026-80827) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09461 |
debian: CVE-2026-80827 was patched at 2026-09-16
1662.
Memory Corruption - Linux Kernel (CVE-2026-80830) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09461 |
debian: CVE-2026-80830 was patched at 2026-09-16
1663.
Memory Corruption - Linux Kernel (CVE-2026-80833) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06448 |
debian: CVE-2026-80833 was patched at 2026-09-16
1664.
Memory Corruption - Linux Kernel (CVE-2026-80834) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06448 |
debian: CVE-2026-80834 was patched at 2026-09-16
1665.
Memory Corruption - Linux Kernel (CVE-2026-80836) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06448 |
debian: CVE-2026-80836 was patched at 2026-09-16
1666.
Memory Corruption - Linux Kernel (CVE-2026-80837) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06449 |
debian: CVE-2026-80837 was patched at 2026-09-16
1667.
Memory Corruption - Linux Kernel (CVE-2026-80841) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06447 |
debian: CVE-2026-80841 was patched at 2026-09-16
1668.
Memory Corruption - Linux Kernel (CVE-2026-80842) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07458 |
debian: CVE-2026-80842 was patched at 2026-09-16
1669.
Memory Corruption - Linux Kernel (CVE-2026-80848) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09459 |
debian: CVE-2026-80848 was patched at 2026-09-16
1670.
Memory Corruption - Linux Kernel (CVE-2026-80849) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06446 |
debian: CVE-2026-80849 was patched at 2026-09-16
1671.
Memory Corruption - Linux Kernel (CVE-2026-80850) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00171, EPSS Percentile is 0.06831 |
debian: CVE-2026-80850 was patched at 2026-09-16
1672.
Memory Corruption - Linux Kernel (CVE-2026-80852) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00161, EPSS Percentile is 0.05672 |
debian: CVE-2026-80852 was patched at 2026-09-16
1673.
Memory Corruption - Linux Kernel (CVE-2026-80863) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00182, EPSS Percentile is 0.08003 |
debian: CVE-2026-80863 was patched at 2026-09-16
1674.
Memory Corruption - Linux Kernel (CVE-2026-80886) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07839 |
debian: CVE-2026-80886 was patched at 2026-09-16
redos: CVE-2026-80886 was patched at 2026-09-16
1675.
Memory Corruption - Linux Kernel (CVE-2026-80917) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.06037 |
debian: CVE-2026-80917 was patched at 2026-09-16
1676.
Memory Corruption - Linux Kernel (CVE-2026-80923) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06065 |
debian: CVE-2026-80923 was patched at 2026-09-16
1677.
Memory Corruption - Linux Kernel (CVE-2026-80941) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11449 |
debian: CVE-2026-80941 was patched at 2026-09-16
1678.
Memory Corruption - Linux Kernel (CVE-2026-80942) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06405 |
debian: CVE-2026-80942 was patched at 2026-09-16
1679.
Memory Corruption - Linux Kernel (CVE-2026-80948) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11374 |
debian: CVE-2026-80948 was patched at 2026-09-16
1680.
Memory Corruption - Linux Kernel (CVE-2026-80949) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07433 |
debian: CVE-2026-80949 was patched at 2026-09-16
1681.
Memory Corruption - Linux Kernel (CVE-2026-80951) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10807 |
debian: CVE-2026-80951 was patched at 2026-09-16
1682.
Memory Corruption - Linux Kernel (CVE-2026-80963) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07433 |
debian: CVE-2026-80963 was patched at 2026-09-16
1683.
Memory Corruption - Linux Kernel (CVE-2026-81005) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07432 |
debian: CVE-2026-81005 was patched at 2026-09-16
1684.
Memory Corruption - Linux Kernel (CVE-2026-89437) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06221 |
debian: CVE-2026-89437 was patched at 2026-09-16
1685.
Memory Corruption - Linux Kernel (CVE-2026-89455) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10046 |
debian: CVE-2026-89455 was patched at 2026-09-16
1686.
Memory Corruption - Linux Kernel (CVE-2026-89457) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07428 |
debian: CVE-2026-89457 was patched at 2026-09-16
1687.
Memory Corruption - Linux Kernel (CVE-2026-89460) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.0641 |
debian: CVE-2026-89460 was patched at 2026-09-16
1688.
Memory Corruption - Linux Kernel (CVE-2026-89463) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.1081 |
debian: CVE-2026-89463 was patched at 2026-09-16
1689.
Memory Corruption - Linux Kernel (CVE-2026-89467) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06222 |
debian: CVE-2026-89467 was patched at 2026-09-16
1690.
Memory Corruption - Linux Kernel (CVE-2026-89468) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06418 |
debian: CVE-2026-89468 was patched at 2026-09-16
1691.
Memory Corruption - Linux Kernel (CVE-2026-89475) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10807 |
debian: CVE-2026-89475 was patched at 2026-09-16
1692.
Memory Corruption - Linux Kernel (CVE-2026-89496) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.0743 |
debian: CVE-2026-89496 was patched at 2026-09-16
1693.
Memory Corruption - Linux Kernel (CVE-2026-89543) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00198, EPSS Percentile is 0.09784 |
debian: CVE-2026-89543 was patched at 2026-09-16
1694.
Memory Corruption - Linux Kernel (CVE-2026-89552) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06414 |
debian: CVE-2026-89552 was patched at 2026-09-16
1695.
Memory Corruption - Linux Kernel (CVE-2026-89575) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00227, EPSS Percentile is 0.13627 |
debian: CVE-2026-89575 was patched at 2026-09-16
1696.
Memory Corruption - Linux Kernel (CVE-2026-89625) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00206, EPSS Percentile is 0.1096 |
debian: CVE-2026-89625 was patched at 2026-09-16
1697.
Memory Corruption - Linux Kernel (CVE-2026-89722) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00198, EPSS Percentile is 0.09787 |
debian: CVE-2026-89722 was patched at 2026-09-16
1698.
Memory Corruption - Linux Kernel (CVE-2026-89726) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07499 |
debian: CVE-2026-89726 was patched at 2026-09-16
1699.
Memory Corruption - Linux Kernel (CVE-2026-89730) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11444 |
debian: CVE-2026-89730 was patched at 2026-09-16
1700.
Memory Corruption - Linux Kernel (CVE-2026-89785) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10808 |
debian: CVE-2026-89785 was patched at 2026-09-16
1701.
Memory Corruption - Linux Kernel (CVE-2026-89787) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10809 |
debian: CVE-2026-89787 was patched at 2026-09-16
1702.
Path Traversal - Spring Framework (CVE-2026-59280) - Medium [251]
Description: Applications using
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.4 | 14 | The Spring Framework is an application framework and inversion of control container for the Java platform | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00237, EPSS Percentile is 0.14854 |
debian: CVE-2026-59280 was patched at 2026-09-16
1703.
Remote Code Execution - Unknown Product (CVE-2026-89329) - Medium [250]
Description: {'nvd_cve_data_all': 'A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.01902 |
debian: CVE-2026-89329 was patched at 2026-09-16
1704.
Server-Side Request Forgery - Unknown Product (CVE-2026-34964) - Medium [250]
Description: {'nvd_cve_data_all': 'Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, which only inspects leading integers for privileged ports and fails to reject non-numeric port values. Attackers can inject PDO DSN keys like host= and port= into the server parameter to bypass the privileged-port restriction and establish TCP connections to arbitrary internal hosts and ports before authentication.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, which only inspects leading integers for privileged ports and fails to reject non-numeric port values. Attackers can inject PDO DSN keys like host= and port= into the server parameter to bypass the privileged-port restriction and establish TCP connections to arbitrary internal hosts and ports before authentication.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00307, EPSS Percentile is 0.23515 |
debian: CVE-2026-34964 was patched at 2026-09-16
1705.
Memory Corruption - MongoDB (CVE-2026-84969) - Medium [248]
Description: A memory-handling error in the BSON-to-JSON conversion helpers of the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06188 |
debian: CVE-2026-84969 was patched at 2026-09-16
1706.
Memory Corruption - gdk-pixbuf (CVE-2026-81893) - Medium [248]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | gdk-pixbuf is an open source image loading and manipulation library used primarily in GNOME-based applications for handling various image formats, including JPEG, PNG, and GIF. | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.01575 |
debian: CVE-2026-81893 was patched at 2026-09-16
1707.
Memory Corruption - libheif (CVE-2026-62291) - Medium [248]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | libheif is an open source HEIF and AVIF image file format decoder and encoder library, supporting modern image codecs and container features. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0013, EPSS Percentile is 0.03026 |
ubuntu: CVE-2026-62291 was patched at 2026-08-26, 2026-09-16
1708.
Elevation of Privilege - Unknown Product (CVE-2026-19624) - Medium [247]
Description: {'nvd_cve_data_all': 'A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected leftupdown directive; pluto executes that command as root when the IKE security association is established, resulting in local privilege escalation. This is the same bug class as CVE-2018-10900 (NetworkManager-vpnc).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected leftupdown directive; pluto executes that command as root when the IKE security association is established, resulting in local privilege escalation. This is the same bug class as CVE-2018-10900 (NetworkManager-vpnc).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0013, EPSS Percentile is 0.02985 |
debian: CVE-2026-19624 was patched at 2026-09-14, 2026-09-16
1709.
Unknown Vulnerability Type - Apache Tomcat (CVE-2026-73180) - Medium [247]
Description: {'nvd_cve_data_all': 'Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.\n\n\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109.\xa0Other unsupported versions may also be affected.\n\n\n\nUsers are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00536, EPSS Percentile is 0.43867 |
altlinux: CVE-2026-73180 was patched at 2026-08-26, 2026-08-27, 2026-09-11, 2026-09-16
debian: CVE-2026-73180 was patched at 2026-09-16
1710.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64485) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: compress: Fix task creation error unwind snd_compr_task_new() allocates the driver task before validating the returned DMA buffers and reserving file descriptors. When either of those later steps fails, the core frees its task wrapper and DMA-buffer references without calling the driver's task_free() callback. Any driver resources allocated by task_create() are therefore leaked. The dual-fd allocation path also jumps to cleanup without storing the negative get_unused_fd_flags() result in retval. Since retval still contains the successful task_create() return value, TASK_CREATE can incorrectly report success although the task was discarded. Preserve the fd allocation errors and call task_free() when failure occurs after a successful task_create() callback.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: compress: Fix task creation error unwind\n\nsnd_compr_task_new() allocates the driver task before validating the\nreturned DMA buffers and reserving file descriptors. When either of\nthose later steps fails, the core frees its task wrapper and DMA-buffer\nreferences without calling the driver's task_free() callback. Any\ndriver resources allocated by task_create() are therefore leaked.\n\nThe dual-fd allocation path also jumps to cleanup without storing the\nnegative get_unused_fd_flags() result in retval. Since retval still\ncontains the successful task_create() return value, TASK_CREATE can\nincorrectly report success although the task was discarded.\n\nPreserve the fd allocation errors and call task_free() when failure\noccurs after a successful task_create() callback.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00137, EPSS Percentile is 0.03474 |
ubuntu: CVE-2026-64485 was patched at 2026-09-07, 2026-09-16
1711.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64575) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: fix double sock release on batch realloc bpf_iter_tcp_batch() releases the current batch via bpf_iter_tcp_put_batch(), which drops the socket refs and rewrites each slot with the socket cookie, then grows the batch. cur_sk/end_sk are kept for bpf_iter_tcp_resume(), but on realloc failure the function returns ERR_PTR() before resume runs, leaving cur_sk < end_sk over slots that now hold cookies rather than sock pointers. bpf_iter_tcp_seq_stop() then calls bpf_iter_tcp_put_batch() again and dereferences a cookie as a struct sock. Empty the batch on the failure path so stop() does not release it again. The sockets were already freed by the first bpf_iter_tcp_put_batch(), so nothing leaks, and a later read() rescans the bucket from the start instead of skipping it. The sibling GFP_NOWAIT failure path still holds real socket references and is left for stop() to release. BUG: KASAN: null-ptr-deref in __sock_gen_cookie Read of size 8 at addr 0000000000000059 by task exploit ... __sock_gen_cookie (net/core/sock_diag.c:28) bpf_iter_tcp_put_batch (net/ipv4/tcp_ipv4.c:2918) bpf_iter_tcp_seq_stop (net/ipv4/tcp_ipv4.c:3270) bpf_seq_read (kernel/bpf/bpf_iter.c:205) vfs_read (fs/read_write.c:572) ksys_read (fs/read_write.c:716) do_syscall_64 entry_SYSCALL_64_after_hwframe Kernel panic - not syncing: Fatal exception', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: tcp: fix double sock release on batch realloc\n\nbpf_iter_tcp_batch() releases the current batch via\nbpf_iter_tcp_put_batch(), which drops the socket refs and rewrites\neach slot with the socket cookie, then grows the batch. cur_sk/end_sk\nare kept for bpf_iter_tcp_resume(), but on realloc failure the function\nreturns ERR_PTR() before resume runs, leaving cur_sk < end_sk over\nslots that now hold cookies rather than sock pointers.\nbpf_iter_tcp_seq_stop() then calls bpf_iter_tcp_put_batch() again and\ndereferences a cookie as a struct sock.\n\nEmpty the batch on the failure path so stop() does not release it\nagain. The sockets were already freed by the first\nbpf_iter_tcp_put_batch(), so nothing leaks, and a later read() rescans\nthe bucket from the start instead of skipping it. The sibling\nGFP_NOWAIT failure path still holds real socket references and is left\nfor stop() to release.\n\n BUG: KASAN: null-ptr-deref in __sock_gen_cookie\n Read of size 8 at addr 0000000000000059 by task exploit\n ...\n __sock_gen_cookie (net/core/sock_diag.c:28)\n bpf_iter_tcp_put_batch (net/ipv4/tcp_ipv4.c:2918)\n bpf_iter_tcp_seq_stop (net/ipv4/tcp_ipv4.c:3270)\n bpf_seq_read (kernel/bpf/bpf_iter.c:205)\n vfs_read (fs/read_write.c:572)\n ksys_read (fs/read_write.c:716)\n do_syscall_64\n entry_SYSCALL_64_after_hwframe\n Kernel panic - not syncing: Fatal exception', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02188 |
oraclelinux: CVE-2026-64575 was patched at 2026-09-04
1712.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64588) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix data races on ring->ready On weakly-ordered architectures, the store to fiq->ops can be reordered past the store to ring->ready, allowing a CPU that sees ring->ready == true via fuse_uring_ready() to dispatch requests through a stale fiq->ops pointer. Upgrade the store to smp_store_release() and the load in fuse_uring_ready() to smp_load_acquire() so that the preceding WRITE_ONCE(fiq->ops, ...) is visible to any CPU that observes ring->ready == true. Additionally, fuse_uring_do_register() publishes ring->ready with WRITE_ONCE() but the fast-path check reads it with a plain load. This is a marked-vs-unmarked access that KCSAN will flag. Wrap it in READ_ONCE() to mark it without adding unnecessary ordering. Also wrap the fc->ring load in fuse_uring_ready() in READ_ONCE() to prevent the compiler from reloading it between the NULL check and the dereference.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfuse-uring: fix data races on ring->ready\n\nOn weakly-ordered architectures, the store to fiq->ops can be\nreordered past the store to ring->ready, allowing a CPU that sees\nring->ready == true via fuse_uring_ready() to dispatch requests\nthrough a stale fiq->ops pointer. Upgrade the store to\nsmp_store_release() and the load in fuse_uring_ready() to\nsmp_load_acquire() so that the preceding WRITE_ONCE(fiq->ops, ...)\nis visible to any CPU that observes ring->ready == true.\n\nAdditionally, fuse_uring_do_register() publishes ring->ready with\nWRITE_ONCE() but the fast-path check reads it with a plain load.\nThis is a marked-vs-unmarked access that KCSAN will flag. Wrap it in\nREAD_ONCE() to mark it without adding unnecessary ordering.\n\nAlso wrap the fc->ring load in fuse_uring_ready() in READ_ONCE() to\nprevent the compiler from reloading it between the NULL check and the\ndereference.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00119, EPSS Percentile is 0.01981 |
ubuntu: CVE-2026-64588 was patched at 2026-09-07, 2026-09-16
1713.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74590) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions The BPF verifier and the dynptr abstraction ensure that the memory space referenced by a dynptr remains valid. They do not, however, provide any guarantee that the contents of the memory are stable. kfuncs are expected to remain memory-safe even if concurrent modifications occur. bpf_get_fsverity_digest() didn't follow that: it could crash if arg->digest_size was concurrently modified. Fix that by using the known-good value hash_alg->digest_size instead. Also widen 'dynptr_sz' and 'out_digest_sz' to u64 to match the return type of __bpf_dynptr_size(). It doesn't appear that it can actually be more than INT_MAX currently (since __bpf_dynptr_data_rw() excludes file-based pointers), but the correct type might as well be used.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfsverity: Fix bpf_get_fsverity_digest() dynptr assumptions\n\nThe BPF verifier and the dynptr abstraction ensure that the memory space\nreferenced by a dynptr remains valid. They do not, however, provide any\nguarantee that the contents of the memory are stable. kfuncs are\nexpected to remain memory-safe even if concurrent modifications occur.\n\nbpf_get_fsverity_digest() didn't follow that: it could crash if\narg->digest_size was concurrently modified.\n\nFix that by using the known-good value hash_alg->digest_size instead.\n\nAlso widen 'dynptr_sz' and 'out_digest_sz' to u64 to match the return\ntype of __bpf_dynptr_size(). It doesn't appear that it can actually be\nmore than INT_MAX currently (since __bpf_dynptr_data_rw() excludes\nfile-based pointers), but the correct type might as well be used.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.0286 |
debian: CVE-2026-74590 was patched at 2026-08-25
oraclelinux: CVE-2026-74590 was patched at 2026-09-04
1714.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74594) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: sched/psi: Shut down rtpoll_timer in psi_cgroup_free() psi_schedule_rtpoll_work() is called locklessly from the scheduler hotpath and can race psi_trigger_destroy() taking down the last rtpoll trigger under rtpoll_trigger_lock: psi_schedule_rtpoll_work() psi_trigger_destroy() rcu_read_lock(); task = rcu_dereference(rtpoll_task); rcu_assign_pointer(rtpoll_task, NULL); timer_delete(&rtpoll_timer); mod_timer(&rtpoll_timer, ...); rcu_read_unlock(); synchronize_rcu(); kthread_stop(task_to_destroy); The group can then be freed with the re-armed timer still pending, and poll_timer_fn() runs on freed memory. 461daba06bdc ("psi: eliminate kthread_worker from psi trigger scheduling mechanism") deleted the timer synchronously after the synchronize_rcu(), which prevented this but raced trigger creation instead: the deletion could cancel the timer that a new trigger set armed during the grace period and, as creation also reinitialized the timer at the time, corrupt it. 8f91efd870ea ("psi: Fix race between psi_trigger_create/destroy") moved the initialization into group_init() and the deletion into the locked section, trading the creation races for the window above. Neither placement in the destruction path works. A pending timer firing while the group is alive is harmless though. poll_timer_fn() just wakes the rtpoll waitqueue and doesn't re-arm itself. Bind the timer to the group's lifetime instead and shut it down in psi_cgroup_free(). Nothing can arm it by then. timer_shutdown_sync() because the timer is never armed again.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsched/psi: Shut down rtpoll_timer in psi_cgroup_free()\n\npsi_schedule_rtpoll_work() is called locklessly from the scheduler hotpath\nand can race psi_trigger_destroy() taking down the last rtpoll trigger under\nrtpoll_trigger_lock:\n\n psi_schedule_rtpoll_work() psi_trigger_destroy()\n\n rcu_read_lock();\n task = rcu_dereference(rtpoll_task);\n rcu_assign_pointer(rtpoll_task, NULL);\n timer_delete(&rtpoll_timer);\n mod_timer(&rtpoll_timer, ...);\n rcu_read_unlock();\n synchronize_rcu();\n kthread_stop(task_to_destroy);\n\nThe group can then be freed with the re-armed timer still pending, and\npoll_timer_fn() runs on freed memory.\n\n461daba06bdc ("psi: eliminate kthread_worker from psi trigger scheduling\nmechanism") deleted the timer synchronously after the synchronize_rcu(),\nwhich prevented this but raced trigger creation instead: the deletion could\ncancel the timer that a new trigger set armed during the grace period and,\nas creation also reinitialized the timer at the time, corrupt it.\n8f91efd870ea ("psi: Fix race between psi_trigger_create/destroy") moved the\ninitialization into group_init() and the deletion into the locked section,\ntrading the creation races for the window above.\n\nNeither placement in the destruction path works. A pending timer firing\nwhile the group is alive is harmless though. poll_timer_fn() just wakes the\nrtpoll waitqueue and doesn't re-arm itself. Bind the timer to the group's\nlifetime instead and shut it down in psi_cgroup_free(). Nothing can arm it\nby then. timer_shutdown_sync() because the timer is never armed again.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02937 |
debian: CVE-2026-74594 was patched at 2026-08-25
oraclelinux: CVE-2026-74594 was patched at 2026-09-04
1715.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74595) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() fscrypt_ioctl_set_policy() calls inode_owner_or_capable() with &nop_mnt_idmap before allowing an encryption policy to be set, instead of the idmap of the mount the ioctl was issued on. fscrypt is used by filesystems that support idmapped mounts (e.g. ext4, f2fs), so on such a mount this compares the caller's fsuid against the unmapped on-disk owner rather than the mapped owner: the actual owner can be wrongly denied with -EACCES and an unrelated caller wrongly allowed. Use file_mnt_idmap(filp) instead.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy()\n\nfscrypt_ioctl_set_policy() calls inode_owner_or_capable() with\n&nop_mnt_idmap before allowing an encryption policy to be set, instead\nof the idmap of the mount the ioctl was issued on.\n\nfscrypt is used by filesystems that support idmapped mounts (e.g. ext4,\nf2fs), so on such a mount this compares the caller's fsuid against the\nunmapped on-disk owner rather than the mapped owner: the actual owner\ncan be wrongly denied with -EACCES and an unrelated caller wrongly\nallowed. Use file_mnt_idmap(filp) instead.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00092, EPSS Percentile is 0.00605 |
debian: CVE-2026-74595 was patched at 2026-08-25
oraclelinux: CVE-2026-74595 was patched at 2026-09-04
1716.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74601) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Use current_context for safe per-CPU buffer swap The ring_buffer_swap_cpu() function currently checks the per-CPU committing counter to determine if a buffer is actively being written to before performing the swap. However, there exists a race window where this check can be bypassed: ring_buffer_lock_reserve cpu_buffer = buffer->buffers[cpu]; // cpu_buffer_a rb_reserve_next_event rb_start_commit // inc committing if (unlikely(READ_ONCE(cpu_buffer->buffer) != buffer)) {...} __rb_reserve_next rb_move_tail rb_end_commit(cpu_buffer); // dec committing => 0 /* interrupt hits here, successfully swaps! */ local_inc(&cpu_buffer->committing); ring_buffer_unlock_commit cpu_buffer = buffer->buffers[cpu]; // cpu_buffer_b rb_commit rb_end_commit RB_WARN_ON(cpu_buffer, !local_read(&cpu_buffer->committing)) // triggers warning The committing counter can temporarily drop to 0 during a single write operation (within rb_move_tail), creating a window where swap can succeed even though the write is still in progress. This leads to inconsistent buffer state and triggers the RB_WARN_ON in rb_commit(). Replace the committing counter check with current_context checks, which are set at the entry of ring_buffer_lock_reserve() and remain valid throughout the entire write operation, providing a reliable indicator of buffer busy state during swap.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Use current_context for safe per-CPU buffer swap\n\nThe ring_buffer_swap_cpu() function currently checks the per-CPU\ncommitting counter to determine if a buffer is actively being written to\nbefore performing the swap. However, there exists a race window where\nthis check can be bypassed:\n\n ring_buffer_lock_reserve\n cpu_buffer = buffer->buffers[cpu]; // cpu_buffer_a\n rb_reserve_next_event\n rb_start_commit // inc committing\n if (unlikely(READ_ONCE(cpu_buffer->buffer) != buffer)) {...}\n __rb_reserve_next\n rb_move_tail\n rb_end_commit(cpu_buffer); // dec committing => 0\n /* interrupt hits here, successfully swaps! */\n local_inc(&cpu_buffer->committing);\n\n ring_buffer_unlock_commit\n cpu_buffer = buffer->buffers[cpu]; // cpu_buffer_b\n rb_commit\n rb_end_commit\n RB_WARN_ON(cpu_buffer, !local_read(&cpu_buffer->committing))\n // triggers warning\n\nThe committing counter can temporarily drop to 0 during a single write\noperation (within rb_move_tail), creating a window where swap can\nsucceed even though the write is still in progress. This leads to\ninconsistent buffer state and triggers the RB_WARN_ON in rb_commit().\n\nReplace the committing counter check with current_context checks, which\nare set at the entry of ring_buffer_lock_reserve() and remain valid\nthroughout the entire write operation, providing a reliable indicator of\nbuffer busy state during swap.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00136, EPSS Percentile is 0.03377 |
debian: CVE-2026-74601 was patched at 2026-08-25
oraclelinux: CVE-2026-74601 was patched at 2026-09-04
1717.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74605) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: eventfs: Use children field for rcu head and add memory barriers When an eventfs inode is freed, it sets ei->is_freed and then uses its ei->list to add it to the srcu link list as the list field is a union with the rcu list head. As the ei->list is used to iterate over an SRCU protected list without taking the eventfs_mutex, there's nothing stopping the iteration over that list to see the ei->rcu instead of the ei->list and it will read a corrupt target. To fix this, change the union of the rcu list head with the children list. On freeing the eventfs inode, set the is_free and execute a smp_wmb() before adding the eventfs inode to the SRCU list. On iteration of the ei->children list, at the start, execute a smp_rmb() and then read the is_freed of the ei to see if the children list is still valid. If is_freed is set, then the ei_child read is not valid and the loop should exit immediately.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\neventfs: Use children field for rcu head and add memory barriers\n\nWhen an eventfs inode is freed, it sets ei->is_freed and then uses its\nei->list to add it to the srcu link list as the list field is a union with\nthe rcu list head. As the ei->list is used to iterate over an SRCU\nprotected list without taking the eventfs_mutex, there's nothing stopping\nthe iteration over that list to see the ei->rcu instead of the ei->list\nand it will read a corrupt target.\n\nTo fix this, change the union of the rcu list head with the children list.\nOn freeing the eventfs inode, set the is_free and execute a smp_wmb()\nbefore adding the eventfs inode to the SRCU list.\n\nOn iteration of the ei->children list, at the start, execute a smp_rmb()\nand then read the is_freed of the ei to see if the children list is still\nvalid. If is_freed is set, then the ei_child read is not valid and the\nloop should exit immediately.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02133 |
debian: CVE-2026-74605 was patched at 2026-08-25
1718.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74614) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: read virtqueues under worker locks Commit bd50c5dc182b ("vsock/virtio: add support for device suspend/resume") made the *_run flags transition from false to true when restore installs replacement virtqueues. The RX, TX and event workers read their virtqueue before locking and checking the corresponding flag, so a worker delayed across freeze and restore can observe the replacement queue's running state while retaining a pointer to the deleted queue. Read each virtqueue under its mutex after checking the run flag, keeping the pointer and state in the same queue generation.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: read virtqueues under worker locks\n\nCommit bd50c5dc182b ("vsock/virtio: add support for device\nsuspend/resume") made the *_run flags transition from false to true when\nrestore installs replacement virtqueues. The RX, TX and event workers\nread their virtqueue before locking and checking the corresponding flag,\nso a worker delayed across freeze and restore can observe the replacement\nqueue's running state while retaining a pointer to the deleted queue.\n\nRead each virtqueue under its mutex after checking the run flag, keeping\nthe pointer and state in the same queue generation.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.03851 |
debian: CVE-2026-74614 was patched at 2026-08-25
oraclelinux: CVE-2026-74614 was patched at 2026-09-04
1719.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74632) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix huge_zero_pfn race Patch series "mm/huge_memory: fix huge_zero_pfn race", v2. There is a subtle race in the reference-counted huge_zero_folio implementation. The fast path atomic logic fails to account for the fact that the shrinker (which drops the final huge_zero_refcount pin) can overwrite huge_zero_pfn with the ~0UL sentinel value in shrink_huge_zero_folio_scan() after a racing get_huge_zero_folio() installed a valid value there. This results in huge_zero_folio being correctly set but huge_zero_pfn being set incorrectly and thus is_huge_zero_pfn() and consequently is_huge_zero_pmd() will misidentify the huge zero folio as being an ordinary THP folio. This can result in the huge zero folio being split and otherwise treated incorrectly. The solution to this is very subtle as there is an atomic fast path, and thus ordering in weakly ordered architectures has to be treated very carefully. The first commit fixes the issue by introducing a spinlock around huge_zero_[pfn, folio, refcount] write, with careful consideration paid to load/store ordering in the fast path. It is placed first and kept as small as possible so that it can be backported on its own. The second commit is a pure cleanup which reworks the CONFIG_PERSISTENT_HUGE_ZERO_FOLIO logic to better separate the persistent logic from the dynamically allocated one. This patch (of 2): If !CONFIG_PERSISTENT_HUGE_ZERO_FOLIO, the huge_zero_folio is refcounted by huge_zero_refcount and returned by mm_get_huge_zero_folio(). When the caller is done with the huge zero page, its reference count is decremented. Only a shrinker can set the reference count to zero. A race can unfortunately occur between a shrinker decrementing the reference count to zero and a concurrent page fault. This is because shrink_huge_zero_folio_scan() might, if very unlucky, be preempted between setting huge_zero_refcount to zero and writing an invalid value. During this time get_huge_zero_folio() could write to huge_zero_pfn before shrink_huge_zero_folio_scan() resumes. In this event the huge zero folio will be persistently misidentified causing the THP code path to be entered inappropriately for the huge zero folio: CPU 0 CPU 1 =======================================|================================= shrink_huge_zero_folio_scan() | atomic_cmpxchg() sets refcount to 0 | xchg() sets huge_zero_folio to NULL | get_huge_zero_folio() | | atomic_inc_not_zero() -> zero preempted for a long time | Allocate new huge zero folio | | Write valid huge_zero_folio v | Write valid huge_zero_pfn Overwrite huge_zero_pfn with ~0UL <--- Invalid overwrite! This results in is_huge_zero_pfn() and is_huge_zero_pmd() incorrectly returning false for a huge zero page which could result in issues like the huge zero folio being incorrectly split. Note that the issue is with huge_zero_pfn not huge_zero_folio, as get_huge_zero_folio() uses cmpxchg() gated on huge_zero_folio being NULL with a retry loop and shrink_huge_zero_folio_scan() uses xchg() to set huge_zero_folio. Fix the issue by introducing a spinlock, huge_zero_lock, to prevent concurrent write of huge_zero_folio, huge_zero_pfn and huge_zero_refcount. There needs to be significant care taken here to ensure correctness: The fast path in get_huge_zero_folio() uses atomic_inc_not_zero(), which is outside of the critical section, and means huge zero allocation is gated on zero huge_zero_refcount. The fast path doesn't use huge_zero_lock, so the critical section is irrelevant to it. So invariants are required - huge_zero_refcount MUST: * Only be set in the huge_zero_lock critical section to ensure serialisation of huge_zero_pfn, huge_zero_folio and ---truncated---', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/huge_memory: fix huge_zero_pfn race\n\nPatch series "mm/huge_memory: fix huge_zero_pfn race", v2.\n\nThere is a subtle race in the reference-counted huge_zero_folio\nimplementation.\n\nThe fast path atomic logic fails to account for the fact that the shrinker\n(which drops the final huge_zero_refcount pin) can overwrite huge_zero_pfn\nwith the ~0UL sentinel value in shrink_huge_zero_folio_scan() after a\nracing get_huge_zero_folio() installed a valid value there.\n\nThis results in huge_zero_folio being correctly set but huge_zero_pfn\nbeing set incorrectly and thus is_huge_zero_pfn() and consequently\nis_huge_zero_pmd() will misidentify the huge zero folio as being an\nordinary THP folio.\n\nThis can result in the huge zero folio being split and otherwise treated\nincorrectly.\n\nThe solution to this is very subtle as there is an atomic fast path, and\nthus ordering in weakly ordered architectures has to be treated very\ncarefully.\n\nThe first commit fixes the issue by introducing a spinlock around\nhuge_zero_[pfn, folio, refcount] write, with careful consideration paid to\nload/store ordering in the fast path. It is placed first and kept as\nsmall as possible so that it can be backported on its own.\n\nThe second commit is a pure cleanup which reworks the\nCONFIG_PERSISTENT_HUGE_ZERO_FOLIO logic to better separate the persistent\nlogic from the dynamically allocated one.\n\n\nThis patch (of 2):\n\nIf !CONFIG_PERSISTENT_HUGE_ZERO_FOLIO, the huge_zero_folio is refcounted\nby huge_zero_refcount and returned by mm_get_huge_zero_folio().\n\nWhen the caller is done with the huge zero page, its reference count is\ndecremented. Only a shrinker can set the reference count to zero.\n\nA race can unfortunately occur between a shrinker decrementing the\nreference count to zero and a concurrent page fault.\n\nThis is because shrink_huge_zero_folio_scan() might, if very unlucky, be\npreempted between setting huge_zero_refcount to zero and writing an\ninvalid value.\n\nDuring this time get_huge_zero_folio() could write to huge_zero_pfn before\nshrink_huge_zero_folio_scan() resumes.\n\nIn this event the huge zero folio will be persistently misidentified\ncausing the THP code path to be entered inappropriately for the huge zero\nfolio:\n\n CPU 0 CPU 1\n=======================================|=================================\nshrink_huge_zero_folio_scan() |\n atomic_cmpxchg() sets refcount to 0 |\n xchg() sets huge_zero_folio to NULL | get_huge_zero_folio()\n | | atomic_inc_not_zero() -> zero\n preempted for a long time | Allocate new huge zero folio\n | | Write valid huge_zero_folio\n v | Write valid huge_zero_pfn\n Overwrite huge_zero_pfn with ~0UL <--- Invalid overwrite!\n\nThis results in is_huge_zero_pfn() and is_huge_zero_pmd() incorrectly\nreturning false for a huge zero page which could result in issues like the\nhuge zero folio being incorrectly split.\n\nNote that the issue is with huge_zero_pfn not huge_zero_folio, as\nget_huge_zero_folio() uses cmpxchg() gated on huge_zero_folio being NULL\nwith a retry loop and shrink_huge_zero_folio_scan() uses xchg() to set\nhuge_zero_folio.\n\nFix the issue by introducing a spinlock, huge_zero_lock, to prevent\nconcurrent write of huge_zero_folio, huge_zero_pfn and huge_zero_refcount.\n\nThere needs to be significant care taken here to ensure correctness:\n\nThe fast path in get_huge_zero_folio() uses atomic_inc_not_zero(), which\nis outside of the critical section, and means huge zero allocation is\ngated on zero huge_zero_refcount.\n\nThe fast path doesn't use huge_zero_lock, so the critical section is\nirrelevant to it.\n\nSo invariants are required - huge_zero_refcount MUST:\n\n* Only be set in the huge_zero_lock critical section to ensure\n serialisation of huge_zero_pfn, huge_zero_folio and\n---truncated---', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02946 |
debian: CVE-2026-74632 was patched at 2026-08-25
oraclelinux: CVE-2026-74632 was patched at 2026-09-04
1720.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74641) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: usx2y: bound the hwdep mmap fault offset snd_us428ctls_vm_fault() turns the faulting page offset into a kernel address with no bound of any kind: \toffset = vmf->pgoff << PAGE_SHIFT; \tvaddr = (char *)(...)->us428ctls_sharedmem + offset; \tpage = virt_to_page(vaddr); \tget_page(page); \tvmf->page = page; \treturn 0; snd_us428ctls_mmap() checks only the length of the mapping, never the offset, and us428ctls_sharedmem is a single page from alloc_pages_exact(). For a character device file_mmap_size_max() returns ULONG_MAX, so the mm layer imposes no ceiling either. Every page offset above zero resolves to a struct page outside the object, and the handler installs it into the caller's address space read-write; the vma is not marked read-only. The caller picks the page frame with a single mmap() argument and gets read-write access to a page of kernel memory it does not own; an offset that lands in an unpopulated vmemmap region oopses instead. A process that can open the hwdep node of an attached US-X2Y reaches this after loading the FPGA image through the same node; no capability check is involved. On 7.2.0-rc5 (arm64), mmap() with a large offset: Unable to handle kernel paging request at virtual address fffffdffc45d5ac8 pc : snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y] Call trace: snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y] __do_fault __handle_mm_fault handle_mm_fault el0_da Reject any offset outside the shared region. The pcm hwdep handler in usx2yhwdeppcm.c computes its address the same way and needs the same bound. Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usx2y: bound the hwdep mmap fault offset\n\nsnd_us428ctls_vm_fault() turns the faulting page offset into a kernel\naddress with no bound of any kind:\n\n\toffset = vmf->pgoff << PAGE_SHIFT;\n\tvaddr = (char *)(...)->us428ctls_sharedmem + offset;\n\tpage = virt_to_page(vaddr);\n\tget_page(page);\n\tvmf->page = page;\n\n\treturn 0;\n\nsnd_us428ctls_mmap() checks only the length of the mapping, never the\noffset, and us428ctls_sharedmem is a single page from\nalloc_pages_exact(). For a character device file_mmap_size_max()\nreturns ULONG_MAX, so the mm layer imposes no ceiling either. Every page\noffset above zero resolves to a struct page outside the object, and the\nhandler installs it into the caller's address space read-write; the vma\nis not marked read-only.\n\nThe caller picks the page frame with a single mmap() argument and gets\nread-write access to a page of kernel memory it does not own; an offset\nthat lands in an unpopulated vmemmap region oopses instead.\n\nA process that can open the hwdep node of an attached US-X2Y reaches\nthis after loading the FPGA image through the same node; no capability\ncheck is involved.\n\nOn 7.2.0-rc5 (arm64), mmap() with a large offset:\n\n Unable to handle kernel paging request at virtual address fffffdffc45d5ac8\n pc : snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y]\n Call trace:\n snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y]\n __do_fault\n __handle_mm_fault\n handle_mm_fault\n el0_da\n\nReject any offset outside the shared region. The pcm hwdep handler in\nusx2yhwdeppcm.c computes its address the same way and needs the same\nbound.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02948 |
debian: CVE-2026-74641 was patched at 2026-08-25
oraclelinux: CVE-2026-74641 was patched at 2026-09-04
1721.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74646) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke When an invoke is interrupted by a signal, wait_for_completion_interruptible() returns -ERESTARTSYS and fastrpc_internal_invoke() moves every buffer from fl->mmaps onto cctx->invoke_interrupted_mmaps. This list_del()/list_add_tail() walk runs without holding fl->lock, the lock that serialises fl->mmaps in fastrpc_req_mmap() and fastrpc_req_munmap() everywhere else. Take fl->lock around the move, matching every other fl->mmaps accessor.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: take fl->lock when moving mmaps on interrupted invoke\n\nWhen an invoke is interrupted by a signal,\nwait_for_completion_interruptible() returns -ERESTARTSYS and\nfastrpc_internal_invoke() moves every buffer from fl->mmaps onto\ncctx->invoke_interrupted_mmaps. This list_del()/list_add_tail() walk\nruns without holding fl->lock, the lock that serialises fl->mmaps in\nfastrpc_req_mmap() and fastrpc_req_munmap() everywhere else.\n\nTake fl->lock around the move, matching every other fl->mmaps accessor.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02873 |
debian: CVE-2026-74646 was patched at 2026-08-25
1722.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74647) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Remove buffer from list prior to unmap operation fastrpc_req_munmap_impl() is called to unmap any buffer. The buffer is getting removed from the list after it is unmapped from DSP. This can create potential race conditions if multiple threads invoke unmap concurrently, where one thread may remove the entry from the list while another thread's unmap operation is still ongoing. Fix this by removing the buffer entry from the list before calling the unmap operation. If the unmap fails, the entry is re-added to the list so that userspace can retry the unmap, or alternatively, the buffer will be cleaned up during device release when the DSP process is torn down and all DSP-side mappings are freed along with remaining buffers in the list.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: Remove buffer from list prior to unmap operation\n\nfastrpc_req_munmap_impl() is called to unmap any buffer. The buffer is\ngetting removed from the list after it is unmapped from DSP. This can\ncreate potential race conditions if multiple threads invoke unmap\nconcurrently, where one thread may remove the entry from the list while\nanother thread's unmap operation is still ongoing.\n\nFix this by removing the buffer entry from the list before calling the\nunmap operation. If the unmap fails, the entry is re-added to the list\nso that userspace can retry the unmap, or alternatively, the buffer\nwill be cleaned up during device release when the DSP process is torn\ndown and all DSP-side mappings are freed along with remaining buffers\nin the list.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02938 |
debian: CVE-2026-74647 was patched at 2026-08-25
1723.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74648) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: validate monitor transmit frame lengths rtw_cfg80211_monitor_if_xmit_entry() removes the radiotap header and then reads the 802.11 frame control field without checking that a base 802.11 header remains. The data path also pulls the calculated 802.11, QoS and SNAP header span before confirming that the skb contains it. A truncated frame can therefore cause out-of-bounds reads or leave insufficient data for the Ethernet address writes. Reject frames that do not contain the base 802.11 header and data frames that do not contain their complete calculated header span.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: validate monitor transmit frame lengths\n\nrtw_cfg80211_monitor_if_xmit_entry() removes the radiotap header and\nthen reads the 802.11 frame control field without checking that a base\n802.11 header remains.\n\nThe data path also pulls the calculated 802.11, QoS and SNAP header\nspan before confirming that the skb contains it. A truncated frame can\ntherefore cause out-of-bounds reads or leave insufficient data for the\nEthernet address writes.\n\nReject frames that do not contain the base 802.11 header and data\nframes that do not contain their complete calculated header span.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02947 |
debian: CVE-2026-74648 was patched at 2026-08-25
oraclelinux: CVE-2026-74648 was patched at 2026-09-04
1724.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74663) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/sched: reject overly deep qdisc hierarchies Deep qdisc hierarchies can lead to excessive recursion in qdisc tree walkers and exhaust the kernel stack. The existing loop check does not cover the create-and-graft path, so a hierarchy can still be extended by creating a new child qdisc below an already deep parent. Store the hierarchy depth in struct Qdisc and update it when qdiscs are grafted. Reject new child qdiscs once the parent is already at the maximum allowed depth.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: reject overly deep qdisc hierarchies\n\nDeep qdisc hierarchies can lead to excessive recursion in qdisc tree\nwalkers and exhaust the kernel stack. The existing loop check does not\ncover the create-and-graft path, so a hierarchy can still be extended by\ncreating a new child qdisc below an already deep parent.\n\nStore the hierarchy depth in struct Qdisc and update it when qdiscs are\ngrafted. Reject new child qdiscs once the parent is already at the maximum\nallowed depth.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02939 |
debian: CVE-2026-74663 was patched at 2026-08-25
oraclelinux: CVE-2026-74663 was patched at 2026-09-04
1725.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74666) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: packet: synchronize pressure clearing with ring reconfiguration packet_set_ring() updates the RX ring state under sk_receive_queue.lock, but used to publish the tpacket receive mode through po->prot_hook.func after releasing that lock. packet_poll() and packet_recvmsg() can then run the pressure clearing path after the ring has been cleared while still seeing tpacket_rcv, causing __packet_rcv_has_room() to dereference stale or NULL ring storage. Move the existing receive hook assignment into the same sk_receive_queue.lock section as the ring state update. Keep the assignment otherwise unchanged, including on TX ring reconfiguration, to avoid adding behavior changes that are not required for the fix. Serialize packet_recvmsg() pressure clearing with the same queue lock only after PACKET_SOCK_PRESSURE has been observed. If the flag is clear and the socket has moved away from tpacket_rcv, packet_set_ring() has already detached the socket and waited for synchronize_net(), so no new packet input can set the flag again. packet_poll() already holds sk_receive_queue.lock, so it uses the new unlocked helper directly.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\npacket: synchronize pressure clearing with ring reconfiguration\n\npacket_set_ring() updates the RX ring state under sk_receive_queue.lock,\nbut used to publish the tpacket receive mode through po->prot_hook.func\nafter releasing that lock. packet_poll() and packet_recvmsg() can then\nrun the pressure clearing path after the ring has been cleared while\nstill seeing tpacket_rcv, causing __packet_rcv_has_room() to dereference\nstale or NULL ring storage.\n\nMove the existing receive hook assignment into the same\nsk_receive_queue.lock section as the ring state update. Keep the\nassignment otherwise unchanged, including on TX ring reconfiguration, to\navoid adding behavior changes that are not required for the fix.\n\nSerialize packet_recvmsg() pressure clearing with the same queue lock\nonly after PACKET_SOCK_PRESSURE has been observed. If the flag is clear\nand the socket has moved away from tpacket_rcv, packet_set_ring() has\nalready detached the socket and waited for synchronize_net(), so no new\npacket input can set the flag again.\n\npacket_poll() already holds sk_receive_queue.lock, so it uses the new\nunlocked helper directly.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02944 |
debian: CVE-2026-74666 was patched at 2026-08-25
oraclelinux: CVE-2026-74666 was patched at 2026-09-04
1726.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74667) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/packet: reset the MAC header on the packet-socket transmit path packet_parse_headers() resets the MAC header only for a SOCK_RAW frame whose socket did not bind a protocol. A protocol-bound SOCK_RAW socket, any SOCK_DGRAM frame, and the legacy SOCK_PACKET path therefore leave skb->mac_header unset here. For frames sent via __dev_queue_xmit() this is harmless: it resets the MAC header unconditionally. But the packet-socket PACKET_QDISC_BYPASS path uses dev_direct_xmit(), which does not, so the frame reaches ndo_start_xmit() with the MAC header unset. A driver that reads eth_hdr(skb) on transmit then dereferences skb->head + (u16)~0, an out-of-bounds access ~64 KiB past the head -- the same class fixed for one consumer in commit f5089008f90c ("macsec: do not read an unset MAC header in macsec_encrypt()"). packet_parse_headers() runs only on the transmit path, where skb->data points at the start of the L2 header for every packet-socket type regardless of its length: SOCK_RAW and SOCK_PACKET carry a user-supplied header and SOCK_DGRAM has one built by dev_hard_header(). Reset the MAC header unconditionally, mirroring __dev_queue_xmit(), so the frame is anchored on the bypass path too. Found by 0sec (https://0sec.ai) using automated source analysis; verified against source and matched to the macsec KASAN report in f5089008f90c. Compile-tested.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/packet: reset the MAC header on the packet-socket transmit path\n\npacket_parse_headers() resets the MAC header only for a SOCK_RAW frame\nwhose socket did not bind a protocol. A protocol-bound SOCK_RAW socket,\nany SOCK_DGRAM frame, and the legacy SOCK_PACKET path therefore leave\nskb->mac_header unset here.\n\nFor frames sent via __dev_queue_xmit() this is harmless: it resets the\nMAC header unconditionally. But the packet-socket PACKET_QDISC_BYPASS\npath uses dev_direct_xmit(), which does not, so the frame reaches\nndo_start_xmit() with the MAC header unset. A driver that reads\neth_hdr(skb) on transmit then dereferences skb->head + (u16)~0, an\nout-of-bounds access ~64 KiB past the head -- the same class fixed for\none consumer in commit f5089008f90c ("macsec: do not read an unset MAC\nheader in macsec_encrypt()").\n\npacket_parse_headers() runs only on the transmit path, where skb->data\npoints at the start of the L2 header for every packet-socket type\nregardless of its length: SOCK_RAW and SOCK_PACKET carry a user-supplied\nheader and SOCK_DGRAM has one built by dev_hard_header(). Reset the MAC\nheader unconditionally, mirroring __dev_queue_xmit(), so the frame is\nanchored on the bypass path too.\n\nFound by 0sec (https://0sec.ai) using automated source analysis;\nverified against source and matched to the macsec KASAN report in\nf5089008f90c. Compile-tested.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00136, EPSS Percentile is 0.03377 |
debian: CVE-2026-74667 was patched at 2026-08-25
oraclelinux: CVE-2026-74667 was patched at 2026-09-04
1727.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74668) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: packet: use consistent hard_header_len in TX_RING send path tpacket_snd() reads dev->hard_header_len independently for skb allocation and header construction in tpacket_fill_skb(). Concurrent netdevice reconfiguration can therefore make the reserved headroom smaller than the amount later pushed, or make copylen - hard_header_len negative. Snapshot hard_header_len once before processing ring frames and use it for the frame limit, headroom allocation, copy length, and skb construction. Pass the snapshot to tpacket_fill_skb(). The separate SOCK_DGRAM consistency problem between hard_header_len and header_ops->create is not addressed here.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\npacket: use consistent hard_header_len in TX_RING send path\n\ntpacket_snd() reads dev->hard_header_len independently for skb\nallocation and header construction in tpacket_fill_skb(). Concurrent\nnetdevice reconfiguration can therefore make the reserved headroom\nsmaller than the amount later pushed, or make copylen - hard_header_len\nnegative.\n\nSnapshot hard_header_len once before processing ring frames and use it\nfor the frame limit, headroom allocation, copy length, and skb\nconstruction. Pass the snapshot to tpacket_fill_skb().\n\nThe separate SOCK_DGRAM consistency problem between hard_header_len and\nheader_ops->create is not addressed here.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.0294 |
debian: CVE-2026-74668 was patched at 2026-08-25
oraclelinux: CVE-2026-74668 was patched at 2026-09-04
1728.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74670) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipvs: stop estimator after disabled calc phase IPVS estimator kthread 0 starts with zeroed chain and tick limits until its initial calculation phase completes. If network namespace teardown clears ipvs->enable during that phase, ip_vs_est_calc_phase() can return without installing positive limits. The kthread can then continue into its main loop and drain est_temp_list with zero chain_max, tick_max and est_max_count values. Each enqueue consumes one available tick row, but est_count never reaches the zero est_max_count value. After all rows are consumed, the row lookup returns IPVS_EST_NTICKS and ip_vs_enqueue_estimator() writes past the ticks and tick_len arrays. Exit kthread 0 after the calculation phase if the kthread is stopping or IPVS has been disabled. That keeps temporary estimators from being drained after the limits failed to initialize. Estimator kthreads can now self-exit before teardown or reload stops kd->task. Keep an extra task reference after creation and release it with kthread_stop_put(), so kd->task remains valid until the stop paths consume that reference.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: stop estimator after disabled calc phase\n\nIPVS estimator kthread 0 starts with zeroed chain and tick limits until\nits initial calculation phase completes. If network namespace teardown\nclears ipvs->enable during that phase, ip_vs_est_calc_phase() can return\nwithout installing positive limits.\n\nThe kthread can then continue into its main loop and drain\nest_temp_list with zero chain_max, tick_max and est_max_count values.\nEach enqueue consumes one available tick row, but est_count never\nreaches the zero est_max_count value. After all rows are consumed, the\nrow lookup returns IPVS_EST_NTICKS and ip_vs_enqueue_estimator() writes\npast the ticks and tick_len arrays.\n\nExit kthread 0 after the calculation phase if the kthread is stopping or\nIPVS has been disabled. That keeps temporary estimators from being\ndrained after the limits failed to initialize.\n\nEstimator kthreads can now self-exit before teardown or reload stops\nkd->task. Keep an extra task reference after creation and release it\nwith kthread_stop_put(), so kd->task remains valid until the stop paths\nconsume that reference.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02866 |
debian: CVE-2026-74670 was patched at 2026-08-25
oraclelinux: CVE-2026-74670 was patched at 2026-09-04
1729.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74675) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: vt: stabilize tty reference in kbd_keycode with tty_port_tty_get kbd_keycode() reads vc->port.tty without acquiring a tty reference, racing against con_shutdown() which clears port.tty under a different lock. Use tty_port_tty_get()/tty_kref_put() to hold a proper reference for the duration the tty pointer is needed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvt: stabilize tty reference in kbd_keycode with tty_port_tty_get\n\nkbd_keycode() reads vc->port.tty without acquiring a tty reference,\nracing against con_shutdown() which clears port.tty under a different\nlock. Use tty_port_tty_get()/tty_kref_put() to hold a proper reference\nfor the duration the tty pointer is needed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02939 |
debian: CVE-2026-74675 was patched at 2026-08-25
oraclelinux: CVE-2026-74675 was patched at 2026-09-04
1730.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74687) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: watchdog: at91sam9_wdt: prevent timer rearm during teardown at91_ping() rearms the watchdog timer from its callback. timer_delete() neither waits for a running callback nor prevents it from rearming the timer, so probe failure or driver removal can leave the timer accessing the devm-allocated at91wdt after it has been freed. Use timer_shutdown_sync() on both teardown paths. It waits for a running callback and rejects any attempt by the callback to rearm the timer.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwatchdog: at91sam9_wdt: prevent timer rearm during teardown\n\nat91_ping() rearms the watchdog timer from its callback. timer_delete()\nneither waits for a running callback nor prevents it from rearming the\ntimer, so probe failure or driver removal can leave the timer accessing the\ndevm-allocated at91wdt after it has been freed.\n\nUse timer_shutdown_sync() on both teardown paths. It waits for a running\ncallback and rejects any attempt by the callback to rearm the timer.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00127, EPSS Percentile is 0.02732 |
debian: CVE-2026-74687 was patched at 2026-08-25
1731.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74690) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: s390/ism: Fix UAF of sba and ieq during ism_dev_exit() A ism interrupt handler can be active in parallel with ism_dev_exit(), accessing freed data structures. No new interrupts will be generated after unregister_ieq(). Drain ongoing interrupt handlers by free_irq(), before freeing ism data structures.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/ism: Fix UAF of sba and ieq during ism_dev_exit()\n\nA ism interrupt handler can be active in parallel with ism_dev_exit(),\naccessing freed data structures.\n\nNo new interrupts will be generated after unregister_ieq(). Drain ongoing\ninterrupt handlers by free_irq(), before freeing ism data structures.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0014, EPSS Percentile is 0.03748 |
debian: CVE-2026-74690 was patched at 2026-08-25
1732.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74701) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/openvswitch: check Ethernet header length in key_extract() When a packet arrives on an ARPHRD_NONE device (e.g. TUN), ovs_flow_key_extract() trusts the user-provided skb->protocol field: if it is ETH_P_TEB, the packet is classified as MAC_PROTO_ETHERNET and key_extract() is called without ensuring the skb has ETH_HLEN (14) bytes of linear data. key_extract() unconditionally pulls 2 * ETH_ALEN bytes for MAC addresses and parse_ethertype() pulls 2 more, either of which triggers a kernel BUG in __skb_pull() when the linear area is too small. kernel BUG at include/linux/skbuff.h:2848! RIP: 0010:key_extract+0xa7e/0xd90 net/openvswitch/flow.c:933 ovs_flow_key_extract+0x419/0xa70 ovs_vport_receive+0x222/0x390 netdev_frame_hook+0x3e0/0x630 tun_get_user+0x2d0c/0x38e0 Fixed by calling check_header() in key_extract() before accessing the Ethernet header.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/openvswitch: check Ethernet header length in key_extract()\n\nWhen a packet arrives on an ARPHRD_NONE device (e.g. TUN),\novs_flow_key_extract() trusts the user-provided skb->protocol field: if\nit is ETH_P_TEB, the packet is classified as MAC_PROTO_ETHERNET and\nkey_extract() is called without ensuring the skb has ETH_HLEN (14) bytes\nof linear data. key_extract() unconditionally pulls 2 * ETH_ALEN bytes\nfor MAC addresses and parse_ethertype() pulls 2 more, either of which\ntriggers a kernel BUG in __skb_pull() when the linear area is too small.\n\n kernel BUG at include/linux/skbuff.h:2848!\n RIP: 0010:key_extract+0xa7e/0xd90 net/openvswitch/flow.c:933\n ovs_flow_key_extract+0x419/0xa70\n ovs_vport_receive+0x222/0x390\n netdev_frame_hook+0x3e0/0x630\n tun_get_user+0x2d0c/0x38e0\n\nFixed by calling check_header() in key_extract() before accessing the\nEthernet header.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0013, EPSS Percentile is 0.02977 |
debian: CVE-2026-74701 was patched at 2026-08-25
oraclelinux: CVE-2026-74701 was patched at 2026-09-04
1733.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74710) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xsk: require at least 16 bytes of TX metadata AF_XDP accepts a TX metadata length as small as eight bytes, but every supported request needs the flags plus at least one eight-byte request field. Such short metadata also lets the kernel read beyond the registered area. Require 16 bytes rather than sizeof(struct xsk_tx_metadata) to preserve compatibility with applications that do not use launch-time metadata.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxsk: require at least 16 bytes of TX metadata\n\nAF_XDP accepts a TX metadata length as small as eight bytes, but every\nsupported request needs the flags plus at least one eight-byte request\nfield. Such short metadata also lets the kernel read beyond the registered\narea.\n\nRequire 16 bytes rather than sizeof(struct xsk_tx_metadata) to preserve\ncompatibility with applications that do not use launch-time metadata.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02865 |
debian: CVE-2026-74710 was patched at 2026-08-25
oraclelinux: CVE-2026-74710 was patched at 2026-09-04
1734.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74715) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: bpf: Fix netns reference imbalance in conntrack kfuncs The opts argument of the BPF conntrack kfuncs can point to a shared map value. __bpf_nf_ct_lookup() and __bpf_nf_ct_alloc_entry() read opts->netns_id separately when acquiring and releasing the network namespace reference. The reference imbalance can occur as follows: CPU 0 CPU 1 read opts->netns_id (-1) skip get_net_ns_by_id() write opts->netns_id (id) read opts->netns_id (id) put_net(net) /* no matching get */ The reverse transition leaks the reference. Repeating the unmatched put can destroy a live namespace and crash later users. The kernel reported: Oops: general protection fault, probably for non-canonical address KASAN: null-ptr-deref in range [0x00000000000000e8-0x00000000000000ef] RIP: 0010:bpf_prog_test_run_xdp+0x52c/0x1700 Call Trace: __sys_bpf+0x1662/0x50c0 __x64_sys_bpf+0x73/0xb0 do_syscall_64+0xf9/0x540 entry_SYSCALL_64_after_hwframe+0x77/0x7f Kernel panic - not syncing: Fatal exception Snapshot every input field of opts with READ_ONCE() before validating or using it. The netns_id snapshot keeps the namespace get/put pair balanced, while the other snapshots keep the remaining options from changing partway through an invocation. The individual reads can still observe an inconsistent combination during a concurrent update, but each selected field value remains stable for that invocation.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix netns reference imbalance in conntrack kfuncs\n\nThe opts argument of the BPF conntrack kfuncs can point to a shared\nmap value. __bpf_nf_ct_lookup() and __bpf_nf_ct_alloc_entry() read\nopts->netns_id separately when acquiring and releasing the network\nnamespace reference.\n\nThe reference imbalance can occur as follows:\n\n CPU 0 CPU 1\n read opts->netns_id (-1)\n skip get_net_ns_by_id()\n write opts->netns_id (id)\n read opts->netns_id (id)\n put_net(net) /* no matching get */\n\nThe reverse transition leaks the reference. Repeating the unmatched put\ncan destroy a live namespace and crash later users.\n\nThe kernel reported:\n\n Oops: general protection fault, probably for non-canonical address\n KASAN: null-ptr-deref in range [0x00000000000000e8-0x00000000000000ef]\n RIP: 0010:bpf_prog_test_run_xdp+0x52c/0x1700\n Call Trace:\n __sys_bpf+0x1662/0x50c0\n __x64_sys_bpf+0x73/0xb0\n do_syscall_64+0xf9/0x540\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n Kernel panic - not syncing: Fatal exception\n\nSnapshot every input field of opts with READ_ONCE() before validating or\nusing it. The netns_id snapshot keeps the namespace get/put pair\nbalanced, while the other snapshots keep the remaining options from\nchanging partway through an invocation. The individual reads can still\nobserve an inconsistent combination during a concurrent update, but each\nselected field value remains stable for that invocation.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02138 |
debian: CVE-2026-74715 was patched at 2026-08-25
1735.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74720) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve pointer state for commuted arithmetic When scalar += pointer is handled in adjust_ptr_min_max_vals(), the destination register inherits the pointer state from the source pointer. Copying only selected fields is fragile because pointer provenance is tracked by several bpf_reg_state fields. Use the caller's temporary offset register to preserve the scalar operand while replacing the destination with the full pointer state. This preserves the frame number for PTR_TO_STACK registers and keeps parent identity fields consistent.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Preserve pointer state for commuted arithmetic\n\nWhen scalar += pointer is handled in adjust_ptr_min_max_vals(), the\ndestination register inherits the pointer state from the source pointer.\nCopying only selected fields is fragile because pointer provenance is\ntracked by several bpf_reg_state fields.\n\nUse the caller's temporary offset register to preserve the scalar operand\nwhile replacing the destination with the full pointer state. This preserves\nthe frame number for PTR_TO_STACK registers and keeps parent identity\nfields consistent.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.0293 |
debian: CVE-2026-74720 was patched at 2026-08-25
oraclelinux: CVE-2026-74720 was patched at 2026-09-04
1736.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74733) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock Locking is disabled in the regmap config as this driver uses its own lock. This means that all calls to regmap functions (read or write) must hold the i2c_lock. The function pca953x_irq_bus_sync_unlock() did not do this, and it was therefore possible that multiple threads could cause an incorrect register to be read/written. A previous patch partly fixed this, but only protected the write to the interrupt mask register, and not the read from the direction register.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock\n\nLocking is disabled in the regmap config as this driver uses its own\nlock. This means that all calls to regmap functions (read or write) must\nhold the i2c_lock. The function pca953x_irq_bus_sync_unlock() did not do\nthis, and it was therefore possible that multiple threads could cause an\nincorrect register to be read/written.\n\nA previous patch partly fixed this, but only protected the write to the\ninterrupt mask register, and not the read from the direction register.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.024 |
debian: CVE-2026-74733 was patched at 2026-08-25
1737.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74736) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_bpf: reject dev-bound programs bound to a different device cls_bpf_prog_from_efd() obtained a SCHED_CLS program via bpf_prog_get_type_dev() but never verified that a device-bound (offloaded) program's bound netdev matches the TC netdev the classifier is being attached to. This let a program loaded with prog_ifindex for device A be attached via cls_bpf + skip_sw to device B; deleting device A then destroyed the program's offload state while it was still attached to device B, triggering a netdevsim WARN (panic with panic_on_warn=1). Mirror the XDP attach path (net/core/dev.c) and reject the attach with -EINVAL when a dev-bound program's bound device does not match the target device.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: cls_bpf: reject dev-bound programs bound to a different device\n\ncls_bpf_prog_from_efd() obtained a SCHED_CLS program via\nbpf_prog_get_type_dev() but never verified that a device-bound (offloaded)\nprogram's bound netdev matches the TC netdev the classifier is being\nattached to. This let a program loaded with prog_ifindex for device A be\nattached via cls_bpf + skip_sw to device B; deleting device A then\ndestroyed the program's offload state while it was still attached to\ndevice B, triggering a netdevsim WARN (panic with panic_on_warn=1).\n\nMirror the XDP attach path (net/core/dev.c) and reject the attach with\n-EINVAL when a dev-bound program's bound device does not match the\ntarget device.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00138, EPSS Percentile is 0.03541 |
debian: CVE-2026-74736 was patched at 2026-09-16
1738.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74747) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipvs: revalidate ihl to prevent out-of-bounds access While the outer IP header is already pulled into the skb head, we must be careful and revalidate the embedded headers after reading them from the skb frags to prevent out-of-bounds access. One such place reported by Sashiko is ip_vs_nat_icmp() where local process can change the ihl field and after skb_ensure_writable() we can see larger value which is a problem for the ip_send_check(cih) calls. Add check to drop the packet if the ihl field is changed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: revalidate ihl to prevent out-of-bounds access\n\nWhile the outer IP header is already pulled into the skb head,\nwe must be careful and revalidate the embedded headers after\nreading them from the skb frags to prevent out-of-bounds\naccess.\n\nOne such place reported by Sashiko is ip_vs_nat_icmp() where\nlocal process can change the ihl field and after\nskb_ensure_writable() we can see larger value which is a\nproblem for the ip_send_check(cih) calls.\n\nAdd check to drop the packet if the ihl field is changed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02922 |
debian: CVE-2026-74747 was patched at 2026-09-16
1739.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74748) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix refcount race between list:set GC and swap __ip_set_put_byindex() resolved the index to a set pointer under RCU, then took ip_set_ref_lock in __ip_set_put() to decrement set->ref. ip_set_swap() holds that same lock while swapping both the ip_set_list slots and the two sets' ref counters, so it can interleave between the dereference and the lock acquisition, leaving the caller to decrement a set whose reference already moved to the other index and hit BUG_ON(set->ref == 0). list_set_gc() reaches this from timer softirq, which the nfnl mutex does not serialize against swap: an expiring list:set member calls list_set_del() -> ip_set_put_byindex() while IPSET_CMD_SWAP runs on the referenced sets. Resolve the index and decrement under ip_set_ref_lock, as ip_set_swap() already does, keeping the refcount tied to the index rather than to a stale set pointer. kernel BUG at net/netfilter/ipset/ip_set_core.c:685! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI RIP: 0010:ip_set_put_byindex (net/netfilter/ipset/ip_set_core.c:870) Call Trace: <IRQ> list_set_del (net/netfilter/ipset/ip_set_list_set.c:159) set_cleanup_entries (net/netfilter/ipset/ip_set_list_set.c:181) list_set_gc (net/netfilter/ipset/ip_set_list_set.c:578) call_timer_fn (kernel/time/timer.c:1748) __run_timers (kernel/time/timer.c:1799 kernel/time/timer.c:2374) run_timer_softirq (kernel/time/timer.c:2405) </IRQ> Kernel panic - not syncing: Fatal exception in interrupt', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: fix refcount race between list:set GC and swap\n\n__ip_set_put_byindex() resolved the index to a set pointer under RCU,\nthen took ip_set_ref_lock in __ip_set_put() to decrement set->ref.\nip_set_swap() holds that same lock while swapping both the ip_set_list\nslots and the two sets' ref counters, so it can interleave between the\ndereference and the lock acquisition, leaving the caller to decrement a\nset whose reference already moved to the other index and hit\nBUG_ON(set->ref == 0). list_set_gc() reaches this from timer softirq,\nwhich the nfnl mutex does not serialize against swap: an expiring\nlist:set member calls list_set_del() -> ip_set_put_byindex() while\nIPSET_CMD_SWAP runs on the referenced sets.\n\nResolve the index and decrement under ip_set_ref_lock, as ip_set_swap()\nalready does, keeping the refcount tied to the index rather than to a\nstale set pointer.\n\n kernel BUG at net/netfilter/ipset/ip_set_core.c:685!\n Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\n RIP: 0010:ip_set_put_byindex (net/netfilter/ipset/ip_set_core.c:870)\n Call Trace:\n <IRQ>\n list_set_del (net/netfilter/ipset/ip_set_list_set.c:159)\n set_cleanup_entries (net/netfilter/ipset/ip_set_list_set.c:181)\n list_set_gc (net/netfilter/ipset/ip_set_list_set.c:578)\n call_timer_fn (kernel/time/timer.c:1748)\n __run_timers (kernel/time/timer.c:1799 kernel/time/timer.c:2374)\n run_timer_softirq (kernel/time/timer.c:2405)\n </IRQ>\n Kernel panic - not syncing: Fatal exception in interrupt', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00138, EPSS Percentile is 0.03599 |
debian: CVE-2026-74748 was patched at 2026-09-16
oraclelinux: CVE-2026-74748 was patched at 2026-09-04
1740.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74753) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: perf: Reject exited events as group leaders perf_event_remove_on_exec() sets remove-on-exec events to the EXIT state and detaches their group relationships. The event's file descriptor can remain open, however, and perf_event_open() currently accepts that event as a group leader because its early validation rejects only REVOKED and DEAD events. A new sibling can consequently be linked to the detached leader. When the leader is closed, perf_group_detach() observes that its PERF_ATTACH_GROUP bit is already clear and skips the new sibling. The sibling then retains a group_leader pointer to the freed event. Reject group leaders in the EXIT state. Perform the check while holding the shared context mutex so that an exec in the target task cannot detach the leader between validation and group attachment. [peterz: make the earlier test fully consistent]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Reject exited events as group leaders\n\nperf_event_remove_on_exec() sets remove-on-exec events to the EXIT state\nand detaches their group relationships. The event's file descriptor can\nremain open, however, and perf_event_open() currently accepts that event\nas a group leader because its early validation rejects only REVOKED and\nDEAD events.\n\nA new sibling can consequently be linked to the detached leader. When\nthe leader is closed, perf_group_detach() observes that its\nPERF_ATTACH_GROUP bit is already clear and skips the new sibling. The\nsibling then retains a group_leader pointer to the freed event.\n\nReject group leaders in the EXIT state. Perform the check while holding\nthe shared context mutex so that an exec in the target task cannot detach\nthe leader between validation and group attachment.\n\n[peterz: make the earlier test fully consistent]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02851 |
debian: CVE-2026-74753 was patched at 2026-09-16
1741.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80522) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req() Perform rctx->cryptlen calculation in tegra_gcm_do_one_req() the same way it is done in tegra_ccm_crypt_init(). The current formulae may lead to a crash if a caller does not call tegra_gcm_setauthsize() and so ctx->authsize remains zero. Then a decrypt operation with incorrect rctx->cryptlen will lead to a write beyound rctx->dst_sg buffer. As a follow-up cleanup delete struct tegra_aead_ctx->authsize field since it appears to be completely unused. Also simplify tegra_ccm_setauthsize() and tegra_gcm_setauthsize() functions respectively.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req()\n\nPerform rctx->cryptlen calculation in tegra_gcm_do_one_req() the same way\nit is done in tegra_ccm_crypt_init(). The current formulae may lead to a\ncrash if a caller does not call tegra_gcm_setauthsize() and so ctx->authsize\nremains zero. Then a decrypt operation with incorrect rctx->cryptlen will\nlead to a write beyound rctx->dst_sg buffer.\n\nAs a follow-up cleanup delete struct tegra_aead_ctx->authsize field since\nit appears to be completely unused. Also simplify tegra_ccm_setauthsize()\nand tegra_gcm_setauthsize() functions respectively.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02852 |
debian: CVE-2026-80522 was patched at 2026-09-16
1742.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80526) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ASoC: tas2562: Validate values for volume writes tas2562_volume_control_put() does not do any validation of the control value written by userspace, it uses it to look up a value in a fixed size array which can easily be overflowed and then writes whatever value it gets back to the device. Add validation that we are loading a value we have in the array.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: tas2562: Validate values for volume writes\n\ntas2562_volume_control_put() does not do any validation of the control\nvalue written by userspace, it uses it to look up a value in a fixed\nsize array which can easily be overflowed and then writes whatever value\nit gets back to the device. Add validation that we are loading a value\nwe have in the array.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02853 |
debian: CVE-2026-80526 was patched at 2026-09-16
1743.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80531) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xfs: avoid UAF on sc->tempip in xrep_tempfile_create LOLLM noticed a potential UAF if the tempfile creation code fails after it set sc->tempip. Fix that.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: avoid UAF on sc->tempip in xrep_tempfile_create\n\nLOLLM noticed a potential UAF if the tempfile creation code fails after\nit set sc->tempip. Fix that.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02852 |
debian: CVE-2026-80531 was patched at 2026-09-16
1744.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80540) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix UVD decode image min size calculation This needs to use pitch instead of width. Also reject pitch over 4096 to avoid overflow. (cherry picked from commit b41c8cb12e202b220353332ab87dc01a11f69304)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix UVD decode image min size calculation\n\nThis needs to use pitch instead of width. Also reject pitch\nover 4096 to avoid overflow.\n\n(cherry picked from commit b41c8cb12e202b220353332ab87dc01a11f69304)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02906 |
debian: CVE-2026-80540 was patched at 2026-09-16
oraclelinux: CVE-2026-80540 was patched at 2026-09-04
1745.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80541) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate GEM_CREATE domain combinations AMDGPU_GEM_CREATE checked domain bits against AMDGPU_GEM_DOMAIN_MASK, but did not validate domain combinations. Userspace could combine CPU|GTT|VRAM with DOORBELL, GDS, GWS, or OA, making amdgpu_bo_placement_from_domain() exceed AMDGPU_BO_MAX_PLACEMENTS and hit BUG_ON(). Allow combinations only within CPU/GTT/VRAM, and require non-CPU/GTT/ VRAM domains to be specified one at a time. Return -EINVAL for invalid combinations in amdgpu_gem_create_ioctl(). v2: Rename helper from amdgpu_gem_domain_valid() to amdgpu_gem_are_domains_valid() (Christian) (cherry picked from commit db39852d0c39843cb02048dfb47e4b8c703e9080)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: validate GEM_CREATE domain combinations\n\nAMDGPU_GEM_CREATE checked domain bits against AMDGPU_GEM_DOMAIN_MASK,\nbut did not validate domain combinations. Userspace could combine\nCPU|GTT|VRAM with DOORBELL, GDS, GWS, or OA, making\namdgpu_bo_placement_from_domain() exceed AMDGPU_BO_MAX_PLACEMENTS and\nhit BUG_ON().\n\nAllow combinations only within CPU/GTT/VRAM, and require non-CPU/GTT/\nVRAM domains to be specified one at a time. Return -EINVAL for invalid\ncombinations in amdgpu_gem_create_ioctl().\n\nv2: Rename helper from amdgpu_gem_domain_valid() to\n amdgpu_gem_are_domains_valid() (Christian)\n\n(cherry picked from commit db39852d0c39843cb02048dfb47e4b8c703e9080)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02905 |
debian: CVE-2026-80541 was patched at 2026-09-16
oraclelinux: CVE-2026-80541 was patched at 2026-09-04
1746.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80549) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Move cp cleanup out of not operational The fsm_notoper() routine is called when the device has been lost, and is (by definition) no longer operational. Since this can happen asynchronously from the normal behavior of the driver, the cleanup may happen when holding other locks in the calling sequence (notably, the cio subchannel lock). Push the cleanup of the private->cp resources to a workqueue, where it can be done out from under that lock sequence and a future patch can safely manage the locking requirements.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Move cp cleanup out of not operational\n\nThe fsm_notoper() routine is called when the device has been\nlost, and is (by definition) no longer operational. Since this\ncan happen asynchronously from the normal behavior of the\ndriver, the cleanup may happen when holding other locks\nin the calling sequence (notably, the cio subchannel lock).\n\nPush the cleanup of the private->cp resources to a workqueue,\nwhere it can be done out from under that lock sequence and\na future patch can safely manage the locking requirements.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.03306 |
debian: CVE-2026-80549 was patched at 2026-09-16
1747.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80550) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Fix out of bounds check on CCW array The routine ccwchain_calc_length() counts the number of channel command words (CCWs) that are chained together in a single channel program, and rejects anything larger than CCWCHAIN_LEN_MAX (256) CCWs. The loop itself is "do..while (count < 257)", and while the logic in is_cpa_within_range() correctly adjusts between the 0-index array of CCWs and the count of CCWs starting at 1, this means it would look at a possible 257th CCW before ending the loop and (correctly) returning an error. Fix this by restructuring the loop to break as soon as 256 CCWs (thus indexes 0-255) are examined, without looking at memory outside the range.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Fix out of bounds check on CCW array\n\nThe routine ccwchain_calc_length() counts the number of channel\ncommand words (CCWs) that are chained together in a single channel\nprogram, and rejects anything larger than CCWCHAIN_LEN_MAX (256) CCWs.\n\nThe loop itself is "do..while (count < 257)", and while the logic in\nis_cpa_within_range() correctly adjusts between the 0-index array of\nCCWs and the count of CCWs starting at 1, this means it would look\nat a possible 257th CCW before ending the loop and (correctly)\nreturning an error.\n\nFix this by restructuring the loop to break as soon as 256 CCWs\n(thus indexes 0-255) are examined, without looking at memory\noutside the range.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00137, EPSS Percentile is 0.03464 |
debian: CVE-2026-80550 was patched at 2026-09-16
1748.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80559) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Input: sur40 - fix input device registration ordering In sur40_probe(), input_register_device() was previously called early before the V4L2 video device and vb2_queue components were fully initialized. If userspace opened the input device immediately upon registration, sur40_open() would trigger and start the sur40_poll() worker thread. This worker thread invokes sur40_process_video() and accesses the uninitialized vb2_queue structure, leading to a data race and potential system crash. Furthermore, if V4L2 or video registration failed after input_register_device() succeeded, the error path fell through to calling input_free_device() on a successfully registered device instead of input_unregister_device(), corrupting input core state. Move input_register_device() to the very end of sur40_probe(). This ensures the V4L2 and video queue structures are fully initialized before polling can start, and naturally resolves the error path bug since input_free_device() is now only called when input registration has not yet occurred. To maintain strict LIFO (Last-In, First-Out) teardown ordering, also move input_unregister_device() to the very beginning of sur40_disconnect(). This guarantees that the input polling worker thread is stopped before V4L2 video components or control handlers are unregistered.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nInput: sur40 - fix input device registration ordering\n\nIn sur40_probe(), input_register_device() was previously called early before\nthe V4L2 video device and vb2_queue components were fully initialized. If\nuserspace opened the input device immediately upon registration, sur40_open()\nwould trigger and start the sur40_poll() worker thread. This worker thread\ninvokes sur40_process_video() and accesses the uninitialized vb2_queue\nstructure, leading to a data race and potential system crash.\n\nFurthermore, if V4L2 or video registration failed after input_register_device()\nsucceeded, the error path fell through to calling input_free_device() on a\nsuccessfully registered device instead of input_unregister_device(), corrupting\ninput core state.\n\nMove input_register_device() to the very end of sur40_probe(). This ensures\nthe V4L2 and video queue structures are fully initialized before polling can\nstart, and naturally resolves the error path bug since input_free_device()\nis now only called when input registration has not yet occurred.\n\nTo maintain strict LIFO (Last-In, First-Out) teardown ordering, also move\ninput_unregister_device() to the very beginning of sur40_disconnect(). This\nguarantees that the input polling worker thread is stopped before V4L2\nvideo components or control handlers are unregistered.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.0291 |
debian: CVE-2026-80559 was patched at 2026-09-16
1749.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80565) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: crypto: qce - fix error path in devm_qce_register_algs If ops->register_algs() fails, the error path repeatedly calls the same ops->unregister_algs() from the failed registration. Use the loop index to unregister the previously registered algorithms instead.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qce - fix error path in devm_qce_register_algs\n\nIf ops->register_algs() fails, the error path repeatedly calls the same\nops->unregister_algs() from the failed registration. Use the loop index\nto unregister the previously registered algorithms instead.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02102 |
debian: CVE-2026-80565 was patched at 2026-09-16
1750.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80569) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer rmi_f54_work() reads a diagnostics report from the device into f54->report_data, sizing the transfer with rmi_f54_get_report_size(): \treport_size = rmi_f54_get_report_size(f54); \t... \tfor (i = 0; i < report_size; i += F54_REPORT_DATA_SIZE) { \t\tint size = min(F54_REPORT_DATA_SIZE, report_size - i); \t\t... \t\trmi_read_block(.., f54->report_data + i, size); \t} report_data is allocated once at probe from F54's own electrode counts (array3_size(f54->num_tx_electrodes, f54->num_rx_electrodes, sizeof(u16))), but rmi_f54_get_report_size() computes the size from drv_data->num_*_electrodes when those are set, i.e. from the F55 function's electrode counts. Both counts come straight from device queries (F54 and F55 each report up to 255 electrodes) and nothing constrains the F55 counts to the F54 ones. A malicious or malfunctioning RMI4 device that reports larger F55 electrode counts than its F54 counts makes report_size exceed the allocation, so the read loop writes past report_data (and the V4L2 dequeue memcpy() then reads past it). On conforming hardware the F55 configured electrodes are a subset of the F54 physical electrodes, so report_size never exceeds the buffer and well-behaved devices are unaffected. Record the allocation size and reject a report that does not fit, mirroring the existing zero-size check.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - bound the F54 report size to the allocated buffer\n\nrmi_f54_work() reads a diagnostics report from the device into\nf54->report_data, sizing the transfer with rmi_f54_get_report_size():\n\n\treport_size = rmi_f54_get_report_size(f54);\n\t...\n\tfor (i = 0; i < report_size; i += F54_REPORT_DATA_SIZE) {\n\t\tint size = min(F54_REPORT_DATA_SIZE, report_size - i);\n\t\t...\n\t\trmi_read_block(.., f54->report_data + i, size);\n\t}\n\nreport_data is allocated once at probe from F54's own electrode counts\n(array3_size(f54->num_tx_electrodes, f54->num_rx_electrodes, sizeof(u16))),\nbut rmi_f54_get_report_size() computes the size from\ndrv_data->num_*_electrodes when those are set, i.e. from the F55\nfunction's electrode counts. Both counts come straight from device\nqueries (F54 and F55 each report up to 255 electrodes) and nothing\nconstrains the F55 counts to the F54 ones.\n\nA malicious or malfunctioning RMI4 device that reports larger F55\nelectrode counts than its F54 counts makes report_size exceed the\nallocation, so the read loop writes past report_data (and the V4L2\ndequeue memcpy() then reads past it). On conforming hardware the F55\nconfigured electrodes are a subset of the F54 physical electrodes, so\nreport_size never exceeds the buffer and well-behaved devices are\nunaffected.\n\nRecord the allocation size and reject a report that does not fit,\nmirroring the existing zero-size check.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02104 |
debian: CVE-2026-80569 was patched at 2026-09-16
1751.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80572) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Input: byd - synchronize timer deletion before freeing private data byd_disconnect() uses timer_delete() before freeing the driver's private data. This does not wait for a running byd_clear_touch() callback, which dereferences the private data and its psmouse pointer. A callback racing with disconnect can therefore access the private data after it has been freed. The timer can also still be re-armed by byd_process_byte() while the disconnect is in progress. Use timer_shutdown_sync() before freeing the private data: it waits for a running callback and turns any later re-arm attempt into a no-op.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nInput: byd - synchronize timer deletion before freeing private data\n\nbyd_disconnect() uses timer_delete() before freeing the driver's private\ndata. This does not wait for a running byd_clear_touch() callback, which\ndereferences the private data and its psmouse pointer. A callback racing\nwith disconnect can therefore access the private data after it has been\nfreed. The timer can also still be re-armed by byd_process_byte() while\nthe disconnect is in progress.\n\nUse timer_shutdown_sync() before freeing the private data: it waits for\na running callback and turns any later re-arm attempt into a no-op.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02104 |
debian: CVE-2026-80572 was patched at 2026-08-29, 2026-09-16
1752.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80574) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet Make finger2 (and also finger1) unsigned, so that if the finger index in the packet is 0 then subtracting 1 creates an array index which overflows above the existing check for FOC_MAX_FINGERS, as the existing comment says it should, instead of writing to state->fingers[-1].', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nInput: focaltech - fix array out-of-bounds in focaltech_process_rel_packet\n\nMake finger2 (and also finger1) unsigned, so that if the finger index in\nthe packet is 0 then subtracting 1 creates an array index which overflows\nabove the existing check for FOC_MAX_FINGERS, as the existing comment says\nit should, instead of writing to state->fingers[-1].', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.03261 |
debian: CVE-2026-80574 was patched at 2026-09-16
oraclelinux: CVE-2026-80574 was patched at 2026-09-04
1753.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80575) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Input: cs40l50-vibra - validate custom data from user space cs40l50_add() copies the custom data of an FF_PERIODIC/FF_CUSTOM effect straight from the ff_effect the user passed to EVIOCSFF, without requiring it to hold anything: work_data.custom_data = memdup_array_user(periodic->custom_data, periodic->custom_len, sizeof(s16)); work_data.custom_len = periodic->custom_len; The driver then reads two words out of that buffer: custom_data[0] as the waveform bank in cs40l50_effect_bank_set(), and custom_data[1] as the index within the bank in cs40l50_effect_index_set(). Neither read is covered by a length check, and custom_len is fully user controlled: - custom_len == 0 makes memdup_array_user() call memdup_user() with a length of zero, which returns ZERO_SIZE_PTR rather than an error, so custom_data[0] dereferences it. - custom_len == 1 allocates two bytes. A bank of ROM or RAM keeps effect->type out of the OWT case, and custom_data[1] is then read one word past the allocation. The bank value itself is also mishandled. It is masked with CS40L50_CUSTOM_DATA_MASK (0xffff) but stored in an s16, so a custom_data[0] of 0x8000 or above wraps to a negative value that passes the "bank_type >= CS40L50_WVFRM_BANK_NUM" test. cs40l50_effect_index_set() indexes vib->dsp.banks[] with it before the switch statement's default case gets a chance to reject it: base_index = vib->dsp.banks[effect->type].base_index; max_index = vib->dsp.banks[effect->type].max_index; Require the two words the driver reads to be present, and hold the masked bank in a u32 so the existing upper-bound test covers the whole range. The da7280 haptic driver already range checks custom_len this way.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nInput: cs40l50-vibra - validate custom data from user space\n\ncs40l50_add() copies the custom data of an FF_PERIODIC/FF_CUSTOM effect\nstraight from the ff_effect the user passed to EVIOCSFF, without\nrequiring it to hold anything:\n\n work_data.custom_data = memdup_array_user(periodic->custom_data,\n periodic->custom_len,\n sizeof(s16));\n work_data.custom_len = periodic->custom_len;\n\nThe driver then reads two words out of that buffer: custom_data[0] as the\nwaveform bank in cs40l50_effect_bank_set(), and custom_data[1] as the\nindex within the bank in cs40l50_effect_index_set(). Neither read is\ncovered by a length check, and custom_len is fully user controlled:\n\n - custom_len == 0 makes memdup_array_user() call memdup_user() with a\n length of zero, which returns ZERO_SIZE_PTR rather than an error, so\n custom_data[0] dereferences it.\n\n - custom_len == 1 allocates two bytes. A bank of ROM or RAM keeps\n effect->type out of the OWT case, and custom_data[1] is then read one\n word past the allocation.\n\nThe bank value itself is also mishandled. It is masked with\nCS40L50_CUSTOM_DATA_MASK (0xffff) but stored in an s16, so a\ncustom_data[0] of 0x8000 or above wraps to a negative value that passes\nthe "bank_type >= CS40L50_WVFRM_BANK_NUM" test.\ncs40l50_effect_index_set() indexes vib->dsp.banks[] with it before the\nswitch statement's default case gets a chance to reject it:\n\n base_index = vib->dsp.banks[effect->type].base_index;\n max_index = vib->dsp.banks[effect->type].max_index;\n\nRequire the two words the driver reads to be present, and hold the masked\nbank in a u32 so the existing upper-bound test covers the whole range.\nThe da7280 haptic driver already range checks custom_len this way.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02057 |
debian: CVE-2026-80575 was patched at 2026-09-16
1754.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80579) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fbdev: clear fb_info->mode before deleting a videomode fb_set_var() can delete a mode from info->modelist when userspace passes FB_ACTIVATE_INV_MODE through FBIOPUT_VSCREENINFO. The code checks that the mode being deleted is not the current info->var and that fbcon is not using it, but it does not check fb_info->mode. fb_info->mode may still point into the modelist entry being deleted. If the entry is freed, later mode sysfs reads through show_mode() can dereference a stale pointer. Clear fb_info->mode before calling fb_delete_videomode() when it matches the mode being removed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: clear fb_info->mode before deleting a videomode\n\nfb_set_var() can delete a mode from info->modelist when userspace\npasses FB_ACTIVATE_INV_MODE through FBIOPUT_VSCREENINFO. The code\nchecks that the mode being deleted is not the current info->var and\nthat fbcon is not using it, but it does not check fb_info->mode.\n\nfb_info->mode may still point into the modelist entry being deleted.\nIf the entry is freed, later mode sysfs reads through show_mode() can\ndereference a stale pointer.\n\nClear fb_info->mode before calling fb_delete_videomode() when it\nmatches the mode being removed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.01552 |
debian: CVE-2026-80579 was patched at 2026-09-16
1755.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80580) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fbdev: bound mode sysfs output to the sysfs buffer mode_string() uses snprintf() which can return a value larger than the remaining buffer space. show_modes() accumulates the return value into i without checking whether i has reached PAGE_SIZE, causing the offset to advance past the sysfs buffer if the modelist is long enough. Add a size parameter to mode_string() and use scnprintf() to return only the bytes actually written. Add an early return when offset already exceeds the buffer. In show_modes(), stop accumulating once the buffer is full.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: bound mode sysfs output to the sysfs buffer\n\nmode_string() uses snprintf() which can return a value larger than the\nremaining buffer space. show_modes() accumulates the return value into i\nwithout checking whether i has reached PAGE_SIZE, causing the offset to\nadvance past the sysfs buffer if the modelist is long enough.\n\nAdd a size parameter to mode_string() and use scnprintf() to return\nonly the bytes actually written. Add an early return when offset\nalready exceeds the buffer. In show_modes(), stop accumulating once\nthe buffer is full.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.01552 |
debian: CVE-2026-80580 was patched at 2026-09-16
1756.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80583) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses The "DEC0 MODE" to "DEC7 MODE" controls are enumerated, but tx_macro_dec_mode_get() and tx_macro_dec_mode_put() access their value through ucontrol->value.integer.value[0] (a long) instead of ucontrol->value.enumerated.item[0] (an unsigned int). This same pattern was fixed in the sibling drivers by commit bcfe5f76cc40 ("ASoC: codecs: rx-macro: fix accessing array out of bounds for enum type") and commit 0ea5eff7c606 ("ASoC: codecs: va-macro: fix accessing array out of bounds for enum type"), but tx-macro was missed. On 64-bit kernels built with CONFIG_SND_CTL_DEBUG, the elem value sanity check catches the 4 bytes written past the enumerated item and every read of these controls fails with -EINVAL: snd-sm8250 sound: control 2:0:0:DEC0 MODE:0: access overflow', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses\n\nThe "DEC0 MODE" to "DEC7 MODE" controls are enumerated, but\ntx_macro_dec_mode_get() and tx_macro_dec_mode_put() access their\nvalue through ucontrol->value.integer.value[0] (a long) instead of\nucontrol->value.enumerated.item[0] (an unsigned int).\n\nThis same pattern was fixed in the sibling drivers by\ncommit bcfe5f76cc40 ("ASoC: codecs: rx-macro: fix accessing array\nout of bounds for enum type") and\ncommit 0ea5eff7c606 ("ASoC: codecs: va-macro: fix accessing array\nout of bounds for enum type"), but tx-macro was missed.\n\nOn 64-bit kernels built with CONFIG_SND_CTL_DEBUG, the elem value\nsanity check catches the 4 bytes written past the enumerated item\nand every read of these controls fails with -EINVAL:\n\n snd-sm8250 sound: control 2:0:0:DEC0 MODE:0: access overflow', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02102 |
debian: CVE-2026-80583 was patched at 2026-08-29, 2026-09-16
1757.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80584) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: s390/qeth: validate user buffer length in SNMP and ARP query ioctls qeth_snmp_command() and qeth_l3_arp_query() allocate a buffer sized by a user-supplied length (udata_len) without checking a lower bound, then set udata_offset to a fixed non-zero value and pass both to a reply callback. The callback bounds-checks the copy with if ((udata_len - udata_offset) < len) Both fields are u32, so a udata_len smaller than udata_offset makes the subtraction wrap and the check pass, and the following memcpy() writes past the allocation. A udata_len of 0 also yields ZERO_SIZE_PTR from kzalloc(), which the existing NULL check does not catch. Reject buffers smaller than udata_offset before allocating, so the callback subtraction can no longer underflow.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/qeth: validate user buffer length in SNMP and ARP query ioctls\n\nqeth_snmp_command() and qeth_l3_arp_query() allocate a buffer sized by\na user-supplied length (udata_len) without checking a lower bound, then\nset udata_offset to a fixed non-zero value and pass both to a reply\ncallback. The callback bounds-checks the copy with\n\n if ((udata_len - udata_offset) < len)\n\nBoth fields are u32, so a udata_len smaller than udata_offset makes the\nsubtraction wrap and the check pass, and the following memcpy() writes\npast the allocation. A udata_len of 0 also yields ZERO_SIZE_PTR from\nkzalloc(), which the existing NULL check does not catch.\n\nReject buffers smaller than udata_offset before allocating, so the\ncallback subtraction can no longer underflow.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.03261 |
debian: CVE-2026-80584 was patched at 2026-09-16
1758.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80591) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: f2fs: fix listxattr handling of corrupted xattr entries Validate the xattr entry before reading its fields in f2fs_listxattr(). Return -EFSCORRUPTED when the entry is outside the valid xattr storage area instead of returning a successful partial result.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix listxattr handling of corrupted xattr entries\n\nValidate the xattr entry before reading its fields in f2fs_listxattr().\nReturn -EFSCORRUPTED when the entry is outside the valid xattr storage\narea instead of returning a successful partial result.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02909 |
debian: CVE-2026-80591 was patched at 2026-09-16
ubuntu: CVE-2026-80591 was patched at 2026-09-07, 2026-09-16
1759.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80596) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - only expose sysfs attributes on control interface When the driver was converted to use the driver core to instantiate device attributes (via .dev_groups in the usb_driver structure), the attributes started appearing on all interfaces bound to the driver. Since the ims-pcu driver manually claims the secondary data interface during probe, the driver core automatically creates the sysfs attributes for that interface as well. However, the driver only supports these attributes on the primary control interface. Data interfaces lack the necessary descriptors and internal state to handle these requests, and accessing them can lead to unexpected behavior or crashes. Fix this by updating the is_visible() callbacks for both the main and OFN attribute groups to verify that the interface being accessed is indeed the control interface.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ims-pcu - only expose sysfs attributes on control interface\n\nWhen the driver was converted to use the driver core to instantiate device\nattributes (via .dev_groups in the usb_driver structure), the attributes\nstarted appearing on all interfaces bound to the driver. Since the ims-pcu\ndriver manually claims the secondary data interface during probe, the\ndriver core automatically creates the sysfs attributes for that interface\nas well.\n\nHowever, the driver only supports these attributes on the primary control\ninterface. Data interfaces lack the necessary descriptors and internal\nstate to handle these requests, and accessing them can lead to unexpected\nbehavior or crashes.\n\nFix this by updating the is_visible() callbacks for both the main and OFN\nattribute groups to verify that the interface being accessed is indeed the\ncontrol interface.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04026 |
debian: CVE-2026-80596 was patched at 2026-09-16
1760.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80613) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: veth: fix NAPI leak in XDP enable error path During XDP enablement in veth, if xdp_rxq_info_reg() or xdp_rxq_info_reg_mem_model() fails, the driver rolls back the changes. However, the rollback loop: \tfor (i--; i >= start; i--) { decrements the loop index 'i' before the first iteration. This correctly skips unregistering the rxq for the failed index 'i' (as registration failed or was already cleaned up), but it also erroneously skips calling netif_napi_deli() for rq[i].xdp_napi. Since netif_napi_add() was already called for index 'i', this leaves a dangling napi_struct in the device's napi_list. When the veth device is later destroyed, the freed queue memory (which contains the leaked NAPI structure) can be reused. The subsequent device teardown iterates the NAPI list and corrupts the reallocated memory, leading to UAF. Fix this by explicitly deleting the NAPI association for the failed index 'i' before rolling back the successfully configured queues.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nveth: fix NAPI leak in XDP enable error path\n\nDuring XDP enablement in veth, if xdp_rxq_info_reg() or\nxdp_rxq_info_reg_mem_model() fails, the driver rolls back the changes.\n\nHowever, the rollback loop:\n\tfor (i--; i >= start; i--) {\n\ndecrements the loop index 'i' before the first iteration. This\ncorrectly skips unregistering the rxq for the failed index 'i' (as\nregistration failed or was already cleaned up), but it also\nerroneously skips calling netif_napi_deli() for rq[i].xdp_napi.\n\nSince netif_napi_add() was already called for index 'i', this leaves\na dangling napi_struct in the device's napi_list. When the veth\ndevice is later destroyed, the freed queue memory (which contains the\nleaked NAPI structure) can be reused.\n\nThe subsequent device teardown iterates the NAPI list and\ncorrupts the reallocated memory, leading to UAF.\n\nFix this by explicitly deleting the NAPI association for the failed\nindex 'i' before rolling back the successfully configured queues.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02905 |
debian: CVE-2026-80613 was patched at 2026-09-16
oraclelinux: CVE-2026-80613 was patched at 2026-09-04
redos: CVE-2026-80613 was patched at 2026-09-16
1761.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80619) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: apparmor: fix potential UAF in aa_replace_profiles The function aa_replace_profiles was accessing udata->size after calling aa_put_loaddata(udata), causing a potential UAF. Fixed this by saving the size to a local variable before dropping the reference.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix potential UAF in aa_replace_profiles\n\nThe function aa_replace_profiles was accessing udata->size after calling\naa_put_loaddata(udata), causing a potential UAF.\n\nFixed this by saving the size to a local variable before dropping the\nreference.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02908 |
debian: CVE-2026-80619 was patched at 2026-09-16
redos: CVE-2026-80619 was patched at 2026-09-16
1762.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80628) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: oss: Serialize readq reset state with q->lock snd_seq_oss_readq_clear() resets qlen, head, and tail without q->lock even though the normal reader and producer paths serialize the same ring state under that spinlock. A reset can therefore race snd_seq_oss_readq_free() or snd_seq_oss_readq_put_event() and leave stale records in the queue, drop freshly queued ones, or report the wrong readiness after wakeup. KCSAN reports a data race between snd_seq_oss_readq_clear() and snd_seq_oss_readq_free(). Take q->lock while clearing the ring and resetting input_time. Factor the enqueue logic into a caller-locked helper so snd_seq_oss_readq_put_timestamp() updates its suppression state under the same lock instead of racing the reset path. The buggy scenario involves two paths, with each column showing the order within that path: reset path: locked readq updater: 1. snd_seq_oss_reset() or 1. A reader or callback producer release reaches takes q->lock on the same queue. snd_seq_oss_readq_clear(). 2. snd_seq_oss_readq_clear() 2. The updater tests or modifies resets qlen, head, tail, qlen, head, and tail. and input_time. 3. snd_seq_oss_readq_clear() 3. The updater completes its wakes sleepers on read-modify-write sequence. q->midi_sleep. 4. Without q->lock, the reset 4. The resulting ring state drives can overlap the locked later reads and readiness. update. KCSAN reports: BUG: KCSAN: data-race in snd_seq_oss_readq_clear / snd_seq_oss_readq_free write to 0xffff8881069fe608 of 4 bytes by task 120516 on cpu 0: snd_seq_oss_readq_free+0x6c/0x80 snd_seq_oss_read+0xcb/0x250 odev_read+0x38/0x60 vfs_read+0xff/0x600 ksys_read+0xb4/0x140 __x64_sys_read+0x46/0x60 do_syscall_64+0xbb/0x2f0 entry_SYSCALL_64_after_hwframe+0x77/0x7f read to 0xffff8881069fe608 of 4 bytes by task 120517 on cpu 1: snd_seq_oss_readq_clear+0x1f/0x90 snd_seq_oss_reset+0xa7/0xf0 snd_seq_oss_ioctl+0x6f6/0x7e0 odev_ioctl+0x56/0xc0 __x64_sys_ioctl+0xd1/0x120 do_syscall_64+0xbb/0x2f0 entry_SYSCALL_64_after_hwframe+0x77/0x7f value changed: 0x00000001 -> 0x00000000', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: oss: Serialize readq reset state with q->lock\n\nsnd_seq_oss_readq_clear() resets qlen, head, and tail without\nq->lock even though the normal reader and producer paths serialize the\nsame ring state under that spinlock. A reset can therefore race\nsnd_seq_oss_readq_free() or snd_seq_oss_readq_put_event() and leave\nstale records in the queue, drop freshly queued ones, or report the\nwrong readiness after wakeup. KCSAN reports a data race between\nsnd_seq_oss_readq_clear() and snd_seq_oss_readq_free().\n\nTake q->lock while clearing the ring and resetting input_time. Factor\nthe enqueue logic into a caller-locked helper so\nsnd_seq_oss_readq_put_timestamp() updates its suppression state under\nthe same lock instead of racing the reset path.\n\nThe buggy scenario involves two paths, with each column showing the\norder within that path:\n\nreset path: locked readq updater:\n1. snd_seq_oss_reset() or 1. A reader or callback producer\n release reaches takes q->lock on the same queue.\n snd_seq_oss_readq_clear().\n2. snd_seq_oss_readq_clear() 2. The updater tests or modifies\n resets qlen, head, tail, qlen, head, and tail.\n and input_time.\n3. snd_seq_oss_readq_clear() 3. The updater completes its\n wakes sleepers on read-modify-write sequence.\n q->midi_sleep.\n4. Without q->lock, the reset 4. The resulting ring state drives\n can overlap the locked later reads and readiness.\n update.\n\nKCSAN reports:\n\nBUG: KCSAN: data-race in snd_seq_oss_readq_clear /\nsnd_seq_oss_readq_free\n\nwrite to 0xffff8881069fe608 of 4 bytes by task 120516 on cpu 0:\n snd_seq_oss_readq_free+0x6c/0x80\n snd_seq_oss_read+0xcb/0x250\n odev_read+0x38/0x60\n vfs_read+0xff/0x600\n ksys_read+0xb4/0x140\n __x64_sys_read+0x46/0x60\n do_syscall_64+0xbb/0x2f0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nread to 0xffff8881069fe608 of 4 bytes by task 120517 on cpu 1:\n snd_seq_oss_readq_clear+0x1f/0x90\n snd_seq_oss_reset+0xa7/0xf0\n snd_seq_oss_ioctl+0x6f6/0x7e0\n odev_ioctl+0x56/0xc0\n __x64_sys_ioctl+0xd1/0x120\n do_syscall_64+0xbb/0x2f0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nvalue changed: 0x00000001 -> 0x00000000', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00127, EPSS Percentile is 0.02716 |
debian: CVE-2026-80628 was patched at 2026-09-16
1763.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80649) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix OOB in scmi_power_name_get() scmi_power_name_get() does not validate the domain number passed by the external caller, which may lead to an out-of-bounds access. Fix this by returning "unknown" for invalid domains, like scmi_reset_name_get() does.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Fix OOB in scmi_power_name_get()\n\nscmi_power_name_get() does not validate the domain number passed by the\nexternal caller, which may lead to an out-of-bounds access.\n\nFix this by returning "unknown" for invalid domains, like\nscmi_reset_name_get() does.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02906 |
debian: CVE-2026-80649 was patched at 2026-09-16
redos: CVE-2026-80649 was patched at 2026-09-16
1764.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80653) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: scsi: hisi_sas: Add slave_destroy interface for v3 hw WARNING is triggered when executing link reset of remote PHY and rmmod SAS driver simultaneously. Following is the WARNING log: WARNING: CPU: 61 PID: 21818 at drivers/base/core.c:1347 __device_links_no_driver+0xb4/0xc0 Call trace: __device_links_no_driver+0xb4/0xc0 device_links_driver_cleanup+0xb0/0xfc __device_release_driver+0x198/0x23c device_release_driver+0x38/0x50 bus_remove_device+0x130/0x140 device_del+0x184/0x434 __scsi_remove_device+0x118/0x150 scsi_remove_target+0x1bc/0x240 sas_rphy_remove+0x90/0x94 sas_rphy_delete+0x24/0x3c sas_destruct_devices+0x64/0xa0 [libsas] sas_revalidate_domain+0xe4/0x150 [libsas] process_one_work+0x1e0/0x46c worker_thread+0x15c/0x464 kthread+0x160/0x170 ret_from_fork+0x10/0x20 ---[ end trace 71e059eb58f85d4a ]--- During SAS phy up, link->status is set to DL_STATE_AVAILABLE in device_links_driver_bound, then this setting influences __device_links_no_driver() before driver rmmod and caused WARNING. Add the slave_destroy interface to make sure link is removed after flush workque.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: hisi_sas: Add slave_destroy interface for v3 hw\n\nWARNING is triggered when executing link reset of remote PHY and rmmod\nSAS driver simultaneously. Following is the WARNING log:\n\nWARNING: CPU: 61 PID: 21818 at drivers/base/core.c:1347 __device_links_no_driver+0xb4/0xc0\n Call trace:\n __device_links_no_driver+0xb4/0xc0\n device_links_driver_cleanup+0xb0/0xfc\n __device_release_driver+0x198/0x23c\n device_release_driver+0x38/0x50\n bus_remove_device+0x130/0x140\n device_del+0x184/0x434\n __scsi_remove_device+0x118/0x150\n scsi_remove_target+0x1bc/0x240\n sas_rphy_remove+0x90/0x94\n sas_rphy_delete+0x24/0x3c\n sas_destruct_devices+0x64/0xa0 [libsas]\n sas_revalidate_domain+0xe4/0x150 [libsas]\n process_one_work+0x1e0/0x46c\n worker_thread+0x15c/0x464\n kthread+0x160/0x170\n ret_from_fork+0x10/0x20\n ---[ end trace 71e059eb58f85d4a ]---\n\nDuring SAS phy up, link->status is set to DL_STATE_AVAILABLE in\ndevice_links_driver_bound, then this setting influences\n__device_links_no_driver() before driver rmmod and caused WARNING.\n\nAdd the slave_destroy interface to make sure link is removed after flush\nworkque.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.03881 |
debian: CVE-2026-80653 was patched at 2026-09-16
1765.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80677) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() dev_has_sync_state() reads dev->driver twice without holding device_lock() -- once for the NULL check and once to dereference ->sync_state. Some callers only hold device_links_write_lock, which doesn't prevent a concurrent unbind from clearing dev->driver via device_unbind_cleanup(). Fix it by reading dev->driver exactly once with READ_ONCE(), pairing with the WRITE_ONCE() in device_set_driver().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: use READ_ONCE() for dev->driver in dev_has_sync_state()\n\ndev_has_sync_state() reads dev->driver twice without holding\ndevice_lock() -- once for the NULL check and once to dereference\n->sync_state. Some callers only hold device_links_write_lock, which\ndoesn't prevent a concurrent unbind from clearing dev->driver via\ndevice_unbind_cleanup().\n\nFix it by reading dev->driver exactly once with READ_ONCE(), pairing\nwith the WRITE_ONCE() in device_set_driver().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02905 |
debian: CVE-2026-80677 was patched at 2026-09-16
oraclelinux: CVE-2026-80677 was patched at 2026-09-04
redos: CVE-2026-80677 was patched at 2026-09-16
1766.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80680) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: i2c: amd-mp2: Unregister callback on adapter add failure amd_mp2_register_cb() stores the platform I2C context in the MP2 PCI driver's callback table before the adapter is registered. If i2c_add_adapter() fails, probe returns and devres frees the context, but the PCI driver can still dereference the stale pointer from its IRQ and system-sleep callbacks. Unregister the callback before returning the adapter registration error.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: amd-mp2: Unregister callback on adapter add failure\n\namd_mp2_register_cb() stores the platform I2C context in the MP2 PCI\ndriver's callback table before the adapter is registered. If\ni2c_add_adapter() fails, probe returns and devres frees the context,\nbut the PCI driver can still dereference the stale pointer from its IRQ\nand system-sleep callbacks.\n\nUnregister the callback before returning the adapter registration error.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02906 |
debian: CVE-2026-80680 was patched at 2026-09-16
1767.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80696) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: hwmon: (ltc4282) Fix reading the minimum alarm voltage Coverity reports an out-of-bounds access when reading the minimum alarm voltage for the VGPIO channel. Add the missing return statement to fix the problem.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (ltc4282) Fix reading the minimum alarm voltage\n\nCoverity reports an out-of-bounds access when reading the minimum alarm\nvoltage for the VGPIO channel. Add the missing return statement to fix\nthe problem.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02853 |
debian: CVE-2026-80696 was patched at 2026-09-16
1768.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80700) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: validate external BO copy bounds for both stride paths vmw_external_bo_copy() trusts caller-supplied offsets, strides, and heights and operates on imported dma-buf vmaps: - The equal-stride memcpy() bound was clamped after subtracting the offsets from dst_size and src_size; an offset larger than the BO size wraps the unsigned subtraction to a huge value and the resulting memcpy() runs off the end of the vmap. dst_stride * height is also a u32 multiplication that can overflow. - The non-equal-stride row-by-row path had no bound at all. The loop touches bytes through offset + (height - 1) * stride + width_in_bytes, with only a WARN_ON(dst_stride < width_in_bytes), and could likewise step past the end of either mapping. The offsets and strides are derived from STDU/SOU plane state, so a configured CRTC submitting a crafted atomic commit on an imported framebuffer can reach this path. Validate the exact row-copy endpoint against each BO's size up front using check_mul_overflow() and check_add_overflow(). Use the bulk memcpy() path only when width_in_bytes covers the whole stride; otherwise copy one row at a time so partial-row updates near the bottom of a framebuffer remain valid. Also reject zero strides and stride < width_in_bytes, both of which the row-by-row path cannot represent safely.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: validate external BO copy bounds for both stride paths\n\nvmw_external_bo_copy() trusts caller-supplied offsets, strides, and\nheights and operates on imported dma-buf vmaps:\n\n - The equal-stride memcpy() bound was clamped after subtracting the\n offsets from dst_size and src_size; an offset larger than the BO\n size wraps the unsigned subtraction to a huge value and the\n resulting memcpy() runs off the end of the vmap. dst_stride *\n height is also a u32 multiplication that can overflow.\n - The non-equal-stride row-by-row path had no bound at all. The\n loop touches bytes through offset + (height - 1) * stride +\n width_in_bytes, with only a WARN_ON(dst_stride < width_in_bytes),\n and could likewise step past the end of either mapping.\n\nThe offsets and strides are derived from STDU/SOU plane state, so a\nconfigured CRTC submitting a crafted atomic commit on an imported\nframebuffer can reach this path.\n\nValidate the exact row-copy endpoint against each BO's size up front\nusing check_mul_overflow() and check_add_overflow(). Use the bulk\nmemcpy() path only when width_in_bytes covers the whole stride;\notherwise copy one row at a time so partial-row updates near the bottom\nof a framebuffer remain valid. Also reject zero strides and stride <\nwidth_in_bytes, both of which the row-by-row path cannot represent\nsafely.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02852 |
debian: CVE-2026-80700 was patched at 2026-09-16
1769.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80702) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size Two sites in vmwgfx_resource.c assign boolean literals to res->guest_memory_size, which is an unsigned long allocation-size field; the intended target is the adjacent res->guest_memory_dirty bitfield. After the assignments the field holds 0 or 1 instead of the resource's MOB allocation size: - vmw_resource_release() writes 0 (false), and - vmw_resource_unbind_list() writes 1 (true). Subsequent revalidation paths read guest_memory_size when computing the dirty page range (vmw_bo_dirty_transfer_to_res()) and the buffer allocation size (vmw_resource_buf_alloc()), producing zero-length walks or wrap-around ranges that read or write past the MOB bitmap. The dirty-tracking intent of the original code (mark the resource as dirtied since the last sync) is also lost, since guest_memory_dirty is never updated. Rename both assignments to guest_memory_dirty.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size\n\nTwo sites in vmwgfx_resource.c assign boolean literals to\nres->guest_memory_size, which is an unsigned long allocation-size\nfield; the intended target is the adjacent res->guest_memory_dirty\nbitfield. After the assignments the field holds 0 or 1 instead of\nthe resource's MOB allocation size:\n\n - vmw_resource_release() writes 0 (false), and\n - vmw_resource_unbind_list() writes 1 (true).\n\nSubsequent revalidation paths read guest_memory_size when computing\nthe dirty page range (vmw_bo_dirty_transfer_to_res()) and the buffer\nallocation size (vmw_resource_buf_alloc()), producing zero-length\nwalks or wrap-around ranges that read or write past the MOB bitmap.\nThe dirty-tracking intent of the original code (mark the resource as\ndirtied since the last sync) is also lost, since guest_memory_dirty\nis never updated.\n\nRename both assignments to guest_memory_dirty.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02853 |
debian: CVE-2026-80702 was patched at 2026-09-16
1770.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80706) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: can: softing: fw_parse(): validate firmware record spans fw_parse() reads a fixed record header, a firmware-provided payload, and a trailing checksum without knowing the end of the firmware blob. A truncated record can therefore make those reads exceed the blob. The same record also supplies addresses and lengths for writes into DPRAM. The generic loader uses wrap-prone mixed signed arithmetic for its bounds check, while the application loader does not bound the staging copy at all. Pass the firmware end to the parser and validate the full source record. Use a signed wide offset for generic DPRAM records and validate the application staging span against the mapped DPRAM before copying.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncan: softing: fw_parse(): validate firmware record spans\n\nfw_parse() reads a fixed record header, a firmware-provided payload,\nand a trailing checksum without knowing the end of the firmware blob. A\ntruncated record can therefore make those reads exceed the blob.\n\nThe same record also supplies addresses and lengths for writes into\nDPRAM. The generic loader uses wrap-prone mixed signed arithmetic for its\nbounds check, while the application loader does not bound the staging\ncopy at all.\n\nPass the firmware end to the parser and validate the full source record.\nUse a signed wide offset for generic DPRAM records and validate the\napplication staging span against the mapped DPRAM before copying.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02104 |
debian: CVE-2026-80706 was patched at 2026-09-16
oraclelinux: CVE-2026-80706 was patched at 2026-09-04
1771.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80709) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs There is a wrong upper limit check for the domain value when an EP11 CPRB is processed for sending to a crypto card. This check is only active on custom device nodes but may lead to access heap memory behind perms->adm when an administrative CPRB is sent. Add correct limit (AP_DOMAINS = 256) checking to fix this.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/zcrypt: Fix wrong domain value verification with EP11 CPRBs\n\nThere is a wrong upper limit check for the domain value when an EP11\nCPRB is processed for sending to a crypto card. This check is only\nactive on custom device nodes but may lead to access heap memory\nbehind perms->adm when an administrative CPRB is sent.\nAdd correct limit (AP_DOMAINS = 256) checking to fix this.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02103 |
debian: CVE-2026-80709 was patched at 2026-09-16
1772.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80710) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Fix undersized format-check buffer fmt_buffer_size in dasd_eckd_check_device_format() is declared as int, even though one of the multiplicands, sizeof(struct eckd_count), is a size_t. The expression trkcount * rpt_max * sizeof(struct eckd_count) is therefore correctly evaluated at 64-bit width, but the result is silently truncated when it is stored back into the 32-bit fmt_buffer_size variable. For a sufficiently large track range (start_unit/stop_unit are caller-controlled) this truncation yields a buffer size far smaller than the number of tracks actually requested. kzalloc() then succeeds with an undersized allocation, while the subsequent channel program build still operates on the untruncated track count and writes past the end of that buffer. Compute the buffer size with check_mul_overflow() and keep it in a size_t, so that a value that no longer fits results in -EINVAL instead of a silently truncated allocation size.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/dasd: Fix undersized format-check buffer\n\nfmt_buffer_size in dasd_eckd_check_device_format() is declared as\nint, even though one of the multiplicands, sizeof(struct eckd_count),\nis a size_t. The expression\n\n trkcount * rpt_max * sizeof(struct eckd_count)\n\nis therefore correctly evaluated at 64-bit width, but the result is\nsilently truncated when it is stored back into the 32-bit\nfmt_buffer_size variable. For a sufficiently large track range\n(start_unit/stop_unit are caller-controlled) this truncation\nyields a buffer size far smaller than the number of tracks actually\nrequested. kzalloc() then succeeds with an undersized allocation,\nwhile the subsequent channel program build still operates on the\nuntruncated track count and writes past the end of that buffer.\n\nCompute the buffer size with check_mul_overflow() and keep it in a\nsize_t, so that a value that no longer fits results in -EINVAL\ninstead of a silently truncated allocation size.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02057 |
debian: CVE-2026-80710 was patched at 2026-09-16
1773.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80716) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: wake linked drain waiters on unlink snd_pcm_drain() on a linked stream parks an on-stack wait entry on the drained peer's runtime->sleep, and after schedule_timeout() removes it only if that peer is still found in the caller's group. If group membership changes during the wait and the sleep ends by signal or timeout (so autoremove_wake_function() does not run), finish_wait() is skipped and snd_pcm_drain() returns with the entry still queued on that stream's sleep list; a later wake_up() then walks a freed stack frame. This is reachable by unlinking either the drained or the draining stream. Unlike the close path (snd_pcm_drop() -> snd_pcm_post_stop()), snd_pcm_unlink() never wakes the sleep queues. Wake every group member under the group lock before the membership change, so a linked drainer is released and drops its entry while the streams are still grouped. The window was opened when snd_pcm_link_rwsem stopped being held across the wait and the removal became conditional on group membership (see Fixes). The later switch to finish_wait() kept that conditional removal, so the signal/timeout case remained.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: wake linked drain waiters on unlink\n\nsnd_pcm_drain() on a linked stream parks an on-stack wait entry on the\ndrained peer's runtime->sleep, and after schedule_timeout() removes it\nonly if that peer is still found in the caller's group. If group\nmembership changes during the wait and the sleep ends by signal or\ntimeout (so autoremove_wake_function() does not run), finish_wait() is\nskipped and snd_pcm_drain() returns with the entry still queued on that\nstream's sleep list; a later wake_up() then walks a freed stack frame.\nThis is reachable by unlinking either the drained or the draining stream.\n\nUnlike the close path (snd_pcm_drop() -> snd_pcm_post_stop()),\nsnd_pcm_unlink() never wakes the sleep queues. Wake every group member\nunder the group lock before the membership change, so a linked drainer is\nreleased and drops its entry while the streams are still grouped.\n\nThe window was opened when snd_pcm_link_rwsem stopped being held across\nthe wait and the removal became conditional on group membership (see\nFixes). The later switch to finish_wait() kept that conditional removal,\nso the signal/timeout case remained.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02102 |
debian: CVE-2026-80716 was patched at 2026-09-16
oraclelinux: CVE-2026-80716 was patched at 2026-09-04
1774.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80718) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() In pcpu_create_chunk(), nr_pages is the total contiguous backing allocation, i.e., nr_units * pcpu_unit_pages, but pcpu_chunk_populated() uses it to set chunk->populated, whose size is pcpu_unit_pages, bitmap. Since bit N in chunk->populated means page offset N inside every unit is backed. When nr_units > 1, the function writes beyond chunk->populated. Fix it by using chunk->nr_pages. It also fixes the global pcpu_nr_empty_pop_pages accounting, since pcpu_balance_free() only iterates up to chunk->nr_pages. Commit a63d4ac4ab609 ("percpu: make percpu-km set chunk->populated bitmap properly") introduced the bitmap overflow issue. Later, commit b539b87fed37f ("percpu: implmeent pcpu_nr_empty_pop_pages and chunk->nr_populated") added pcpu_nr_empty_pop_pages and caused the accounting issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()\n\nIn pcpu_create_chunk(), nr_pages is the total contiguous backing\nallocation, i.e., nr_units * pcpu_unit_pages, but pcpu_chunk_populated()\nuses it to set chunk->populated, whose size is pcpu_unit_pages, bitmap. \nSince bit N in chunk->populated means page offset N inside every unit is\nbacked. When nr_units > 1, the function writes beyond chunk->populated. \nFix it by using chunk->nr_pages.\n\nIt also fixes the global pcpu_nr_empty_pop_pages accounting, since\npcpu_balance_free() only iterates up to chunk->nr_pages.\n\nCommit a63d4ac4ab609 ("percpu: make percpu-km set chunk->populated bitmap\nproperly") introduced the bitmap overflow issue. Later, commit\nb539b87fed37f ("percpu: implmeent pcpu_nr_empty_pop_pages and\nchunk->nr_populated") added pcpu_nr_empty_pop_pages and caused the\naccounting issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02103 |
debian: CVE-2026-80718 was patched at 2026-09-16
1775.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80723) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: of: reserved_mem: prevent OOB when too many dynamic regions are defined On boot, fdt_scan_reserved_mem() saves each dynamically-placed /reserved-memory subnode into a local array of size MAX_RESERVED_REGIONS. If the device tree defines more than MAX_RESERVED_REGIONS dynamically-placed regions, fdt_scan_reserved_mem() writes past the end of the local array. Add a bounds check that logs an error and skips the excess regions, restoring the original behavior.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nof: reserved_mem: prevent OOB when too many dynamic regions are defined\n\nOn boot, fdt_scan_reserved_mem() saves each dynamically-placed\n/reserved-memory subnode into a local array of size\nMAX_RESERVED_REGIONS.\n\nIf the device tree defines more than MAX_RESERVED_REGIONS\ndynamically-placed regions, fdt_scan_reserved_mem() writes past the\nend of the local array.\n\nAdd a bounds check that logs an error and skips the excess regions,\nrestoring the original behavior.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.03261 |
debian: CVE-2026-80723 was patched at 2026-09-16
1776.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80749) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/connector/hdmi: Fix out of bounds memory read A helper function was copying a given audio infoframe into the connector's copy but using the size of the destination (a generic target, sized to accept many different data blocks) not the source (a very specific type of data block). Thus, it was copying 60 bytes of data from a 28 byte allocation. Fix that by using the source size instead, together with a build bug on the source size actually being smaller than the destination. I hit this running KUnit tests under KASAN (while debugging something else entirely). In the real world, it seems unlikely to cause an actual problem. It is a read not a write so it can't corrupt any memory. However, it could potentially fall off the end of a page and cause an accvio bug.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/connector/hdmi: Fix out of bounds memory read\n\nA helper function was copying a given audio infoframe into the\nconnector's copy but using the size of the destination (a generic\ntarget, sized to accept many different data blocks) not the source (a\nvery specific type of data block). Thus, it was copying 60 bytes of\ndata from a 28 byte allocation.\n\nFix that by using the source size instead, together with a build bug\non the source size actually being smaller than the destination.\n\nI hit this running KUnit tests under KASAN (while debugging something\nelse entirely). In the real world, it seems unlikely to cause an\nactual problem. It is a read not a write so it can't corrupt any\nmemory. However, it could potentially fall off the end of a page and\ncause an accvio bug.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05438 |
debian: CVE-2026-80749 was patched at 2026-09-16
1777.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80928) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: smack: fix cred UAF in smack_file_send_sigiotask() When inspecting the credentials of another task, objective credentials (->real_cred, accessed with __task_cred()) must always be used. Accessing ->cred on a non-current task is forbidden unless that task is being created or destroyed; a task is allowed to change its own ->cred pointer with no synchronization, and changing ->cred should only affect the current syscall. smack_file_send_sigiotask() was accessing both sets of credentials: First tsk->cred, then __task_cred(tsk). Fix it, always access the objective credentials here. I have tested that this bug can lead to a KASAN-reported UAF of struct cred in smack_file_send_sigiotask(), and that this fix prevents the race.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsmack: fix cred UAF in smack_file_send_sigiotask()\n\nWhen inspecting the credentials of another task, objective credentials\n(->real_cred, accessed with __task_cred()) must always be used.\n\nAccessing ->cred on a non-current task is forbidden unless that task is\nbeing created or destroyed; a task is allowed to change its own ->cred\npointer with no synchronization, and changing ->cred should only affect the\ncurrent syscall.\n\nsmack_file_send_sigiotask() was accessing both sets of credentials: First\ntsk->cred, then __task_cred(tsk).\n\nFix it, always access the objective credentials here.\n\nI have tested that this bug can lead to a KASAN-reported UAF of struct cred\nin smack_file_send_sigiotask(), and that this fix prevents the race.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.0291 |
debian: CVE-2026-80928 was patched at 2026-09-16
1778.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80931) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: w1: ds28e17: reject an oversize length on an I2C block read w1_f19_i2c_master_transfer() is the master_xfer for the DS28E17 1-Wire to I2C bridge. On an I2C_M_RECV_LEN read, it takes the length from the device. The downstream slave puts a length byte in buf[0]. The driver then reads that many bytes into buf[1] with w1_f19_i2c_read(). buf[0] is controlled by the device and can be 0 to 255. w1_f19_i2c_read() only rejects a zero count. The caller buffer is I2C_SMBUS_BLOCK_MAX + 2, so 34 bytes. A length above 32 makes the read run past it, up to about 222 bytes out of bounds. The SMBus core does check buf[0] against I2C_SMBUS_BLOCK_MAX. That check runs after master_xfer returns. By then the write is already done. i2c-algo-bit rejects an oversize length before it copies, and returns -EPROTO. Reject a length above I2C_SMBUS_BLOCK_MAX at both RECV_LEN sites, the same way i2c-algo-bit does.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nw1: ds28e17: reject an oversize length on an I2C block read\n\nw1_f19_i2c_master_transfer() is the master_xfer for the DS28E17 1-Wire\nto I2C bridge. On an I2C_M_RECV_LEN read, it takes the length from the\ndevice. The downstream slave puts a length byte in buf[0]. The driver\nthen reads that many bytes into buf[1] with w1_f19_i2c_read().\n\nbuf[0] is controlled by the device and can be 0 to 255.\nw1_f19_i2c_read() only rejects a zero count. The caller buffer is\nI2C_SMBUS_BLOCK_MAX + 2, so 34 bytes. A length above 32 makes the read\nrun past it, up to about 222 bytes out of bounds.\n\nThe SMBus core does check buf[0] against I2C_SMBUS_BLOCK_MAX. That\ncheck runs after master_xfer returns. By then the write is already\ndone. i2c-algo-bit rejects an oversize length before it copies, and\nreturns -EPROTO.\n\nReject a length above I2C_SMBUS_BLOCK_MAX at both RECV_LEN sites, the\nsame way i2c-algo-bit does.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02908 |
debian: CVE-2026-80931 was patched at 2026-09-16
1779.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80933) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: validate default EEPROM firmware size The default EEPROM firmware is parsed and copied as a full EEPROM without checking its length. A truncated file can make the driver read beyond the firmware buffer during variant validation or the fallback copy. Reject files shorter than MT7996_EEPROM_SIZE before parsing or copying the firmware.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7996: validate default EEPROM firmware size\n\nThe default EEPROM firmware is parsed and copied as a full EEPROM\nwithout checking its length. A truncated file can make the driver\nread beyond the firmware buffer during variant validation or the\nfallback copy.\n\nReject files shorter than MT7996_EEPROM_SIZE before parsing or\ncopying the firmware.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.0285 |
debian: CVE-2026-80933 was patched at 2026-09-16
1780.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80944) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Detach sync cmd buffer on interrupted wait mwifiex synchronous commands keep the caller-provided data buffer in cmd_node->data_buf. Several callers pass stack-allocated objects there. If wait_event_interruptible_timeout() is interrupted, the caller can return and release that stack object while the firmware command is still the current command. A late firmware response then reaches the normal response handler, which can copy data through cmd_node->data_buf into the stale stack address. This fixes a stack corruption observed during repeated association and disassociation cycles. The panic trace showed the command wait being interrupted immediately before a bad pointer dereference: cmd_wait_q terminated: -512 Unable to handle kernel paging request at virtual address 002c583837384662 Kernel panic - not syncing: stack-protector: Kernel stack is corrupted ... Tainted: [M]=MACHINE_CHECK The fault address decodes as little-endian ASCII: 0x002c583837384662 -> "bF878X,\\0" which is a fragment of the VERSION_EXT firmware string exposed as debugfs "verext": w8997o-V4, RF878X, FP92, 16.92.21.p153.7 The same runs also showed corrupted control data containing: 0x2400372e333531 -> "153.7\\0$" which is the tail of the same VERSION_EXT string. This points at a late VERSION_EXT response writing through a stale stack-backed data_buf after the interrupted wait returned. After cancelling pending commands on an interrupted or timed-out wait, detach the caller-owned data buffer from the still-current command. This preserves the existing command cancellation behaviour while preventing a late response from writing through a pointer whose lifetime ended with the waiting caller. Tested on an i.MX8MP board using an 88W8997.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: Detach sync cmd buffer on interrupted wait\n\nmwifiex synchronous commands keep the caller-provided data buffer in\ncmd_node->data_buf. Several callers pass stack-allocated objects there.\n\nIf wait_event_interruptible_timeout() is interrupted, the caller can\nreturn and release that stack object while the firmware command is still\nthe current command. A late firmware response then reaches the normal\nresponse handler, which can copy data through cmd_node->data_buf into the\nstale stack address.\n\nThis fixes a stack corruption observed during repeated association and\ndisassociation cycles. The panic trace showed the command wait being\ninterrupted immediately before a bad pointer dereference:\n\n cmd_wait_q terminated: -512\n Unable to handle kernel paging request at virtual address 002c583837384662\n Kernel panic - not syncing: stack-protector: Kernel stack is corrupted\n ...\n Tainted: [M]=MACHINE_CHECK\n\nThe fault address decodes as little-endian ASCII:\n\n 0x002c583837384662 -> "bF878X,\\0"\n\nwhich is a fragment of the VERSION_EXT firmware string exposed as\ndebugfs "verext":\n\n w8997o-V4, RF878X, FP92, 16.92.21.p153.7\n\nThe same runs also showed corrupted control data containing:\n\n 0x2400372e333531 -> "153.7\\0$"\n\nwhich is the tail of the same VERSION_EXT string. This points at a late\nVERSION_EXT response writing through a stale stack-backed data_buf after\nthe interrupted wait returned.\n\nAfter cancelling pending commands on an interrupted or timed-out wait,\ndetach the caller-owned data buffer from the still-current command. This\npreserves the existing command cancellation behaviour while preventing a\nlate response from writing through a pointer whose lifetime ended with the\nwaiting caller.\n\nTested on an i.MX8MP board using an 88W8997.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02909 |
debian: CVE-2026-80944 was patched at 2026-09-16
1781.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80977) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: skbuff: don't touch shared zerocopy state in skb_tx_error() skb_tx_error() completes the zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, and skb_zcopy_downgrade_managed() clears SKBFL_MANAGED_FRAG_REFS. Both live in skb_shinfo(), which every clone shares, while the caller only owns the reference it is about to drop. Through a clone it tells the producer its pages are free and drops SKBFL_SHARED_FRAG for an skb that is still in flight. Open vSwitch reaches this with a non-last OVS_ACTION_ATTR_RECIRC: clone_execute() sends a skb_clone() into ovs_dp_process_packet() while do_execute_actions() keeps forwarding the original, and skb_clone() does not privatise the frags here -- skb_orphan_frags() returns early on SKBFL_DONT_ORPHAN. A flow miss on the clone then strips the marker from the packet still being forwarded, and a later local ESP delivery decrypts in place over frags it does not own privately. Skip it for a cloned skb. Nothing is lost: skb_release_data() clears the zerocopy state once the last reference to the shared data goes.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: don't touch shared zerocopy state in skb_tx_error()\n\nskb_tx_error() completes the zerocopy uarg and clears\nSKBFL_ALL_ZEROCOPY, and skb_zcopy_downgrade_managed() clears\nSKBFL_MANAGED_FRAG_REFS. Both live in skb_shinfo(), which every clone\nshares, while the caller only owns the reference it is about to drop.\nThrough a clone it tells the producer its pages are free and drops\nSKBFL_SHARED_FRAG for an skb that is still in flight.\n\nOpen vSwitch reaches this with a non-last OVS_ACTION_ATTR_RECIRC:\nclone_execute() sends a skb_clone() into ovs_dp_process_packet() while\ndo_execute_actions() keeps forwarding the original, and skb_clone()\ndoes not privatise the frags here -- skb_orphan_frags() returns early\non SKBFL_DONT_ORPHAN. A flow miss on the clone then strips the marker\nfrom the packet still being forwarded, and a later local ESP delivery\ndecrypts in place over frags it does not own privately.\n\nSkip it for a cloned skb. Nothing is lost: skb_release_data() clears\nthe zerocopy state once the last reference to the shared data goes.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02909 |
debian: CVE-2026-80977 was patched at 2026-09-16
1782.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80978) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: cap advertised IP tunnel headroom IP tunnel devices derive their advertised needed_headroom from lower output devices. A stack of user-created devices can make the derived value larger than the 16-bit skb header offsets can represent. Once IP output reserves it, skb head expansion can wrap those offsets. The runtime transmit path already caps a growing needed_headroom at 512. Apply the same cap when tunnel configuration publishes needed_headroom derived from a lower output device. Capping the advertised value is safe: IP tunnel transmit still expands the skb when a packet needs more headroom. A nonsensical stacked configuration can therefore incur an extra reallocation, but it cannot publish an unbounded reservation to upper layers.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: cap advertised IP tunnel headroom\n\nIP tunnel devices derive their advertised needed_headroom from lower\noutput devices. A stack of user-created devices can make the derived\nvalue larger than the 16-bit skb header offsets can represent. Once IP\noutput reserves it, skb head expansion can wrap those offsets.\n\nThe runtime transmit path already caps a growing needed_headroom at 512.\nApply the same cap when tunnel configuration publishes needed_headroom\nderived from a lower output device.\n\nCapping the advertised value is safe: IP tunnel transmit still expands\nthe skb when a packet needs more headroom. A nonsensical stacked\nconfiguration can therefore incur an extra reallocation, but it cannot\npublish an unbounded reservation to upper layers.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.0291 |
debian: CVE-2026-80978 was patched at 2026-09-16
1783.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80979) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/smc: unregister the connection before draining the rx tasklet smc_conn_free() calls smc_ism_unset_conn() only while the link group is still on its device list, and never sets conn->killed. smc_lgr_terminate_sched() unlinks the group immediately and defers killing its connections to a work item, so a connection freed in that window keeps its smcd->conn[] slot with both gates in smcd_handle_irq() open, and the device can re-arm the receive tasklet after tasklet_kill() has returned. On the DMB-nocopy path the ghost send buffer is freed right after that drain, so the re-armed tasklet dereferences it. Unregister unconditionally and drain before the detach at both teardown sites, mirroring rmb_desc, which smc_buf_unuse() releases after the drain. Clear conn->sndbuf_desc before freeing it as well, so a reader that samples the pointer cannot get one that is already freed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: unregister the connection before draining the rx tasklet\n\nsmc_conn_free() calls smc_ism_unset_conn() only while the link group is\nstill on its device list, and never sets conn->killed.\nsmc_lgr_terminate_sched() unlinks the group immediately and defers killing\nits connections to a work item, so a connection freed in that window keeps\nits smcd->conn[] slot with both gates in smcd_handle_irq() open, and the\ndevice can re-arm the receive tasklet after tasklet_kill() has returned. On\nthe DMB-nocopy path the ghost send buffer is freed right after that drain,\nso the re-armed tasklet dereferences it.\n\nUnregister unconditionally and drain before the detach at both teardown\nsites, mirroring rmb_desc, which smc_buf_unuse() releases after the drain.\nClear conn->sndbuf_desc before freeing it as well, so a reader that samples\nthe pointer cannot get one that is already freed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02851 |
debian: CVE-2026-80979 was patched at 2026-09-16
1784.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-81010) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: honor task_work cancellation io_waitid_cb() may run through the fallback task_work path when task_work_add() can no longer queue work to the originating task. The fallback runs from a kworker and io_uring marks such task work as canceled through tw.cancel. io_waitid_cb() currently ignores tw.cancel and calls __do_wait(). waitid is task-context dependent: __do_wait() performs child lookup relative to current, and the retry path also uses current->signal->wait_chldexit. If the callback runs from the fallback kworker, current is therefore not the task that submitted the request. Honor tw.cancel before entering __do_wait(). Complete the request with -ECANCELED and skip the siginfo copy, since canceled task work may run without the submitting task's userspace execution context. Keep the existing siginfo handling for normal waitid completion and explicit cancellation.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/waitid: honor task_work cancellation\n\nio_waitid_cb() may run through the fallback task_work path when\ntask_work_add() can no longer queue work to the originating task. The\nfallback runs from a kworker and io_uring marks such task work as\ncanceled through tw.cancel.\n\nio_waitid_cb() currently ignores tw.cancel and calls __do_wait().\nwaitid is task-context dependent: __do_wait() performs child lookup\nrelative to current, and the retry path also uses\ncurrent->signal->wait_chldexit. If the callback runs from the fallback\nkworker, current is therefore not the task that submitted the request.\n\nHonor tw.cancel before entering __do_wait(). Complete the request with\n-ECANCELED and skip the siginfo copy, since canceled task work may run\nwithout the submitting task's userspace execution context.\n\nKeep the existing siginfo handling for normal waitid completion and\nexplicit cancellation.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.03274 |
debian: CVE-2026-81010 was patched at 2026-09-16
1785.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-81012) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() hp_get_string_from_buffer() clamps the converted string length against the destination buffer size with "size > dst_size", so when the converted length is exactly equal to dst_size, conv_dst_size is left at dst_size and the unconditional NUL terminator write \tdst[conv_dst_size] = 0; lands one byte past the destination buffer. This is the same shape of bug as the previously fixed off-by-one in hp_convert_hexstr_to_str(): the buffer is sized correctly for the content, but the terminator write is never checked against that size. Fix by changing the comparison to ">=" so conv_dst_size is always left with room for the terminator. All fixed-size destinations that reach this function (path[512], current_value[512], current_password/current_value[64], and the per-entry buffers in encodings[][512] and prerequisites[][512]) are affected.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer()\n\nhp_get_string_from_buffer() clamps the converted string length against\nthe destination buffer size with "size > dst_size", so when the\nconverted length is exactly equal to dst_size, conv_dst_size is left\nat dst_size and the unconditional NUL terminator write\n\n\tdst[conv_dst_size] = 0;\n\nlands one byte past the destination buffer. This is the same shape of\nbug as the previously fixed off-by-one in hp_convert_hexstr_to_str():\nthe buffer is sized correctly for the content, but the terminator\nwrite is never checked against that size.\n\nFix by changing the comparison to ">=" so conv_dst_size is always left\nwith room for the terminator.\n\nAll fixed-size destinations that reach this function (path[512],\ncurrent_value[512], current_password/current_value[64], and the\nper-entry buffers in encodings[][512] and prerequisites[][512]) are\naffected.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04028 |
debian: CVE-2026-81012 was patched at 2026-09-16
1786.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89441) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mmc: via-sdmmc: cancel card-detect work on remove Disabling the device interrupt and freeing the IRQ prevents new card-detect work from being queued, but carddet_work already queued by the handler can still run after via_sd_remove() returns. via_sdc_card_detect() recovers the host through container_of() and dereferences its MMIO base; once remove() returns the host can be freed, so that work would touch freed memory. Cancel carddet_work after freeing the IRQ and before cancelling finish_bh_work, which the card-detect handler can also queue. carddet_work can re-enable the interrupt through via_reset_pcictrl(); mask it again afterwards. This issue was found by an in-house static analysis tool and confirmed by manual code review.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: via-sdmmc: cancel card-detect work on remove\n\nDisabling the device interrupt and freeing the IRQ prevents new card-detect\nwork from being queued, but carddet_work already queued by the handler can\nstill run after via_sd_remove() returns. via_sdc_card_detect() recovers the\nhost through container_of() and dereferences its MMIO base; once remove()\nreturns the host can be freed, so that work would touch freed memory.\n\nCancel carddet_work after freeing the IRQ and before cancelling\nfinish_bh_work, which the card-detect handler can also queue. carddet_work\ncan re-enable the interrupt through via_reset_pcictrl(); mask it again\nafterwards.\n\nThis issue was found by an in-house static analysis tool and confirmed by\nmanual code review.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00127, EPSS Percentile is 0.02718 |
debian: CVE-2026-89441 was patched at 2026-09-16
1787.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89443) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate level in perf mask ioctls isst_if_get_perf_level_mask() and isst_if_get_base_freq_mask() use the user-provided level as an index into perf_levels[] via _read_pp_level_info() and _read_bf_level_info(), but neither helper validates it first. The adjacent level-info helpers reject levels above max_level before reading the same per-level register block. Add the same bounds checks to the mask helpers, and reject disabled SST-PP levels in isst_if_get_perf_level_mask() to match isst_if_get_perf_level_info(). This prevents out-of-bounds reads from the per-level offset table on invalid ioctl input.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: ISST: Validate level in perf mask ioctls\n\nisst_if_get_perf_level_mask() and isst_if_get_base_freq_mask() use the\nuser-provided level as an index into perf_levels[] via\n_read_pp_level_info() and _read_bf_level_info(), but neither helper\nvalidates it first.\n\nThe adjacent level-info helpers reject levels above max_level before\nreading the same per-level register block. Add the same bounds checks to\nthe mask helpers, and reject disabled SST-PP levels in\nisst_if_get_perf_level_mask() to match isst_if_get_perf_level_info().\n\nThis prevents out-of-bounds reads from the per-level offset table on\ninvalid ioctl input.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05438 |
debian: CVE-2026-89443 was patched at 2026-09-16
1788.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89465) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: quiesce delayed work before teardown The threaded IRQ handler can queue pwr_rdy_work, max_charging_time_work and batt_presence_work. pwr_rdy_work and batt_presence_work can also queue max_charging_time_work, while batt_presence_work can requeue itself. rt9455_remove() cancels max_charging_time_work before batt_presence_work. The latter can therefore queue max_charging_time_work after it has already been cancelled: rt9455_remove() workqueue cancel pwr_rdy_work cancel max_charging_time_work batt_presence_work queues max_charging_time_work cancel batt_presence_work return devres frees rt9455_info max_charging_time_work dereferences rt9455_info The IRQ also remains registered until devres cleanup and can queue more work after any of the cancellation calls. If rt9455_hw_init() fails after the IRQ has been requested, probe returns without cancelling work that may already have been queued. A pending callback can then access rt9455_info after it has been freed. Register rt9455_cancel_all_delayed_works() through devm_add_action_or_reset() right after devm_power_supply_register(). devres invokes the action in reverse registration order, after the managed IRQ has been freed and before rt9455_info is released, so the delayed works are drained in both rt9455_remove() and the probe error path. Cancel pwr_rdy_work and batt_presence_work before max_charging_time_work because both can queue the latter. This issue was found by an in-house static analysis tool.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: rt9455: quiesce delayed work before teardown\n\nThe threaded IRQ handler can queue pwr_rdy_work,\nmax_charging_time_work and batt_presence_work. pwr_rdy_work and\nbatt_presence_work can also queue max_charging_time_work, while\nbatt_presence_work can requeue itself.\n\nrt9455_remove() cancels max_charging_time_work before\nbatt_presence_work. The latter can therefore queue\nmax_charging_time_work after it has already been cancelled:\n\n rt9455_remove() workqueue\n cancel pwr_rdy_work\n cancel max_charging_time_work\n batt_presence_work queues\n max_charging_time_work\n cancel batt_presence_work\n return\n devres frees rt9455_info\n max_charging_time_work dereferences\n rt9455_info\n\nThe IRQ also remains registered until devres cleanup and can queue more\nwork after any of the cancellation calls. If rt9455_hw_init() fails\nafter the IRQ has been requested, probe returns without cancelling work\nthat may already have been queued. A pending callback can then access\nrt9455_info after it has been freed.\n\nRegister rt9455_cancel_all_delayed_works() through\ndevm_add_action_or_reset() right after devm_power_supply_register().\ndevres invokes the action in reverse registration order, after the\nmanaged IRQ has been freed and before rt9455_info is released, so the\ndelayed works are drained in both rt9455_remove() and the probe error\npath. Cancel pwr_rdy_work and batt_presence_work before\nmax_charging_time_work because both can queue the latter.\n\nThis issue was found by an in-house static analysis tool.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04028 |
debian: CVE-2026-89465 was patched at 2026-09-16
1789.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89466) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: power: supply: qcom_battmgr: terminate the strings from firmware The qcom_battmgr_sc8280xp_strcpy() takes a Pascal-style string when the firmware sends one. Otherwise it copies all BATTMGR_STRING_LEN bytes and leaves the destination without a terminator. Those destinations are model_number, serial_number and oem_info, each BATTMGR_STRING_LEN and declared next to each other. They go out to user space as val->strval, which power_supply_format_property() prints with "%s", so a firmware string that fills the whole field makes that read run into the following members. Use strscpy() so the copy always terminates, the way the SM8350 path already does for the same field.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: qcom_battmgr: terminate the strings from firmware\n\nThe qcom_battmgr_sc8280xp_strcpy() takes a Pascal-style string when the\nfirmware sends one. Otherwise it copies all BATTMGR_STRING_LEN bytes and\nleaves the destination without a terminator.\n\nThose destinations are model_number, serial_number and oem_info, each\nBATTMGR_STRING_LEN and declared next to each other. They go out to user\nspace as val->strval, which power_supply_format_property() prints with\n"%s", so a firmware string that fills the whole field makes that read run\ninto the following members.\n\nUse strscpy() so the copy always terminates, the way the SM8350 path\nalready does for the same field.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04029 |
debian: CVE-2026-89466 was patched at 2026-09-16
1790.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89487) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: openvswitch: only skb_tx_error() a packet we are about to drop queue_userspace_packet() borrows the packet skb -- it only copies it into a private netlink message (user_skb) and does not own it; on return do_execute_actions() keeps forwarding it through the flow's remaining actions. Its error path nevertheless calls skb_tx_error(skb), which via skb_zcopy_clear() does skb_shinfo(skb)->flags &= ~SKBFL_ALL_ZEROCOPY, stripping SKBFL_SHARED_FRAG from that live skb (skb_tx_error()'s kerneldoc says "skb must be freed afterwards"). For a MSG_ZEROCOPY skb carrying page-cache frags, SKBFL_SHARED_FRAG is what makes esp_input() skb_cow_data() before in-place AEAD; once it is stripped a later local ESP-in-UDP delivery decrypts in place over pages the sender does not own -- an unprivileged page-cache write (the "Fragnesia" primitive). do_execute_actions() ignores output_userspace()'s return value, so any action after a failed USERSPACE upcall inherits the stripped skb. Move the skb_tx_error() to the flow-miss drop path - the "default" branch of ovs_dp_process_packet()'s switch(error), before kfree_skb(). The call has been here since commit 36d5fe6a0007 ("core, nfqueue, openvswitch: Orphan frags in skb_zerocopy and handle errors") but was harmless until esp_input() began relying on SKBFL_SHARED_FRAG to gate in-place decrypt; only then did stripping it on a still-forwarded skb become a page-cache write primitive.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nopenvswitch: only skb_tx_error() a packet we are about to drop\n\nqueue_userspace_packet() borrows the packet skb -- it only copies it into\na private netlink message (user_skb) and does not own it; on return\ndo_execute_actions() keeps forwarding it through the flow's remaining\nactions. Its error path nevertheless calls skb_tx_error(skb), which via\nskb_zcopy_clear() does skb_shinfo(skb)->flags &= ~SKBFL_ALL_ZEROCOPY,\nstripping SKBFL_SHARED_FRAG from that live skb (skb_tx_error()'s kerneldoc\nsays "skb must be freed afterwards").\n\nFor a MSG_ZEROCOPY skb carrying page-cache frags, SKBFL_SHARED_FRAG is\nwhat makes esp_input() skb_cow_data() before in-place AEAD; once it is\nstripped a later local ESP-in-UDP delivery decrypts in place over pages\nthe sender does not own -- an unprivileged page-cache write (the\n"Fragnesia" primitive).\ndo_execute_actions() ignores output_userspace()'s return value, so any\naction after a failed USERSPACE upcall inherits the stripped skb.\n\nMove the skb_tx_error() to the flow-miss drop path - the "default"\nbranch of ovs_dp_process_packet()'s switch(error), before kfree_skb().\n\nThe call has been here since commit 36d5fe6a0007 ("core, nfqueue,\nopenvswitch: Orphan frags in skb_zerocopy and handle errors") but was\nharmless until esp_input() began relying on SKBFL_SHARED_FRAG to gate\nin-place decrypt; only then did stripping it on a still-forwarded skb\nbecome a page-cache write primitive.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02907 |
debian: CVE-2026-89487 was patched at 2026-09-16
1791.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89497) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: orangefs: skip leading spaces before parsing client debug masks orangefs_prepare_cdm_array() sizes each client debug keyword buffer with strcspn(cds_head, " "), but then parses the keyword with %s. The %s conversion skips leading whitespace, while strcspn() does not. If a client debug entry starts with a space, the allocation can be sized for an empty keyword while sscanf() copies the following non-empty token. This can write past the end of the allocated keyword buffer. Skip leading spaces before computing the keyword length so the allocation matches the string parsed by sscanf().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\norangefs: skip leading spaces before parsing client debug masks\n\norangefs_prepare_cdm_array() sizes each client debug keyword buffer\nwith strcspn(cds_head, " "), but then parses the keyword with %s. The\n%s conversion skips leading whitespace, while strcspn() does not.\n\nIf a client debug entry starts with a space, the allocation can be sized\nfor an empty keyword while sscanf() copies the following non-empty token.\nThis can write past the end of the allocated keyword buffer.\n\nSkip leading spaces before computing the keyword length so the allocation\nmatches the string parsed by sscanf().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02906 |
debian: CVE-2026-89497 was patched at 2026-09-16
1792.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89504) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer In as3722_get_regulator_dt_data(), of_get_child_by_name() acquires a reference on np, which is then assigned to pdev->dev.of_node. The function immediately calls of_node_put(np), releasing the reference and leaving pdev->dev.of_node as a dangling pointer. Remove the of_node_put(np) call to let the device hold the reference.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nregulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer\n\nIn as3722_get_regulator_dt_data(), of_get_child_by_name() acquires a\nreference on np, which is then assigned to pdev->dev.of_node. The\nfunction immediately calls of_node_put(np), releasing the reference and\nleaving pdev->dev.of_node as a dangling pointer.\n\nRemove the of_node_put(np) call to let the device hold the reference.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04028 |
debian: CVE-2026-89504 was patched at 2026-09-16
1793.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89540) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: sunrpc: init gssp_lock before publishing proc entry create_use_gss_proxy_proc_entry() publishes /proc/net/rpc/use-gss-proxy via proc_create_data() before init_gssp_clnt() runs mutex_init() on sn->gssp_lock. Once the dentry is linked under proc_subdir_lock it is immediately reachable from userspace, so a write that lands in the window drives set_gssp_clnt() into mutex_lock() on a zero-initialized struct mutex. create_use_gss_proxy_proc_entry(net) proc_create_data("use-gss-proxy", ...) /* dentry live */ init_gssp_clnt(sn) mutex_init(&sn->gssp_lock) /* too late */ write_gssp() set_gssp_clnt(net) mutex_lock(&sn->gssp_lock) /* uninitialized */ gssp_rpc_create(...) sn->gssp_clnt = clnt mutex_unlock(&sn->gssp_lock) The window spans only the two statements between proc_create_data() returning and init_gssp_clnt(), so a writer reaches it only if the registering thread is preempted there while another task is already opening the freshly published file. register_pernet_subsys() runs in preemptible context under pernet_ops_rwsem, so that preemption is possible, and the window widens on auth_rpcgss module load, when the proc entry is created for every live net namespace whose tasks are already running. A writer that wins the race locks a zero-filled struct mutex. On CONFIG_DEBUG_MUTEXES the missing magic value trips a "lock used without init" splat; on a production kernel the fast path acquires the lock via CMPXCHG(owner, 0, current). In the latter case a second writer that arrives before init_gssp_clnt() re-zeroes owner can enter set_gssp_clnt() concurrently, shut down the first writer's clnt while it is still in use, and leak the loser's clnt. Fix by initializing sn->gssp_lock in sunrpc_init_net() so its lifetime matches the sunrpc_net it lives in. sn->gssp_clnt is already NULL from the kzalloc that backs net_generic storage, so the lazy helper is no longer needed; drop init_gssp_clnt(), its prototype, and the call from create_use_gss_proxy_proc_entry(). sunrpc.ko is a build-time dependency of auth_rpcgss.ko, so sunrpc_init_net() has always run on every netns before any auth_gss pernet init can publish the proc entry.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsunrpc: init gssp_lock before publishing proc entry\n\ncreate_use_gss_proxy_proc_entry() publishes /proc/net/rpc/use-gss-proxy\nvia proc_create_data() before init_gssp_clnt() runs mutex_init() on\nsn->gssp_lock. Once the dentry is linked under proc_subdir_lock it is\nimmediately reachable from userspace, so a write that lands in the\nwindow drives set_gssp_clnt() into mutex_lock() on a zero-initialized\nstruct mutex.\n\n create_use_gss_proxy_proc_entry(net)\n proc_create_data("use-gss-proxy", ...) /* dentry live */\n init_gssp_clnt(sn)\n mutex_init(&sn->gssp_lock) /* too late */\n\n write_gssp()\n set_gssp_clnt(net)\n mutex_lock(&sn->gssp_lock) /* uninitialized */\n gssp_rpc_create(...)\n sn->gssp_clnt = clnt\n mutex_unlock(&sn->gssp_lock)\n\nThe window spans only the two statements between proc_create_data()\nreturning and init_gssp_clnt(), so a writer reaches it only if the\nregistering thread is preempted there while another task is already\nopening the freshly published file. register_pernet_subsys() runs in\npreemptible context under pernet_ops_rwsem, so that preemption is\npossible, and the window widens on auth_rpcgss module load, when the\nproc entry is created for every live net namespace whose tasks are\nalready running. A writer that wins the race locks a zero-filled\nstruct mutex. On CONFIG_DEBUG_MUTEXES the missing magic value trips a\n"lock used without init" splat; on a production kernel the fast path\nacquires the lock via CMPXCHG(owner, 0, current). In the latter case\na second writer that arrives before init_gssp_clnt() re-zeroes owner\ncan enter set_gssp_clnt() concurrently, shut down the first writer's\nclnt while it is still in use, and leak the loser's clnt.\n\nFix by initializing sn->gssp_lock in sunrpc_init_net() so its lifetime\nmatches the sunrpc_net it lives in. sn->gssp_clnt is already NULL from\nthe kzalloc that backs net_generic storage, so the lazy helper is no\nlonger needed; drop init_gssp_clnt(), its prototype, and the call from\ncreate_use_gss_proxy_proc_entry(). sunrpc.ko is a build-time\ndependency of auth_rpcgss.ko, so sunrpc_init_net() has always run on\nevery netns before any auth_gss pernet init can publish the proc\nentry.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02905 |
debian: CVE-2026-89540 was patched at 2026-09-16
1794.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89560) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation Whiteout objects are used in the upper layer of an OverlayFS to indicate that the file with this name does not exist in the unified view, even if it is present in one of the lower layer file systems. For the userspace implementations of OverlayFS (fuse-overlayfs), whiteout objects can be created from userspace as well: * mknod(2) with S_IFCHR and makedev(0, 0) * renameat2(2) with RENAME_WHITEOUT, creating the whiteout in the old place of the moved file. This commit guards whiteout creation in both of these cases with LANDLOCK_ACCESS_FS_MAKE_REG. Whiteout objects are *not* considered character devices and are not bound to a driver. LANDLOCK_ACCESS_FS_MAKE_REG describes the same permission class as a whiteout object: creating one is the only S_IFCHR creation that the VFS exempts from CAP_MKNOD, so it is as unprivileged as creating a regular file, while LANDLOCK_ACCESS_FS_MAKE_CHAR and LANDLOCK_ACCESS_FS_MAKE_BLOCK keep meaning the creation of devices that expose a kernel interface [1]. For the mknod(2) case, introduce a Landlock erratum. The creation of whiteout objects through mknod(2) was previously guarded using LANDLOCK_ACCESS_FS_MAKE_CHAR, and it is now guarded using LANDLOCK_ACCESS_FS_MAKE_REG. For the renameat2(2) case, fix a bug: Before this commit, renameat2(2) with RENAME_WHITEOUT would create a directory entry even when all LANDLOCK_ACCESS_FS_MAKE_* rights were denied. This does not affect normal renames within layered OverlayFS mounts: When doing a regular rename() on a mounted fuse-overlayfs, it is the fuse-overlayfs daemon that exercises renameat2() with RENAME_WHITEOUT, and only the Landlock domain of that daemon is checked there. Depends-on: 49c9e09d9610 ("landlock: Fix handling of disconnected directories") Depends-on: fe72ce6710cb ("landlock: Add errata documentation section") [mic: Record why LANDLOCK_ACCESS_FS_MAKE_REG is the matching right, and add link(2) to the user doc]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nlandlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation\n\nWhiteout objects are used in the upper layer of an OverlayFS to\nindicate that the file with this name does not exist in the unified\nview, even if it is present in one of the lower layer file systems.\n\nFor the userspace implementations of OverlayFS (fuse-overlayfs),\nwhiteout objects can be created from userspace as well:\n\n* mknod(2) with S_IFCHR and makedev(0, 0)\n* renameat2(2) with RENAME_WHITEOUT,\n creating the whiteout in the old place of the moved file.\n\nThis commit guards whiteout creation in both of these cases with\nLANDLOCK_ACCESS_FS_MAKE_REG. Whiteout objects are *not* considered\ncharacter devices and are not bound to a driver.\n\nLANDLOCK_ACCESS_FS_MAKE_REG describes the same permission class as a\nwhiteout object: creating one is the only S_IFCHR creation that the VFS\nexempts from CAP_MKNOD, so it is as unprivileged as creating a regular\nfile, while LANDLOCK_ACCESS_FS_MAKE_CHAR and\nLANDLOCK_ACCESS_FS_MAKE_BLOCK keep meaning the creation of devices that\nexpose a kernel interface [1].\n\nFor the mknod(2) case, introduce a Landlock erratum. The creation of\nwhiteout objects through mknod(2) was previously guarded using\nLANDLOCK_ACCESS_FS_MAKE_CHAR, and it is now guarded using\nLANDLOCK_ACCESS_FS_MAKE_REG.\n\nFor the renameat2(2) case, fix a bug: Before this commit, renameat2(2)\nwith RENAME_WHITEOUT would create a directory entry even when all\nLANDLOCK_ACCESS_FS_MAKE_* rights were denied.\n\nThis does not affect normal renames within layered OverlayFS mounts:\nWhen doing a regular rename() on a mounted fuse-overlayfs, it is the\nfuse-overlayfs daemon that exercises renameat2() with RENAME_WHITEOUT,\nand only the Landlock domain of that daemon is checked there.\n\nDepends-on: 49c9e09d9610 ("landlock: Fix handling of disconnected directories")\nDepends-on: fe72ce6710cb ("landlock: Add errata documentation section")\n[mic: Record why LANDLOCK_ACCESS_FS_MAKE_REG is the matching right, and\nadd link(2) to the user doc]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02625 |
debian: CVE-2026-89560 was patched at 2026-09-16
1795.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89562) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ip6_gre: fix hardware header length for NBMA tunnels ip6gre_tnl_link_config_route() accumulates the lower device's hardware header length into dev->hard_header_len whenever header_ops is set. This is incorrect for both users of header_ops. ip6gretap and ip6erspan have a fixed Ethernet hardware header length. For an NBMA ip6gre tunnel, ip6gre_header() creates only the GRE header, the optional FOU or GUE header, and the outer IPv6 header. The lower device header is headroom needed later, not part of the tunnel device's hardware header. Keep the lower device header in needed_headroom. Set hard_header_len to the tunnel header length only for ARPHRD_IP6GRE devices with header_ops, and leave the fixed Ethernet header length unchanged for tap and erspan devices.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nip6_gre: fix hardware header length for NBMA tunnels\n\nip6gre_tnl_link_config_route() accumulates the lower device's hardware\nheader length into dev->hard_header_len whenever header_ops is set. This\nis incorrect for both users of header_ops.\n\nip6gretap and ip6erspan have a fixed Ethernet hardware header length.\nFor an NBMA ip6gre tunnel, ip6gre_header() creates only the GRE header,\nthe optional FOU or GUE header, and the outer IPv6 header. The lower\ndevice header is headroom needed later, not part of the tunnel device's\nhardware header.\n\nKeep the lower device header in needed_headroom. Set hard_header_len to\nthe tunnel header length only for ARPHRD_IP6GRE devices with header_ops,\nand leave the fixed Ethernet header length unchanged for tap and erspan\ndevices.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02908 |
debian: CVE-2026-89562 was patched at 2026-09-16
1796.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89563) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit() ip6_tnl_xmit() may need to expand headroom before it can push the outer IPv6 and optional encap headers. It currently does that with skb_realloc_headroom(), copies skb->sk ownership, consumes the original skb, and then continues processing with the replacement skb kept only in its local variable. That is safe only if the helper cannot fail afterwards. But this helper still has post-reallocation error exits. collect_md tunnels reject non-NONE encap after the replacement, and ip6_tnl_encap() can also fail later. In those cases the helper returns an error to its callers while the caller still only has the original skb pointer. Both ip6_tnl_start_xmit() and the IPv6 GRE paths free the caller skb on error, so they can end up freeing an skb that ip6_tnl_xmit() already consumed. Use skb_cow_head() instead. It provides the required headroom and writability without privately replacing the caller-owned skb, so later error returns cannot leave callers with a stale pointer. The Ethernet users, ip6gretap and ip6erspan, clear IFF_TX_SKB_SHARING and already call skb_cow_head() before entering ip6_tnl_xmit(). They do not rely on the removed skb_shared() reallocation. This also makes the IPv6 tunnel path consistent with ip_tunnel_xmit().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nip6_tunnel: use skb_cow_head() in ip6_tnl_xmit()\n\nip6_tnl_xmit() may need to expand headroom before it can push the\nouter IPv6 and optional encap headers. It currently does that with\nskb_realloc_headroom(), copies skb->sk ownership, consumes the original\nskb, and then continues processing with the replacement skb kept only in\nits local variable.\n\nThat is safe only if the helper cannot fail afterwards. But this helper\nstill has post-reallocation error exits. collect_md tunnels reject\nnon-NONE encap after the replacement, and ip6_tnl_encap() can also fail\nlater. In those cases the helper returns an error to its callers while\nthe caller still only has the original skb pointer.\n\nBoth ip6_tnl_start_xmit() and the IPv6 GRE paths free the caller skb on\nerror, so they can end up freeing an skb that ip6_tnl_xmit() already\nconsumed.\n\nUse skb_cow_head() instead. It provides the required headroom and\nwritability without privately replacing the caller-owned skb, so later\nerror returns cannot leave callers with a stale pointer.\n\nThe Ethernet users, ip6gretap and ip6erspan, clear IFF_TX_SKB_SHARING\nand already call skb_cow_head() before entering ip6_tnl_xmit(). They do\nnot rely on the removed skb_shared() reallocation. This also makes the\nIPv6 tunnel path consistent with ip_tunnel_xmit().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00138, EPSS Percentile is 0.036 |
debian: CVE-2026-89563 was patched at 2026-09-16
1797.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89564) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ip: orphan prefetched skbs before multicast forwarding IPv4 and IPv6 input preserve an skb->sk association installed by bpf_sk_assign() so that local delivery can use the selected socket under RCU. Both address families can also prefetch a socket in UDP early demux. In both paths (BPF and UDP early demux) a reference is not guaranteed to be held on the socket. When a multicast packet is not locally deliverable, IPv6 hands the original skb to ip6_mr_input(). IPv4's ip_mr_input() similarly keeps the original skb when local delivery is not needed. Either path can put the skb on an unresolved multicast route queue or forward it after the receive-side RCU section ends. After the prefetched socket is destroyed, a later skb free invokes sock_pfree() and dereferences the stale skb->sk. Orphan the skb before each non-local multicast forwarding path. Local delivery retains the original skb; the existing skb_clone() calls provide multicast forwarding with a socket-free clone.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nip: orphan prefetched skbs before multicast forwarding\n\nIPv4 and IPv6 input preserve an skb->sk association installed by\nbpf_sk_assign() so that local delivery can use the selected socket under\nRCU. Both address families can also prefetch a socket in UDP early demux.\nIn both paths (BPF and UDP early demux) a reference is not guaranteed to\nbe held on the socket.\n\nWhen a multicast packet is not locally deliverable, IPv6 hands the\noriginal skb to ip6_mr_input(). IPv4's ip_mr_input() similarly keeps the\noriginal skb when local delivery is not needed. Either path can put the\nskb on an unresolved multicast route queue or forward it after the\nreceive-side RCU section ends.\n\nAfter the prefetched socket is destroyed, a later skb free invokes\nsock_pfree() and dereferences the stale skb->sk. Orphan the skb before\neach non-local multicast forwarding path. Local delivery retains the\noriginal skb; the existing skb_clone() calls provide multicast forwarding\nwith a socket-free clone.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00136, EPSS Percentile is 0.03432 |
debian: CVE-2026-89564 was patched at 2026-09-16
1798.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89573) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: dm array: reject an array block whose value size is not the caller's array_block_check() can only compare the header against itself, so a block with value_size 4 and max_entries 1018 is internally consistent and passes. dm-cache keeps two arrays -- mappings at 8 bytes and hints at 4 -- and the roots for both live in the superblock. Point the mappings root at a hint block and __load_mappings() walks it through an info whose value size is 8, so element_at() strides 8 bytes over 4-byte entries and reaches offset 8160 of a 4096-byte block. get_ablock() and __shadow_ablock() are the two places that hold the block and the caller at once. Reject there when the two value sizes disagree. Arrays only ever read their own blocks, so this fires on crafted metadata only.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndm array: reject an array block whose value size is not the caller's\n\narray_block_check() can only compare the header against itself, so a block\nwith value_size 4 and max_entries 1018 is internally consistent and passes.\ndm-cache keeps two arrays -- mappings at 8 bytes and hints at 4 -- and the\nroots for both live in the superblock. Point the mappings root at a hint\nblock and __load_mappings() walks it through an info whose value size is 8,\nso element_at() strides 8 bytes over 4-byte entries and reaches offset 8160\nof a 4096-byte block.\n\nget_ablock() and __shadow_ablock() are the two places that hold the block\nand the caller at once. Reject there when the two value sizes disagree.\nArrays only ever read their own blocks, so this fires on crafted metadata\nonly.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02909 |
debian: CVE-2026-89573 was patched at 2026-09-16
1799.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89581) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: bpf, x86: Fix per-CPU address resolution into an extended register The destination of the per-CPU address MOV is encoded in ModRM.reg, which is extended by REX.R, but the REX prefix is built with add_1mod(), which sets REX.B. REX.B extends ModRM.rm and SIB.base, and this instruction addresses memory as disp32 with no base, so the bit has no effect at all and the high register bit is simply lost. Every is_ereg() destination therefore resolves to the wrong register, picking whichever one shares the low three bits: R5 -> RAX R7 -> RBP R8 -> RSI R9 -> RDI With BPF_REG_5, whose reg2hex is 0, the emitted 65 49 03 04 25 <off>\tadd %gs:<off>,%rax adds the per-CPU offset to RAX rather than R8. The destination keeps the unadjusted address and RAX is clobbered, so the program goes on to dereference a pointer that was never made per-CPU: BUG: unable to handle page fault for address: 0000607e386a8894 RIP: bpf_prog_707837aafd2aa9ae_update_percpu_data+0x93/0xc9 Call Trace: __bpf_prog_test_run_raw_tp+0x2dc/0x7d0 __flush_smp_call_function_queue+0x1e9/0xc80 Kernel panic - not syncing: Fatal exception in interrupt R5 is the mildest of the four, aliasing a scratch register and faulting at the store. R7 aliases RBP and would corrupt the frame pointer, R8 and R9 alias the argument registers. Use add_2mod() so the register goes through REX.R, matching how add_2reg() places it in ModRM.reg and how emit_priv_frame_ptr() hardcodes 0x4c for the same instruction with R9. Encodings for the non-extended registers are unchanged. Problem showed up when trying to resurrect BPF_GCC CI (selftests built with BPF_GCC). This has gone unnoticed because clang reloads the address into R1 before each per-CPU access, so the destination is never an extended register. GCC keeps several per-CPU addresses live at once, and test_progs-bpf_gcc panics the kernel in global_percpu_data/init, where the address of a .percpu variable ends up in R5.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, x86: Fix per-CPU address resolution into an extended register\n\nThe destination of the per-CPU address MOV is encoded in ModRM.reg,\nwhich is extended by REX.R, but the REX prefix is built with\nadd_1mod(), which sets REX.B. REX.B extends ModRM.rm and SIB.base, and\nthis instruction addresses memory as disp32 with no base, so the bit\nhas no effect at all and the high register bit is simply lost.\n\nEvery is_ereg() destination therefore resolves to the wrong register,\npicking whichever one shares the low three bits:\n\n R5 -> RAX R7 -> RBP R8 -> RSI R9 -> RDI\n\nWith BPF_REG_5, whose reg2hex is 0, the emitted\n\n 65 49 03 04 25 <off>\tadd %gs:<off>,%rax\n\nadds the per-CPU offset to RAX rather than R8. The destination keeps\nthe unadjusted address and RAX is clobbered, so the program goes on to\ndereference a pointer that was never made per-CPU:\n\n BUG: unable to handle page fault for address: 0000607e386a8894\n RIP: bpf_prog_707837aafd2aa9ae_update_percpu_data+0x93/0xc9\n Call Trace:\n __bpf_prog_test_run_raw_tp+0x2dc/0x7d0\n __flush_smp_call_function_queue+0x1e9/0xc80\n Kernel panic - not syncing: Fatal exception in interrupt\n\nR5 is the mildest of the four, aliasing a scratch register and faulting\nat the store. R7 aliases RBP and would corrupt the frame pointer, R8\nand R9 alias the argument registers.\n\nUse add_2mod() so the register goes through REX.R, matching how\nadd_2reg() places it in ModRM.reg and how emit_priv_frame_ptr()\nhardcodes 0x4c for the same instruction with R9. Encodings for the\nnon-extended registers are unchanged.\n\nProblem showed up when trying to resurrect BPF_GCC CI (selftests built\nwith BPF_GCC).\n\nThis has gone unnoticed because clang reloads the address into R1\nbefore each per-CPU access, so the destination is never an extended\nregister. GCC keeps several per-CPU addresses live at once, and\ntest_progs-bpf_gcc panics the kernel in global_percpu_data/init, where\nthe address of a .percpu variable ends up in R5.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02853 |
debian: CVE-2026-89581 was patched at 2026-09-16
1800.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89599) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fbdev: omapfb: panel-dsi-cm: initialize lock before registering display dsicm_probe() registers the display before initializing ddata->lock. Once omapdss_register_display() publishes the display, another consumer can reach a dsicm callback that takes this mutex while it is still uninitialized. Initialize the mutex before registering the display so the published callbacks always see a valid lock.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: omapfb: panel-dsi-cm: initialize lock before registering display\n\ndsicm_probe() registers the display before initializing ddata->lock.\nOnce omapdss_register_display() publishes the display, another consumer\ncan reach a dsicm callback that takes this mutex while it is still\nuninitialized.\n\nInitialize the mutex before registering the display so the published\ncallbacks always see a valid lock.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.0403 |
debian: CVE-2026-89599 was patched at 2026-09-16
1801.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89606) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ecryptfs: reject too-small tag 70 packets ecryptfs_parse_tag_70_packet() subtracts fixed metadata fields from the parsed packet body size to derive the encrypted filename size. A malformed packet with a body smaller than those fixed fields can underflow that size calculation. Reject tag 70 packets before the subtraction unless the body contains the signature, cipher code, and at least one byte of encrypted filename data.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\necryptfs: reject too-small tag 70 packets\n\necryptfs_parse_tag_70_packet() subtracts fixed metadata fields from the\nparsed packet body size to derive the encrypted filename size. A\nmalformed packet with a body smaller than those fixed fields can underflow\nthat size calculation.\n\nReject tag 70 packets before the subtraction unless the body contains the\nsignature, cipher code, and at least one byte of encrypted filename data.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00138, EPSS Percentile is 0.036 |
debian: CVE-2026-89606 was patched at 2026-09-16
1802.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89608) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ecryptfs: pass packet set buffer size to parser ecryptfs_parse_packet_set() receives a pointer into the file header, but it calculates the remaining packet buffer size from PAGE_SIZE - 8. For version 1 headers the packet set starts later in the header, so this can overstate the available buffer. Pass the actual packet set buffer length from the caller and calculate per-packet limits from the remaining bytes in that buffer. Recompute the remaining length after consuming a tag 3 packet before parsing the following tag 11 packet.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\necryptfs: pass packet set buffer size to parser\n\necryptfs_parse_packet_set() receives a pointer into the file header, but\nit calculates the remaining packet buffer size from PAGE_SIZE - 8. For\nversion 1 headers the packet set starts later in the header, so this can\noverstate the available buffer.\n\nPass the actual packet set buffer length from the caller and calculate\nper-packet limits from the remaining bytes in that buffer. Recompute the\nremaining length after consuming a tag 3 packet before parsing the\nfollowing tag 11 packet.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05505 |
debian: CVE-2026-89608 was patched at 2026-09-16
1803.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89615) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound page_lcns[] index by the log record The copy_lcns loop and the redo shorten loop index page_lcns[] at j + i, where i runs up to the log record's lcns_follow. That count is checked only against the record's own length, not the target entry, so check_dp_table() (which validates the entry's lcns_follow) does not cover it: the copy_lcns entry may even be freshly allocated after that check, and find_dp() bounds j but not i. A crafted record thus overflows page_lcns[] of an otherwise valid entry. Add dp_range_ok() and reject, before each loop, any record whose run does not fit the entry. These are the only two page_lcns[] accesses indexed by the record rather than the entry, so together with the entry validation every access is now bounded. [almaz.alexandrovich@paragon-software.com: original patch contained changes to the problem already handled, applied partly]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: bound page_lcns[] index by the log record\n\nThe copy_lcns loop and the redo shorten loop index page_lcns[] at j + i,\nwhere i runs up to the log record's lcns_follow. That count is checked only\nagainst the record's own length, not the target entry, so check_dp_table()\n(which validates the entry's lcns_follow) does not cover it: the copy_lcns\nentry may even be freshly allocated after that check, and find_dp() bounds j\nbut not i. A crafted record thus overflows page_lcns[] of an otherwise valid\nentry.\n\nAdd dp_range_ok() and reject, before each loop, any record whose run does\nnot fit the entry. These are the only two page_lcns[] accesses indexed by\nthe record rather than the entry, so together with the entry validation\nevery access is now bounded.\n\n[almaz.alexandrovich@paragon-software.com: original patch contained changes to the problem already handled, applied partly]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00154, EPSS Percentile is 0.04918 |
debian: CVE-2026-89615 was patched at 2026-09-16
1804.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89617) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate dirty page table on log replay Each DIR_PAGE_ENTRY ends in a page_lcns[] array whose length is the on-disk lcns_follow field. check_rstbl() validates the table bookkeeping but never checks that this array fits in the entry, so a crafted lcns_follow lets the v0->v1 conversion memmove and later replay passes run off the entry. Add check_dp_table() to reject, right after check_rstbl(), any entry larger than its size claims via struct_size() (the same expression used to allocate these entries, so the check is overflow-safe by construction). All consumers can then trust lcns_follow as the real capacity. This covers every page_lcns[] access whose index is bounded by the entry itself (the conversion memmove, the HotFix store via find_dp(), and the self-bounded scan loops). Accesses whose index comes from the log record need a separate bound and are handled in a follow-up patch.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: validate dirty page table on log replay\n\nEach DIR_PAGE_ENTRY ends in a page_lcns[] array whose length is the on-disk\nlcns_follow field. check_rstbl() validates the table bookkeeping but never\nchecks that this array fits in the entry, so a crafted lcns_follow lets the\nv0->v1 conversion memmove and later replay passes run off the entry.\n\nAdd check_dp_table() to reject, right after check_rstbl(), any entry larger\nthan its size claims via struct_size() (the same expression used to allocate\nthese entries, so the check is overflow-safe by construction). All consumers\ncan then trust lcns_follow as the real capacity. This covers every\npage_lcns[] access whose index is bounded by the entry itself (the\nconversion memmove, the HotFix store via find_dp(), and the self-bounded\nscan loops). Accesses whose index comes from the log record need a separate\nbound and are handled in a follow-up patch.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00138, EPSS Percentile is 0.03601 |
debian: CVE-2026-89617 was patched at 2026-09-16
1805.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89744) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: device property: fix infinite loop in fwnode_for_each_child_node() When iterate over children of a fwnode that has a secondary fwnode, fwnode_get_next_child_node() can enter an infinite loop if the secondary fwnode has more than one child. Parent Child (Primary fwnode) FWa: {FWa1, FWa2, FWa3} (Secondary fwnode) FWb: {FWb1, FWb2} In this case: ┌─> fwnode_get_next_child_node(FWa, FWa1) │ - fwnode_call_ptr_op(FWa, get_next_child_node, FWa1) returns FWa2 │ │ ... │ │ fwnode_get_next_child_node(FWa, FWa3) │ - fwnode_call_ptr_op(FWa, get_next_child_node, FWa3) returns NULL │ - fwnode_call_ptr_op(FWb, get_next_child_node, FWa3) returns FWb1 │ │ fwnode_get_next_child_node(FWa, FWb1) │ - fwnode_call_ptr_op(FWa, get_next_child_node, FWb1) returns FWa1 └────┘ This cause fwnode_for_each_child_node() to loop indefinitely, reapeatedly output {FWa1, FWa2, FWa3, FWb1, FWa1, ...}. The root cause is that when the current child (FWb1) belongs to the secondary fwnode, calling get_next_child_node() on the parimary fwnode incorrectly returns the first child (FWa1) again instead of NULL. Fix this by dynamically checking the parent fwnode of the current child before calling get_next_child_node(). This approach follows the pattern established in commit b5b41ab6b0c1 ("device property: Check fwnode->secondary in fwnode_graph_get_next_endpoint()").', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndevice property: fix infinite loop in fwnode_for_each_child_node()\n\nWhen iterate over children of a fwnode that has a secondary fwnode,\nfwnode_get_next_child_node() can enter an infinite loop if the secondary\nfwnode has more than one child.\n\n Parent Child\n (Primary fwnode) FWa: {FWa1, FWa2, FWa3}\n (Secondary fwnode) FWb: {FWb1, FWb2}\n\nIn this case:\n\n ┌─> fwnode_get_next_child_node(FWa, FWa1)\n │ - fwnode_call_ptr_op(FWa, get_next_child_node, FWa1) returns FWa2\n │\n │ ...\n │\n │ fwnode_get_next_child_node(FWa, FWa3)\n │ - fwnode_call_ptr_op(FWa, get_next_child_node, FWa3) returns NULL\n │ - fwnode_call_ptr_op(FWb, get_next_child_node, FWa3) returns FWb1\n │\n │ fwnode_get_next_child_node(FWa, FWb1)\n │ - fwnode_call_ptr_op(FWa, get_next_child_node, FWb1) returns FWa1\n └────┘\n\nThis cause fwnode_for_each_child_node() to loop indefinitely, reapeatedly\noutput {FWa1, FWa2, FWa3, FWb1, FWa1, ...}.\n\nThe root cause is that when the current child (FWb1) belongs to the\nsecondary fwnode, calling get_next_child_node() on the parimary fwnode\nincorrectly returns the first child (FWa1) again instead of NULL.\n\nFix this by dynamically checking the parent fwnode of the current child\nbefore calling get_next_child_node(). This approach follows the pattern\nestablished in commit b5b41ab6b0c1 ("device property: Check\nfwnode->secondary in fwnode_graph_get_next_endpoint()").', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04027 |
debian: CVE-2026-89744 was patched at 2026-09-16
1806.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89755) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: clear stale mapping after freeing swapcache __migrate_device_pages() reads the folio mapping before calling folio_free_swap(). When folio_free_swap() succeeds, the folio is removed from the swap cache, but the saved mapping still points to swap_space. Passing the stale mapping to folio_migrate_mapping() makes it use the mapped-folio path for a folio that is no longer in swapcache. It can then operate on swap_space.i_pages with invalid reference accounting, eventually triggering a folio reference count BUG. After a successful split, nr still contains the number of pages in the original large folio, although each resulting page is now a separate order-0 folio. Reset nr to 1 so each split folio is processed separately, including its own swapcache removal and mapping lookup. Refresh the saved mapping after folio_free_swap() so the current folio state is used during migration.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/migrate_device: clear stale mapping after freeing swapcache\n\n__migrate_device_pages() reads the folio mapping before calling\nfolio_free_swap(). When folio_free_swap() succeeds, the folio is removed\nfrom the swap cache, but the saved mapping still points to swap_space.\n\nPassing the stale mapping to folio_migrate_mapping() makes it use the\nmapped-folio path for a folio that is no longer in swapcache. It can then\noperate on swap_space.i_pages with invalid reference accounting,\neventually triggering a folio reference count BUG.\n\nAfter a successful split, nr still contains the number of pages in the\noriginal large folio, although each resulting page is now a separate\norder-0 folio. Reset nr to 1 so each split folio is processed separately,\nincluding its own swapcache removal and mapping lookup.\n\nRefresh the saved mapping after folio_free_swap() so the current folio\nstate is used during migration.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00143, EPSS Percentile is 0.04002 |
debian: CVE-2026-89755 was patched at 2026-09-16
1807.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89762) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: apparmor: fix cred UAF caused by begin_current_label_crit_section() AppArmor's begin_current_label_crit_section() is a scary function called from lots of LSM hooks (in particular VFS/socket-related ones) that checks if the label referenced by the current creds is marked FLAG_STALE, and if so, attempts to use aa_replace_current_label() to replace the creds with an updated version that uses a new label. The first problem with this is that it would directly lead to UAF of `struct cred` if anything in the kernel takes a pointer to the current creds and accesses these past a security hook invocation that replaces creds, like so: ``` const struct cred *cred = current_cred(); alloc_file_pseudo(...); uid_t uid = cred->euid; ``` I don't know if anything in the kernel actually does this, but I think it is very surprising that this pattern could lead to UAF. The second problem is that things go wrong when aa_replace_current_label() runs with overridden credentials. aa_replace_current_label() bails out if `current_cred() != current_real_cred()` (mirroring the check in proc_pid_attr_write()), but this check can't actually reliably detect overridden credentials because the overridden creds can be the same as the objective creds. So in approximately the following scenario, things go wrong: 1. task begins with <creds A> (as both objective and subjective creds), with refcount=2 2. task grabs an extra reference on <creds A> for overriding 3. task calls override_creds(<creds A>), which returns a pointer to the old subjective creds (<creds A>) 4. task enters AppArmor LSM hook 5. AppArmor checks that objective/subjective creds are equal 6. AppArmor replaces both cred pointers with <creds B> and drops 2 refs on <creds A> 7. task leaves AppArmor LSM hook 8. task calls revert_creds(<creds A>) 9. now task->cred is <creds A> while task->real_cred is <creds B>, but the task_struct logically holds two references to <creds B> 10. another task drops the extra reference on <creds A> that was used for overriding, refcount drops to 0 11. now task->real_cred points to freed creds At this point, any access to current_cred() will be UAF. I have a test case where I run aa-disable on a profile while a process using that profile is blocked on splice() from a FUSE passthrough file into a full pipe; after the profile update, the pipe becomes empty, splice() resumes, the credentials go out of sync, and a subsequent getuid() syscall results in a KASAN UAF splat. To fix this, instead of directly replacing creds, do it via task_work that will run at the end of the current syscall. (The point in time at which the cred replacement happens should have no correctness impact; it is just a performance optimization to avoid unnecessarily touching the refcount of the new label.) Note that AppArmor still performs direct cred replacements in the sb_pivotroot LSM hook after this change, and that direct cred replacements can still happen in VFS ->write() callbacks via proc_pid_attr_write(). There are two options for what to do with aa_dup_task_ctx(): Either explicitly reset new->label_replacement_pending after the entire aa_task_ctx has been copied, or switch to manually copying members over. I am switching to manually copying members over because that should make bugs more obvious.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix cred UAF caused by begin_current_label_crit_section()\n\nAppArmor's begin_current_label_crit_section() is a scary function called\nfrom lots of LSM hooks (in particular VFS/socket-related ones) that checks\nif the label referenced by the current creds is marked FLAG_STALE, and if\nso, attempts to use aa_replace_current_label() to replace the creds with an\nupdated version that uses a new label.\n\nThe first problem with this is that it would directly lead to UAF of\n`struct cred` if anything in the kernel takes a pointer to the current\ncreds and accesses these past a security hook invocation that replaces\ncreds, like so:\n```\nconst struct cred *cred = current_cred();\nalloc_file_pseudo(...);\nuid_t uid = cred->euid;\n```\nI don't know if anything in the kernel actually does this, but I think it\nis very surprising that this pattern could lead to UAF.\n\nThe second problem is that things go wrong when aa_replace_current_label()\nruns with overridden credentials. aa_replace_current_label() bails out if\n`current_cred() != current_real_cred()` (mirroring the check in\nproc_pid_attr_write()), but this check can't actually reliably detect\noverridden credentials because the overridden creds can be the same as the\nobjective creds.\n\nSo in approximately the following scenario, things go wrong:\n\n1. task begins with <creds A> (as both objective and subjective creds),\n with refcount=2\n2. task grabs an extra reference on <creds A> for overriding\n3. task calls override_creds(<creds A>), which returns a pointer to the old\n subjective creds (<creds A>)\n4. task enters AppArmor LSM hook\n5. AppArmor checks that objective/subjective creds are equal\n6. AppArmor replaces both cred pointers with <creds B> and drops 2 refs on\n <creds A>\n7. task leaves AppArmor LSM hook\n8. task calls revert_creds(<creds A>)\n9. now task->cred is <creds A> while task->real_cred is <creds B>, but the\n task_struct logically holds two references to <creds B>\n10. another task drops the extra reference on <creds A> that was used for\n overriding, refcount drops to 0\n11. now task->real_cred points to freed creds\n\nAt this point, any access to current_cred() will be UAF.\n\nI have a test case where I run aa-disable on a profile while a process\nusing that profile is blocked on splice() from a FUSE passthrough file into\na full pipe; after the profile update, the pipe becomes empty, splice()\nresumes, the credentials go out of sync, and a subsequent getuid() syscall\nresults in a KASAN UAF splat.\n\nTo fix this, instead of directly replacing creds, do it via task_work that\nwill run at the end of the current syscall. (The point in time at which the\ncred replacement happens should have no correctness impact; it is just a\nperformance optimization to avoid unnecessarily touching the refcount of\nthe new label.)\n\nNote that AppArmor still performs direct cred replacements in the\nsb_pivotroot LSM hook after this change, and that direct cred replacements\ncan still happen in VFS ->write() callbacks via proc_pid_attr_write().\n\nThere are two options for what to do with aa_dup_task_ctx(): Either\nexplicitly reset new->label_replacement_pending after the entire\naa_task_ctx has been copied, or switch to manually copying members over.\nI am switching to manually copying members over because that should make\nbugs more obvious.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02057 |
debian: CVE-2026-89762 was patched at 2026-09-16
1808.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89771) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix subbuf resize race with ring buffer readers trace_buffer subbuf_size is read lockless in ring_buffer_read_page() and ring_buffer_read_start(), while it can simultaneously be resized with ring_buffer_subbuf_order_set(). Instead of trace_buffer::subbuf_size, use bpage::order in ring_buffer_read_start() and ring_buffer_read_page(). In ring_buffer_read_start(), even with resize_disabled, there is still a possibility of a race with a buffer modification. Hold the trace_buffer mutex to synchronise with any pending ring buffer order modification. trace_buffer::subbuf_size is now actually useless, remove it. Also, create accessors rb_subbuf_capacity() and rb_page_capacity() which return the actual size available for storing events, while rb_subbuf_size() returns the actual subbuf page-size.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Fix subbuf resize race with ring buffer readers\n\ntrace_buffer subbuf_size is read lockless in ring_buffer_read_page() and\nring_buffer_read_start(), while it can simultaneously be resized with\nring_buffer_subbuf_order_set().\n\nInstead of trace_buffer::subbuf_size, use bpage::order in\nring_buffer_read_start() and ring_buffer_read_page().\n\nIn ring_buffer_read_start(), even with resize_disabled, there is still a\npossibility of a race with a buffer modification. Hold the trace_buffer\nmutex to synchronise with any pending ring buffer order modification.\n\ntrace_buffer::subbuf_size is now actually useless, remove it. Also,\ncreate accessors rb_subbuf_capacity() and rb_page_capacity() which\nreturn the actual size available for storing events, while\nrb_subbuf_size() returns the actual subbuf page-size.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02058 |
debian: CVE-2026-89771 was patched at 2026-09-16
1809.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89792) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds reads in share config responses Validate IPC share configuration payload sizes before consuming variable-length fields. Bound veto list parsing and account for the separator byte when deriving the path length.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: prevent out-of-bounds reads in share config responses\n\nValidate IPC share configuration payload sizes before consuming\nvariable-length fields. Bound veto list parsing and account for\nthe separator byte when deriving the path length.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00189, EPSS Percentile is 0.08778 |
debian: CVE-2026-89792 was patched at 2026-09-16
1810.
Unknown Vulnerability Type - Sudo (CVE-2026-54552) - Medium [245]
Description: {'nvd_cve_data_all': 'sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplete privilege drop on Linux and Unix-like systems. When sh runs from an elevated process and launches a command with _uid set to an unprivileged user, the child changes its UID but can retain the parent process's supplementary groups because the privilege-drop sequence does not fully establish the target user's UID, primary GID, and supplementary groups. The child can therefore retain access to files or resources granted to privileged groups such as root, docker, disk, shadow, or sudo, violating the expected _uid privilege boundary. This issue is fixed in version 2.2.4.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplete privilege drop on Linux and Unix-like systems. When sh runs from an elevated process and launches a command with _uid set to an unprivileged user, the child changes its UID but can retain the parent process's supplementary groups because the privilege-drop sequence does not fully establish the target user's UID, primary GID, and supplementary groups. The child can therefore retain access to files or resources granted to privileged groups such as root, docker, disk, shadow, or sudo, violating the expected _uid privilege boundary. This issue is fixed in version 2.2.4.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | Sudo is a widely used Unix/Linux utility that allows permitted users to execute commands with elevated (typically root) privileges while providing extensive logging and fine-grained security controls. It is a foundational component in most Linux and BSD distributions. | |
| 0.8 | 10 | CVSS Base Score is 7.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.0253 |
debian: CVE-2026-54552 was patched at 2026-08-25
1811.
Unknown Vulnerability Type - nghttp2 (CVE-2026-73513) - Medium [245]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's optional oghttp2 upstream HTTP/2 codec accepts a response trailer HEADERS frame without END_STREAM. Envoy completes and deferred-deletes the ActiveRequest while oghttp2 keeps the stream open, leaving ClientStreamImpl with a dangling response_decoder_ reference. A later frame on the stream can dispatch through the freed object and crash the process. The relevant scope boundary is that the default nghttp2 codec rejects the malformed trailers, and the trigger is upstream-only with oghttp2 enabled. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | nghttp2 is an implementation of HTTP/2 and its header compression algorithm HPACK in C | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-73513 was patched at 2026-08-28, 2026-08-31
1812.
Unknown Vulnerability Type - util-linux (CVE-2026-78410) - Medium [245]
Description: {'nvd_cve_data_all': 'A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | Linux utility suite providing core system tools including mount. Vulnerability affects SUID mount binary due to TOCTOU race condition. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00096, EPSS Percentile is 0.00778 |
debian: CVE-2026-78410 was patched at 2026-09-16
1813.
Denial of Service - Unknown Product (CVE-2026-52687) - Medium [244]
Description: {'nvd_cve_data_all': 'An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and open several such connections. The memory limit of the process is reached with only a few connections, terminating the process and all connections it handles, which can cause degradation or denial of service for IMAP. Disable IMAP compression. Alternatively limit the number of connections handled by a single imap-login process, though this has a performance impact. Update to non-vulnerable version. No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and open several such connections. The memory limit of the process is reached with only a few connections, terminating the process and all connections it handles, which can cause degradation or denial of service for IMAP. Disable IMAP compression. Alternatively limit the number of connections handled by a single imap-login process, though this has a performance impact. Update to non-vulnerable version. No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00321, EPSS Percentile is 0.25095 |
altlinux: CVE-2026-52687 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-52687 was patched at 2026-09-16
1814.
Denial of Service - Unknown Product (CVE-2026-68555) - Medium [244]
Description: {'nvd_cve_data_all': 'Coturn is a free open source implementation of TURN and STUN Server. In 4.15.0, an authenticated TURN user can repeatedly resume one allocation from fresh UDP 5-tuples without completing a handoff when the server enables --mobility. mobile_begin_transition() in src/server/ns_turn_server.c disarms each new session's allocation timeout and overwrites the allocation's single mobile_pending_resume link, leaving earlier pending sessions unreachable by the cleanup path, while copy_auth_parameters() ignores inc_quota() failure. The attacker can therefore retain unbounded server-side sessions and exhaust process memory even when --user-quota=1 is configured. This issue is fixed in version 4.16.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Coturn is a free open source implementation of TURN and STUN Server. In 4.15.0, an authenticated TURN user can repeatedly resume one allocation from fresh UDP 5-tuples without completing a handoff when the server enables --mobility. mobile_begin_transition() in src/server/ns_turn_server.c disarms each new session's allocation timeout and overwrites the allocation's single mobile_pending_resume link, leaving earlier pending sessions unreachable by the cleanup path, while copy_auth_parameters() ignores inc_quota() failure. The attacker can therefore retain unbounded server-side sessions and exhaust process memory even when --user-quota=1 is configured. This issue is fixed in version 4.16.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00368, EPSS Percentile is 0.30428 |
debian: CVE-2026-68555 was patched at 2026-08-25
1815.
Denial of Service - Unknown Product (CVE-2026-73209) - Medium [244]
Description: {'nvd_cve_data_all': 'An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash. The affected process is terminated, which can cause degradation or denial of service for IMAP. Update to non-vulnerable version. No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash. The affected process is terminated, which can cause degradation or denial of service for IMAP. Update to non-vulnerable version. No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00321, EPSS Percentile is 0.25095 |
altlinux: CVE-2026-73209 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-73209 was patched at 2026-09-16
1816.
Denial of Service - Unknown Product (CVE-2026-86433) - Medium [244]
Description: {'nvd_cve_data_all': 'commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Attributes extension where AttributesListener::findTargetAndDirection() performs quadratic-time sibling list scanning. Unauthenticated attackers can submit approximately 32 KB of repeated attribute blocks to cause parsing to take over 5 seconds, exhausting server resources.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Attributes extension where AttributesListener::findTargetAndDirection() performs quadratic-time sibling list scanning. Unauthenticated attackers can submit approximately 32 KB of repeated attribute blocks to cause parsing to take over 5 seconds, exhausting server resources.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00291, EPSS Percentile is 0.21756 |
debian: CVE-2026-86433 was patched at 2026-09-16
1817.
Denial of Service - Unknown Product (CVE-2026-86434) - Medium [244]
Description: {'nvd_cve_data_all': 'league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeric-suffix search from 1 on every slug collision, resulting in O(K^2) time complexity for K headings that collapse to the same base slug. The vulnerable path is reached when HeadingPermalinkExtension, FootnoteExtension, or TableOfContentsExtension is registered. An unauthenticated attacker can force many headings onto a single base slug (e.g., via empty ATX headings, identical heading text, or punctuation-only headings) in a small Markdown document, consuming excessive CPU and denying service.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeric-suffix search from 1 on every slug collision, resulting in O(K^2) time complexity for K headings that collapse to the same base slug. The vulnerable path is reached when HeadingPermalinkExtension, FootnoteExtension, or TableOfContentsExtension is registered. An unauthenticated attacker can force many headings onto a single base slug (e.g., via empty ATX headings, identical heading text, or punctuation-only headings) in a small Markdown document, consuming excessive CPU and denying service.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00291, EPSS Percentile is 0.21756 |
debian: CVE-2026-86434 was patched at 2026-09-16
1818.
Denial of Service - Unknown Product (CVE-2026-86435) - Medium [244]
Description: {'nvd_cve_data_all': 'commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to create quadratic output expansion, consuming excessive memory and CPU to exhaust server resources.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to create quadratic output expansion, consuming excessive memory and CPU to exhaust server resources.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00279, EPSS Percentile is 0.20425 |
debian: CVE-2026-86435 was patched at 2026-09-16
1819.
Incorrect Calculation - OpenEXR (CVE-2026-55373) - Medium [244]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | OpenEXR is an open source high-dynamic-range image file format and reference implementation widely used in computer graphics, visual effects, animation, and motion picture production. | |
| 0.6 | 10 | CVSS Base Score is 6.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0011, EPSS Percentile is 0.0143 |
debian: CVE-2026-55373 was patched at 2026-09-16
1820.
Incorrect Calculation - Unknown Product (CVE-2026-87020) - Medium [244]
Description: {'nvd_cve_data_all': 'An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc\xa0DICOM Server\xa0decodes an attacker-supplied PNG.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.0056, EPSS Percentile is 0.45164 |
debian: CVE-2026-87020 was patched at 2026-09-16
1821.
Memory Corruption - OpenEXR (CVE-2026-55059) - Medium [244]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | OpenEXR is an open source high-dynamic-range image file format and reference implementation widely used in computer graphics, visual effects, animation, and motion picture production. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00103, EPSS Percentile is 0.01115 |
debian: CVE-2026-55059 was patched at 2026-09-16
1822.
Memory Corruption - Suricata (CVE-2026-57225) - Medium [244]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Suricata is an open-source intrusion detection and prevention system (IDS/IPS) and network security monitoring engine that supports deep packet inspection and threat detection. | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-57225 was patched at 2026-09-16
1823.
Memory Corruption - Suricata (CVE-2026-57226) - Medium [244]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Suricata is an open-source intrusion detection and prevention system (IDS/IPS) and network security monitoring engine that supports deep packet inspection and threat detection. | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-57226 was patched at 2026-09-16
1824.
Memory Corruption - Unknown Product (CVE-2026-85504) - Medium [244]
Description: {'nvd_cve_data_all': 'FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00388, EPSS Percentile is 0.32586 |
debian: CVE-2026-85504 was patched at 2026-09-16
1825.
Memory Corruption - Unknown Product (CVE-2026-85506) - Medium [244]
Description: {'nvd_cve_data_all': 'ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00388, EPSS Percentile is 0.32586 |
debian: CVE-2026-85506 was patched at 2026-09-16
1826.
Memory Corruption - Unknown Product (CVE-2026-85507) - Medium [244]
Description: {'nvd_cve_data_all': 'ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00388, EPSS Percentile is 0.32586 |
debian: CVE-2026-85507 was patched at 2026-09-16
1827.
Memory Corruption - Unknown Product (CVE-2026-85508) - Medium [244]
Description: {'nvd_cve_data_all': 'ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00388, EPSS Percentile is 0.32587 |
debian: CVE-2026-85508 was patched at 2026-09-16
1828.
Memory Corruption - Unknown Product (CVE-2026-85509) - Medium [244]
Description: {'nvd_cve_data_all': 'FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00388, EPSS Percentile is 0.32586 |
debian: CVE-2026-85509 was patched at 2026-09-16
1829.
Memory Corruption - tesseract_ocr (CVE-2026-88050) - Medium [244]
Description: Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharcompress.h validates length_ but accepts negative code_ values from a crafted .traineddata recoder component. UnicharCompress::ComputeCodeRange in src/ccutil/unicharcompress.cpp can consequently produce code_range_ equal to zero, after which SetupDecoder indexes is_valid_start_ with the negative code on a size-zero vector. The resulting out-of-bounds bit write uses a large wrapped index and reliably causes a wild-address crash or allocation failure on the default LSTM engine. No fixed release is available as of this review.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:tesseract-ocr:tesseract_ocr (does NOT exist in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0015, EPSS Percentile is 0.04571 |
debian: CVE-2026-88050 was patched at 2026-09-16
1830.
Path Traversal - Unknown Product (CVE-2026-87910) - Medium [244]
Description: {'nvd_cve_data_all': 'When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00423, EPSS Percentile is 0.36026 |
debian: CVE-2026-87910 was patched at 2026-09-16
1831.
Security Feature Bypass - Unknown Product (CVE-2026-48548) - Medium [244]
Description: {'nvd_cve_data_all': 'Nagios Core before 4.5.12 contains a cross-site request forgery vulnerability in cmd.cgi where the CSRF protection mechanism passes validation when the NagFormId cookie is absent. Attackers can craft a malicious cross-site POST request to execute arbitrary Nagios commands as a currently authenticated user without their knowledge or consent.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Nagios Core before 4.5.12 contains a cross-site request forgery vulnerability in cmd.cgi where the CSRF protection mechanism passes validation when the NagFormId cookie is absent. Attackers can craft a malicious cross-site POST request to execute arbitrary Nagios commands as a currently authenticated user without their knowledge or consent.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00139, EPSS Percentile is 0.03648 |
debian: CVE-2026-48548 was patched at 2026-09-16
1832.
Security Feature Bypass - Unknown Product (CVE-2026-75032) - Medium [244]
Description: {'nvd_cve_data_all': 'A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability, affecting the parse_media_element() and parse_media_folder() functions, can lead to a crash of the bluetoothd daemon, resulting in a Denial of Service (DoS). It could also potentially expose sensitive heap memory contents. Exploitation requires user interaction to pair with the malicious device.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability, affecting the parse_media_element() and parse_media_folder() functions, can lead to a crash of the bluetoothd daemon, resulting in a Denial of Service (DoS). It could also potentially expose sensitive heap memory contents. Exploitation requires user interaction to pair with the malicious device.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00201, EPSS Percentile is 0.10224 |
debian: CVE-2026-75032 was patched at 2026-08-20
1833.
Unknown Vulnerability Type - Gitea (CVE-2026-28740) - Medium [244]
Description: {'nvd_cve_data_all': 'Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.75 | 14 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.25319 |
altlinux: CVE-2026-28740 was patched at 2026-08-27, 2026-08-29, 2026-09-04
1834.
Unknown Vulnerability Type - xmldom (CVE-2026-83611) - Medium [244]
Description: {'nvd_cve_data_all': 'xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, DOMParser.parseFromString() can silently accept an end tag such as </a\\njunk>, close the element, and discard the trailing content. On 0.9.x, the lib/sax.js end-tag validator inherits the multiline flag from reg(), allowing the first line to satisfy the anchored XML ETag production; older lines have no equivalent residue validation. This parser differential can bypass a parse-before-trust well-formedness gate, although it does not inject the discarded content; onError on 0.9.x and errorHandler on 0.8.x are the relevant reporting interfaces. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, DOMParser.parseFromString() can silently accept an end tag such as </a\\njunk>, close the element, and discard the trailing content. On 0.9.x, the lib/sax.js end-tag validator inherits the multiline flag from reg(), allowing the first line to satisfy the anchored XML ETag production; older lines have no equivalent residue validation. This parser differential can bypass a parse-before-trust well-formedness gate, although it does not inject the discarded content; onError on 0.9.x and errorHandler on 0.8.x are the relevant reporting interfaces. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.75 | 14 | JavaScript XML parser and serializer implementing W3C DOM standards. | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00352, EPSS Percentile is 0.28668 |
debian: CVE-2026-83611 was patched at 2026-09-16
1835.
XXE Injection - Unknown Product (CVE-2026-19614) - Medium [244]
Description: {'nvd_cve_data_all': 'The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The API is prone to XML external entity (XXE) injection. By default, XML external entity\xa0support is enabled.\nThis issue affects NanoXML: 2.2.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | XXE Injection | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00232, EPSS Percentile is 0.14166 |
debian: CVE-2026-19614 was patched at 2026-09-16
1836.
Information Disclosure - Unknown Product (CVE-2026-20708) - Medium [243]
Description: {'nvd_cve_data_all': 'Insertion of sensitive information into log file in the subsystem for the Intel(R) AMT and Intel(R) Standard Manageability may allow an information disclosure. Network adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Insertion of sensitive information into log file in the subsystem for the Intel(R) AMT and Intel(R) Standard Manageability may allow an information disclosure. Network adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00245, EPSS Percentile is 0.15903 |
oraclelinux: CVE-2026-20708 was patched at 2026-09-02, 2026-09-16
1837.
Unknown Vulnerability Type - Perl (CVE-2026-81928) - Medium [242]
Description: {'nvd_cve_data_all': 'Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG record. sig_data signs a message by re-encoding it, and removes TSIG records only from the additional section. A TSIG decoded into the answer or authority section survives that step and is signed again, so encoding re-enters sig_data with no termination condition. Decoding does not reject such a message: a TSIG that is not the last record on the wire raises "misplaced or corrupt TSIG", but the error is caught, reported as a warning, and the record is left in the packet. RFC 8945 section 5.2 requires the message to be dropped. The recursion is reached only when the decoded TSIG carries an empty MAC, since a MAC recovered from the wire short-circuits the signing step. It is reached only from code that re-encodes a message it decoded, such as a forwarder or a proxy. A decoded message that is never re-encoded is unaffected. Message direction does not matter: a query reaches the same path as a response. Each cycle re-encodes the whole message, so fewer than 100 bytes on the wire exhaust available memory and terminate the process.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG record.\n\nsig_data signs a message by re-encoding it, and removes TSIG records only from the additional section. A TSIG decoded into the answer or authority section survives that step and is signed again, so encoding re-enters sig_data with no termination condition. Decoding does not reject such a message: a TSIG that is not the last record on the wire raises "misplaced or corrupt TSIG", but the error is caught, reported as a warning, and the record is left in the packet. RFC 8945 section 5.2 requires the message to be dropped.\n\nThe recursion is reached only when the decoded TSIG carries an empty MAC, since a MAC recovered from the wire short-circuits the signing step. It is reached only from code that re-encodes a message it decoded, such as a forwarder or a proxy. A decoded message that is never re-encoded is unaffected. Message direction does not matter: a query reaches the same path as a response.\n\nEach cycle re-encodes the whole message, so fewer than 100 bytes on the wire exhaust available memory and terminate the process.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00485, EPSS Percentile is 0.40605 |
debian: CVE-2026-81928 was patched at 2026-09-16
1838.
Open Redirect - Unknown Product (CVE-2026-55185) - Medium [241]
Description: {'nvd_cve_data_all': 'Miniflux 2 is an open source feed reader. Prior to 2.3.1, IsRelativePath in internal/urllib/url.go accepts redirect targets containing backslashes because Go URL parsing treats them as path characters. Browser backslash normalization converts them to forward slashes. An unauthenticated attacker can provide such a redirect_url value to the login flow, bypass the relative-path and host checks, and redirect a victim to an attacker-controlled external site. This issue is fixed in version 2.3.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Miniflux 2 is an open source feed reader. Prior to 2.3.1, IsRelativePath in internal/urllib/url.go accepts redirect targets containing backslashes because Go URL parsing treats them as path characters. Browser backslash normalization converts them to forward slashes. An unauthenticated attacker can provide such a redirect_url value to the login flow, bypass the relative-path and host checks, and redirect a victim to an attacker-controlled external site. This issue is fixed in version 2.3.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.75 | 15 | Open Redirect | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00426, EPSS Percentile is 0.36262 |
debian: CVE-2026-55185 was patched at 2026-08-25
1839.
Denial of Service - kin-openapi (CVE-2026-73502) - Medium [240]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.12 | 14 | kin-openapi is a Go library for parsing, converting, validating, and working with OpenAPI and Swagger specifications and for validating HTTP requests and responses against OpenAPI schemas. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00372, EPSS Percentile is 0.3083 |
debian: CVE-2026-73502 was patched at 2026-08-20
1840.
Unknown Vulnerability Type - Chromium (CVE-2026-78914) - Medium [240]
Description: {'nvd_cve_data_all': 'Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0027, EPSS Percentile is 0.19229 |
altlinux: CVE-2026-78914 was patched at 2026-08-28
debian: CVE-2026-78914 was patched at 2026-09-03, 2026-09-16
1841.
Unknown Vulnerability Type - Chromium (CVE-2026-78947) - Medium [240]
Description: {'nvd_cve_data_all': 'Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00273, EPSS Percentile is 0.19803 |
altlinux: CVE-2026-78947 was patched at 2026-08-28
debian: CVE-2026-78947 was patched at 2026-09-03, 2026-09-16
1842.
Unknown Vulnerability Type - Chromium (CVE-2026-78968) - Medium [240]
Description: {'nvd_cve_data_all': 'Missing authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially spoof address bar via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially spoof address bar via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00297, EPSS Percentile is 0.22411 |
altlinux: CVE-2026-78968 was patched at 2026-08-28
debian: CVE-2026-78968 was patched at 2026-09-03, 2026-09-16
1843.
Unknown Vulnerability Type - Chromium (CVE-2026-79005) - Medium [240]
Description: {'nvd_cve_data_all': 'Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00303, EPSS Percentile is 0.22983 |
altlinux: CVE-2026-79005 was patched at 2026-08-28
debian: CVE-2026-79005 was patched at 2026-09-03, 2026-09-16
1844.
Unknown Vulnerability Type - Chromium (CVE-2026-79107) - Medium [240]
Description: {'nvd_cve_data_all': 'Incorrect authorization in TabGroups in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially leak sensitive information via crafted network traffic. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in TabGroups in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially leak sensitive information via crafted network traffic. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00277, EPSS Percentile is 0.20197 |
altlinux: CVE-2026-79107 was patched at 2026-08-28
debian: CVE-2026-79107 was patched at 2026-09-03, 2026-09-16
1845.
Unknown Vulnerability Type - Chromium (CVE-2026-79108) - Medium [240]
Description: {'nvd_cve_data_all': 'UI misrepresentation in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'UI misrepresentation in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00251, EPSS Percentile is 0.16754 |
altlinux: CVE-2026-79108 was patched at 2026-08-28
debian: CVE-2026-79108 was patched at 2026-09-03, 2026-09-16
1846.
Unknown Vulnerability Type - Chromium (CVE-2026-79177) - Medium [240]
Description: {'nvd_cve_data_all': 'Incorrect authorization in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00262, EPSS Percentile is 0.18211 |
altlinux: CVE-2026-79177 was patched at 2026-08-28
debian: CVE-2026-79177 was patched at 2026-09-03, 2026-09-16
1847.
Unknown Vulnerability Type - Chromium (CVE-2026-79179) - Medium [240]
Description: {'nvd_cve_data_all': 'Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00238, EPSS Percentile is 0.15005 |
altlinux: CVE-2026-79179 was patched at 2026-08-28
debian: CVE-2026-79179 was patched at 2026-09-03, 2026-09-16
1848.
Unknown Vulnerability Type - Chromium (CVE-2026-79221) - Medium [240]
Description: {'nvd_cve_data_all': 'Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0027, EPSS Percentile is 0.19229 |
altlinux: CVE-2026-79221 was patched at 2026-08-28
debian: CVE-2026-79221 was patched at 2026-09-03, 2026-09-16
1849.
Unknown Vulnerability Type - Chromium (CVE-2026-79258) - Medium [240]
Description: {'nvd_cve_data_all': 'Incorrect authorization in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00305, EPSS Percentile is 0.23191 |
altlinux: CVE-2026-79258 was patched at 2026-08-28
debian: CVE-2026-79258 was patched at 2026-09-03, 2026-09-16
1850.
Unknown Vulnerability Type - Chromium (CVE-2026-87429) - Medium [240]
Description: {'nvd_cve_data_all': 'Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00306, EPSS Percentile is 0.23406 |
altlinux: CVE-2026-87429 was patched at 2026-09-17
debian: CVE-2026-87429 was patched at 2026-09-16
1851.
Unknown Vulnerability Type - Chromium (CVE-2026-87473) - Medium [240]
Description: {'nvd_cve_data_all': 'Incorrect authorization in FileHandling in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in FileHandling in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00259, EPSS Percentile is 0.17726 |
altlinux: CVE-2026-87473 was patched at 2026-09-17
debian: CVE-2026-87473 was patched at 2026-09-16
1852.
Unknown Vulnerability Type - Chromium (CVE-2026-87519) - Medium [240]
Description: {'nvd_cve_data_all': 'Incorrect authorization in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00253, EPSS Percentile is 0.16983 |
altlinux: CVE-2026-87519 was patched at 2026-09-17
debian: CVE-2026-87519 was patched at 2026-09-16
1853.
Unknown Vulnerability Type - Chromium (CVE-2026-87522) - Medium [240]
Description: {'nvd_cve_data_all': 'Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00299, EPSS Percentile is 0.22589 |
altlinux: CVE-2026-87522 was patched at 2026-09-17
debian: CVE-2026-87522 was patched at 2026-09-16
1854.
Unknown Vulnerability Type - Keycloak (CVE-2026-18214) - Medium [240]
Description: {'nvd_cve_data_all': 'Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloak token, does not check these domain restrictions. This means an attacker with a valid Google account from a different domain could bypass the security check and gain access to the Keycloak realm.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloak token, does not check these domain restrictions. This means an attacker with a valid Google account from a different domain could bypass the security check and gain access to the Keycloak realm.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00189, EPSS Percentile is 0.08751 |
altlinux: CVE-2026-18214 was patched at 2026-09-01, 2026-09-04, 2026-09-07
1855.
Unknown Vulnerability Type - Keycloak (CVE-2026-18571) - Medium [240]
Description: {'nvd_cve_data_all': 'A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00245, EPSS Percentile is 0.15852 |
altlinux: CVE-2026-18571 was patched at 2026-09-01, 2026-09-04, 2026-09-07
1856.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92019) - Medium [240]
Description: {'nvd_cve_data_all': 'Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.05988 |
altlinux: CVE-2026-92019 was patched at 2026-09-16
debian: CVE-2026-92019 was patched at 2026-09-16, 2026-09-17
1857.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92021) - Medium [240]
Description: {'nvd_cve_data_all': 'Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 140.16 and Thunderbird 140.16.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 140.16 and Thunderbird 140.16.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.0015, EPSS Percentile is 0.04568 |
debian: CVE-2026-92021 was patched at 2026-09-16, 2026-09-17
1858.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92034) - Medium [240]
Description: {'nvd_cve_data_all': 'Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.0015, EPSS Percentile is 0.04567 |
altlinux: CVE-2026-92034 was patched at 2026-09-16
1859.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92040) - Medium [240]
Description: {'nvd_cve_data_all': 'Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.0015, EPSS Percentile is 0.04567 |
altlinux: CVE-2026-92040 was patched at 2026-09-16
1860.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92046) - Medium [240]
Description: {'nvd_cve_data_all': 'Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04708 |
altlinux: CVE-2026-92046 was patched at 2026-09-16
1861.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92048) - Medium [240]
Description: {'nvd_cve_data_all': 'Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.0. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04708 |
altlinux: CVE-2026-92048 was patched at 2026-09-16
1862.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92049) - Medium [240]
Description: {'nvd_cve_data_all': 'Use-after-free in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Use-after-free in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04022 |
altlinux: CVE-2026-92049 was patched at 2026-09-16
1863.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92056) - Medium [240]
Description: {'nvd_cve_data_all': 'Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.0402 |
altlinux: CVE-2026-92056 was patched at 2026-09-16
1864.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92057) - Medium [240]
Description: {'nvd_cve_data_all': 'Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00151, EPSS Percentile is 0.04601 |
altlinux: CVE-2026-92057 was patched at 2026-09-16
1865.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92058) - Medium [240]
Description: {'nvd_cve_data_all': 'Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04021 |
altlinux: CVE-2026-92058 was patched at 2026-09-16
1866.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92059) - Medium [240]
Description: {'nvd_cve_data_all': 'Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04022 |
altlinux: CVE-2026-92059 was patched at 2026-09-16
1867.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92060) - Medium [240]
Description: {'nvd_cve_data_all': 'Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04022 |
altlinux: CVE-2026-92060 was patched at 2026-09-16
1868.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92064) - Medium [240]
Description: {'nvd_cve_data_all': 'Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04024 |
altlinux: CVE-2026-92064 was patched at 2026-09-16
1869.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92065) - Medium [240]
Description: {'nvd_cve_data_all': 'Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04023 |
altlinux: CVE-2026-92065 was patched at 2026-09-16
1870.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92067) - Medium [240]
Description: {'nvd_cve_data_all': 'Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04023 |
altlinux: CVE-2026-92067 was patched at 2026-09-16
1871.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92076) - Medium [240]
Description: {'nvd_cve_data_all': 'Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04708 |
altlinux: CVE-2026-92076 was patched at 2026-09-16
1872.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92079) - Medium [240]
Description: {'nvd_cve_data_all': 'Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00151, EPSS Percentile is 0.04602 |
altlinux: CVE-2026-92079 was patched at 2026-09-16
1873.
Unknown Vulnerability Type - OpenSSL (CVE-2026-62243) - Medium [240]
Description: {'nvd_cve_data_all': 'Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsafe-based trust-manager wrapping is unavailable (Java 25+). In this configuration the OpenSSL client does not perform hostname verification, allowing a man-in-the-middle attacker to present a certificate issued for a different hostname that is accepted without validation. Fixed in 4.2.17.Final and 4.1.137.Final.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsafe-based trust-manager wrapping is unavailable (Java 25+). In this configuration the OpenSSL client does not perform hostname verification, allowing a man-in-the-middle attacker to present a certificate issued for a different hostname that is accepted without validation. Fixed in 4.2.17.Final and 4.1.137.Final.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.05005 |
debian: CVE-2026-62243 was patched at 2026-08-25
1874.
Unknown Vulnerability Type - jackson-databind (CVE-2026-59888) - Medium [240]
Description: {'nvd_cve_data_all': 'jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Jackson Databind is a widely used Java library for converting JSON data to and from Java objects, providing data-binding functionality within the Jackson JSON processing ecosystem. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00309, EPSS Percentile is 0.23745 |
altlinux: CVE-2026-59888 was patched at 2026-08-20, 2026-08-26, 2026-08-28
1875.
Denial of Service - GVfs (CVE-2026-84270) - Medium [239]
Description: A flaw was found in the MTP backend in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | GVfs (GNOME Virtual File System) is userspace virtual filesystem software for GNOME that provides backends (including FTP) to access different remote and local file systems transparently. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0015, EPSS Percentile is 0.04556 |
debian: CVE-2026-84270 was patched at 2026-09-16
1876.
Unknown Vulnerability Type - idna (CVE-2026-17084) - Medium [239]
Description: {'nvd_cve_data_all': 'The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of the "stringprep" module. This only affects domain names containing characters that were not previously registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The "stringprep" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the "idna" \ncodec) and the in_table_b2() function of the "stringprep" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.65 | 14 | idna is a Python library implementing Internationalized Domain Names in Applications (IDNA), providing support for Unicode domain name encoding and decoding according to the IDNA standard. It is widely used by Python networking, HTTP, and DNS-related software. | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to Vulners data source | |
| 0.5 | 10 | EPSS Probability is 0.00601, EPSS Percentile is 0.47182 |
debian: CVE-2026-17084 was patched at 2026-08-20
1877.
Memory Corruption - zstd-jni (CVE-2026-90852) - Medium [238]
Description: A vulnerability has been found in luben
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.25 | 14 | zstd-jni provides Java Native Interface bindings for the Zstandard lossless compression library, enabling high-performance compression and decompression from Java, Android, and other JVM languages. | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00314, EPSS Percentile is 0.24362 |
debian: CVE-2026-90852 was patched at 2026-09-16
1878.
Unknown Vulnerability Type - OpenNLP (CVE-2026-82617) - Medium [238]
Description: {'nvd_cve_data_all': 'The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URL - contain ambiguous nested quantifiers. An application that obtains these finders through RegexNameFinderFactory.getDefaultRegexNameFinders(...) and then applies them to untrusted text through RegexNameFinder.find(String[]) or RegexNameFinder.find(String) can be driven into super-linear backtracking or into unbounded matcher recursion by a small crafted input. For the EMAIL pattern, a long run of local-part characters that is never followed by an @ forces the matcher to re-scan to end-of-input from every starting offset. Cost grows quadratically with input length: an input of approximately 32 KB consumes several seconds of CPU in a single find() call and returns no match, and each doubling of the input multiplies the cost roughly four-fold. For the URL pattern, the query-string sub-expression nests a capturing repetition inside an outer repetition. The JDK matcher recurses once per query token, so an input of approximately 4 KB containing many &-separated tokens exhausts the thread stack and causes java.lang.StackOverflowError to propagate out of find(), terminating the calling thread. On a thread created with a smaller stack (for example -Xss512k, typical of server worker pools) approximately 1 KB is sufficient. In both cases an attacker who can supply text for analysis can convert a single request into seconds to minutes of pinned CPU, or into an abrupt thread death, denying service to the embedding application. No authentication, special configuration, or model file is required beyond the application having selected one of the two built-in finders. This issue affects Apache OpenNLP: from 2.0.0 through 2.5.11; from 3.0.0-M1 through 3.0.0-M5. Users are recommended to upgrade to version 2.5.12, or to 3.0.0-M6 for users tracking the 3.0.0 milestone line, which fix the issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The two built-in name-finder patterns exposed by\nopennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL\nand DEFAULT_REGEX_NAME_FINDER.URL\xa0- contain ambiguous nested quantifiers. An\napplication that obtains these finders through\nRegexNameFinderFactory.getDefaultRegexNameFinders(...) and then applies them to\nuntrusted text through RegexNameFinder.find(String[]) or RegexNameFinder.find(String)\ncan be driven into super-linear backtracking or into unbounded matcher recursion by a\nsmall crafted input.\n\n\n\n\n\nFor the EMAIL pattern, a long run of local-part characters that is never followed by an\n@ forces the matcher to re-scan to end-of-input from every starting offset. Cost grows\nquadratically with input length: an input of approximately 32 KB consumes several seconds\nof CPU in a single find() call and returns no match, and each doubling of the input\nmultiplies the cost roughly four-fold.\n\n\n\n\n\nFor the URL pattern, the query-string sub-expression nests a capturing repetition inside\nan outer repetition. The JDK matcher recurses once per query token, so an input of\napproximately 4 KB containing many &-separated tokens exhausts the thread stack and\ncauses java.lang.StackOverflowError to propagate out of find(), terminating the\ncalling thread. On a thread created with a smaller stack (for example -Xss512k, typical\nof server worker pools) approximately 1 KB is sufficient.\n\n\n\n\n\nIn both cases an attacker who can supply text for analysis can convert a single request\ninto seconds to minutes of pinned CPU, or into an abrupt thread death, denying service to\nthe embedding application. No authentication, special configuration, or model file is\nrequired beyond the application having selected one of the two built-in finders.\n\n\n\n\n\nThis issue affects Apache OpenNLP: from 2.0.0 through 2.5.11; from 3.0.0-M1 through\n3.0.0-M5.\n\n\n\n\n\n\n\n\n\nUsers are recommended to upgrade to version 2.5.12, or to 3.0.0-M6 for users tracking the\n3.0.0 milestone line, which fix the issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:apache:opennlp (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00345, EPSS Percentile is 0.27875 |
debian: CVE-2026-82617 was patched at 2026-09-16
1879.
Unknown Vulnerability Type - SPIP (CVE-2026-72709) - Medium [238]
Description: {'nvd_cve_data_all': 'SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any server-side permission check. Attackers can bypass template-level authorization guards through direct HTTP requests to invoke actions such as editer_auteur, enabling arbitrary account password rewrites including administrator accounts and resulting in full account takeover.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any server-side permission check. Attackers can bypass template-level authorization guards through direct HTTP requests to invoke actions such as editer_auteur, enabling arbitrary account password rewrites including administrator accounts and resulting in full account takeover.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | SPIP is an open-source software content management system designed for web site publishing, oriented towards online collaborative editing | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00364, EPSS Percentile is 0.29988 |
debian: CVE-2026-72709 was patched at 2026-09-16
1880.
Incorrect Calculation - gitoxide (CVE-2026-82250) - Medium [234]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.3 | 14 | gitoxide is an idiomatic, lean, fast & safe pure Rust implementation of Git, designed for correctness and performance, available both as a Rust library (gix crate) and command-line interface tools. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.14609 |
debian: CVE-2026-82250 was patched at 2026-09-16
1881.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64460) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: PCI/IOV: Skip VF Resizable BAR restore on read error sriov_restore_vf_rebar_state() uses the VF Resizable BAR Control register to decide how many VF BARs to restore (nbars) and which VF BAR each iteration addresses (bar_idx). bar_idx indexes into dev->sriov->barsz[], which has only PCI_SRIOV_NUM_BARS (6) entries. When a device does not respond, config reads typically return PCI_ERROR_RESPONSE (~0). Both fields are 3 bits wide, so nbars and bar_idx both evaluate to 7. The barsz[] access then goes out of bounds. UBSAN reports this as: UBSAN: array-index-out-of-bounds in drivers/pci/iov.c:948:51 index 7 is out of range for type 'resource_size_t [6]' Observed on an NVIDIA RTX PRO 1000 GPU (GB207GLM) that stopped responding during a failed GC6 power state exit. The subsequent pci_restore_state() invoked sriov_restore_vf_rebar_state() while config reads returned 0xffffffff, triggering the splat. Bail out if any VF Resizable BAR Control read returns PCI_ERROR_RESPONSE. No further VF BARs are touched, which is safe because a config read that returns PCI_ERROR_RESPONSE indicates the device is unreachable and restoration is pointless. This mirrors the guard in pci_restore_rebar_state().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI/IOV: Skip VF Resizable BAR restore on read error\n\nsriov_restore_vf_rebar_state() uses the VF Resizable BAR Control register\nto decide how many VF BARs to restore (nbars) and which VF BAR each\niteration addresses (bar_idx). bar_idx indexes into dev->sriov->barsz[],\nwhich has only PCI_SRIOV_NUM_BARS (6) entries.\n\nWhen a device does not respond, config reads typically return\nPCI_ERROR_RESPONSE (~0). Both fields are 3 bits wide, so nbars and bar_idx\nboth evaluate to 7. The barsz[] access then goes out of bounds. UBSAN\nreports this as:\n\n UBSAN: array-index-out-of-bounds in drivers/pci/iov.c:948:51 index 7 is out of range for type 'resource_size_t [6]'\n\nObserved on an NVIDIA RTX PRO 1000 GPU (GB207GLM) that stopped responding\nduring a failed GC6 power state exit. The subsequent pci_restore_state()\ninvoked sriov_restore_vf_rebar_state() while config reads returned\n0xffffffff, triggering the splat.\n\nBail out if any VF Resizable BAR Control read returns PCI_ERROR_RESPONSE.\nNo further VF BARs are touched, which is safe because a config read that\nreturns PCI_ERROR_RESPONSE indicates the device is unreachable and\nrestoration is pointless. This mirrors the guard in\npci_restore_rebar_state().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00118, EPSS Percentile is 0.01941 |
ubuntu: CVE-2026-64460 was patched at 2026-09-07, 2026-09-16
1882.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64501) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad_sigma_delta: fix CS held asserted and state leaks In ad_sigma_delta_single_conversion(), set_mode(AD_SD_MODE_IDLE) and disable_one() were called from the out: block while keep_cs_asserted was still true. This caused any SPI transfer issued by those callbacks to carry cs_change=1, leaving CS permanently asserted after the conversion. Fix by moving both calls into the out_unlock: block, after keep_cs_asserted is cleared, matching the pattern already used in ad_sd_calibrate(). In the error path of ad_sd_buffer_postenable(), if an operation fails after set_mode(AD_SD_MODE_CONTINUOUS) has already succeeded (e.g. spi_offload_trigger_enable()), the device is left in continuous conversion mode with CS physically asserted. Additionally, bus_locked remaining true after spi_bus_unlock() causes subsequent SPI operations to call spi_sync_locked() without the bus lock actually held, allowing concurrent SPI access. Fix the error path by clearing keep_cs_asserted first, then calling set_mode(AD_SD_MODE_IDLE) to revert the device mode and deassert CS, then clearing bus_locked before releasing the bus. For devices that implement neither set_mode nor disable_one (such as MAX11205, which has no physical CS pin), no SPI transfer is issued during cleanup and the cs_change flag has no effect on any physical line.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ad_sigma_delta: fix CS held asserted and state leaks\n\nIn ad_sigma_delta_single_conversion(), set_mode(AD_SD_MODE_IDLE) and\ndisable_one() were called from the out: block while keep_cs_asserted\nwas still true. This caused any SPI transfer issued by those callbacks\nto carry cs_change=1, leaving CS permanently asserted after the\nconversion. Fix by moving both calls into the out_unlock: block, after\nkeep_cs_asserted is cleared, matching the pattern already used in\nad_sd_calibrate().\n\nIn the error path of ad_sd_buffer_postenable(), if an operation fails\nafter set_mode(AD_SD_MODE_CONTINUOUS) has already succeeded (e.g.\nspi_offload_trigger_enable()), the device is left in continuous\nconversion mode with CS physically asserted. Additionally,\nbus_locked remaining true after spi_bus_unlock() causes subsequent\nSPI operations to call spi_sync_locked() without the bus lock actually\nheld, allowing concurrent SPI access.\n\nFix the error path by clearing keep_cs_asserted first, then calling\nset_mode(AD_SD_MODE_IDLE) to revert the device mode and deassert CS,\nthen clearing bus_locked before releasing the bus.\n\nFor devices that implement neither set_mode nor disable_one (such as\nMAX11205, which has no physical CS pin), no SPI transfer is issued\nduring cleanup and the cs_change flag has no effect on any physical\nline.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00116, EPSS Percentile is 0.0179 |
ubuntu: CVE-2026-64501 was patched at 2026-09-07, 2026-09-16
1883.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74584) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: zero shared page before exposing to userspace bnxt_re_alloc_ucontext() allocates uctx->shpg via __get_free_page(GFP_KERNEL). The buddy allocator does not zero pages without __GFP_ZERO, so the page contains stale kernel data from whatever object most recently freed it. The page is then mapped into userspace via vm_insert_page() under BNXT_RE_MMAP_SH_PAGE in bnxt_re_mmap(). The driver only ever writes 4 bytes (a u32 AVID) at offset BNXT_RE_AVID_OFFT (0x10) inside bnxt_re_create_ah(); the remaining 4092 bytes of the page are exposed to userspace unsanitised, leaking kernel memory contents. Any user with access to /dev/infiniband/uverbsX on a host with a bnxt_re device (typically rdma group membership) can read this data via a single mmap() at pgoff 0 after IB_USER_VERBS_CMD_GET_CONTEXT. Other shared pages in the same file already use get_zeroed_page() correctly: drivers/infiniband/hw/bnxt_re/ib_verbs.c srq->uctx_srq_page = (void *)get_zeroed_page(GFP_KERNEL); cq->uctx_cq_page = (void *)get_zeroed_page(GFP_KERNEL); uctx->shpg is the only outlier. Bring it in line with the existing convention by switching to get_zeroed_page().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: zero shared page before exposing to userspace\n\nbnxt_re_alloc_ucontext() allocates uctx->shpg via\n__get_free_page(GFP_KERNEL). The buddy allocator does not zero pages\nwithout __GFP_ZERO, so the page contains stale kernel data from\nwhatever object most recently freed it.\n\nThe page is then mapped into userspace via vm_insert_page() under\nBNXT_RE_MMAP_SH_PAGE in bnxt_re_mmap(). The driver only ever writes\n4 bytes (a u32 AVID) at offset BNXT_RE_AVID_OFFT (0x10) inside\nbnxt_re_create_ah(); the remaining 4092 bytes of the page are exposed\nto userspace unsanitised, leaking kernel memory contents.\n\nAny user with access to /dev/infiniband/uverbsX on a host with a\nbnxt_re device (typically rdma group membership) can read this data\nvia a single mmap() at pgoff 0 after IB_USER_VERBS_CMD_GET_CONTEXT.\n\nOther shared pages in the same file already use get_zeroed_page()\ncorrectly:\n\n drivers/infiniband/hw/bnxt_re/ib_verbs.c\n srq->uctx_srq_page = (void *)get_zeroed_page(GFP_KERNEL);\n cq->uctx_cq_page = (void *)get_zeroed_page(GFP_KERNEL);\n\nuctx->shpg is the only outlier. Bring it in line with the existing\nconvention by switching to get_zeroed_page().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00131, EPSS Percentile is 0.0309 |
debian: CVE-2026-74584 was patched at 2026-08-25
oraclelinux: CVE-2026-74584 was patched at 2026-09-04
ubuntu: CVE-2026-74584 was patched at 2026-09-07, 2026-09-16
1884.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74603) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ptp: ocp: Fix board ID over-read The EEPROM board ID is a fixed 13-byte field and is not guaranteed to contain a NUL terminator. Passing it directly to devlink_info_version_fixed_put() treats it as a C string and may read beyond the field. Format at most OCP_BOARD_ID_LEN bytes into the existing local buffer before reporting the ID. Use a precision limit because the snprintf() output size alone does not bound the source string scan.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nptp: ocp: Fix board ID over-read\n\nThe EEPROM board ID is a fixed 13-byte field and is not guaranteed to\ncontain a NUL terminator. Passing it directly to\ndevlink_info_version_fixed_put() treats it as a C string and may read\nbeyond the field.\n\nFormat at most OCP_BOARD_ID_LEN bytes into the existing local buffer\nbefore reporting the ID. Use a precision limit because the snprintf()\noutput size alone does not bound the source string scan.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.0261 |
debian: CVE-2026-74603 was patched at 2026-08-25
oraclelinux: CVE-2026-74603 was patched at 2026-09-04
1885.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74713) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: vhost_iotlb: bound map allocation in add_range vhost_iotlb_add_range_ctx() only retires an old entry when the table has a non-zero limit, has exactly reached that limit and has VHOST_IOTLB_FLAG_RETIRE set. Non-retiring tables can keep allocating entries after reaching their configured limit. Existing vhost devices allocate their IOTLB with max_iotlb_entries from vhost.c, which defaults to 2048 and is tunable by module parameter. Use the caller-provided limit at the allocation point instead of adding a separate default in the common IOTLB helper, and reject non-positive values in vhost paths that can report an error. Other vhost IOTLB users should not create zero-limit tables when entries can be populated from userspace or guest-controlled requests. Add caller-side max_iotlb_entries parameters for mlx5 vDPA, VDUSE and vhost-vDPA. Reject non-positive VDUSE and vhost-vDPA values, and require at least two entries for vdpa_sim and mlx5 vDPA paths that install full-range mappings, since those mappings are split into two IOTLB entries. Handle full-range mappings in the common helper by checking that the IOTLB can hold both split entries before inserting the first half. This avoids returning an error after leaving a half mapping behind. When the table is full, keep the existing retire behavior for retiring tables and return -ENOSPC for non-retiring tables. Reuse the retired map node instead of freeing it and allocating a replacement, so a stream of IOTLB updates cannot keep forcing GFP_ATOMIC allocations after the table has reached its limit. If a zero-limit IOTLB still reaches the common helper, treat it as a configuration error and return -EINVAL. I found this bug myself, though the patch was written with AI assistance.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvhost_iotlb: bound map allocation in add_range\n\nvhost_iotlb_add_range_ctx() only retires an old entry when the table\nhas a non-zero limit, has exactly reached that limit and has\nVHOST_IOTLB_FLAG_RETIRE set. Non-retiring tables can keep allocating\nentries after reaching their configured limit.\n\nExisting vhost devices allocate their IOTLB with max_iotlb_entries from\nvhost.c, which defaults to 2048 and is tunable by module parameter. Use\nthe caller-provided limit at the allocation point instead of adding a\nseparate default in the common IOTLB helper, and reject non-positive\nvalues in vhost paths that can report an error.\n\nOther vhost IOTLB users should not create zero-limit tables when entries\ncan be populated from userspace or guest-controlled requests. Add\ncaller-side max_iotlb_entries parameters for mlx5 vDPA, VDUSE and\nvhost-vDPA. Reject non-positive VDUSE and vhost-vDPA values, and require\nat least two entries for vdpa_sim and mlx5 vDPA paths that install\nfull-range mappings, since those mappings are split into two IOTLB\nentries.\n\nHandle full-range mappings in the common helper by checking that the\nIOTLB can hold both split entries before inserting the first half. This\navoids returning an error after leaving a half mapping behind.\n\nWhen the table is full, keep the existing retire behavior for retiring\ntables and return -ENOSPC for non-retiring tables. Reuse the retired map\nnode instead of freeing it and allocating a replacement, so a stream of\nIOTLB updates cannot keep forcing GFP_ATOMIC allocations after the table\nhas reached its limit. If a zero-limit IOTLB still reaches the common\nhelper, treat it as a configuration error and return -EINVAL.\n\nI found this bug myself, though the patch was written with AI assistance.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02107 |
debian: CVE-2026-74713 was patched at 2026-08-25
1886.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74726) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor bond_alb_monitor() reads primary_is_promisc under RCU, then drops RCU and takes RTNL via rtnl_trylock() before undoing the promiscuity it set on the active slave. In that window the active slave can change under RTNL (RTM_DELLINK -> __bond_release_one() -> bond_alb_handle_active_change()), which already drops the promiscuity and clears primary_is_promisc. The monitor still acts on the stale decision: if the slave was removed with no failover, curr_active_slave is now NULL and the deref faults; if it failed over, the stale dev_set_promiscuity(-1) underflows the new slave's promiscuity counter and pins it in IFF_PROMISC. Oops: general protection fault, probably for non-canonical address ... KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] Workqueue: b42 bond_alb_monitor RIP: 0010:bond_alb_monitor (drivers/net/bonding/bond_alb.c:1600) process_one_work (kernel/workqueue.c:3322) worker_thread (kernel/workqueue.c:3486) kthread (kernel/kthread.c:436) ret_from_fork (arch/x86/kernel/process.c:158) Kernel panic - not syncing: Fatal exception Re-check primary_is_promisc (and curr_active_slave) after taking RTNL so the monitor only undoes an increment it still owns. The other bonding monitors already re-read state under RTNL in their commit phase (bond_miimon_commit/bond_ab_arp_commit); bond_alb_monitor() was the only one acting on the pre-trylock decision.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor\n\nbond_alb_monitor() reads primary_is_promisc under RCU, then drops RCU and\ntakes RTNL via rtnl_trylock() before undoing the promiscuity it set on the\nactive slave. In that window the active slave can change under RTNL\n(RTM_DELLINK -> __bond_release_one() -> bond_alb_handle_active_change()),\nwhich already drops the promiscuity and clears primary_is_promisc. The\nmonitor still acts on the stale decision: if the slave was removed with no\nfailover, curr_active_slave is now NULL and the deref faults; if it failed\nover, the stale dev_set_promiscuity(-1) underflows the new slave's\npromiscuity counter and pins it in IFF_PROMISC.\n\n Oops: general protection fault, probably for non-canonical address ...\n KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n Workqueue: b42 bond_alb_monitor\n RIP: 0010:bond_alb_monitor (drivers/net/bonding/bond_alb.c:1600)\n process_one_work (kernel/workqueue.c:3322)\n worker_thread (kernel/workqueue.c:3486)\n kthread (kernel/kthread.c:436)\n ret_from_fork (arch/x86/kernel/process.c:158)\n Kernel panic - not syncing: Fatal exception\n\nRe-check primary_is_promisc (and curr_active_slave) after taking RTNL so\nthe monitor only undoes an increment it still owns. The other bonding\nmonitors already re-read state under RTNL in their commit phase\n(bond_miimon_commit/bond_ab_arp_commit); bond_alb_monitor() was the only\none acting on the pre-trylock decision.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02616 |
debian: CVE-2026-74726 was patched at 2026-08-25
oraclelinux: CVE-2026-74726 was patched at 2026-09-04
1887.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80530) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN When exchanging two full-file ranges, xmi_can_exchange_reflink_flags() can move the reflink inode flag from the file that currently has it to the other file, as long as exactly one side is marked. This assumes that the file contents, and therefore all shared extents, are exchanged. That assumption is not true when XFS_EXCHMAPS_INO1_WRITTEN is set. xfs_exchmaps_can_skip_mapping() can skip hole and unwritten mappings from file1, so an exchange can complete without moving every mapping that the earlier flag-swap decision accounted for. In that case the post-operation cleanup can clear the reflink flag from an inode that still owns shared written extents. Later writes then take the non-reflink write path and may update blocks that should still have been protected by CoW, which shows up as data corruption between reflink-related files. Fix this by disabling the reflink flag exchange whenever XFS_EXCHMAPS_INO1_WRITTEN is requested. The contents exchange can still proceed; the conservative outcome is that both inodes keep the reflink flag. The regular reflink flag cleanup path can drop the extra flag later once the inode no longer has shared extents.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN\n\nWhen exchanging two full-file ranges, xmi_can_exchange_reflink_flags()\ncan move the reflink inode flag from the file that currently has it to\nthe other file, as long as exactly one side is marked. This assumes\nthat the file contents, and therefore all shared extents, are exchanged.\n\nThat assumption is not true when XFS_EXCHMAPS_INO1_WRITTEN is set.\nxfs_exchmaps_can_skip_mapping() can skip hole and unwritten mappings\nfrom file1, so an exchange can complete without moving every mapping\nthat the earlier flag-swap decision accounted for. In that case the\npost-operation cleanup can clear the reflink flag from an inode that\nstill owns shared written extents. Later writes then take the\nnon-reflink write path and may update blocks that should still have\nbeen protected by CoW, which shows up as data corruption between\nreflink-related files.\n\nFix this by disabling the reflink flag exchange whenever\nXFS_EXCHMAPS_INO1_WRITTEN is requested. The contents exchange can still\nproceed; the conservative outcome is that both inodes keep the reflink\nflag. The regular reflink flag cleanup path can drop the extra flag\nlater once the inode no longer has shared extents.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02623 |
debian: CVE-2026-80530 was patched at 2026-09-16
1888.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80555) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Free all memory if cp_init() fails The routine cp_free() is called to unpin/free any memory once an I/O is completed successfully, or if cp_prefetch() fails. But if cp_init() fails, and cp->initialized is not enabled, the same routine cannot be used to free all the memory. An attempt to address this exists in ccwchain_handle_ccw(), where a single call to ccwchain_free() is made for the currently-processed CCW segment. But this will leak other segments (created as a result of a Transfer in Channel) that had been allocated as part of the same channel program. Address this by performing the cleanup outside of the recursive ccwchain_handle_ccw()/ccwchain_loop_tic() logic.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/vfio_ccw: Free all memory if cp_init() fails\n\nThe routine cp_free() is called to unpin/free any memory once an I/O\nis completed successfully, or if cp_prefetch() fails. But if cp_init()\nfails, and cp->initialized is not enabled, the same routine cannot be\nused to free all the memory.\n\nAn attempt to address this exists in ccwchain_handle_ccw(), where a\nsingle call to ccwchain_free() is made for the currently-processed\nCCW segment. But this will leak other segments (created as a result\nof a Transfer in Channel) that had been allocated as part of the same\nchannel program.\n\nAddress this by performing the cleanup outside of the recursive\nccwchain_handle_ccw()/ccwchain_loop_tic() logic.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0014, EPSS Percentile is 0.03726 |
debian: CVE-2026-80555 was patched at 2026-09-16
1889.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80578) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fbdev: core: Fix pointer desynchronization in fb_io_read() In fb_io_read(), if copy_to_user() performs a partial copy (e.g., due to a faulty user buffer), the loop adjusts the chunk size 'c' and updates the remaining 'count'. However, the hardware 'src' pointer has already been eagerly advanced by the original chunk size. If the loop is allowed to continue, the read will resume from an incorrect, over-advanced offset. Since the remaining 'count' was only decremented by the successful bytes, this desynchronization causes the next iterations to execute more hardware reads than originally bounded, eventually leading to out-of-bounds I/O reads. Fix this by breaking out of the loop immediately upon a partial copy_to_user(). A partial copy indicates a faulty user buffer, making subsequent read attempts futile. Breaking out ensures we return the number of successfully read bytes without risking out-of-bounds hardware accesses in subsequent mismatched iterations.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: core: Fix pointer desynchronization in fb_io_read()\n\nIn fb_io_read(), if copy_to_user() performs a partial copy (e.g., due to\na faulty user buffer), the loop adjusts the chunk size 'c' and updates\nthe remaining 'count'. However, the hardware 'src' pointer has already\nbeen eagerly advanced by the original chunk size.\n\nIf the loop is allowed to continue, the read will resume from an\nincorrect, over-advanced offset. Since the remaining 'count' was only\ndecremented by the successful bytes, this desynchronization causes the\nnext iterations to execute more hardware reads than originally bounded,\neventually leading to out-of-bounds I/O reads.\n\nFix this by breaking out of the loop immediately upon a partial\ncopy_to_user(). A partial copy indicates a faulty user buffer, making\nsubsequent read attempts futile. Breaking out ensures we return the\nnumber of successfully read bytes without risking out-of-bounds hardware\naccesses in subsequent mismatched iterations.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00116, EPSS Percentile is 0.01846 |
debian: CVE-2026-80578 was patched at 2026-09-16
1890.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80662) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size The CXL r4.0 8.2.4.17.7 RAS Capability Structure has total length 0x58 bytes (CXL_RAS_CAPABILITY_LENGTH); the Header Log occupies the trailing 64 bytes at offset 0x18. CXL_HEADERLOG_SIZE was defined as SZ_512, eight times the actual on-device size. header_log_copy() reads CXL_HEADERLOG_SIZE_U32 (128) dwords from the RAS capability iomap, overrunning the 88-byte mapping by 448 bytes. The cxl_aer_uncorrectable_error trace event memcpy()s CXL_HEADERLOG_SIZE (512) bytes from its source. For the CPER caller the source is struct cxl_ras_capability_regs::header_log[16] (64 bytes) embedded in a stack-local cxl_cper_prot_err_work_data, so the memcpy reads 448 bytes of kernel stack into the trace event ring buffer where userspace can read it via tracefs. Set CXL_HEADERLOG_SIZE to 64 and derive CXL_HEADERLOG_SIZE_U32 from it, bringing all iomap readers into agreement on 16 dwords. Userspace tools such as rasdaemon have grown a dependency on the buggy 512-byte (128 u32) header_log layout in the cxl_aer_uncorrectable_error trace event. Add CXL_HEADERLOG_TRACE_SIZE_U32 = 128 and use it for the trace event __array and its memcpy to preserve that ABI. Both callers now pass a zero-filled u32[CXL_HEADERLOG_TRACE_SIZE_U32] staging buffer with only the first CXL_HEADERLOG_SIZE_U32 (16) entries populated from hardware; the remaining 112 u32s are zero-padded, keeping the 512-byte trace ring buffer layout intact. [ dj: Replaced 64 with SZ_64 per RichardC ]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size\n\nThe CXL r4.0 8.2.4.17.7 RAS Capability Structure has total length 0x58\nbytes (CXL_RAS_CAPABILITY_LENGTH); the Header Log occupies the trailing\n64 bytes at offset 0x18. CXL_HEADERLOG_SIZE was defined as SZ_512,\neight times the actual on-device size.\n\nheader_log_copy() reads CXL_HEADERLOG_SIZE_U32 (128) dwords from the\nRAS capability iomap, overrunning the 88-byte mapping by 448 bytes.\nThe cxl_aer_uncorrectable_error trace event memcpy()s CXL_HEADERLOG_SIZE\n(512) bytes from its source. For the CPER caller the source is\nstruct cxl_ras_capability_regs::header_log[16] (64 bytes) embedded in a\nstack-local cxl_cper_prot_err_work_data, so the memcpy reads 448 bytes\nof kernel stack into the trace event ring buffer where userspace can\nread it via tracefs.\n\nSet CXL_HEADERLOG_SIZE to 64 and derive CXL_HEADERLOG_SIZE_U32 from it,\nbringing all iomap readers into agreement on 16 dwords. Userspace tools\nsuch as rasdaemon have grown a dependency on the buggy 512-byte (128 u32)\nheader_log layout in the cxl_aer_uncorrectable_error trace event. Add\nCXL_HEADERLOG_TRACE_SIZE_U32 = 128 and use it for the trace event\n__array and its memcpy to preserve that ABI. Both callers now pass a\nzero-filled u32[CXL_HEADERLOG_TRACE_SIZE_U32] staging buffer with only\nthe first CXL_HEADERLOG_SIZE_U32 (16) entries populated from hardware;\nthe remaining 112 u32s are zero-padded, keeping the 512-byte trace ring\nbuffer layout intact.\n\n[ dj: Replaced 64 with SZ_64 per RichardC ]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.02439 |
debian: CVE-2026-80662 was patched at 2026-09-16
1891.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80663) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: tools/power/x86/intel-speed-select: Harden daemon pidfile open Avoid symlink-based pidfile clobbering by opening the pidfile with O_NOFOLLOW and validating it with fstat() before locking/writing. The daemon currently uses a fixed pidfile path under /tmp. A local unprivileged user can pre-create a symlink at that path and cause a root-run daemon instance to write into an attacker-chosen file.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntools/power/x86/intel-speed-select: Harden daemon pidfile open\n\nAvoid symlink-based pidfile clobbering by opening the pidfile with\nO_NOFOLLOW and validating it with fstat() before locking/writing.\n\nThe daemon currently uses a fixed pidfile path under /tmp. A local\nunprivileged user can pre-create a symlink at that path and cause a\nroot-run daemon instance to write into an attacker-chosen file.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02625 |
debian: CVE-2026-80663 was patched at 2026-09-16
redos: CVE-2026-80663 was patched at 2026-09-16
1892.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80738) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie bpf_tcp_gen_syncookie and bpf_tcp_check_syncookie accept a socket pointer 'sk' with argument type ARG_PTR_TO_BTF_ID_SOCK_COMMON. However, they access sk->sk_protocol without validating whether 'sk' represents a full socket. Fix this issue by checking sk->sk_state != TCP_LISTEN before inspecting sk->sk_protocol in both bpf_tcp_gen_syncookie and bpf_tcp_check_syncookie. Since mini-sockets are never in the TCP_LISTEN state, the condition short-circuits and prevents dereferencing fullsock-specific fields.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie\n\nbpf_tcp_gen_syncookie and bpf_tcp_check_syncookie accept a socket pointer\n'sk' with argument type ARG_PTR_TO_BTF_ID_SOCK_COMMON. However, they access\nsk->sk_protocol without validating whether 'sk' represents a full socket.\n\nFix this issue by checking sk->sk_state != TCP_LISTEN before inspecting\nsk->sk_protocol in both bpf_tcp_gen_syncookie and bpf_tcp_check_syncookie.\nSince mini-sockets are never in the TCP_LISTEN state, the condition\nshort-circuits and prevents dereferencing fullsock-specific fields.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00118, EPSS Percentile is 0.01955 |
debian: CVE-2026-80738 was patched at 2026-09-16
1893.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-81007) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipmi: ipmb: validate write message length ipmb_write() read message fields before validating the length byte. A zero or short write can read uninitialized stack bytes. A length smaller than the SMBus header underflows the block write length. Require a non-empty buffer and the minimum IPMB request length. Also require the length byte plus payload before parsing the message.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipmi: ipmb: validate write message length\n\nipmb_write() read message fields before validating the length byte.\n\nA zero or short write can read uninitialized stack bytes.\n\nA length smaller than the SMBus header underflows the block write length.\n\nRequire a non-empty buffer and the minimum IPMB request length.\n\nAlso require the length byte plus payload before parsing the message.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02587 |
debian: CVE-2026-81007 was patched at 2026-09-16
1894.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-81011) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: pass validated element count to package parsers The per-type package parsers are handed the wrong element count. hp_init_bios_package_attribute() validates obj->package.count and then calls one of the five hp_populate_*_package_data() wrappers (string, integer, enumeration, ordered list, password). Each wrapper forwards a count to its hp_populate_*_elements_from_package() parser, but instead of forwarding the validated obj->package.count it derives the count from elements[0]. elements[0] is the NAME field and is always an ACPI_TYPE_STRING, so reading ->package.count from it in fact reads ->string.length through the union acpi_object. The parsers thus bound themselves against the length of the name string rather than against the real number of elements in the package. This is safe today because hp_init_bios_package_attribute() refuses any package that has fewer than the type's element count, so a parser only ever runs on a full package and never reads past it regardless of the bogus bound. An upcoming change relaxes that check to accept shorter packages. Once a parser can receive fewer elements than its per-type count, a bound taken from the name length no longer reflects the array size, and the "elem < count" loop conditions and "elem + n >= count" sub-loop guards read past the end of elements[] - an out-of-bounds heap read. Forward the validated obj->package.count to every *_package_data() wrapper so the parsers bound themselves against the real package size. This does not change behaviour for the packages that enumerate correctly today and is a prerequisite for accepting shorter packages safely.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: hp-bioscfg: pass validated element count to package parsers\n\nThe per-type package parsers are handed the wrong element count.\n\nhp_init_bios_package_attribute() validates obj->package.count and then\ncalls one of the five hp_populate_*_package_data() wrappers (string,\ninteger, enumeration, ordered list, password). Each wrapper forwards a\ncount to its hp_populate_*_elements_from_package() parser, but instead\nof forwarding the validated obj->package.count it derives the count\nfrom elements[0]. elements[0] is the NAME field and is always an\nACPI_TYPE_STRING, so reading ->package.count from it in fact reads\n->string.length through the union acpi_object. The parsers thus bound\nthemselves against the length of the name string rather than against\nthe real number of elements in the package.\n\nThis is safe today because hp_init_bios_package_attribute() refuses any\npackage that has fewer than the type's element count, so a parser only\never runs on a full package and never reads past it regardless of the\nbogus bound.\n\nAn upcoming change relaxes that check to accept shorter packages. Once\na parser can receive fewer elements than its per-type count, a bound\ntaken from the name length no longer reflects the array size, and the\n"elem < count" loop conditions and "elem + n >= count" sub-loop guards\nread past the end of elements[] - an out-of-bounds heap read.\n\nForward the validated obj->package.count to every *_package_data()\nwrapper so the parsers bound themselves against the real package size.\nThis does not change behaviour for the packages that enumerate\ncorrectly today and is a prerequisite for accepting shorter packages\nsafely.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.0254 |
debian: CVE-2026-81011 was patched at 2026-09-16
1895.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89456) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Propagate partial completion length across ERP recovery dasd_default_erp_postaction() copies the timing and device state from the finished ERP request back to the original request but drops proc_bytes. A request that was partially completed, an ESE read of a not-yet-allocated track returns fewer bytes than requested, and then recovered through the ERP chain loses its partial-completion length. __dasd_cleanup_cqr() then sees proc_bytes == 0 and completes the whole request instead of requeueing the remainder, silently returning zeroed data for the part that was never read. Carry proc_bytes over to the original request like the other per-request state.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/dasd: Propagate partial completion length across ERP recovery\n\ndasd_default_erp_postaction() copies the timing and device state from\nthe finished ERP request back to the original request but drops\nproc_bytes. A request that was partially completed, an ESE read of a\nnot-yet-allocated track returns fewer bytes than requested, and then\nrecovered through the ERP chain loses its partial-completion length.\n__dasd_cleanup_cqr() then sees proc_bytes == 0 and completes the whole\nrequest instead of requeueing the remainder, silently returning zeroed\ndata for the part that was never read.\n\nCarry proc_bytes over to the original request like the other\nper-request state.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00145, EPSS Percentile is 0.04149 |
debian: CVE-2026-89456 was patched at 2026-09-16
1896.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89593) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: hugetlb: only adjust reservation during unmapping if mapcount is 0 Since df7a6d1f6405, __unmap_hugepage_range can adjust reservations. In the case of folio mapped in both a parent and a child, if the parent unmaps the range first, the reservation adjustment will result in an underflow of the reserved count. Once the child unmaps the range, the count is restored. Change __unmap_hugepage_range() to check the mapcount before adjusting the reservation.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhugetlb: only adjust reservation during unmapping if mapcount is 0\n\nSince df7a6d1f6405, __unmap_hugepage_range can adjust reservations. In\nthe case of folio mapped in both a parent and a child, if the parent\nunmaps the range first, the reservation adjustment will result in an\nunderflow of the reserved count. Once the child unmaps the range, the\ncount is restored. Change __unmap_hugepage_range() to check the mapcount\nbefore adjusting the reservation.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02562 |
debian: CVE-2026-89593 was patched at 2026-09-16
1897.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89639) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC cifs_do_truncate() is invoked from cifs_open() without i_rwsem, so it cannot use cifs_resize_file_locked() to perform a proper fscache cookie resize. Instead, add cifs_invalidate_cache() after cifs_setsize(). cifs_invalidate_cache() calls fscache_invalidate(), which works without holding i_rwsem: it unconditionally increments inval_counter and sets FSCACHE_COOKIE_NO_DATA_TO_READ, ensuring that stale cached data is not served once the cookie is later activated by fscache_use_cookie(). Truncation to zero leaves no valid cached data, making invalidation the correct semantic here.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC\n\ncifs_do_truncate() is invoked from cifs_open() without i_rwsem, so it\ncannot use cifs_resize_file_locked() to perform a proper fscache cookie\nresize. Instead, add cifs_invalidate_cache() after cifs_setsize().\n\ncifs_invalidate_cache() calls fscache_invalidate(), which works without\nholding i_rwsem: it unconditionally increments inval_counter and sets\nFSCACHE_COOKIE_NO_DATA_TO_READ, ensuring that stale cached data is not\nserved once the cookie is later activated by fscache_use_cookie().\nTruncation to zero leaves no valid cached data, making invalidation the\ncorrect semantic here.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.02506 |
debian: CVE-2026-89639 was patched at 2026-09-16
1898.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89640) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0 With len == 0 (clone to EOF), the effective length is computed as: len = src_inode->i_size - off; If off > i_size, this is a negative loff_t, corrupting the ByteCount in the FSCTL_DUPLICATE_EXTENTS_TO_FILE request and inverting the range in filemap_write_and_wait_range(). The existing off >= i_size check fires only after the ioctl has already been sent. Snapshot i_size_read() once for both the bounds check and the length calculation, eliminating the TOCTOU and 32-bit torn-read risk. Reject off > src_size with -EINVAL. Treat off == src_size as a no-op, consistent with __generic_remap_file_range_prep().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: fix loff_t underflow in cifs_remap_file_range() when len == 0\n\nWith len == 0 (clone to EOF), the effective length is computed as:\n\n len = src_inode->i_size - off;\n\nIf off > i_size, this is a negative loff_t, corrupting the ByteCount\nin the FSCTL_DUPLICATE_EXTENTS_TO_FILE request and inverting the range\nin filemap_write_and_wait_range(). The existing off >= i_size check\nfires only after the ioctl has already been sent.\n\nSnapshot i_size_read() once for both the bounds check and the length\ncalculation, eliminating the TOCTOU and 32-bit torn-read risk. Reject\noff > src_size with -EINVAL. Treat off == src_size as a no-op,\nconsistent with __generic_remap_file_range_prep().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02625 |
debian: CVE-2026-89640 was patched at 2026-09-16
1899.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89691) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: clear opcnt on compound arg release to prevent OOB read nfsd4_release_compoundargs() resets args->ops to the inline iops[8] array when the dynamically-allocated ops buffer is freed, but leaves args->opcnt at its original value (which can be up to 200 for NFSv4.1+ compounds). If rq_status_counter is stuck at an odd value (which can happen when nfsd_dispatch() hits an error path after setting it odd), the RPC status dumpit handler reads min(opcnt, 16) entries from args->ops[]. Since iops only has 8 elements and is the last field in struct nfsd4_compoundargs, reading indices 8-15 accesses adjacent slab memory and leaks it to userspace via netlink. Zero opcnt unconditionally in nfsd4_release_compoundargs() so stale compound metadata is never exposed through the status interface. [ cel: Remove the kvfree_rcu_mightsleep() sleep from the exposure window ]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: clear opcnt on compound arg release to prevent OOB read\n\nnfsd4_release_compoundargs() resets args->ops to the inline iops[8]\narray when the dynamically-allocated ops buffer is freed, but leaves\nargs->opcnt at its original value (which can be up to 200 for NFSv4.1+\ncompounds).\n\nIf rq_status_counter is stuck at an odd value (which can happen when\nnfsd_dispatch() hits an error path after setting it odd), the RPC\nstatus dumpit handler reads min(opcnt, 16) entries from args->ops[].\nSince iops only has 8 elements and is the last field in struct\nnfsd4_compoundargs, reading indices 8-15 accesses adjacent slab memory\nand leaks it to userspace via netlink.\n\nZero opcnt unconditionally in nfsd4_release_compoundargs() so stale\ncompound metadata is never exposed through the status interface.\n\n[ cel: Remove the kvfree_rcu_mightsleep() sleep from the exposure window ]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.0254 |
debian: CVE-2026-89691 was patched at 2026-09-16
1900.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89705) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: restore rq_status_counter to even on all nfsd_dispatch() exit paths nfsd_dispatch() sets rq_status_counter to an odd value once a request has been decoded, and back to an even value once it has been fully processed, forming a seq-lock like protocol with the lockless reader in nfsd_nl_rpc_status_get_dumpit(). Only the fully successful path restored the counter to even. The cache-hit (RC_REPLY), drop (RC_DROPIT / RQ_DROPME) and encode-error paths all return after the odd-valued store without ever bringing the counter back to even. Once one of those paths is taken, rq_status_counter is left odd: the next request's decode ORs in 1 (still odd) and only a subsequent successful encode restores even. While stuck odd, the dumpit reader treats the rqstp fields as stable and its retry check compares against the same unchanging odd value, so it never detects concurrent mutation. This exposes actively mutating fields (e.g. args->ops / args->opcnt during compound decode and release) to the lockless reader, which can read past the end of the 8-element inline ops array. Add a helper that advances the counter to the next even value and call it on every return path that follows the odd-valued store. The decode-error path is left untouched as it is reached before the counter is set odd.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: restore rq_status_counter to even on all nfsd_dispatch() exit paths\n\nnfsd_dispatch() sets rq_status_counter to an odd value once a request has\nbeen decoded, and back to an even value once it has been fully processed,\nforming a seq-lock like protocol with the lockless reader in\nnfsd_nl_rpc_status_get_dumpit().\n\nOnly the fully successful path restored the counter to even. The cache-hit\n(RC_REPLY), drop (RC_DROPIT / RQ_DROPME) and encode-error paths all return\nafter the odd-valued store without ever bringing the counter back to even.\nOnce one of those paths is taken, rq_status_counter is left odd: the next\nrequest's decode ORs in 1 (still odd) and only a subsequent successful\nencode restores even. While stuck odd, the dumpit reader treats the rqstp\nfields as stable and its retry check compares against the same unchanging\nodd value, so it never detects concurrent mutation. This exposes actively\nmutating fields (e.g. args->ops / args->opcnt during compound decode and\nrelease) to the lockless reader, which can read past the end of the\n8-element inline ops array.\n\nAdd a helper that advances the counter to the next even value and call it\non every return path that follows the odd-valued store. The decode-error\npath is left untouched as it is reached before the counter is set odd.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0015, EPSS Percentile is 0.04523 |
debian: CVE-2026-89705 was patched at 2026-09-16
1901.
Denial of Service - Unknown Product (CVE-2026-40014) - Medium [232]
Description: {'nvd_cve_data_all': 'An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to the size of the message. When a mail client issues a THREAD command on the affected mailbox, this can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage, kill the offending process and remove the offending message from the affected mailbox. Update to non-vulnerable version. No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to the size of the message. When a mail client issues a THREAD command on the affected mailbox, this can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage, kill the offending process and remove the offending message from the affected mailbox. Update to non-vulnerable version. No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00272, EPSS Percentile is 0.19671 |
altlinux: CVE-2026-40014 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-40014 was patched at 2026-09-16
1902.
Denial of Service - Unknown Product (CVE-2026-40017) - Medium [232]
Description: {'nvd_cve_data_all': 'An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table, which makes the IMAP THREAD command consume CPU disproportionate to the size of the message. This is a separate issue from CVE-2026-40014 and is not addressed by that fix. Whenever a mail client issues a THREAD command on the affected mailbox, this can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage, kill the offending process and remove the offending message from the affected mailbox. Update to non-vulnerable version. No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table, which makes the IMAP THREAD command consume CPU disproportionate to the size of the message. This is a separate issue from CVE-2026-40014 and is not addressed by that fix. Whenever a mail client issues a THREAD command on the affected mailbox, this can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage, kill the offending process and remove the offending message from the affected mailbox. Update to non-vulnerable version. No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00272, EPSS Percentile is 0.19671 |
altlinux: CVE-2026-40017 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-40017 was patched at 2026-09-16
1903.
Denial of Service - Unknown Product (CVE-2026-65976) - Medium [232]
Description: {'nvd_cve_data_all': 'Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.300, a connected peer can send repeated DCLP DataChunk messages to ClipboardChunk::assemble() in src/lib/deskflow/ClipboardChunk.cpp, causing the server path in src/lib/server/ClientProxy1_6.cpp or client path in src/lib/client/ServerProxy.cpp to append data beyond the DataStart declared size and configured clipboard limit before DataEnd validation, exhausting receiver memory. This issue is fixed in continuous build 1.26.0.300.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.300, a connected peer can send repeated DCLP DataChunk messages to ClipboardChunk::assemble() in src/lib/deskflow/ClipboardChunk.cpp, causing the server path in src/lib/server/ClientProxy1_6.cpp or client path in src/lib/client/ServerProxy.cpp to append data beyond the DataStart declared size and configured clipboard limit before DataEnd validation, exhausting receiver memory. This issue is fixed in continuous build 1.26.0.300.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00311, EPSS Percentile is 0.23892 |
debian: CVE-2026-65976 was patched at 2026-08-20
1904.
Denial of Service - Unknown Product (CVE-2026-73199) - Medium [232]
Description: {'nvd_cve_data_all': 'A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending a malformed Lightweight Directory Access Protocol (LDAP) extended operation. By omitting the request value for the `JOIN_OID` in the `ipa-enrollment` extended operation, an attacker can trigger a server crash, potentially causing a denial of service.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending a malformed Lightweight Directory Access Protocol (LDAP) extended operation. By omitting the request value for the `JOIN_OID` in the `ipa-enrollment` extended operation, an attacker can trigger a server crash, potentially causing a denial of service.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00297, EPSS Percentile is 0.22382 |
debian: CVE-2026-73199 was patched at 2026-08-25
1905.
Denial of Service - Unknown Product (CVE-2026-78322) - Medium [232]
Description: {'nvd_cve_data_all': 'A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path into a fixed-size stack buffer using an unbounded string copy. This can trigger a stack buffer overflow and cause file-roller to terminate, resulting in a denial of service. To exploit this flaw, a victim must open or extract the crafted archive using file-roller.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path into a fixed-size stack buffer using an unbounded string copy. This can trigger a stack buffer overflow and cause file-roller to terminate, resulting in a denial of service. To exploit this flaw, a victim must open or extract the crafted archive using file-roller.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00282, EPSS Percentile is 0.20794 |
debian: CVE-2026-78322 was patched at 2026-09-16
1906.
Denial of Service - Unknown Product (CVE-2026-79590) - Medium [232]
Description: {'nvd_cve_data_all': 'A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling functions, resulting in undefined behavior and application crash.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling functions, resulting in undefined behavior and application crash.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00254, EPSS Percentile is 0.17118 |
debian: CVE-2026-79590 was patched at 2026-09-16
1907.
Denial of Service - Unknown Product (CVE-2026-81665) - Medium [232]
Description: {'nvd_cve_data_all': 'A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00212, EPSS Percentile is 0.11675 |
debian: CVE-2026-81665 was patched at 2026-09-16
oraclelinux: CVE-2026-81665 was patched at 2026-09-16
1908.
Denial of Service - Unknown Product (CVE-2026-81666) - Medium [232]
Description: {'nvd_cve_data_all': 'An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems due to an integer overflow in the calculation of the expected message length, allowing a crafted network packet to trigger an out-of-bounds memory access that crashes the Corosync daemon. This results in a denial of service for the affected cluster node. The overflow does not occur on 64-bit systems, where the length calculation is correctly performed in 64-bit arithmetic.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems due to an integer overflow in the calculation of the expected message length, allowing a crafted network packet to trigger an out-of-bounds memory access that crashes the Corosync daemon. This results in a denial of service for the affected cluster node. The overflow does not occur on 64-bit systems, where the length calculation is correctly performed in 64-bit arithmetic.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00271, EPSS Percentile is 0.19416 |
debian: CVE-2026-81666 was patched at 2026-09-16
1909.
Denial of Service - Unknown Product (CVE-2026-87724) - Medium [232]
Description: {'nvd_cve_data_all': 'Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0026, EPSS Percentile is 0.17867 |
debian: CVE-2026-87724 was patched at 2026-09-16
1910.
Memory Corruption - Unknown Product (CVE-2026-54789) - Medium [232]
Description: {'nvd_cve_data_all': 'mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available. As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed `Cookie` headers (tokens lacking `=`) can reduce exposure, but upgrading is the recommended remediation.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available. As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed `Cookie` headers (tokens lacking `=`) can reduce exposure, but upgrading is the recommended remediation.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00488, EPSS Percentile is 0.40854 |
debian: CVE-2026-54789 was patched at 2026-08-25, 2026-09-02
1911.
Memory Corruption - Unknown Product (CVE-2026-89266) - Medium [232]
Description: {'nvd_cve_data_all': 'stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes, causing process crashes or heap corruption.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes, causing process crashes or heap corruption.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00473, EPSS Percentile is 0.39822 |
debian: CVE-2026-89266 was patched at 2026-09-16
1912.
Path Traversal - Unknown Product (CVE-2026-82035) - Medium [232]
Description: {'nvd_cve_data_all': 'PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is constructed by joining a document-controlled BaseFont name directly onto the user-supplied output directory without stripping path separators or dot-dot sequences. Attackers can supply a crafted PDF, EPUB, XPS, or FB2 file with a BaseFont name containing encoded path separators that decode to ../ sequences or absolute paths, causing arbitrary file writes outside the intended output directory without requiring authentication or elevated privileges.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is constructed by joining a document-controlled BaseFont name directly onto the user-supplied output directory without stripping path separators or dot-dot sequences. Attackers can supply a crafted PDF, EPUB, XPS, or FB2 file with a BaseFont name containing encoded path separators that decode to ../ sequences or absolute paths, causing arbitrary file writes outside the intended output directory without requiring authentication or elevated privileges.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00315, EPSS Percentile is 0.24459 |
debian: CVE-2026-82035 was patched at 2026-09-16
1913.
Security Feature Bypass - Unknown Product (CVE-2025-31356) - Medium [232]
Description: {'nvd_cve_data_all': 'Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: Hypervisor may allow an information disclosure. A system software adversary with a privileged user access combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without any user interaction. The potential vulnerability may impact the confidentiality (high), integrity (low) and no effect on availability. Subsequent system impacts include reduced confidentiality (low), integrity (low), and no effect on availability.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: Hypervisor may allow an information disclosure. A system software adversary with a privileged user access combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without any user interaction. The potential vulnerability may impact the confidentiality (high), integrity (low) and no effect on availability. Subsequent system impacts include reduced confidentiality (low), integrity (low), and no effect on availability.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.6. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00072, EPSS Percentile is 0.00065 |
oraclelinux: CVE-2025-31356 was patched at 2026-09-02, 2026-09-16
1914.
Security Feature Bypass - Unknown Product (CVE-2026-34959) - Medium [232]
Description: {'nvd_cve_data_all': 'Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no trusted-proxy check and no validation of the prefix value. An attacker can supply an absolute URL (e.g. X-Forwarded-Prefix: https://evil.example) that flows into Location redirect headers, the Set-Cookie path attribute, and self-referential links. This enables an authenticated open redirect after state-changing POSTs, unauthenticated control of the session cookie path attribute, and poisoning of self-referential links; CR/LF cannot be injected, so header splitting/XSS is not possible.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no trusted-proxy check and no validation of the prefix value. An attacker can supply an absolute URL (e.g. X-Forwarded-Prefix: https://evil.example) that flows into Location redirect headers, the Set-Cookie path attribute, and self-referential links. This enables an authenticated open redirect after state-changing POSTs, unauthenticated control of the session cookie path attribute, and poisoning of self-referential links; CR/LF cannot be injected, so header splitting/XSS is not possible.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00208, EPSS Percentile is 0.11121 |
debian: CVE-2026-34959 was patched at 2026-09-16
1915.
Security Feature Bypass - Unknown Product (CVE-2026-87732) - Medium [232]
Description: {'nvd_cve_data_all': 'An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and only then compares the tag. On a forged tag, the functions returns false, but the destination buffer already holds the full plaintext.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and only then compares the tag. On a forged tag, the functions returns false, but the destination buffer already holds the full plaintext.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00077, EPSS Percentile is 0.00128 |
debian: CVE-2026-87732 was patched at 2026-09-16
1916.
Security Feature Bypass - Unknown Product (CVE-2026-87733) - Medium [232]
Description: {'nvd_cve_data_all': 'An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key, signatures can be forged without a private key.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key, signatures can be forged without a private key.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00105, EPSS Percentile is 0.0119 |
debian: CVE-2026-87733 was patched at 2026-09-16
1917.
Unknown Vulnerability Type - xmldom (CVE-2026-83610) - Medium [232]
Description: {'nvd_cve_data_all': 'xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createEntityReference(name) accepts an invalid name and the ENTITY_REFERENCE_NODE serializer emits the resulting nodeName directly in &name; form. Directly serializing the node or fragment with XMLSerializer.serializeToString() and requireWellFormed: true can therefore break the entity-reference boundary and produce attacker-controlled XML markup when reparsed. The parser does not ordinarily create these nodes, and element-child insertion is rejected, so exploitation requires an application to create and directly serialize an EntityReference. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createEntityReference(name) accepts an invalid name and the ENTITY_REFERENCE_NODE serializer emits the resulting nodeName directly in &name; form. Directly serializing the node or fragment with XMLSerializer.serializeToString() and requireWellFormed: true can therefore break the entity-reference boundary and produce attacker-controlled XML markup when reparsed. The parser does not ordinarily create these nodes, and element-child insertion is rejected, so exploitation requires an application to create and directly serialize an EntityReference. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available for xmldom.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.75 | 14 | JavaScript XML parser and serializer implementing W3C DOM standards. | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00355, EPSS Percentile is 0.29035 |
debian: CVE-2026-83610 was patched at 2026-09-16
1918.
Unknown Vulnerability Type - Perl (CVE-2026-75589) - Medium [230]
Description: {'nvd_cve_data_all': 'Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. Each of the three compares the signature carried in the message against the locally computed one with the eq operator, which returns as soon as the two strings differ. The time taken to reject a signature varies with the length of the matching prefix. RSA-SHA1 is not affected, as it verifies through the RSA key object rather than by comparing strings. A client that can submit messages and time the replies may recover a valid signature one byte at a time rather than searching the whole signature space. Under PLAINTEXT the value compared against is the signature key itself, so the search recovers consumer_secret and token_secret.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify.\n\nEach of the three compares the signature carried in the message against the locally computed one with the eq operator, which returns as soon as the two strings differ. The time taken to reject a signature varies with the length of the matching prefix. RSA-SHA1 is not affected, as it verifies through the RSA key object rather than by comparing strings.\n\nA client that can submit messages and time the replies may recover a valid signature one byte at a time rather than searching the whole signature space. Under PLAINTEXT the value compared against is the signature key itself, so the search recovers consumer_secret and token_secret.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00409, EPSS Percentile is 0.34676 |
debian: CVE-2026-75589 was patched at 2026-08-20
1919.
Unknown Vulnerability Type - Chromium (CVE-2026-79021) - Medium [228]
Description: {'nvd_cve_data_all': 'Missing authorization in InterestGroups in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted PDF file. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in InterestGroups in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted PDF file. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00234, EPSS Percentile is 0.14432 |
altlinux: CVE-2026-79021 was patched at 2026-08-28
debian: CVE-2026-79021 was patched at 2026-09-03, 2026-09-16
1920.
Unknown Vulnerability Type - Chromium (CVE-2026-79060) - Medium [228]
Description: {'nvd_cve_data_all': 'Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00229, EPSS Percentile is 0.13855 |
altlinux: CVE-2026-79060 was patched at 2026-08-28
debian: CVE-2026-79060 was patched at 2026-09-03, 2026-09-16
1921.
Unknown Vulnerability Type - Chromium (CVE-2026-79208) - Medium [228]
Description: {'nvd_cve_data_all': 'Missing authorization in HTTP2 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via crafted network traffic. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in HTTP2 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via crafted network traffic. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00301, EPSS Percentile is 0.22795 |
altlinux: CVE-2026-79208 was patched at 2026-08-28
debian: CVE-2026-79208 was patched at 2026-09-03, 2026-09-16
1922.
Unknown Vulnerability Type - Chromium (CVE-2026-85044) - Medium [228]
Description: {'nvd_cve_data_all': 'Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00228, EPSS Percentile is 0.13713 |
altlinux: CVE-2026-85044 was patched at 2026-09-05
debian: CVE-2026-85044 was patched at 2026-09-05, 2026-09-16
1923.
Unknown Vulnerability Type - Chromium (CVE-2026-87534) - Medium [228]
Description: {'nvd_cve_data_all': 'Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00214, EPSS Percentile is 0.1186 |
altlinux: CVE-2026-87534 was patched at 2026-09-17
debian: CVE-2026-87534 was patched at 2026-09-16
1924.
Unknown Vulnerability Type - Chromium (CVE-2026-87627) - Medium [228]
Description: {'nvd_cve_data_all': 'Interpretation conflict in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted file. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Interpretation conflict in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted file. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10005 |
altlinux: CVE-2026-87627 was patched at 2026-09-17
debian: CVE-2026-87627 was patched at 2026-09-16
1925.
Unknown Vulnerability Type - Chromium (CVE-2026-87631) - Medium [228]
Description: {'nvd_cve_data_all': 'Missing authorization in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00222, EPSS Percentile is 0.12923 |
altlinux: CVE-2026-87631 was patched at 2026-09-17
debian: CVE-2026-87631 was patched at 2026-09-16
1926.
Unknown Vulnerability Type - GNU C Library (CVE-2026-19542) - Medium [228]
Description: {'nvd_cve_data_all': 'Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application. The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree. Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete. The written value is a pointer into a tree node and is not directly attacker controlled. No affected application in common distributions has been identified.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree. Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete. The written value is a pointer into a tree node and is not directly attacker controlled. No affected application in common distributions has been identified.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | The GNU C Library, commonly known as glibc, is the GNU Project's implementation of the C standard library | |
| 0.6 | 10 | CVSS Base Score is 5.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00277, EPSS Percentile is 0.20148 |
debian: CVE-2026-19542 was patched at 2026-08-25
ubuntu: CVE-2026-19542 was patched at 2026-09-08, 2026-09-16
1927.
Unknown Vulnerability Type - Keycloak (CVE-2026-16106) - Medium [228]
Description: {'nvd_cve_data_all': 'A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, an attacker with limited administrative permissions can remove privileged roles they are not authorized to manage, leading to a loss of access for other users and administrators.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, an attacker with limited administrative permissions can remove privileged roles they are not authorized to manage, leading to a loss of access for other users and administrators.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.5 | 10 | CVSS Base Score is 4.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0033, EPSS Percentile is 0.26112 |
altlinux: CVE-2026-16106 was patched at 2026-09-01, 2026-09-04, 2026-09-07
1928.
Unknown Vulnerability Type - Keycloak (CVE-2026-18572) - Medium [228]
Description: {'nvd_cve_data_all': 'Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the user to bypass these time-based restrictions and access protected resources at unauthorized times.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the user to bypass these time-based restrictions and access protected resources at unauthorized times.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00182, EPSS Percentile is 0.08006 |
altlinux: CVE-2026-18572 was patched at 2026-09-01, 2026-09-04, 2026-09-07
1929.
Unknown Vulnerability Type - Keycloak (CVE-2026-18573) - Medium [228]
Description: {'nvd_cve_data_all': 'A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication requirements on confidential clients. Due to improper evaluation of the client state during an update operation, an attacker with client management permissions can bypass these security policies by first creating a public client and then updating it to a confidential client with weaker authentication. This can result in the persistence of clients that do not comply with the intended security hardening of the realm.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication requirements on confidential clients. Due to improper evaluation of the client state during an update operation, an attacker with client management permissions can bypass these security policies by first creating a public client and then updating it to a confidential client with weaker authentication. This can result in the persistence of clients that do not comply with the intended security hardening of the realm.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00221, EPSS Percentile is 0.12764 |
altlinux: CVE-2026-18573 was patched at 2026-09-01, 2026-09-04, 2026-09-07
1930.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-74984) - Medium [228]
Description: {'nvd_cve_data_all': 'Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00186, EPSS Percentile is 0.08442 |
altlinux: CVE-2026-74984 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
1931.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92042) - Medium [228]
Description: {'nvd_cve_data_all': 'Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04707 |
altlinux: CVE-2026-92042 was patched at 2026-09-16
1932.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92044) - Medium [228]
Description: {'nvd_cve_data_all': 'Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04707 |
altlinux: CVE-2026-92044 was patched at 2026-09-16
1933.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92072) - Medium [228]
Description: {'nvd_cve_data_all': 'Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04021 |
altlinux: CVE-2026-92072 was patched at 2026-09-16
1934.
Unknown Vulnerability Type - Node.js (CVE-2026-87859) - Medium [228]
Description: {'nvd_cve_data_all': 'morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the double quote character, which delimits the quoted fields of the Apache combined log format that morgan emits. An unauthenticated remote attacker who controls a value written to a quoted field, such as the User-Agent or Referer header, can include a double quote to close that field early, so a log consumer that parses the log by field position reads attacker-supplied text as the following field. In the built-in formats this makes the recorded value differ from the value that was sent, and in custom formats that quote an attacker-controlled token before a server-controlled one it can forge values such as the response status. No newline is injected, so record separation stays intact. The issue is fixed in morgan 1.12.1, which escapes the double quote. Users should upgrade to morgan 1.12.1 or later.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the double quote character, which delimits the quoted fields of the Apache combined log format that morgan emits. An unauthenticated remote attacker who controls a value written to a quoted field, such as the User-Agent or Referer header, can include a double quote to close that field early, so a log consumer that parses the log by field position reads attacker-supplied text as the following field. In the built-in formats this makes the recorded value differ from the value that was sent, and in custom formats that quote an attacker-controlled token before a server-controlled one it can forge values such as the response status. No newline is injected, so record separation stays intact. The issue is fixed in morgan 1.12.1, which escapes the double quote. Users should upgrade to morgan 1.12.1 or later.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00393, EPSS Percentile is 0.33061 |
debian: CVE-2026-87859 was patched at 2026-09-16
1935.
Unknown Vulnerability Type - RPC (CVE-2026-84303) - Medium [228]
Description: {'nvd_cve_data_all': 'gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are lowercase. A DENY policy using a mixed-case name such as X-Role or User-Agent therefore does not match and fails open, allowing requests that should be rejected. The same case mismatch permits :Scheme or Grpc-Status to evade gRFC A41 validation and prevents Host from being rewritten to :authority. This issue is fixed in version 1.83.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are lowercase. A DENY policy using a mixed-case name such as X-Role or User-Agent therefore does not match and fails open, allowing requests that should be rejected. The same case mismatch permits :Scheme or Grpc-Status to evade gRFC A41 validation and prevents Host from being rewritten to :authority. This issue is fixed in version 1.83.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Remote Procedure Call Runtime | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00311, EPSS Percentile is 0.23892 |
debian: CVE-2026-84303 was patched at 2026-09-16
1936.
Unknown Vulnerability Type - OpenTelemetry (CVE-2026-55701) - Medium [226]
Description: {'nvd_cve_data_all': 'The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, the githubreceiver validates the receiver/githubreceiver/config.go RequiredHeaders configuration at startup, but receiver/githubreceiver/trace_receiver.go handleReq() does not check those headers on incoming webhook requests. An unauthenticated sender can therefore bypass an operator's required_headers authentication control and submit arbitrary webhook payloads. When the Secret field is empty, github.ValidatePayload also skips HMAC validation, leaving the webhook endpoint without either configured authentication mechanism. Successful exploitation can inject fabricated CI/CD trace data into the observability pipeline. This issue is fixed in version 0.151.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, the githubreceiver validates the receiver/githubreceiver/config.go RequiredHeaders configuration at startup, but receiver/githubreceiver/trace_receiver.go handleReq() does not check those headers on incoming webhook requests. An unauthenticated sender can therefore bypass an operator's required_headers authentication control and submit arbitrary webhook payloads. When the Secret field is empty, github.ValidatePayload also skips HMAC validation, leaving the webhook endpoint without either configured authentication mechanism. Successful exploitation can inject fabricated CI/CD trace data into the observability pipeline. This issue is fixed in version 0.151.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | OpenTelemetry is a collection of APIs, SDKs, and tools. Use it to instrument, generate, collect, and export telemetry data (metrics, logs and traces) to help you analyze your software's performance and behavior | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0.5 | 10 | EPSS Probability is 0.00672, EPSS Percentile is 0.50336 |
debian: CVE-2026-55701 was patched at 2026-09-16
1937.
Unknown Vulnerability Type - Thunderbird (CVE-2026-84639) - Medium [226]
Description: {'nvd_cve_data_all': 'Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:mozilla:thunderbird (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.25331 |
altlinux: CVE-2026-84639 was patched at 2026-09-03, 2026-09-09
debian: CVE-2026-84639 was patched at 2026-09-04, 2026-09-16
1938.
Memory Corruption - libxml2 (CVE-2026-86141) - Medium [224]
Description: xmlregexp in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | libxml2 is an XML toolkit implemented in C, originally developed for the GNOME Project | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00116, EPSS Percentile is 0.01845 |
debian: CVE-2026-86141 was patched at 2026-09-16
1939.
Authentication Bypass - Unknown Product (CVE-2026-40204) - Medium [222]
Description: {'nvd_cve_data_all': 'None None None No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'None None None No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00179, EPSS Percentile is 0.07724 |
debian: CVE-2026-40204 was patched at 2026-09-16
1940.
Unknown Vulnerability Type - Erlang/OTP (CVE-2026-66835) - Medium [221]
Description: {'nvd_cve_data_all': 'Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by prefixing the request path with an extra slash. httpd_request:validate_uri/1 normalises the request URI with uri_string:normalize/1, which performs RFC 3986 dot-segment removal but does not collapse empty path segments, so a doubled slash survives. mod_alias:real_name/3 concatenates the document root with that URI, and mod_auth:secret_path/3 then decides whether the result lies inside a protected directory block by running the configured directory path as an unanchored regular expression against it. The doubled slash breaks the contiguous substring the regex needs, so the request is treated as unprotected and no authentication challenge is issued, while mod_get opens the same path and the operating system collapses the doubled slash and returns the protected file. The same path mismatch also evades the per-path accounting in mod_security. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by prefixing the request path with an extra slash.\n\nhttpd_request:validate_uri/1 normalises the request URI with uri_string:normalize/1, which performs RFC 3986 dot-segment removal but does not collapse empty path segments, so a doubled slash survives. mod_alias:real_name/3 concatenates the document root with that URI, and mod_auth:secret_path/3 then decides whether the result lies inside a protected directory block by running the configured directory path as an unanchored regular expression against it. The doubled slash breaks the contiguous substring the regex needs, so the request is treated as unprotected and no authentication challenge is issued, while mod_get opens the same path and the operating system collapses the doubled slash and returns the protected file. The same path mismatch also evades the per-path accounting in mod_security.\n\nThis issue affects OTP from OTP\xa017.0 before OTP\xa027.3.4.17, from OTP\xa028.0 before OTP\xa028.5.0.6, and from OTP\xa029.0 before OTP\xa029.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP\xa017.0, corresponding to inets before 5.10, is affected is unknown.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.4 | 14 | Erlang/OTP is a set of libraries for the Erlang programming language | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Vulners data source | |
| 0.5 | 10 | EPSS Probability is 0.00635, EPSS Percentile is 0.48757 |
debian: CVE-2026-66835 was patched at 2026-09-16
1941.
Unknown Vulnerability Type - Erlang/OTP (CVE-2026-73270) - Medium [221]
Description: {'nvd_cve_data_all': 'Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by requesting them with different casing, on deployments whose filesystem is case-insensitive. mod_auth:secret_path/3 decides whether a resolved filesystem path lies inside a protected directory block by running the configured directory path through re:run/3 without the caseless option. A request for /secret/file against a directory configured as /Secret therefore does not match, so the request is treated as unprotected and no authentication challenge is issued, while the filesystem resolves the differently cased path to the same file and mod_get serves it. Deployments on case-sensitive filesystems are unaffected, because there the filesystem itself rejects the mismatched casing. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by requesting them with different casing, on deployments whose filesystem is case-insensitive.\n\nmod_auth:secret_path/3 decides whether a resolved filesystem path lies inside a protected directory block by running the configured directory path through re:run/3 without the caseless option. A request for /secret/file against a directory configured as /Secret therefore does not match, so the request is treated as unprotected and no authentication challenge is issued, while the filesystem resolves the differently cased path to the same file and mod_get serves it. Deployments on case-sensitive filesystems are unaffected, because there the filesystem itself rejects the mismatched casing.\n\nThis issue affects OTP from OTP\xa017.0 before OTP\xa027.3.4.17, from OTP\xa028.0 before OTP\xa028.5.0.6, and from OTP\xa029.0 before OTP\xa029.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP\xa017.0, corresponding to inets before 5.10, is affected is unknown.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.4 | 14 | Erlang/OTP is a set of libraries for the Erlang programming language | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Vulners data source | |
| 0.5 | 10 | EPSS Probability is 0.00661, EPSS Percentile is 0.49935 |
debian: CVE-2026-73270 was patched at 2026-09-16
1942.
Unknown Vulnerability Type - Spring Framework (CVE-2026-47892) - Medium [221]
Description: {'nvd_cve_data_all': 'A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.5.RELEASE - 5.2.25.RELEASE', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpring Framework 6.1.0 - 6.1.28\nSpring Framework 6.0.0 - 6.0.30\nSpring Framework 5.3.0 - 5.3.49\nSpring Framework 5.2.5.RELEASE - 5.2.25.RELEASE', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.4 | 14 | The Spring Framework is an application framework and inversion of control container for the Java platform | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00365, EPSS Percentile is 0.30096 |
debian: CVE-2026-47892 was patched at 2026-09-16
1943.
Unknown Vulnerability Type - Spring Framework (CVE-2026-59313) - Medium [221]
Description: {'nvd_cve_data_all': 'Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE).\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpring Framework 6.1.0 - 6.1.28\nSpring Framework 6.0.0 - 6.0.30\nSpring Framework 5.3.0 - 5.3.49', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.4 | 14 | The Spring Framework is an application framework and inversion of control container for the Java platform | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00387, EPSS Percentile is 0.32394 |
debian: CVE-2026-59313 was patched at 2026-09-16
1944.
Denial of Service - OpenEXR (CVE-2026-54920) - Medium [220]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | OpenEXR is an open source high-dynamic-range image file format and reference implementation widely used in computer graphics, visual effects, animation, and motion picture production. | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00213, EPSS Percentile is 0.11796 |
debian: CVE-2026-54920 was patched at 2026-09-16
1945.
Denial of Service - Unknown Product (CVE-2026-16599) - Medium [220]
Description: {'nvd_cve_data_all': 'GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation. This issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation.\n\n\nThis issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.0038, EPSS Percentile is 0.3166 |
debian: CVE-2026-16599 was patched at 2026-09-16
1946.
Denial of Service - Unknown Product (CVE-2026-40019) - Medium [220]
Description: {'nvd_cve_data_all': 'An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop consuming CPU. This can cause degradation or denial of service for Sieve script management, and repeated connections can consume all available CPU on the server. Monitor system for abnormal CPU usage and kill the offending process. Restrict network access to the ManageSieve service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop consuming CPU. This can cause degradation or denial of service for Sieve script management, and repeated connections can consume all available CPU on the server. Monitor system for abnormal CPU usage and kill the offending process. Restrict network access to the ManageSieve service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00316, EPSS Percentile is 0.24518 |
debian: CVE-2026-40019 was patched at 2026-09-16
1947.
Denial of Service - Unknown Product (CVE-2026-53495) - Medium [220]
Description: {'nvd_cve_data_all': 'containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go when CRI ExecSync is used by exec probes or lifecycle hooks that launch long-lived background child processes retaining standard input and output pipes. The input and output drain phase has no default timeout and did not stop when the request context was canceled, so repeated ExecSync invocations can accumulate blocked goroutines and host memory. The resulting resource exhaustion can cause the OOM killer to terminate containerd, leaving the container runtime unavailable until restart. Deployments not using containerd's CRI implementation and containers not running on Linux are not affected. This issue is fixed in versions 1.7.35, 2.0.12, 2.2.8, and 2.3.5.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go when CRI ExecSync is used by exec probes or lifecycle hooks that launch long-lived background child processes retaining standard input and output pipes. The input and output drain phase has no default timeout and did not stop when the request context was canceled, so repeated ExecSync invocations can accumulate blocked goroutines and host memory. The resulting resource exhaustion can cause the OOM killer to terminate containerd, leaving the container runtime unavailable until restart. Deployments not using containerd's CRI implementation and containers not running on Linux are not affected. This issue is fixed in versions 1.7.35, 2.0.12, 2.2.8, and 2.3.5.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00193, EPSS Percentile is 0.09182 |
debian: CVE-2026-53495 was patched at 2026-09-16
1948.
Denial of Service - Unknown Product (CVE-2026-80179) - Medium [220]
Description: {'nvd_cve_data_all': 'A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memory, leading to a MemoryError. This issue results in a denial of service (DoS) for services that process untrusted JWE values.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memory, leading to a MemoryError. This issue results in a denial of service (DoS) for services that process untrusted JWE values.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00251, EPSS Percentile is 0.16678 |
altlinux: CVE-2026-80179 was patched at 2026-08-28, 2026-08-31
debian: CVE-2026-80179 was patched at 2026-09-16
1949.
Denial of Service - Unknown Product (CVE-2026-83530) - Medium [220]
Description: {'nvd_cve_data_all': 'A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit would be checked / enforced.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit would be checked / enforced.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00208, EPSS Percentile is 0.11198 |
debian: CVE-2026-83530 was patched at 2026-09-16
1950.
Memory Corruption - Unknown Product (CVE-2026-59949) - Medium [220]
Description: {'nvd_cve_data_all': 'yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00453, EPSS Percentile is 0.38439 |
debian: CVE-2026-59949 was patched at 2026-08-25
1951.
Memory Corruption - Unknown Product (CVE-2026-63409) - Medium [220]
Description: {'nvd_cve_data_all': 'Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malicious Deskflow server can send an odd-length DSOP vector to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp, causing the missing value after the final option key to be read beyond the vector during the PacketStreamFilter::filterEvent to ServerProxy::handleData() to ServerProxy::parseHandshakeMessage() call chain and crash the connected client. This issue is fixed in continuous build 1.26.0.296.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malicious Deskflow server can send an odd-length DSOP vector to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp, causing the missing value after the final option key to be read beyond the vector during the PacketStreamFilter::filterEvent to ServerProxy::handleData() to ServerProxy::parseHandshakeMessage() call chain and crash the connected client. This issue is fixed in continuous build 1.26.0.296.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.25415 |
debian: CVE-2026-63409 was patched at 2026-08-25
1952.
Memory Corruption - Unknown Product (CVE-2026-65832) - Medium [220]
Description: {'nvd_cve_data_all': 'Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthenticated Deskflow server can send kMsgDSetOptions (DSOP) values to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp so that the value following a modifier option poisons m_modifierTranslationTable, after which ServerProxy::translateKey() or ServerProxy::translateModifierMask() indexes the seven-row s_translationTable or s_masks arrays out of bounds, disclosing four bytes at an attacker-selected relative offset or crashing the connected client; an odd option count also causes an out-of-bounds OptionsList read. This issue is fixed in continuous build 1.26.0.299.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthenticated Deskflow server can send kMsgDSetOptions (DSOP) values to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp so that the value following a modifier option poisons m_modifierTranslationTable, after which ServerProxy::translateKey() or ServerProxy::translateModifierMask() indexes the seven-row s_translationTable or s_masks arrays out of bounds, disclosing four bytes at an attacker-selected relative offset or crashing the connected client; an odd option count also causes an out-of-bounds OptionsList read. This issue is fixed in continuous build 1.26.0.299.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0038, EPSS Percentile is 0.31715 |
debian: CVE-2026-65832 was patched at 2026-08-20
1953.
Memory Corruption - Unknown Product (CVE-2026-78376) - Medium [220]
Description: {'nvd_cve_data_all': 'A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00276, EPSS Percentile is 0.20115 |
debian: CVE-2026-78376 was patched at 2026-09-16
1954.
Memory Corruption - Unknown Product (CVE-2026-83596) - Medium [220]
Description: {'nvd_cve_data_all': 'A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00288, EPSS Percentile is 0.21434 |
debian: CVE-2026-83596 was patched at 2026-09-16
1955.
Memory Corruption - Unknown Product (CVE-2026-85091) - Medium [220]
Description: {'nvd_cve_data_all': 'zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00442, EPSS Percentile is 0.37609 |
debian: CVE-2026-85091 was patched at 2026-09-16
1956.
Memory Corruption - Unknown Product (CVE-2026-85505) - Medium [220]
Description: {'nvd_cve_data_all': 'ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00339, EPSS Percentile is 0.27208 |
debian: CVE-2026-85505 was patched at 2026-09-16
1957.
Path Traversal - Unknown Product (CVE-2026-79655) - Medium [220]
Description: {'nvd_cve_data_all': 'A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By crafting a malicious tar archive, an attacker can exploit a path traversal issue during tar extraction, where symlink and hardlink targets are not properly validated. This enables the attacker to write files to arbitrary locations on the system with the privileges of the sos clean process, which often runs as root.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By crafting a malicious tar archive, an attacker can exploit a path traversal issue during tar extraction, where symlink and hardlink targets are not properly validated. This enables the attacker to write files to arbitrary locations on the system with the privileges of the sos clean process, which often runs as root.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.03867 |
debian: CVE-2026-79655 was patched at 2026-09-16
1958.
Information Disclosure - Unknown Product (CVE-2026-20734) - Medium [219]
Description: {'nvd_cve_data_all': 'Improper initialization in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT), and some Intel(R) Standard Manageability may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Improper initialization in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT), and some Intel(R) Standard Manageability may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.6. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02078 |
oraclelinux: CVE-2026-20734 was patched at 2026-09-02, 2026-09-16
1959.
Unknown Vulnerability Type - MongoDB (CVE-2026-18690) - Medium [219]
Description: {'nvd_cve_data_all': 'An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not permit. This could result in critical system collections being dropped and recreated without proper authorization.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not permit. This could result in critical system collections being dropped and recreated without proper authorization.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00265, EPSS Percentile is 0.18526 |
altlinux: CVE-2026-18690 was patched at 2026-08-26
1960.
Unknown Vulnerability Type - MongoDB (CVE-2026-82053) - Medium [219]
Description: {'nvd_cve_data_all': 'A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent authorization queries may execute under an unintended LDAP identity rather than the expected one. This can result in incorrect role assignments based on the LDAP directory's access control configuration, potentially allowing an authenticated user to acquire elevated privileges that were not intended by the deployment's authorization policy.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent authorization queries may execute under an unintended LDAP identity rather than the expected one. This can result in incorrect role assignments based on the LDAP directory's access control configuration, potentially allowing an authenticated user to acquire elevated privileges that were not intended by the deployment's authorization policy.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00244, EPSS Percentile is 0.15749 |
altlinux: CVE-2026-82053 was patched at 2026-09-09, 2026-09-10
1961.
Unknown Vulnerability Type - MongoDB (CVE-2026-82067) - Medium [219]
Description: {'nvd_cve_data_all': 'Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state during server startup. An unauthenticated user with network access to a deployment where this condition occurs can perform arbitrary administrative operations, resulting in full impact of data confidentiality, integrity, and availability.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state during server startup. An unauthenticated user with network access to a deployment where this condition occurs can perform arbitrary administrative operations, resulting in full impact of data confidentiality, integrity, and availability.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00283, EPSS Percentile is 0.20888 |
altlinux: CVE-2026-82067 was patched at 2026-09-09, 2026-09-10
1962.
Unknown Vulnerability Type - MongoDB (CVE-2026-88029) - Medium [219]
Description: {'nvd_cve_data_all': 'Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable. The affected rename operation may also rename a stored file other than the intended target.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable. The affected rename operation may also rename a stored file other than the intended target.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00259, EPSS Percentile is 0.1772 |
debian: CVE-2026-88029 was patched at 2026-09-16
1963.
Unknown Vulnerability Type - MongoDB (CVE-2026-88030) - Medium [219]
Description: {'nvd_cve_data_all': 'Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00259, EPSS Percentile is 0.17719 |
debian: CVE-2026-88030 was patched at 2026-09-16
1964.
Unknown Vulnerability Type - MongoDB (CVE-2026-88031) - Medium [219]
Description: {'nvd_cve_data_all': 'Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00261, EPSS Percentile is 0.1802 |
debian: CVE-2026-88031 was patched at 2026-09-16
1965.
Unknown Vulnerability Type - MongoDB (CVE-2026-88033) - Medium [219]
Description: {'nvd_cve_data_all': 'Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable. The affected rename operation may also rename a stored file other than the intended target.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable. The affected rename operation may also rename a stored file other than the intended target.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00259, EPSS Percentile is 0.17719 |
debian: CVE-2026-88033 was patched at 2026-09-16
1966.
Unknown Vulnerability Type - MongoDB (CVE-2026-88036) - Medium [219]
Description: {'nvd_cve_data_all': 'Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00259, EPSS Percentile is 0.1772 |
debian: CVE-2026-88036 was patched at 2026-09-16
1967.
Unknown Vulnerability Type - Perl (CVE-2026-78030) - Medium [219]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM.\n\nDBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. require treats a path-shaped string as a literal filename and does not consult @INC, so the attribute chooses the file that Perl loads and runs.\n\nThe MLDBM::Serializer:: prefix that DBD::DBM prepends to dbm_mldbm is not a boundary: only the :: separators are rewritten to /, so a value containing / traverses out of the serializer directory. The value is also assigned to $MLDBM::Serializer, which MLDBM requires the same way when it ties the table.\n\nA caller that lets an untrusted party influence either attribute, for example through a DSN fragment or a parameter that selects a storage backend, runs the file-scope code of whatever module the value names.\n\nFor example,\n\n my $dsn = "dbi:DBM:f_dir=/var/db;dbm_type=../../Untrusted.pm"\n my $dbh = DBI->connect( $dsn );\n\nNote that DBD::Gofer forwards connect attributes to the server side, and DBI::ProxyServer checks only that a DSN starts with a driver prefix.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-78030 was patched at 2026-09-16
1968.
Incorrect Calculation - libtiff (CVE-2026-52492) - Medium [217]
Description: An integer overflow in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.2 | 14 | libtiff is a widely used library for reading and writing TIFF (Tagged Image File Format) files, offering tools like tiff2ps. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0013, EPSS Percentile is 0.03013 |
debian: CVE-2026-52492 was patched at 2026-09-16
1969.
Open Redirect - Unknown Product (CVE-2025-71405) - Medium [217]
Description: {'nvd_cve_data_all': 'chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary hosts, enabling phishing attacks and credential theft.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary hosts, enabling phishing attacks and credential theft.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.75 | 15 | Open Redirect | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00307, EPSS Percentile is 0.2349 |
debian: CVE-2025-71405 was patched at 2026-08-25
1970.
Unknown Vulnerability Type - Chromium (CVE-2026-78892) - Medium [216]
Description: {'nvd_cve_data_all': 'Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to bypass system access restrictions via a local program. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to bypass system access restrictions via a local program. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00086, EPSS Percentile is 0.00382 |
altlinux: CVE-2026-78892 was patched at 2026-08-28
debian: CVE-2026-78892 was patched at 2026-09-03, 2026-09-16
1971.
Unknown Vulnerability Type - Chromium (CVE-2026-78898) - Medium [216]
Description: {'nvd_cve_data_all': 'Incorrect authorization in Downloads in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in Downloads in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16144 |
altlinux: CVE-2026-78898 was patched at 2026-08-28
debian: CVE-2026-78898 was patched at 2026-09-03, 2026-09-16
1972.
Unknown Vulnerability Type - Chromium (CVE-2026-78965) - Medium [216]
Description: {'nvd_cve_data_all': 'Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00391, EPSS Percentile is 0.3286 |
altlinux: CVE-2026-78965 was patched at 2026-08-28
debian: CVE-2026-78965 was patched at 2026-09-03, 2026-09-16
1973.
Unknown Vulnerability Type - Chromium (CVE-2026-78974) - Medium [216]
Description: {'nvd_cve_data_all': 'UI misrepresentation in Linux Toolkit Theming in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'UI misrepresentation in Linux Toolkit Theming in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0025, EPSS Percentile is 0.16538 |
altlinux: CVE-2026-78974 was patched at 2026-08-28
debian: CVE-2026-78974 was patched at 2026-09-03, 2026-09-16
1974.
Unknown Vulnerability Type - Chromium (CVE-2026-79010) - Medium [216]
Description: {'nvd_cve_data_all': 'Operation on a resource after expiration or release in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Operation on a resource after expiration or release in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0038, EPSS Percentile is 0.31679 |
altlinux: CVE-2026-79010 was patched at 2026-08-28
debian: CVE-2026-79010 was patched at 2026-09-03, 2026-09-16
1975.
Unknown Vulnerability Type - Chromium (CVE-2026-79088) - Medium [216]
Description: {'nvd_cve_data_all': 'Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00295, EPSS Percentile is 0.22166 |
altlinux: CVE-2026-79088 was patched at 2026-08-28
debian: CVE-2026-79088 was patched at 2026-09-03, 2026-09-16
1976.
Unknown Vulnerability Type - Chromium (CVE-2026-79116) - Medium [216]
Description: {'nvd_cve_data_all': 'Missing authorization in Viz in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in Viz in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00322, EPSS Percentile is 0.25287 |
altlinux: CVE-2026-79116 was patched at 2026-08-28
debian: CVE-2026-79116 was patched at 2026-09-03, 2026-09-16
1977.
Unknown Vulnerability Type - Chromium (CVE-2026-79180) - Medium [216]
Description: {'nvd_cve_data_all': 'UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0025, EPSS Percentile is 0.16485 |
altlinux: CVE-2026-79180 was patched at 2026-08-28
debian: CVE-2026-79180 was patched at 2026-09-03, 2026-09-16
1978.
Unknown Vulnerability Type - Chromium (CVE-2026-87453) - Medium [216]
Description: {'nvd_cve_data_all': 'Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00256, EPSS Percentile is 0.17471 |
altlinux: CVE-2026-87453 was patched at 2026-09-17
debian: CVE-2026-87453 was patched at 2026-09-16
1979.
Unknown Vulnerability Type - Chromium (CVE-2026-87458) - Medium [216]
Description: {'nvd_cve_data_all': 'UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0024, EPSS Percentile is 0.15235 |
altlinux: CVE-2026-87458 was patched at 2026-09-17
debian: CVE-2026-87458 was patched at 2026-09-16
1980.
Unknown Vulnerability Type - Chromium (CVE-2026-87555) - Medium [216]
Description: {'nvd_cve_data_all': 'Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0031, EPSS Percentile is 0.23878 |
altlinux: CVE-2026-87555 was patched at 2026-09-17
debian: CVE-2026-87555 was patched at 2026-09-16
1981.
Unknown Vulnerability Type - Chromium (CVE-2026-91720) - Medium [216]
Description: {'nvd_cve_data_all': 'Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00245, EPSS Percentile is 0.15884 |
altlinux: CVE-2026-91720 was patched at 2026-09-17
debian: CVE-2026-91720 was patched at 2026-09-16
1982.
Unknown Vulnerability Type - Keycloak (CVE-2026-18201) - Medium [216]
Description: {'nvd_cve_data_all': 'Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00217, EPSS Percentile is 0.12247 |
altlinux: CVE-2026-18201 was patched at 2026-09-01, 2026-09-04, 2026-09-07
1983.
Unknown Vulnerability Type - Keycloak (CVE-2026-79652) - Medium [216]
Description: {'nvd_cve_data_all': 'A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access tokens. The issue occurs because the JWT Bearer grant fails to check if a client requires user consent before issuing a token. This allows an authenticated attacker with valid client credentials and a trusted identity provider assertion to bypass the consent requirement and obtain unauthorized access to a user account at a consent-gated client.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access tokens. The issue occurs because the JWT Bearer grant fails to check if a client requires user consent before issuing a token. This allows an authenticated attacker with valid client credentials and a trusted identity provider assertion to bypass the consent requirement and obtain unauthorized access to a user account at a consent-gated client.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0017, EPSS Percentile is 0.06657 |
altlinux: CVE-2026-79652 was patched at 2026-09-01, 2026-09-04, 2026-09-07
1984.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92039) - Medium [216]
Description: {'nvd_cve_data_all': 'Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.055 |
altlinux: CVE-2026-92039 was patched at 2026-09-16
1985.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92063) - Medium [216]
Description: {'nvd_cve_data_all': 'Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.03878 |
altlinux: CVE-2026-92063 was patched at 2026-09-16
1986.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92077) - Medium [216]
Description: {'nvd_cve_data_all': 'Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04707 |
altlinux: CVE-2026-92077 was patched at 2026-09-16
1987.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92078) - Medium [216]
Description: {'nvd_cve_data_all': 'Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04021 |
altlinux: CVE-2026-92078 was patched at 2026-09-16
1988.
Cross Site Scripting - Unknown Product (CVE-2026-10618) - Medium [214]
Description: {'nvd_cve_data_all': 'Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go converts every attribute value from a byte slice to a string as it is stored, deliberately dropping the escaping that used to happen there, and RenderAttributes in the same file escapes only values that are still byte slices, so its escaping branch is never reached and every value is written verbatim. The function's documentation states that it performs HTML escaping of string attributes, which it does not. A quote inside an attribute value in the info string therefore terminates the attribute and allows a further attribute, including an event handler, to be placed on the wrapper element, and the script runs for every visitor who loads the page. This path is reached under the default configuration, with code fences enabled and without goldmark's unsafe setting or any custom render hook. Attribute names beginning with on are filtered when the attributes are parsed, so injection is achieved through the value rather than the name.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go converts every attribute value from a byte slice to a string as it is stored, deliberately dropping the escaping that used to happen there, and RenderAttributes in the same file escapes only values that are still byte slices, so its escaping branch is never reached and every value is written verbatim. The function's documentation states that it performs HTML escaping of string attributes, which it does not. A quote inside an attribute value in the info string therefore terminates the attribute and allows a further attribute, including an event handler, to be placed on the wrapper element, and the script runs for every visitor who loads the page. This path is reached under the default configuration, with code fences enabled and without goldmark's unsafe setting or any custom render hook. Attribute names beginning with on are filtered when the attributes are parsed, so injection is achieved through the value rather than the name.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00215, EPSS Percentile is 0.1205 |
debian: CVE-2026-10618 was patched at 2026-09-16
1989.
Cross Site Scripting - Unknown Product (CVE-2026-90848) - Medium [214]
Description: {'nvd_cve_data_all': 'A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of the argument ResultMessage can lead to cross site scripting. The attack can be launched remotely. Upgrading to version 2.5.5 is able to address this issue. It is recommended to upgrade the affected component. This CVE was requested by the vendor.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of the argument ResultMessage can lead to cross site scripting. The attack can be launched remotely. Upgrading to version 2.5.5 is able to address this issue. It is recommended to upgrade the affected component. This CVE was requested by the vendor.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.1836 |
debian: CVE-2026-90848 was patched at 2026-09-16
1990.
Denial of Service - zstd-jni (CVE-2026-89045) - Medium [214]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.25 | 14 | zstd-jni provides Java Native Interface bindings for the Zstandard lossless compression library, enabling high-performance compression and decompression from Java, Android, and other JVM languages. | |
| 0.4 | 10 | CVSS Base Score is 4.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.02505 |
debian: CVE-2026-89045 was patched at 2026-09-16
1991.
Unknown Vulnerability Type - undici (CVE-2026-19534) - Medium [214]
Description: {'nvd_cve_data_all': 'undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:nodejs:undici (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00394, EPSS Percentile is 0.33169 |
debian: CVE-2026-19534 was patched at 2026-09-16
1992.
Unknown Vulnerability Type - undici (CVE-2026-85014) - Medium [214]
Description: {'nvd_cve_data_all': 'undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close handshake. On an unclean close the internal socket-close handler calls abort on the writable stream unconditionally and discards the returned promise, but per the WHATWG Streams standard aborting a locked writable returns a promise that rejects with a TypeError. Because the application holds a writer on that writable, which is the only way to write, the rejection is never observed and Node's default unhandled-rejection behavior terminates the process. An untrusted server can therefore crash a client with a single abrupt disconnect, with no authentication and no application mistake. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close handshake. On an unclean close the internal socket-close handler calls abort on the writable stream unconditionally and discards the returned promise, but per the WHATWG Streams standard aborting a locked writable returns a promise that rejects with a TypeError. Because the application holds a writer on that writable, which is the only way to write, the rejection is never observed and Node's default unhandled-rejection behavior terminates the process. An untrusted server can therefore crash a client with a single abrupt disconnect, with no authentication and no application mistake. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:nodejs:undici (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00368, EPSS Percentile is 0.30373 |
debian: CVE-2026-85014 was patched at 2026-09-16
1993.
Elevation of Privilege - Unknown Product (CVE-2026-70665) - Medium [211]
Description: {'nvd_cve_data_all': 'Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists client-supplied scopes without validating them against the server's configured scope set. Under certain conditions, this allows a self-registered client to obtain scopes beyond what the server intended to grant. In DynamicClientRegistrationController#application_params, the scopes attribute is assigned directly from params[:scope] with no validation against Doorkeeper.configuration.scopes or optional_scopes. Combined with enforce_configured_scopes being off by default and Doorkeeper's ScopeChecker prioritizing application-level scopes over server-level scopes, this creates a privilege escalation path. This issue is fixed in version 1.10.4.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists client-supplied scopes without validating them against the server's configured scope set. Under certain conditions, this allows a self-registered client to obtain scopes beyond what the server intended to grant. In DynamicClientRegistrationController#application_params, the scopes attribute is assigned directly from params[:scope] with no validation against Doorkeeper.configuration.scopes or optional_scopes. Combined with enforce_configured_scopes being off by default and Doorkeeper's ScopeChecker prioritizing application-level scopes over server-level scopes, this creates a privilege escalation path. This issue is fixed in version 1.10.4.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00163, EPSS Percentile is 0.05944 |
debian: CVE-2026-70665 was patched at 2026-09-16
1994.
Unknown Vulnerability Type - Envoy (CVE-2026-73512) - Medium [211]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HttpDatagramHandler caches the current RequestDecoder when Capsule Protocol is enabled. Stream recreation, including an internal redirect, replaces the ActiveStream and updates EnvoyQuicServerStream but does not update the handler's cached pointer. A subsequent HTTP/3 datagram can call decodeData through the freed decoder, causing invalid virtual dispatch and a process crash. The relevant scope boundary is that hTTP/3 datagrams and Capsule Protocol must be enabled, and the request must enter a stream-recreation path such as an internal redirect. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-73512 was patched at 2026-08-28, 2026-08-31
1995.
Unknown Vulnerability Type - Envoy (CVE-2026-73548) - Medium [211]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy forwards data for a configured non-WebSocket HTTP upgrade before the upstream accepts the upgrade. An unauthenticated HTTP/2 client can place a complete HTTP/1.1 request in extended CONNECT data; Envoy downgrades the request, writes the data unframed to a keep-alive HTTP/1.1 upstream, and returns the socket to the shared pool while the smuggled response remains queued. A different downstream client can then receive the attacker's response. The relevant scope boundary is that webSocket upgrades, plain CONNECT, disabled backend keep-alive, per-downstream pools, and max_requests_per_connection set to 1 are not affected by the demonstrated path. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-73548 was patched at 2026-08-28, 2026-08-31
1996.
Unknown Vulnerability Type - Envoy (CVE-2026-73550) - Medium [211]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy copies every decoded HTTP/2 Host header value before discarding it when :authority is already present. The discarded value bypasses saveHeader, so its bytes and count are not charged against request header limits. An unauthenticated client can use HPACK indexing to submit many references to a large Host value across a bounded number of streams, forcing extreme header-copy allocation and causing the proxy to be out-of-memory killed. The relevant scope boundary is that the demonstrated amplification uses HTTP/2 HPACK and the duplicate Host discard behavior. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-73550 was patched at 2026-08-28, 2026-08-31
1997.
Unknown Vulnerability Type - Envoy (CVE-2026-73552) - Medium [211]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy HTTP RBAC accepts RFC-valid opaque header bytes but evaluates safe_regex values with RE2's UTF-8 subject semantics. A downstream client can preserve a prohibited marker and add an unrelated obs-text octet, causing RE2::FullMatch to return false and a negative RBAC policy to treat the invalid subject as an ordinary no-match. A byte-oriented route matcher can still observe the marker, allowing the request to reach a route intended to be denied. The relevant scope boundary is that plain positive ALLOW regexes normally fail closed, and exact, prefix, suffix, and contains matchers are not shown to have this subject-domain failure. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-73552 was patched at 2026-08-28, 2026-08-31
1998.
Unknown Vulnerability Type - Envoy (CVE-2026-73553) - Medium [211]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, When ignore_path_parameters_in_path_matching is enabled, Envoy's router strips the semicolon suffix before matching but the RBAC url_path matcher evaluates the raw path. A downstream request such as /admin;x can therefore miss a DENY rule for /admin while the router still selects the protected /admin backend. The inconsistent canonicalization allows an unauthenticated client to bypass path-based authorization. The relevant scope boundary is that the route option and a path-based RBAC rule must both be present, and the protected route must match after stripping. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-73553 was patched at 2026-08-28, 2026-08-31
1999.
Unknown Vulnerability Type - GLib (CVE-2026-86469) - Medium [209]
Description: {'nvd_cve_data_all': 'A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | GLib is a widely used low-level core library for the GNOME ecosystem and many Linux applications, providing data structures, utility APIs, event loops, IPC facilities, and GDBus for D-Bus communication. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00113, EPSS Percentile is 0.01638 |
debian: CVE-2026-86469 was patched at 2026-09-16
2000.
Unknown Vulnerability Type - Spring Framework (CVE-2026-59283) - Medium [209]
Description: {'nvd_cve_data_all': 'Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpring Framework 6.1.0 - 6.1.28\nSpring Framework 6.0.0 - 6.0.30\nSpring Framework 5.3.0 - 5.3.49\nSpring Framework 5.2.25.RELEASE and earlier', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.4 | 14 | The Spring Framework is an application framework and inversion of control container for the Java platform | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00374, EPSS Percentile is 0.31062 |
debian: CVE-2026-59283 was patched at 2026-09-16
2001.
Denial of Service - Unknown Product (CVE-2026-80185) - Medium [208]
Description: {'nvd_cve_data_all': 'BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00237, EPSS Percentile is 0.14851 |
debian: CVE-2026-80185 was patched at 2026-09-16
2002.
Denial of Service - Unknown Product (CVE-2026-86432) - Medium [208]
Description: {'nvd_cve_data_all': 'commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers can provide deeply nested Markdown or AST structures to cause quadratic memory consumption and output amplification, exhausting server resources.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers can provide deeply nested Markdown or AST structures to cause quadratic memory consumption and output amplification, exhausting server resources.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16142 |
debian: CVE-2026-86432 was patched at 2026-09-16
2003.
Memory Corruption - Unknown Product (CVE-2026-78161) - Medium [208]
Description: {'nvd_cve_data_all': 'A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation results in out-of-bounds write. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as 1d44554a1bb262db63ff4e240152a9deecd99054. It is best practice to apply a patch to resolve this issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation results in out-of-bounds write. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as 1d44554a1bb262db63ff4e240152a9deecd99054. It is best practice to apply a patch to resolve this issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00405, EPSS Percentile is 0.34305 |
debian: CVE-2026-78161 was patched at 2026-08-25
2004.
Memory Corruption - Unknown Product (CVE-2026-79592) - Medium [208]
Description: {'nvd_cve_data_all': 'An out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 due to insufficient validation of file-controlled OLE summary offsets.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 due to insufficient validation of file-controlled OLE summary offsets.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00314, EPSS Percentile is 0.24347 |
debian: CVE-2026-79592 was patched at 2026-09-16
2005.
Memory Corruption - Unknown Product (CVE-2026-92240) - Medium [208]
Description: {'nvd_cve_data_all': 'A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00212, EPSS Percentile is 0.11721 |
debian: CVE-2026-92240 was patched at 2026-09-16, 2026-09-17
2006.
Path Traversal - Unknown Product (CVE-2026-79705) - Medium [208]
Description: {'nvd_cve_data_all': 'A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended destination. Buildah itself uses chroot hardening and is not affected.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended destination. Buildah itself uses chroot hardening and is not affected.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 4.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00246, EPSS Percentile is 0.16053 |
debian: CVE-2026-79705 was patched at 2026-09-16
2007.
Security Feature Bypass - Unknown Product (CVE-2026-89169) - Medium [208]
Description: {'nvd_cve_data_all': 'live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.1. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00109, EPSS Percentile is 0.01389 |
debian: CVE-2026-89169 was patched at 2026-09-16
2008.
Information Disclosure - Unknown Product (CVE-2026-40203) - Medium [207]
Description: {'nvd_cve_data_all': 'When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An attacker that can send mail to a user and can also observe the sizes of that user's IMAP traffic can confirm whether the body of a small message matches a guessed text. Recovery of arbitrary unknown content was not demonstrated, but the attack can disclose whether a secret-like message body matches a candidate. Disable IMAP compression. Update to non-vulnerable version. No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An attacker that can send mail to a user and can also observe the sizes of that user's IMAP traffic can confirm whether the body of a small message matches a guessed text. Recovery of arbitrary unknown content was not demonstrated, but the attack can disclose whether a secret-like message body matches a candidate. Disable IMAP compression. Update to non-vulnerable version. No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00219, EPSS Percentile is 0.12508 |
altlinux: CVE-2026-40203 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-40203 was patched at 2026-09-16
2009.
Information Disclosure - Unknown Product (CVE-2026-42392) - Medium [207]
Description: {'nvd_cve_data_all': 'An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the error response returned to the client. Process memory contents can be disclosed to the client, which may include sensitive data. Disable the IMAP URLAUTH functionality. Update to non-vulnerable version. No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the error response returned to the client. Process memory contents can be disclosed to the client, which may include sensitive data. Disable the IMAP URLAUTH functionality. Update to non-vulnerable version. No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00226, EPSS Percentile is 0.13392 |
altlinux: CVE-2026-42392 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-42392 was patched at 2026-09-16
2010.
Unknown Vulnerability Type - MongoDB (CVE-2026-18696) - Medium [207]
Description: {'nvd_cve_data_all': 'An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00287, EPSS Percentile is 0.21289 |
altlinux: CVE-2026-18696 was patched at 2026-08-26
2011.
Unknown Vulnerability Type - MongoDB (CVE-2026-18712) - Medium [207]
Description: {'nvd_cve_data_all': 'An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data belonging to a different collection. This is due to insufficient validation of certain internal metadata references before they are used to perform operations on other namespaces.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data belonging to a different collection. This is due to insufficient validation of certain internal metadata references before they are used to perform operations on other namespaces.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00179, EPSS Percentile is 0.0767 |
altlinux: CVE-2026-18712 was patched at 2026-08-26
2012.
Unknown Vulnerability Type - MongoDB (CVE-2026-82074) - Medium [207]
Description: {'nvd_cve_data_all': 'MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal privileges can craft a specially formatted aggregation request that causes the server's authorization subsystem to evaluate a different operation than what is actually executed, resulting in unauthorized read access to collection data within the target database.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal privileges can craft a specially formatted aggregation request that causes the server's authorization subsystem to evaluate a different operation than what is actually executed, resulting in unauthorized read access to collection data within the target database.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00248, EPSS Percentile is 0.16254 |
altlinux: CVE-2026-82074 was patched at 2026-09-09, 2026-09-10
2013.
Unknown Vulnerability Type - Perl (CVE-2026-15743) - Medium [207]
Description: {'nvd_cve_data_all': 'Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable. The _serve_static method always sets the Cache-Control header to "public", with no means of overriding it. This advises proxies that the content may be stored in a shared cache, and may be reused in responses to requests from other users. (This includes requests with an Authorization header.) Configuring the expires time to "0" to disable caching, as documented, is ignored.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable.\n\nThe _serve_static method always sets the Cache-Control header to "public", with no means of overriding it. This advises proxies that the content may be stored in a shared cache, and may be reused in responses to requests from other users. (This includes requests with an Authorization header.)\n\nConfiguring the expires time to "0" to disable caching, as documented, is ignored.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00322, EPSS Percentile is 0.25285 |
debian: CVE-2026-15743 was patched at 2026-08-25
2014.
Unknown Vulnerability Type - CUPS (CVE-2026-87876) - Medium [204]
Description: {'nvd_cve_data_all': 'Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | CUPS is a modular printing system for Unix-like computer operating systems which allows a computer to act as a print server | |
| 0.3 | 10 | CVSS Base Score is 3.0. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00389, EPSS Percentile is 0.32666 |
debian: CVE-2026-87876 was patched at 2026-09-16
2015.
Unknown Vulnerability Type - Chromium (CVE-2026-78954) - Medium [204]
Description: {'nvd_cve_data_all': 'Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00311, EPSS Percentile is 0.23965 |
altlinux: CVE-2026-78954 was patched at 2026-08-28
debian: CVE-2026-78954 was patched at 2026-09-03, 2026-09-16
2016.
Unknown Vulnerability Type - Chromium (CVE-2026-78961) - Medium [204]
Description: {'nvd_cve_data_all': 'Incorrect authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00311, EPSS Percentile is 0.23966 |
altlinux: CVE-2026-78961 was patched at 2026-08-28
debian: CVE-2026-78961 was patched at 2026-09-03, 2026-09-16
2017.
Unknown Vulnerability Type - Chromium (CVE-2026-78962) - Medium [204]
Description: {'nvd_cve_data_all': 'Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00256, EPSS Percentile is 0.17483 |
altlinux: CVE-2026-78962 was patched at 2026-08-28
debian: CVE-2026-78962 was patched at 2026-09-03, 2026-09-16
2018.
Unknown Vulnerability Type - Chromium (CVE-2026-78986) - Medium [204]
Description: {'nvd_cve_data_all': 'Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00348, EPSS Percentile is 0.28247 |
altlinux: CVE-2026-78986 was patched at 2026-08-28
debian: CVE-2026-78986 was patched at 2026-09-03, 2026-09-16
2019.
Unknown Vulnerability Type - Chromium (CVE-2026-79003) - Medium [204]
Description: {'nvd_cve_data_all': 'Incorrect authorization in Device in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in Device in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00267, EPSS Percentile is 0.18966 |
altlinux: CVE-2026-79003 was patched at 2026-08-28
debian: CVE-2026-79003 was patched at 2026-09-03, 2026-09-16
2020.
Unknown Vulnerability Type - Chromium (CVE-2026-79007) - Medium [204]
Description: {'nvd_cve_data_all': 'Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00348, EPSS Percentile is 0.28246 |
altlinux: CVE-2026-79007 was patched at 2026-08-28
debian: CVE-2026-79007 was patched at 2026-09-03, 2026-09-16
2021.
Unknown Vulnerability Type - Chromium (CVE-2026-79009) - Medium [204]
Description: {'nvd_cve_data_all': 'UI misrepresentation in UI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'UI misrepresentation in UI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00245, EPSS Percentile is 0.15868 |
altlinux: CVE-2026-79009 was patched at 2026-08-28
debian: CVE-2026-79009 was patched at 2026-09-03, 2026-09-16
2022.
Unknown Vulnerability Type - Chromium (CVE-2026-79014) - Medium [204]
Description: {'nvd_cve_data_all': 'Race condition in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Race condition in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00295, EPSS Percentile is 0.22202 |
altlinux: CVE-2026-79014 was patched at 2026-08-28
debian: CVE-2026-79014 was patched at 2026-09-03, 2026-09-16
2023.
Unknown Vulnerability Type - Chromium (CVE-2026-79022) - Medium [204]
Description: {'nvd_cve_data_all': 'UI misrepresentation in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'UI misrepresentation in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00269, EPSS Percentile is 0.19172 |
altlinux: CVE-2026-79022 was patched at 2026-08-28
debian: CVE-2026-79022 was patched at 2026-09-03, 2026-09-16
2024.
Unknown Vulnerability Type - Chromium (CVE-2026-79040) - Medium [204]
Description: {'nvd_cve_data_all': 'Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0031, EPSS Percentile is 0.23878 |
altlinux: CVE-2026-79040 was patched at 2026-08-28
debian: CVE-2026-79040 was patched at 2026-09-03, 2026-09-16
2025.
Unknown Vulnerability Type - Chromium (CVE-2026-79042) - Medium [204]
Description: {'nvd_cve_data_all': 'Missing authorization in Payments in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in Payments in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00274, EPSS Percentile is 0.19854 |
altlinux: CVE-2026-79042 was patched at 2026-08-28
debian: CVE-2026-79042 was patched at 2026-09-03, 2026-09-16
2026.
Unknown Vulnerability Type - Chromium (CVE-2026-79046) - Medium [204]
Description: {'nvd_cve_data_all': 'Race condition in Permissions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Race condition in Permissions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00244, EPSS Percentile is 0.15766 |
altlinux: CVE-2026-79046 was patched at 2026-08-28
debian: CVE-2026-79046 was patched at 2026-09-03, 2026-09-16
2027.
Unknown Vulnerability Type - Chromium (CVE-2026-79082) - Medium [204]
Description: {'nvd_cve_data_all': 'Incorrect authorization in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00266, EPSS Percentile is 0.18877 |
altlinux: CVE-2026-79082 was patched at 2026-08-28
debian: CVE-2026-79082 was patched at 2026-09-03, 2026-09-16
2028.
Unknown Vulnerability Type - Chromium (CVE-2026-79085) - Medium [204]
Description: {'nvd_cve_data_all': 'Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16136 |
altlinux: CVE-2026-79085 was patched at 2026-08-28
debian: CVE-2026-79085 was patched at 2026-09-03, 2026-09-16
2029.
Unknown Vulnerability Type - Chromium (CVE-2026-79087) - Medium [204]
Description: {'nvd_cve_data_all': 'Injection in Chrome Tabs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Injection in Chrome Tabs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00285, EPSS Percentile is 0.21048 |
altlinux: CVE-2026-79087 was patched at 2026-08-28
debian: CVE-2026-79087 was patched at 2026-09-03, 2026-09-16
2030.
Unknown Vulnerability Type - Chromium (CVE-2026-79089) - Medium [204]
Description: {'nvd_cve_data_all': 'Race condition in Transactions Platform in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Race condition in Transactions Platform in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00196, EPSS Percentile is 0.09531 |
altlinux: CVE-2026-79089 was patched at 2026-08-28
debian: CVE-2026-79089 was patched at 2026-09-03, 2026-09-16
2031.
Unknown Vulnerability Type - Chromium (CVE-2026-79093) - Medium [204]
Description: {'nvd_cve_data_all': 'Incorrect authorization in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00266, EPSS Percentile is 0.18876 |
altlinux: CVE-2026-79093 was patched at 2026-08-28
debian: CVE-2026-79093 was patched at 2026-09-03, 2026-09-16
2032.
Unknown Vulnerability Type - Chromium (CVE-2026-79118) - Medium [204]
Description: {'nvd_cve_data_all': 'Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00277, EPSS Percentile is 0.20181 |
altlinux: CVE-2026-79118 was patched at 2026-08-28
debian: CVE-2026-79118 was patched at 2026-09-03, 2026-09-16
2033.
Unknown Vulnerability Type - Chromium (CVE-2026-79143) - Medium [204]
Description: {'nvd_cve_data_all': 'Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00284, EPSS Percentile is 0.20982 |
altlinux: CVE-2026-79143 was patched at 2026-08-28
debian: CVE-2026-79143 was patched at 2026-09-03, 2026-09-16
2034.
Unknown Vulnerability Type - Chromium (CVE-2026-79174) - Medium [204]
Description: {'nvd_cve_data_all': 'Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00266, EPSS Percentile is 0.18877 |
altlinux: CVE-2026-79174 was patched at 2026-08-28
debian: CVE-2026-79174 was patched at 2026-09-03, 2026-09-16
2035.
Unknown Vulnerability Type - Chromium (CVE-2026-79184) - Medium [204]
Description: {'nvd_cve_data_all': 'Missing authorization in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00256, EPSS Percentile is 0.17395 |
altlinux: CVE-2026-79184 was patched at 2026-08-28
debian: CVE-2026-79184 was patched at 2026-09-03, 2026-09-16
2036.
Unknown Vulnerability Type - Chromium (CVE-2026-79212) - Medium [204]
Description: {'nvd_cve_data_all': 'Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00266, EPSS Percentile is 0.18877 |
altlinux: CVE-2026-79212 was patched at 2026-08-28
debian: CVE-2026-79212 was patched at 2026-09-03, 2026-09-16
2037.
Unknown Vulnerability Type - Chromium (CVE-2026-79248) - Medium [204]
Description: {'nvd_cve_data_all': 'Incorrect authorization in Input in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in Input in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0028, EPSS Percentile is 0.20595 |
altlinux: CVE-2026-79248 was patched at 2026-08-28
debian: CVE-2026-79248 was patched at 2026-09-03, 2026-09-16
2038.
Unknown Vulnerability Type - Chromium (CVE-2026-79269) - Medium [204]
Description: {'nvd_cve_data_all': 'Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00309, EPSS Percentile is 0.23681 |
altlinux: CVE-2026-79269 was patched at 2026-08-28
debian: CVE-2026-79269 was patched at 2026-09-03, 2026-09-16
2039.
Unknown Vulnerability Type - Chromium (CVE-2026-79273) - Medium [204]
Description: {'nvd_cve_data_all': 'Incorrect reference resolution in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect reference resolution in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.17265 |
altlinux: CVE-2026-79273 was patched at 2026-08-28
debian: CVE-2026-79273 was patched at 2026-09-03, 2026-09-16
2040.
Unknown Vulnerability Type - Chromium (CVE-2026-84329) - Medium [204]
Description: {'nvd_cve_data_all': 'Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00169, EPSS Percentile is 0.06609 |
altlinux: CVE-2026-84329 was patched at 2026-09-03
debian: CVE-2026-84329 was patched at 2026-09-03, 2026-09-16
2041.
Unknown Vulnerability Type - Chromium (CVE-2026-87462) - Medium [204]
Description: {'nvd_cve_data_all': 'UI misrepresentation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'UI misrepresentation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00198, EPSS Percentile is 0.09823 |
altlinux: CVE-2026-87462 was patched at 2026-09-17
debian: CVE-2026-87462 was patched at 2026-09-16
2042.
Unknown Vulnerability Type - Chromium (CVE-2026-87507) - Medium [204]
Description: {'nvd_cve_data_all': 'UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00231, EPSS Percentile is 0.14128 |
altlinux: CVE-2026-87507 was patched at 2026-09-17
debian: CVE-2026-87507 was patched at 2026-09-16
2043.
Unknown Vulnerability Type - Chromium (CVE-2026-87550) - Medium [204]
Description: {'nvd_cve_data_all': 'Improper encoding or escaping of output in CSS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Improper encoding or escaping of output in CSS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00242, EPSS Percentile is 0.15593 |
altlinux: CVE-2026-87550 was patched at 2026-09-17
debian: CVE-2026-87550 was patched at 2026-09-16
2044.
Unknown Vulnerability Type - Chromium (CVE-2026-87564) - Medium [204]
Description: {'nvd_cve_data_all': 'Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00266, EPSS Percentile is 0.18617 |
altlinux: CVE-2026-87564 was patched at 2026-09-17
debian: CVE-2026-87564 was patched at 2026-09-16
2045.
Unknown Vulnerability Type - Chromium (CVE-2026-87567) - Medium [204]
Description: {'nvd_cve_data_all': 'UI misrepresentation in UrlFormatting in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted domain name. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'UI misrepresentation in UrlFormatting in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted domain name. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05198 |
altlinux: CVE-2026-87567 was patched at 2026-09-17
debian: CVE-2026-87567 was patched at 2026-09-16
2046.
Unknown Vulnerability Type - Chromium (CVE-2026-87649) - Medium [204]
Description: {'nvd_cve_data_all': 'UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00167, EPSS Percentile is 0.06379 |
altlinux: CVE-2026-87649 was patched at 2026-09-17
debian: CVE-2026-87649 was patched at 2026-09-16
2047.
Unknown Vulnerability Type - Chromium (CVE-2026-91742) - Medium [204]
Description: {'nvd_cve_data_all': 'Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via crafted network traffic. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via crafted network traffic. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00218, EPSS Percentile is 0.12386 |
altlinux: CVE-2026-91742 was patched at 2026-09-17
debian: CVE-2026-91742 was patched at 2026-09-16
2048.
Unknown Vulnerability Type - Keycloak (CVE-2026-16089) - Medium [204]
Description: {'nvd_cve_data_all': 'A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be redeemed by their own client, potentially allowing them to obtain access tokens for a victim's identity.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be redeemed by their own client, potentially allowing them to obtain access tokens for a victim's identity.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.03867 |
altlinux: CVE-2026-16089 was patched at 2026-09-01, 2026-09-04, 2026-09-07
2049.
Unknown Vulnerability Type - Keycloak (CVE-2026-16105) - Medium [204]
Description: {'nvd_cve_data_all': 'A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm permissions to remove essential child roles from built-in admin roles, potentially disrupting administrative functions within a realm.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm permissions to remove essential child roles from built-in admin roles, potentially disrupting administrative functions within a realm.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.5 | 10 | CVSS Base Score is 4.9. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00192, EPSS Percentile is 0.09095 |
altlinux: CVE-2026-16105 was patched at 2026-09-01, 2026-09-04, 2026-09-07
2050.
Unknown Vulnerability Type - Keycloak (CVE-2026-18209) - Medium [204]
Description: {'nvd_cve_data_all': 'A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a redirect URL and ignores the fragment portion. When a client is configured with a wildcard redirect URI, an attacker can use this to inject duplicate security parameters into the login response. If a client application is not configured correctly, it might trust the attacker's injected data instead of the real security information from Keycloak, leading to session fixation or account confusion.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a redirect URL and ignores the fragment portion. When a client is configured with a wildcard redirect URI, an attacker can use this to inject duplicate security parameters into the login response. If a client application is not configured correctly, it might trust the attacker's injected data instead of the real security information from Keycloak, leading to session fixation or account confusion.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00193, EPSS Percentile is 0.09148 |
altlinux: CVE-2026-18209 was patched at 2026-09-01, 2026-09-04, 2026-09-07
2051.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92005) - Medium [204]
Description: {'nvd_cve_data_all': 'Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.0518 |
altlinux: CVE-2026-92005 was patched at 2026-09-16
debian: CVE-2026-92005 was patched at 2026-09-16, 2026-09-17
2052.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92030) - Medium [204]
Description: {'nvd_cve_data_all': 'Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.05987 |
altlinux: CVE-2026-92030 was patched at 2026-09-16
debian: CVE-2026-92030 was patched at 2026-09-16, 2026-09-17
2053.
Unknown Vulnerability Type - Node.js (CVE-2026-88038) - Medium [204]
Description: {'nvd_cve_data_all': 'cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator, but the domain and path options are checked only against a permissive RFC 7230 field-content matcher that allows semicolons, and both are written into the Set-Cookie header unescaped. An application that passes untrusted or request-derived data into the domain or path option can therefore inject additional cookie attributes, overriding SameSite, Secure, HttpOnly, or Domain on the cookies the application issues. This is a Set-Cookie attribute injection issue (CWE-74). The issue is fixed in cookies 0.9.2, which validates domain and path against RFC 6265 character sets. As a workaround, keep domain and path application-set rather than derived from untrusted input.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator, but the domain and path options are checked only against a permissive RFC 7230 field-content matcher that allows semicolons, and both are written into the Set-Cookie header unescaped. An application that passes untrusted or request-derived data into the domain or path option can therefore inject additional cookie attributes, overriding SameSite, Secure, HttpOnly, or Domain on the cookies the application issues. This is a Set-Cookie attribute injection issue (CWE-74). The issue is fixed in cookies 0.9.2, which validates domain and path against RFC 6265 character sets. As a workaround, keep domain and path application-set rather than derived from untrusted input.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0016, EPSS Percentile is 0.05623 |
debian: CVE-2026-88038 was patched at 2026-09-16
2054.
Incorrect Calculation - GPAC (CVE-2026-14801) - Medium [203]
Description: A security vulnerability has been detected in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0016, EPSS Percentile is 0.05565 |
redos: CVE-2026-14801 was patched at 2026-08-24
2055.
Memory Corruption - GPAC (CVE-2025-15667) - Medium [203]
Description: A vulnerability was determined in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0016, EPSS Percentile is 0.05563 |
redos: CVE-2025-15667 was patched at 2026-08-24
2056.
Memory Corruption - GPAC (CVE-2025-15668) - Medium [203]
Description: A vulnerability was identified in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06985 |
redos: CVE-2025-15668 was patched at 2026-08-24
2057.
Memory Corruption - GPAC (CVE-2026-14790) - Medium [203]
Description: A flaw has been found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0016, EPSS Percentile is 0.05564 |
redos: CVE-2026-14790 was patched at 2026-08-24
2058.
Cross Site Scripting - Unknown Product (CVE-2026-77643) - Medium [202]
Description: {'nvd_cve_data_all': 'A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A cross-site scripting vulnerability in \nqueryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of\xa0CVE-2018-0499.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05184 |
debian: CVE-2026-77643 was patched at 2026-08-25
2059.
Unknown Vulnerability Type - Thunderbird (CVE-2026-84640) - Medium [202]
Description: {'nvd_cve_data_all': 'A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:mozilla:thunderbird (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.18269 |
altlinux: CVE-2026-84640 was patched at 2026-09-03, 2026-09-09
debian: CVE-2026-84640 was patched at 2026-09-04, 2026-09-16
2060.
Unknown Vulnerability Type - Thunderbird (CVE-2026-84642) - Medium [202]
Description: {'nvd_cve_data_all': 'The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this could allow certain unintended hostnames to also match and serve remote attachments. This vulnerability was fixed in Thunderbird 155 and Thunderbird 153.2.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this could allow certain unintended hostnames to also match and serve remote attachments. This vulnerability was fixed in Thunderbird 155 and Thunderbird 153.2.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:mozilla:thunderbird (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00254, EPSS Percentile is 0.17165 |
altlinux: CVE-2026-84642 was patched at 2026-09-03, 2026-09-09
2061.
Elevation of Privilege - Unknown Product (CVE-2026-90463) - Low [199]
Description: {'nvd_cve_data_all': 'A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to the NSS responder's UNIX socket, to cause an out-of-bounds read. This out-of-bounds read may lead to a denial of service (DoS) by crashing the NSS responder process. While unprivileged local clients can typically reach the socket, there is no evidence of privilege escalation or reliable data disclosure.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to the NSS responder's UNIX socket, to cause an out-of-bounds read. This out-of-bounds read may lead to a denial of service (DoS) by crashing the NSS responder process. While unprivileged local clients can typically reach the socket, there is no evidence of privilege escalation or reliable data disclosure.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00105, EPSS Percentile is 0.01194 |
debian: CVE-2026-90463 was patched at 2026-09-16
2062.
Unknown Vulnerability Type - BIND (CVE-2026-62437) - Low [199]
Description: {'nvd_cve_data_all': 'When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and the associated removal of tracking structures for IRQs used by the devices occurs relatively early in the process. Unfortunately after that point the guest about to be terminated could cause its device model (DM) to re-establish such tracking structures, by having it bind one or more IRQs anew. While some of those tracking structures would still be cleaned up later on, at least one would not be.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'When guests are terminated, various pieces of cleanup need carrying out.\nThe cleaning up of PCI devices which were assigned to guests, and the\nassociated removal of tracking structures for IRQs used by the devices\noccurs relatively early in the process. Unfortunately after that point\nthe guest about to be terminated could cause its device model (DM) to\nre-establish such tracking structures, by having it bind one or more IRQs\nanew. While some of those tracking structures would still be cleaned up\nlater on, at least one would not be.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00098, EPSS Percentile is 0.00883 |
debian: CVE-2026-62437 was patched at 2026-09-16
2063.
Unknown Vulnerability Type - Envoy (CVE-2026-73546) - Low [199]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's /stats?format=html admin endpoint uses StatsHtmlRender, which sanitizes string statistic values but emits statistic names without HTML encoding. A data-plane component such as grpc_stats with stats_for_all_methods enabled can incorporate attacker-controlled path segments into cached dynamic statistic names. When an operator views the HTML stats page, the stored name can execute script with the admin interface's origin and issue privileged same-origin requests. The relevant scope boundary is that the admin interface must be browser-accessible and an enabled component must persist attacker-influenced text in statistic names. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-73546 was patched at 2026-08-28, 2026-08-31
2064.
Unknown Vulnerability Type - cpp-httplib (CVE-2026-77341) - Low [199]
Description: {'nvd_cve_data_all': 'cpp-httplib is a C++ header-only HTTP/HTTPS library. In version 0.49.0, the chunked-response trailer output path writes trailer header names and values directly to the socket without validating them, allowing CRLF sequences in a trailer field to inject additional headers or split the HTTP response. Unlike every other header-writing path in the library, the trailer-writing code applies none of the field-name and field-value checks that reject carriage return and line feed, so an application that places attacker-influenced data into a chunked response trailer emits attacker-controlled CRLF onto the wire. This enables HTTP response splitting, letting an attacker forge response headers or inject a second response. This issue is fixed in version 0.50.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'cpp-httplib is a C++ header-only HTTP/HTTPS library. In version 0.49.0, the chunked-response trailer output path writes trailer header names and values directly to the socket without validating them, allowing CRLF sequences in a trailer field to inject additional headers or split the HTTP response. Unlike every other header-writing path in the library, the trailer-writing code applies none of the field-name and field-value checks that reject carriage return and line feed, so an application that places attacker-influenced data into a chunked response trailer emits attacker-controlled CRLF onto the wire. This enables HTTP response splitting, letting an attacker forge response headers or inject a second response. This issue is fixed in version 0.50.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00272, EPSS Percentile is 0.19684 |
debian: CVE-2026-77341 was patched at 2026-09-16
2065.
Unknown Vulnerability Type - qs (CVE-2026-82417) - Low [199]
Description: {'nvd_cve_data_all': '### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)` after checking only that the property is truthy, so a value such as `{ constructor: { isBuffer: "x" } }` makes the call throw `TypeError: obj.constructor.isBuffer is not a function`. ### Details `lib/stringify.js:127` calls `utils.isBuffer` on every non-primitive value it serializes. `utils.isBuffer` (`lib/utils.js:332`) reads `obj.constructor.isBuffer` and invokes it without verifying that it is a function. `constructor` and `isBuffer` are ordinary property names, so any object carrying them as own properties reaches the unchecked call. Such an object can be built from untrusted input. `qs.parse("x[constructor][isBuffer]=y", { plainObjects: true })` or `{ allowPrototypes: true }` keeps the `constructor` key as an own property (the default parse options drop it), and `JSON.parse("{\\"a\\":{\\"constructor\\":{\\"isBuffer\\":\\"x\\"}}}")` produces the same shape with no qs option involved. Express 4 with its default `query parser` setting and body-parser with `extended: true` both call `qs.parse` with `allowPrototypes: true`, so on those stacks `req.query` and `req.body` can carry the shape directly. #### PoC ```js var qs = require("qs"); qs.stringify(qs.parse("x[constructor][isBuffer]=y", { plainObjects: true })); qs.stringify(JSON.parse("{\\"a\\":{\\"constructor\\":{\\"isBuffer\\":\\"x\\"}}}")); // TypeError: obj.constructor.isBuffer is not a function // at Object.isBuffer (lib/utils.js:332:78) // at stringify (lib/stringify.js:127:45) ``` #### Fix `lib/utils.js`, applied in e83d321 on `main` and released as v6.16.0: ```diff - return !!(obj.constructor && obj.constructor.isBuffer && obj.constructor.isBuffer(obj)); + return !!(obj.constructor && typeof obj.constructor.isBuffer === "function" && obj.constructor.isBuffer(obj)); ``` Real `Buffer`, `safer-buffer`, and browserify `buffer` polyfill instances serialize exactly as before; only the throw is removed. ### Affected versions `>=2.2.5 <6.16.0`, fixed in v6.16.0. The unguarded duck-type was introduced in 3768a75 and first shipped in v2.2.5 (September 2014). v2.2.4 and earlier used `Buffer.isBuffer` and are not affected. Every release from v2.2.5 through v6.15.3 contains the unguarded call. ### Impact An unauthenticated request can make any code path that re-serializes attacker-influenced data with `qs.stringify` (for example, rebuilding a query string from `req.query` for a redirect or an upstream request, or serializing a parsed JSON body) throw synchronously. In a typical Node.js HTTP framework the throw is caught by the framework error boundary and the affected request returns a 500; the process survives and other requests are unaffected. Where the call runs outside an error boundary, such as an `async` Express 4 handler (where the throw becomes an unhandled promise rejection) or a background job, the process exits, so the impact in that case depends on the application error handling rather than on qs.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': '### Summary\n\n\n\n`qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)` after checking only that the property is truthy, so a value such as `{ constructor: { isBuffer: "x" } }` makes the call throw `TypeError: obj.constructor.isBuffer is not a function`.\n\n\n\n### Details\n\n\n\n`lib/stringify.js:127` calls `utils.isBuffer` on every non-primitive value it serializes. `utils.isBuffer` (`lib/utils.js:332`) reads `obj.constructor.isBuffer` and invokes it without verifying that it is a function. `constructor` and `isBuffer` are ordinary property names, so any object carrying them as own properties reaches the unchecked call.\n\n\n\nSuch an object can be built from untrusted input. `qs.parse("x[constructor][isBuffer]=y", { plainObjects: true })` or `{ allowPrototypes: true }` keeps the `constructor` key as an own property (the default parse options drop it), and `JSON.parse("{\\"a\\":{\\"constructor\\":{\\"isBuffer\\":\\"x\\"}}}")` produces the same shape with no qs option involved. Express 4 with its default `query parser` setting and body-parser with `extended: true` both call `qs.parse` with `allowPrototypes: true`, so on those stacks `req.query` and `req.body` can carry the shape directly.\n\n\n\n#### PoC\n\n\n\n```js\n\n\n\nvar qs = require("qs");\n\n\n\nqs.stringify(qs.parse("x[constructor][isBuffer]=y", { plainObjects: true }));\n\n\n\nqs.stringify(JSON.parse("{\\"a\\":{\\"constructor\\":{\\"isBuffer\\":\\"x\\"}}}"));\n\n\n\n// TypeError: obj.constructor.isBuffer is not a function\n\n\n\n// at Object.isBuffer (lib/utils.js:332:78)\n\n\n\n// at stringify (lib/stringify.js:127:45)\n\n\n\n```\n\n\n\n#### Fix\n\n\n\n`lib/utils.js`, applied in e83d321 on `main` and released as v6.16.0:\n\n\n\n```diff\n\n\n\n- return !!(obj.constructor && obj.constructor.isBuffer && obj.constructor.isBuffer(obj));\n\n\n\n+ return !!(obj.constructor && typeof obj.constructor.isBuffer === "function" && obj.constructor.isBuffer(obj));\n\n\n\n```\n\n\n\nReal `Buffer`, `safer-buffer`, and browserify `buffer` polyfill instances serialize exactly as before; only the throw is removed.\n\n\n\n### Affected versions\n\n\n\n`>=2.2.5 <6.16.0`, fixed in v6.16.0.\n\n\n\nThe unguarded duck-type was introduced in 3768a75 and first shipped in v2.2.5 (September 2014). v2.2.4 and earlier used `Buffer.isBuffer` and are not affected. Every release from v2.2.5 through v6.15.3 contains the unguarded call.\n\n\n\n### Impact\n\n\n\nAn unauthenticated request can make any code path that re-serializes attacker-influenced data with `qs.stringify` (for example, rebuilding a query string from `req.query` for a redirect or an upstream request, or serializing a parsed JSON body) throw synchronously. In a typical Node.js HTTP framework the throw is caught by the framework error boundary and the affected request returns a 500; the process survives and other requests are unaffected. Where the call runs outside an error boundary, such as an `async` Express 4 handler (where the throw becomes an unhandled promise rejection) or a background job, the process exits, so the impact in that case depends on the application error handling rather than on qs.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | qs is a popular JavaScript library for parsing and serializing URL query strings. It supports nested objects, arrays, custom parsing options, and is widely used in Node.js frameworks and middleware to handle HTTP query parameters and form-encoded data. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00261, EPSS Percentile is 0.18038 |
debian: CVE-2026-82417 was patched at 2026-09-16
2066.
Unknown Vulnerability Type - Azure (CVE-2026-48501) - Low [197]
Description: {'nvd_cve_data_all': 'GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh release verify-asset commands. The CLI uses a shared HTTP client with an authentication layer that automatically attaches tokens to outgoing requests. This layer lacks accurate host detection and can incorrectly attribute the target host, providing it with a token it should never receive. Specifically, the host normalization logic collapses any *.github.com subdomain to github.com, so a request to tuf-repo.github.com (a GitHub Pages site, not a GitHub API endpoint) is treated as a request to github.com and receives the user's github.com token. For hosts that don't match github.com or a known GHES instance at all, the resolver falls back to GH_ENTERPRISE_TOKEN if set. The gh attestation, gh release verify and gh release verify-asset commands fetch data from several external hosts as part of their normal operation (TUF metadata from tuf-repo.github.com and tuf-repo-cdn.sigstore.dev, artifact bundles from Azure Blob Storage). Because these requests go through the same authenticated HTTP client, the token is sent to all of them. This vulnerability is fixed in 2.93.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh release verify-asset commands. The CLI uses a shared HTTP client with an authentication layer that automatically attaches tokens to outgoing requests. This layer lacks accurate host detection and can incorrectly attribute the target host, providing it with a token it should never receive. Specifically, the host normalization logic collapses any *.github.com subdomain to github.com, so a request to tuf-repo.github.com (a GitHub Pages site, not a GitHub API endpoint) is treated as a request to github.com and receives the user's github.com token. For hosts that don't match github.com or a known GHES instance at all, the resolver falls back to GH_ENTERPRISE_TOKEN if set. The gh attestation, gh release verify and gh release verify-asset commands fetch data from several external hosts as part of their normal operation (TUF metadata from tuf-repo.github.com and tuf-repo-cdn.sigstore.dev, artifact bundles from Azure Blob Storage). Because these requests go through the same authenticated HTTP client, the token is sent to all of them. This vulnerability is fixed in 2.93.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.4 | 14 | Azure | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00289, EPSS Percentile is 0.21537 |
debian: CVE-2026-48501 was patched at 2026-09-16
2067.
Unknown Vulnerability Type - Erlang/OTP (CVE-2026-59696) - Low [197]
Description: {'nvd_cve_data_all': 'Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP stdlib allows a remote attacker to degrade availability by supplying a URI whose port component is a very long run of digits. uri_string:get_port/1 passes the port substring to binary_to_integer/1 with no length bound, catching only error:badarg, so a syntactically valid port of up to roughly 1.26 million digits converts successfully and costs the calling process hundreds of milliseconds of arbitrary-precision arithmetic. The conversion is reached from every authority-parsing path in uri_string:parse/1, including the host, registered-name, and IPv4 and IPv6 forms. parse/1 is the documented interface for parsing URIs, so any application that parses an attacker-supplied URI is exposed without further configuration. The conversion function is documented to accept integers of any size, so bounding the input is the caller's responsibility. This issue affects OTP from OTP 21.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to stdlib from 3.5 before 6.2.2.5, from 7.0 before 7.3.0.2, and from 8.0 before 8.0.4.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP stdlib allows a remote attacker to degrade availability by supplying a URI whose port component is a very long run of digits.\n\nuri_string:get_port/1 passes the port substring to binary_to_integer/1 with no length bound, catching only error:badarg, so a syntactically valid port of up to roughly 1.26 million digits converts successfully and costs the calling process hundreds of milliseconds of arbitrary-precision arithmetic. The conversion is reached from every authority-parsing path in uri_string:parse/1, including the host, registered-name, and IPv4 and IPv6 forms. parse/1 is the documented interface for parsing URIs, so any application that parses an attacker-supplied URI is exposed without further configuration. The conversion function is documented to accept integers of any size, so bounding the input is the caller's responsibility.\n\nThis issue affects OTP from OTP\xa021.0 before OTP\xa027.3.4.17, from OTP\xa028.0 before OTP\xa028.5.0.6, and from OTP\xa029.0 before OTP\xa029.0.6, corresponding to stdlib from 3.5 before 6.2.2.5, from 7.0 before 7.3.0.2, and from 8.0 before 8.0.4.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.4 | 14 | Erlang/OTP is a set of libraries for the Erlang programming language | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00421, EPSS Percentile is 0.35854 |
debian: CVE-2026-59696 was patched at 2026-09-16
2068.
Denial of Service - Unknown Product (CVE-2026-31911) - Low [196]
Description: {'nvd_cve_data_all': 'libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00098, EPSS Percentile is 0.00884 |
debian: CVE-2026-31911 was patched at 2026-09-16
2069.
Denial of Service - Unknown Product (CVE-2026-33607) - Low [196]
Description: {'nvd_cve_data_all': 'An attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage and kill the offending process and lock account. Alternatively install fixed version. No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage and kill the offending process and lock account. Alternatively install fixed version. No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0029, EPSS Percentile is 0.21621 |
altlinux: CVE-2026-33607 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-33607 was patched at 2026-09-16
2070.
Denial of Service - Unknown Product (CVE-2026-6554) - Low [196]
Description: {'nvd_cve_data_all': 'libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it does not limit the number of loop iterations. In particular uncommon use cases a crafted filter program can cause the interpreter to loop infinitely.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it does not limit the number of loop iterations. In particular uncommon use cases a crafted filter program can cause the interpreter to loop infinitely.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00098, EPSS Percentile is 0.00885 |
debian: CVE-2026-6554 was patched at 2026-09-16
2071.
Denial of Service - Unknown Product (CVE-2026-71832) - Low [196]
Description: {'nvd_cve_data_all': 'Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial of Service', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial of Service', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00118, EPSS Percentile is 0.01935 |
debian: CVE-2026-71832 was patched at 2026-08-25
2072.
Denial of Service - Unknown Product (CVE-2026-90995) - Low [196]
Description: {'nvd_cve_data_all': 'A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_services` configuration is enabled and the service item is omitted from the request, a NULL pointer dereference can occur. This vulnerability leads to a denial of service, causing the PAM responder to crash and disrupt authentication services.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_services` configuration is enabled and the service item is omitted from the request, a NULL pointer dereference can occur. This vulnerability leads to a denial of service, causing the PAM responder to crash and disrupt authentication services.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00108, EPSS Percentile is 0.01325 |
debian: CVE-2026-90995 was patched at 2026-09-16
2073.
Memory Corruption - Unknown Product (CVE-2026-0799) - Low [196]
Description: {'nvd_cve_data_all': 'In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00107, EPSS Percentile is 0.01276 |
debian: CVE-2026-0799 was patched at 2026-09-16
2074.
Memory Corruption - Unknown Product (CVE-2026-77220) - Low [196]
Description: {'nvd_cve_data_all': 'PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a pointer to a stack-local buffer in the document dictionary without copying the string value. In multi-threaded or pooled-request environments, attackers or concurrent users can trigger stack memory reuse across requests, causing cross-tenant document content corruption by silently overwriting one caller's dictionary string values with another caller's data.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a pointer to a stack-local buffer in the document dictionary without copying the string value. In multi-threaded or pooled-request environments, attackers or concurrent users can trigger stack memory reuse across requests, causing cross-tenant document content corruption by silently overwriting one caller's dictionary string values with another caller's data.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00239, EPSS Percentile is 0.15175 |
debian: CVE-2026-77220 was patched at 2026-08-25
2075.
Memory Corruption - Unknown Product (CVE-2026-79602) - Low [196]
Description: {'nvd_cve_data_all': 'A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A guest with a PCI device assigned that has at least a BAR on the IO port\nspace can trigger a BUG() in Xen.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0013, EPSS Percentile is 0.03002 |
debian: CVE-2026-79602 was patched at 2026-09-16
2076.
Memory Corruption - Unknown Product (CVE-2026-87933) - Low [196]
Description: {'nvd_cve_data_all': 'A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00307, EPSS Percentile is 0.23459 |
debian: CVE-2026-87933 was patched at 2026-09-16
2077.
Memory Corruption - Unknown Product (CVE-2026-90698) - Low [196]
Description: {'nvd_cve_data_all': 'A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.44 is able to resolve this issue. The patch is identified as af05c9302bba508b736c3da1d5670f63fe8b7db4. You should upgrade the affected component.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.44 is able to resolve this issue. The patch is identified as af05c9302bba508b736c3da1d5670f63fe8b7db4. You should upgrade the affected component.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00496, EPSS Percentile is 0.41378 |
debian: CVE-2026-90698 was patched at 2026-09-16
2078.
Information Disclosure - Unknown Product (CVE-2026-20712) - Low [195]
Description: {'nvd_cve_data_all': 'Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.0. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02078 |
oraclelinux: CVE-2026-20712 was patched at 2026-09-02, 2026-09-16
2079.
Unknown Vulnerability Type - MongoDB (CVE-2026-81521) - Low [195]
Description: {'nvd_cve_data_all': 'The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input as a database name could therefore have the write directed at a database and collection other than the ones it intended. Only the Client.BulkWrite API is affected.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input as a database name could therefore have the write directed at a database and collection other than the ones it intended. Only the Client.BulkWrite API is affected.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00203, EPSS Percentile is 0.10478 |
debian: CVE-2026-81521 was patched at 2026-09-16
2080.
Unknown Vulnerability Type - Python (CVE-2026-34399) - Low [195]
Description: {'nvd_cve_data_all': 'FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCAD's BIM Workbench contains an eval() call on untrusted data from SVG template files. When a user creates a TechDraw page from a malicious SVG template, arbitrary Python code executes. The vulnerable code is in src/Mod/BIM/bimcommands/BimTDPage.py (line 87). This issue is fixed in version 1.1.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCAD's BIM Workbench contains an eval() call on untrusted data from SVG template files. When a user creates a TechDraw page from a malicious SVG template, arbitrary Python code executes. The vulnerable code is in src/Mod/BIM/bimcommands/BimTDPage.py (line 87). This issue is fixed in version 1.1.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.03309 |
debian: CVE-2026-34399 was patched at 2026-08-25, 2026-08-26
2081.
Unknown Vulnerability Type - Python (CVE-2026-84366) - Low [195]
Description: {'nvd_cve_data_all': 'Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to the corresponding S3 endpoint unless request.meta["is_secure"] is explicitly enabled, then signs and sends the plaintext request with configured AWS credentials. A network attacker who can observe traffic between Scrapy and S3 can read the bucket and key path, AWS Authorization header, X-Amz-Security-Token when temporary credentials are used, S3 object contents, and S3 response headers. An active man-in-the-middle attacker can also modify the plaintext S3 response body, status code, and headers before Scrapy processes them, causing scraped-data poisoning, poisoned exports, HTTP cache poisoning when caching is enabled, or influence over later crawl targets through forged redirects or attacker-controlled links. Users making S3-scheme requests with AWS credentials are affected. This issue is fixed in version 2.17.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to the corresponding S3 endpoint unless request.meta["is_secure"] is explicitly enabled, then signs and sends the plaintext request with configured AWS credentials. A network attacker who can observe traffic between Scrapy and S3 can read the bucket and key path, AWS Authorization header, X-Amz-Security-Token when temporary credentials are used, S3 object contents, and S3 response headers. An active man-in-the-middle attacker can also modify the plaintext S3 response body, status code, and headers before Scrapy processes them, causing scraped-data poisoning, poisoned exports, HTTP cache poisoning when caching is enabled, or influence over later crawl targets through forged redirects or attacker-controlled links. Users making S3-scheme requests with AWS credentials are affected. This issue is fixed in version 2.17.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0016, EPSS Percentile is 0.05583 |
debian: CVE-2026-84366 was patched at 2026-09-16
2082.
Unknown Vulnerability Type - Rclone (CVE-2026-88016) - Low [195]
Description: {'nvd_cve_data_all': 'rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and later directory metadata is applied through that path. MkdirMetadata, writeMetadataToFile, and setTimes operate when Directory.translatedLink=false, so os.Chown, os.Chmod, os.Chtimes, and birth-time handling can bypass os.Root confinement and follow the symlink. An attacker controlling source contents can therefore apply selected ownership, permissions, modification times, or birth times to a file or directory outside the destination, with --metadata required for chmod and chown while modification time is applied by the normal directory workflow. This issue is fixed in version 1.75.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and later directory metadata is applied through that path. MkdirMetadata, writeMetadataToFile, and setTimes operate when Directory.translatedLink=false, so os.Chown, os.Chmod, os.Chtimes, and birth-time handling can bypass os.Root confinement and follow the symlink. An attacker controlling source contents can therefore apply selected ownership, permissions, modification times, or birth times to a file or directory outside the destination, with --metadata required for chmod and chown while modification time is applied by the normal directory workflow. This issue is fixed in version 1.75.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers, supporting over 40 cloud storage products including S3, Google Drive, Dropbox, OneDrive, and many more. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00187, EPSS Percentile is 0.08549 |
altlinux: CVE-2026-88016 was patched at 2026-09-09
debian: CVE-2026-88016 was patched at 2026-09-16
2083.
Unknown Vulnerability Type - Rclone (CVE-2026-88017) - Low [195]
Description: {'nvd_cve_data_all': 'rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.64.0 until 1.75.1, the FTP auth-proxy driver in cmd/serve/ftp/ftp.go stores one obscured password per username in the server-wide userPass map[string]string instead of binding the credential or VFS to the authenticated session. If two accepted credentials use the same username but resolve to different proxy backends, a later CheckPasswd login overwrites userPass[user], and subsequent getVFS operations on the first session are reauthorized with the later password. The first session can then read, create, overwrite, rename, or delete objects using the second credential’s backend authority. Exploitation requires the later same-username login to occur while the first session remains open. This issue is fixed in version 1.75.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.64.0 until 1.75.1, the FTP auth-proxy driver in cmd/serve/ftp/ftp.go stores one obscured password per username in the server-wide userPass map[string]string instead of binding the credential or VFS to the authenticated session. If two accepted credentials use the same username but resolve to different proxy backends, a later CheckPasswd login overwrites userPass[user], and subsequent getVFS operations on the first session are reauthorized with the later password. The first session can then read, create, overwrite, rename, or delete objects using the second credential’s backend authority. Exploitation requires the later same-username login to occur while the first session remains open. This issue is fixed in version 1.75.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers, supporting over 40 cloud storage products including S3, Google Drive, Dropbox, OneDrive, and many more. | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00234, EPSS Percentile is 0.14486 |
altlinux: CVE-2026-88017 was patched at 2026-09-09
2084.
Memory Corruption - libtiff (CVE-2026-18495) - Low [194]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.2 | 14 | libtiff is a widely used library for reading and writing TIFF (Tagged Image File Format) files, offering tools like tiff2ps. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.01875 |
debian: CVE-2026-18495 was patched at 2026-09-16
2085.
Open Redirect - Unknown Product (CVE-2026-53683) - Low [193]
Description: {'nvd_cve_data_all': 'reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.75 | 15 | Open Redirect | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00162, EPSS Percentile is 0.05775 |
debian: CVE-2026-53683 was patched at 2026-09-16
2086.
Unknown Vulnerability Type - Chromium (CVE-2026-78958) - Low [192]
Description: {'nvd_cve_data_all': 'Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00287, EPSS Percentile is 0.21334 |
altlinux: CVE-2026-78958 was patched at 2026-08-28
debian: CVE-2026-78958 was patched at 2026-09-03, 2026-09-16
2087.
Unknown Vulnerability Type - Chromium (CVE-2026-78979) - Low [192]
Description: {'nvd_cve_data_all': 'Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00234, EPSS Percentile is 0.14506 |
altlinux: CVE-2026-78979 was patched at 2026-08-28
debian: CVE-2026-78979 was patched at 2026-09-03, 2026-09-16
2088.
Unknown Vulnerability Type - Chromium (CVE-2026-78984) - Low [192]
Description: {'nvd_cve_data_all': 'Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00276, EPSS Percentile is 0.20103 |
altlinux: CVE-2026-78984 was patched at 2026-08-28
debian: CVE-2026-78984 was patched at 2026-09-03, 2026-09-16
2089.
Unknown Vulnerability Type - Chromium (CVE-2026-79041) - Low [192]
Description: {'nvd_cve_data_all': 'Missing authorization in Browser in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in Browser in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00233, EPSS Percentile is 0.14386 |
altlinux: CVE-2026-79041 was patched at 2026-08-28
debian: CVE-2026-79041 was patched at 2026-09-03, 2026-09-16
2090.
Unknown Vulnerability Type - Chromium (CVE-2026-79067) - Low [192]
Description: {'nvd_cve_data_all': 'Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.1455 |
altlinux: CVE-2026-79067 was patched at 2026-08-28
debian: CVE-2026-79067 was patched at 2026-09-03, 2026-09-16
2091.
Unknown Vulnerability Type - Chromium (CVE-2026-79098) - Low [192]
Description: {'nvd_cve_data_all': 'UI misrepresentation in PermissionElement in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'UI misrepresentation in PermissionElement in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0019, EPSS Percentile is 0.0892 |
altlinux: CVE-2026-79098 was patched at 2026-08-28
debian: CVE-2026-79098 was patched at 2026-09-03, 2026-09-16
2092.
Unknown Vulnerability Type - Chromium (CVE-2026-79117) - Low [192]
Description: {'nvd_cve_data_all': 'Race condition in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a co-installed app. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Race condition in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a co-installed app. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00229, EPSS Percentile is 0.13803 |
altlinux: CVE-2026-79117 was patched at 2026-08-28
debian: CVE-2026-79117 was patched at 2026-09-03, 2026-09-16
2093.
Unknown Vulnerability Type - Chromium (CVE-2026-79137) - Low [192]
Description: {'nvd_cve_data_all': 'Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00217, EPSS Percentile is 0.12237 |
altlinux: CVE-2026-79137 was patched at 2026-08-28
debian: CVE-2026-79137 was patched at 2026-09-03, 2026-09-16
2094.
Unknown Vulnerability Type - Chromium (CVE-2026-79190) - Low [192]
Description: {'nvd_cve_data_all': 'Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11574 |
altlinux: CVE-2026-79190 was patched at 2026-08-28
debian: CVE-2026-79190 was patched at 2026-09-03, 2026-09-16
2095.
Unknown Vulnerability Type - Chromium (CVE-2026-79211) - Low [192]
Description: {'nvd_cve_data_all': 'Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00229, EPSS Percentile is 0.13816 |
altlinux: CVE-2026-79211 was patched at 2026-08-28
debian: CVE-2026-79211 was patched at 2026-09-03, 2026-09-16
2096.
Unknown Vulnerability Type - Chromium (CVE-2026-79222) - Low [192]
Description: {'nvd_cve_data_all': 'Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00181, EPSS Percentile is 0.07897 |
altlinux: CVE-2026-79222 was patched at 2026-08-28
debian: CVE-2026-79222 was patched at 2026-09-03, 2026-09-16
2097.
Unknown Vulnerability Type - Chromium (CVE-2026-79225) - Low [192]
Description: {'nvd_cve_data_all': 'Incorrect authorization in Browser in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via UI Interaction. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in Browser in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via UI Interaction. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00184, EPSS Percentile is 0.08258 |
altlinux: CVE-2026-79225 was patched at 2026-08-28
debian: CVE-2026-79225 was patched at 2026-09-03, 2026-09-16
2098.
Unknown Vulnerability Type - Chromium (CVE-2026-79238) - Low [192]
Description: {'nvd_cve_data_all': 'Incorrect authorization in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10777 |
altlinux: CVE-2026-79238 was patched at 2026-08-28
debian: CVE-2026-79238 was patched at 2026-09-03, 2026-09-16
2099.
Unknown Vulnerability Type - Chromium (CVE-2026-79267) - Low [192]
Description: {'nvd_cve_data_all': 'Race condition in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Race condition in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00209, EPSS Percentile is 0.11253 |
altlinux: CVE-2026-79267 was patched at 2026-08-28
debian: CVE-2026-79267 was patched at 2026-09-03, 2026-09-16
2100.
Unknown Vulnerability Type - Chromium (CVE-2026-79284) - Low [192]
Description: {'nvd_cve_data_all': 'UI misrepresentation in Core in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'UI misrepresentation in Core in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.1402 |
altlinux: CVE-2026-79284 was patched at 2026-08-28
debian: CVE-2026-79284 was patched at 2026-09-03, 2026-09-16
2101.
Unknown Vulnerability Type - Chromium (CVE-2026-87432) - Low [192]
Description: {'nvd_cve_data_all': 'Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00237, EPSS Percentile is 0.149 |
altlinux: CVE-2026-87432 was patched at 2026-09-17
debian: CVE-2026-87432 was patched at 2026-09-16
2102.
Unknown Vulnerability Type - Chromium (CVE-2026-87434) - Low [192]
Description: {'nvd_cve_data_all': 'Missing authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00269, EPSS Percentile is 0.19136 |
altlinux: CVE-2026-87434 was patched at 2026-09-17
debian: CVE-2026-87434 was patched at 2026-09-16
2103.
Unknown Vulnerability Type - Chromium (CVE-2026-87442) - Low [192]
Description: {'nvd_cve_data_all': 'Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00269, EPSS Percentile is 0.19135 |
altlinux: CVE-2026-87442 was patched at 2026-09-17
debian: CVE-2026-87442 was patched at 2026-09-16
2104.
Unknown Vulnerability Type - Chromium (CVE-2026-87465) - Low [192]
Description: {'nvd_cve_data_all': 'Incorrect authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06405 |
altlinux: CVE-2026-87465 was patched at 2026-09-17
debian: CVE-2026-87465 was patched at 2026-09-16
2105.
Unknown Vulnerability Type - Chromium (CVE-2026-87502) - Low [192]
Description: {'nvd_cve_data_all': 'Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06405 |
altlinux: CVE-2026-87502 was patched at 2026-09-17
debian: CVE-2026-87502 was patched at 2026-09-16
2106.
Unknown Vulnerability Type - Chromium (CVE-2026-87511) - Low [192]
Description: {'nvd_cve_data_all': 'Missing authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00209, EPSS Percentile is 0.11274 |
altlinux: CVE-2026-87511 was patched at 2026-09-17
debian: CVE-2026-87511 was patched at 2026-09-16
2107.
Unknown Vulnerability Type - Chromium (CVE-2026-87557) - Low [192]
Description: {'nvd_cve_data_all': 'Missing authorization in LocalNetworkAccess in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in LocalNetworkAccess in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00221, EPSS Percentile is 0.12747 |
altlinux: CVE-2026-87557 was patched at 2026-09-17
debian: CVE-2026-87557 was patched at 2026-09-16
2108.
Unknown Vulnerability Type - Chromium (CVE-2026-87559) - Low [192]
Description: {'nvd_cve_data_all': 'UI misrepresentation in UI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'UI misrepresentation in UI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00203, EPSS Percentile is 0.10503 |
altlinux: CVE-2026-87559 was patched at 2026-09-17
debian: CVE-2026-87559 was patched at 2026-09-16
2109.
Unknown Vulnerability Type - Chromium (CVE-2026-87651) - Low [192]
Description: {'nvd_cve_data_all': 'Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00184, EPSS Percentile is 0.08173 |
altlinux: CVE-2026-87651 was patched at 2026-09-17
debian: CVE-2026-87651 was patched at 2026-09-16
2110.
Unknown Vulnerability Type - Chromium (CVE-2026-91713) - Low [192]
Description: {'nvd_cve_data_all': 'Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00212, EPSS Percentile is 0.11679 |
altlinux: CVE-2026-91713 was patched at 2026-09-17
debian: CVE-2026-91713 was patched at 2026-09-16
2111.
Unknown Vulnerability Type - Chromium (CVE-2026-91739) - Low [192]
Description: {'nvd_cve_data_all': 'Missing authorization in Transactions Platform in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in Transactions Platform in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00222, EPSS Percentile is 0.12956 |
altlinux: CVE-2026-91739 was patched at 2026-09-17
debian: CVE-2026-91739 was patched at 2026-09-16
2112.
Unknown Vulnerability Type - Chromium (CVE-2026-91740) - Low [192]
Description: {'nvd_cve_data_all': 'Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0022, EPSS Percentile is 0.12589 |
altlinux: CVE-2026-91740 was patched at 2026-09-17
debian: CVE-2026-91740 was patched at 2026-09-16
2113.
Unknown Vulnerability Type - Keycloak (CVE-2026-15945) - Low [192]
Description: {'nvd_cve_data_all': 'A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.3 | 10 | CVSS Base Score is 2.7. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00259, EPSS Percentile is 0.17726 |
altlinux: CVE-2026-15945 was patched at 2026-08-20, 2026-08-26, 2026-08-28
2114.
Unknown Vulnerability Type - Keycloak (CVE-2026-18218) - Low [192]
Description: {'nvd_cve_data_all': 'A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm already has an older, non-zero revocation policy in place. This issue can allow previously issued tokens to remain valid for refreshing sessions and accessing user information even after an administrator has attempted to invalidate them. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm already has an older, non-zero revocation policy in place. This issue can allow previously issued tokens to remain valid for refreshing sessions and accessing user information even after an administrator has attempted to invalidate them.\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00131, EPSS Percentile is 0.03102 |
altlinux: CVE-2026-18218 was patched at 2026-09-01, 2026-09-04, 2026-09-07
2115.
Unknown Vulnerability Type - Keycloak (CVE-2026-18570) - Low [192]
Description: {'nvd_cve_data_all': 'A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executor only validates the fullScopeAllowed field when it is explicitly provided in a request. By omitting this field, a delegated user can bypass the policy, resulting in a client created with full scope access. This allows the client to obtain tokens with unauthorized role mappings.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executor only validates the fullScopeAllowed field when it is explicitly provided in a request. By omitting this field, a delegated user can bypass the policy, resulting in a client created with full scope access. This allows the client to obtain tokens with unauthorized role mappings.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00141, EPSS Percentile is 0.03828 |
altlinux: CVE-2026-18570 was patched at 2026-09-01, 2026-09-04, 2026-09-07
2116.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92068) - Low [192]
Description: {'nvd_cve_data_all': 'Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04023 |
altlinux: CVE-2026-92068 was patched at 2026-09-16
2117.
Unknown Vulnerability Type - OpenSSL (CVE-2026-78124) - Low [192]
Description: {'nvd_cve_data_all': 'strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00194, EPSS Percentile is 0.09294 |
altlinux: CVE-2026-78124 was patched at 2026-09-11
debian: CVE-2026-78124 was patched at 2026-09-07, 2026-09-16
2118.
Server-Side Request Forgery - Unknown Product (CVE-2026-77648) - Low [191]
Description: {'nvd_cve_data_all': 'In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that\nbypass import_filtering_opts, allowing an admin to fetch internal\nURLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0 | 14 | Unknown Product | |
| 0.2 | 10 | CVSS Base Score is 2.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00192, EPSS Percentile is 0.09064 |
debian: CVE-2026-77648 was patched at 2026-08-25
2119.
Unknown Vulnerability Type - Hostapd (CVE-2025-24912) - Low [190]
Description: {'nvd_cve_data_all': 'hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:w1.fi:hostapd (exists in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.0076, EPSS Percentile is 0.53525 |
altlinux: CVE-2025-24912 was patched at 2026-08-31
2120.
Unknown Vulnerability Type - Pypdf (CVE-2026-82398) - Low [190]
Description: {'nvd_cve_data_all': 'pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without whitespace. The function repeatedly performs immutable bytes concatenation in a one-byte loop, causing quadratic processing cost for the long non-whitespace input. This issue is fixed in version 6.15.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without whitespace. The function repeatedly performs immutable bytes concatenation in a one-byte loop, causing quadratic processing cost for the long non-whitespace input. This issue is fixed in version 6.15.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | PyPDF is a Python library for reading, manipulating, and writing PDF files, including extraction, splitting, merging, and encryption features. | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00301, EPSS Percentile is 0.22821 |
debian: CVE-2026-82398 was patched at 2026-09-16
2121.
Unknown Vulnerability Type - fast-uri (CVE-2026-75931) - Low [190]
Description: {'nvd_cve_data_all': 'fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes is returned with its host verbatim and no error set. As a result fast-uri's own entry points disagree with each other: parse, resolve, normalize, and equal can yield different hosts for the same input depending only on whether a scheme is written out, and equal can return opposite verdicts for the same pair of hosts. An application that extracts a host with fast-uri to check it against a policy list and then resolves the same reference can make its decision on one host while the destination is another, enabling host confusion and policy bypass. The affected versions are 2.4.2 up to but not including 2.4.5, 3.1.3 up to but not including 3.1.6, and 4.0.1 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which canonicalize the host consistently across the resolve path. Users should upgrade to a patched version.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes is returned with its host verbatim and no error set. As a result fast-uri's own entry points disagree with each other: parse, resolve, normalize, and equal can yield different hosts for the same input depending only on whether a scheme is written out, and equal can return opposite verdicts for the same pair of hosts. An application that extracts a host with fast-uri to check it against a policy list and then resolves the same reference can make its decision on one host while the destination is another, enabling host confusion and policy bypass. The affected versions are 2.4.2 up to but not including 2.4.5, 3.1.3 up to but not including 3.1.6, and 4.0.1 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which canonicalize the host consistently across the resolve path. Users should upgrade to a patched version.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:openjsf:fast-uri (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00232, EPSS Percentile is 0.14195 |
debian: CVE-2026-75931 was patched at 2026-08-25
2122.
Unknown Vulnerability Type - fast-uri (CVE-2026-84292) - Low [190]
Description: {'nvd_cve_data_all': 'fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node's URL read the result back as the attacker's host with no error, so re-validating the built URI does not catch it. This affects applications that build URIs from parts and assign untrusted data to the port component through the serialize, normalize, or equal functions in their object forms. The issue affects fast-uri versions before 2.4.6, from 3.0.0 before 3.1.7, and from 4.0.0 before 4.1.4. It is fixed in 2.4.6, 3.1.7, and 4.1.4, where recomposeAuthority rejects any port that is not a digit sequence per RFC 3986.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a sequence of digits can inject authority delimiters, demoting the intended host to userinfo and pointing the authority at an attacker-controlled host. Both fast-uri and Node's URL read the result back as the attacker's host with no error, so re-validating the built URI does not catch it. This affects applications that build URIs from parts and assign untrusted data to the port component through the serialize, normalize, or equal functions in their object forms. The issue affects fast-uri versions before 2.4.6, from 3.0.0 before 3.1.7, and from 4.0.0 before 4.1.4. It is fixed in 2.4.6, 3.1.7, and 4.1.4, where recomposeAuthority rejects any port that is not a digit sequence per RFC 3986.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:openjsf:fast-uri (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00226, EPSS Percentile is 0.13423 |
debian: CVE-2026-84292 was patched at 2026-09-16
2123.
Unknown Vulnerability Type - BIND (CVE-2026-80158) - Low [188]
Description: {'nvd_cve_data_all': 'A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keytab, is not declared with no_log, unlike the sibling password parameter in the same module. As a consequence, the supplied IPA/LDAP bind password is recorded in cleartext in the managed host's system journal/syslog (the module's "Invoked with" record), is included in the module's return values and verbose (-v) output, and is displayed in Automation Controller / AWX job output. The password is additionally passed on the command line to the ipa-getkeytab helper (as --bindpw <value>), exposing it in the process list to local users while the command runs. An attacker able to read these logs, job output, or the process table can obtain the directory bind credential, potentially compromising the accounts and objects that credential can access.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in the ipa_getkeytab module of the community.general\nAnsible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keytab, is not declared with no_log, unlike the sibling password parameter in the same module. As a consequence, the supplied IPA/LDAP bind password is recorded in cleartext in the managed host's system journal/syslog (the module's "Invoked with" record), is included in the module's return values and verbose (-v) output, and is displayed in Automation Controller / AWX job output. The password is additionally passed on the command line to the ipa-getkeytab helper (as --bindpw <value>), exposing it in the process list to local users while the command runs. An attacker able to read these logs, job output, or the process table can obtain the directory bind credential, potentially compromising the accounts and objects that credential can access.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00102, EPSS Percentile is 0.01065 |
debian: CVE-2026-80158 was patched at 2026-09-16
2124.
Unknown Vulnerability Type - BIND (CVE-2026-88264) - Low [188]
Description: {'nvd_cve_data_all': 'A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.6 | 10 | CVSS Base Score is 5.6. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.019 |
debian: CVE-2026-88264 was patched at 2026-09-16
2125.
Unknown Vulnerability Type - Erlang/OTP (CVE-2026-70405) - Low [185]
Description: {'nvd_cve_data_all': 'Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP snmp allows a remote attacker to degrade availability by sending an SNMP message containing a BER INTEGER whose length field is arbitrarily large. snmp_pdus:dec_integer_notag/1 defaults its size limit to infinity, and do_dec_integer_notag/2 then accumulates the value across every declared byte with a recursive shift and bitwise or. Work grows superlinearly in the declared length because each operation acts on a progressively larger bignum. The size-limited variant dec_integer_notag/2 exists but is reached from only one call site, dec_snmp_version/1, which bounds the version field to ten bytes; the request identifier, error status and index, generic and specific trap fields, engine boots and time, and every varbind value decoded by dec_value/1 all use the unbounded form. The decode runs before the PDU is processed, so no valid request is required beyond what the deployment demands to accept the message at all. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to snmp from 4.25.1 before 5.18.2.1, from 5.19 before 5.20.2.2, and from 5.20.3 before 5.20.5. Whether OTP before OTP 17.0, corresponding to snmp before 4.25.1, is affected is unknown.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP snmp allows a remote attacker to degrade availability by sending an SNMP message containing a BER INTEGER whose length field is arbitrarily large.\n\nsnmp_pdus:dec_integer_notag/1 defaults its size limit to infinity, and do_dec_integer_notag/2 then accumulates the value across every declared byte with a recursive shift and bitwise or. Work grows superlinearly in the declared length because each operation acts on a progressively larger bignum. The size-limited variant dec_integer_notag/2 exists but is reached from only one call site, dec_snmp_version/1, which bounds the version field to ten bytes; the request identifier, error status and index, generic and specific trap fields, engine boots and time, and every varbind value decoded by dec_value/1 all use the unbounded form. The decode runs before the PDU is processed, so no valid request is required beyond what the deployment demands to accept the message at all.\n\nThis issue affects OTP from OTP\xa017.0 before OTP\xa027.3.4.17, from OTP\xa028.0 before OTP\xa028.5.0.6, and from OTP\xa029.0 before OTP\xa029.0.6, corresponding to snmp from 4.25.1 before 5.18.2.1, from 5.19 before 5.20.2.2, and from 5.20.3 before 5.20.5. Whether OTP before OTP\xa017.0, corresponding to snmp before 4.25.1, is affected is unknown.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.4 | 14 | Erlang/OTP is a set of libraries for the Erlang programming language | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00421, EPSS Percentile is 0.35853 |
debian: CVE-2026-70405 was patched at 2026-09-16
2126.
Unknown Vulnerability Type - Erlang/OTP (CVE-2026-70409) - Low [185]
Description: {'nvd_cve_data_all': 'Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP server to degrade availability by returning a referral URL whose port component is a very long run of digits. eldap:parse_port/2 passes the port substring straight to list_to_integer/1 with no length bound. The surrounding try ... catch only rejects a value that fails to parse, so a syntactically valid port of up to roughly 1.26 million digits converts successfully and costs the caller hundreds of milliseconds of arbitrary-precision arithmetic per referral. The conversion function itself is documented to accept integers of any size, so bounding the input is the caller's responsibility. Reaching the flaw requires the application to pass a server-supplied referral to eldap:parse_ldap_url/1, which eldap never calls itself: referral strings are returned to the caller unparsed. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to eldap from 1.0.3 before 1.2.14.2, from 1.2.15 before 1.2.16.1, and from 1.3 before 1.3.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP server to degrade availability by returning a referral URL whose port component is a very long run of digits.\n\neldap:parse_port/2 passes the port substring straight to list_to_integer/1 with no length bound. The surrounding try ... catch only rejects a value that fails to parse, so a syntactically valid port of up to roughly 1.26 million digits converts successfully and costs the caller hundreds of milliseconds of arbitrary-precision arithmetic per referral. The conversion function itself is documented to accept integers of any size, so bounding the input is the caller's responsibility. Reaching the flaw requires the application to pass a server-supplied referral to eldap:parse_ldap_url/1, which eldap never calls itself: referral strings are returned to the caller unparsed.\n\nThis issue affects OTP from OTP\xa017.0 before OTP\xa027.3.4.17, from OTP\xa028.0 before OTP\xa028.5.0.6, and from OTP\xa029.0 before OTP\xa029.0.6, corresponding to eldap from 1.0.3 before 1.2.14.2, from 1.2.15 before 1.2.16.1, and from 1.3 before 1.3.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.4 | 14 | Erlang/OTP is a set of libraries for the Erlang programming language | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00423, EPSS Percentile is 0.35955 |
debian: CVE-2026-70409 was patched at 2026-09-16
2127.
Unknown Vulnerability Type - Spring Framework (CVE-2026-47893) - Low [185]
Description: {'nvd_cve_data_all': 'A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpring Framework 6.1.0 - 6.1.28\nSpring Framework 6.0.0 - 6.0.30\nSpring Framework 5.3.0 - 5.3.49\nSpring Framework 5.2.25.RELEASE and earlier', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.4 | 14 | The Spring Framework is an application framework and inversion of control container for the Java platform | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00245, EPSS Percentile is 0.15933 |
debian: CVE-2026-47893 was patched at 2026-09-16
2128.
Denial of Service - Unknown Product (CVE-2026-42395) - Low [184]
Description: {'nvd_cve_data_all': 'A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt. The login process is terminated, which can cause degradation or denial of service for logins. Deployments that do not configure trusted proxies are not affected. Restrict the list of trusted proxy networks to hosts that are fully under your control. Update to non-vulnerable version. No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt. The login process is terminated, which can cause degradation or denial of service for logins. Deployments that do not configure trusted proxies are not affected. Restrict the list of trusted proxy networks to hosts that are fully under your control. Update to non-vulnerable version. No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00181, EPSS Percentile is 0.07917 |
altlinux: CVE-2026-42395 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-42395 was patched at 2026-09-16
2129.
Denial of Service - Unknown Product (CVE-2026-61712) - Low [184]
Description: {'nvd_cve_data_all': 'BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, BuildKit read attacker-controlled /etc/passwd and /etc/group files without an upper bound while resolving a username to a user identifier or group identifier in executor/oci/user.go and solver/llbsolver/ops/user_linux.go. A malicious base image or build could provide oversized files that exhausted memory during user resolution and caused out-of-memory termination of the buildkitd process. This issue is fixed in version 0.31.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, BuildKit read attacker-controlled /etc/passwd and /etc/group files without an upper bound while resolving a username to a user identifier or group identifier in executor/oci/user.go and solver/llbsolver/ops/user_linux.go. A malicious base image or build could provide oversized files that exhausted memory during user resolution and caused out-of-memory termination of the buildkitd process. This issue is fixed in version 0.31.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.2 | 10 | CVSS Base Score is 2.3. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00404, EPSS Percentile is 0.34223 |
redos: CVE-2026-61712 was patched at 2026-09-07
2130.
Denial of Service - Unknown Product (CVE-2026-71219) - Low [184]
Description: {'nvd_cve_data_all': 'A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 filesystem image with a large di_depth value causes stack exhaustion and a denial of service when processed by fsck.gfs2, gfs2_edit, or savemeta.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 filesystem image with a large di_depth value causes stack exhaustion and a denial of service when processed by fsck.gfs2, gfs2_edit, or savemeta.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00116, EPSS Percentile is 0.01802 |
debian: CVE-2026-71219 was patched at 2026-09-16
2131.
Denial of Service - Unknown Product (CVE-2026-71222) - Low [184]
Description: {'nvd_cve_data_all': 'A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive memory contents or cause a crash when processing crafted GFS2 filesystem images.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive memory contents or cause a crash when processing crafted GFS2 filesystem images.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00109, EPSS Percentile is 0.01385 |
debian: CVE-2026-71222 was patched at 2026-09-16
2132.
Denial of Service - Unknown Product (CVE-2026-71224) - Low [184]
Description: {'nvd_cve_data_all': 'A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata without bounds validation, causing stack exhaustion and a denial of service when processing crafted GFS2 filesystem images.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata without bounds validation, causing stack exhaustion and a denial of service when processing crafted GFS2 filesystem images.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00116, EPSS Percentile is 0.01803 |
debian: CVE-2026-71224 was patched at 2026-09-16
2133.
Denial of Service - Unknown Product (CVE-2026-79515) - Low [184]
Description: {'nvd_cve_data_all': 'An out-of-bounds read in the stbtt_GetGlyphShape component of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted TTF file.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An out-of-bounds read in the stbtt_GetGlyphShape component of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted TTF file.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00226, EPSS Percentile is 0.13472 |
debian: CVE-2026-79515 was patched at 2026-09-16
2134.
Denial of Service - Unknown Product (CVE-2026-81723) - Low [184]
Description: {'nvd_cve_data_all': 'NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read. Attackers can provide malformed XML corpus files to cause severe CPU consumption and denial of service through affected readers like BNCCorpusReader.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read. Attackers can provide malformed XML corpus files to cause severe CPU consumption and denial of service through affected readers like BNCCorpusReader.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00222, EPSS Percentile is 0.12855 |
debian: CVE-2026-81723 was patched at 2026-09-16
2135.
Denial of Service - Unknown Product (CVE-2026-84965) - Low [184]
Description: {'nvd_cve_data_all': 'An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where sizes are 32 bits, an unauthenticated party able to supply a sufficiently large JSON input to an application that links the library may cause that application to terminate unexpectedly, resulting in denial of service.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where sizes are 32 bits, an unauthenticated party able to supply a sufficiently large JSON input to an application that links the library may cause that application to terminate unexpectedly, resulting in denial of service.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00096, EPSS Percentile is 0.008 |
debian: CVE-2026-84965 was patched at 2026-09-16
2136.
Denial of Service - Unknown Product (CVE-2026-91926) - Low [184]
Description: {'nvd_cve_data_all': 'A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. The parser allocates memory for each string value but does not free the previous allocation when the same AV_PAIR type appears more than once, leaking the earlier allocation. A malicious or man-in-the-middle server can exploit this to cause gradual memory exhaustion on the client during NTLM authentication, leading to a denial of service.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. The parser allocates memory for each string value but does not free the previous allocation when the same AV_PAIR type appears more than once, leaking the earlier allocation. A malicious or man-in-the-middle server can exploit this to cause gradual memory exhaustion on the client during NTLM authentication, leading to a denial of service.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00232, EPSS Percentile is 0.14178 |
debian: CVE-2026-91926 was patched at 2026-09-16
2137.
Memory Corruption - Unknown Product (CVE-2026-77118) - Low [184]
Description: {'nvd_cve_data_all': 'A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage() (coders/pcd.c), the Huffman delta loop advances its output pointer with q++ after every decoded delta and never checks it against the end of the heap-allocated luma/chroma plane buffers. The pointer is repositioned only when a sync marker introduces a new plane/row; between sync markers the run length is bounded solely by the input. A crafted PCD file that positions the pointer near the end of a plane and then supplies a long run of deltas with no intervening sync therefore walks the pointer past the end of the allocation and writes through it. Processing an untrusted PCD file — for example with gm convert or gm identify, or through any application linked against libGraphicsMagick — can corrupt heap memory beyond the buffers.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage() (coders/pcd.c), the Huffman delta loop advances its output pointer with q++ after every decoded delta and never checks it against the end of the heap-allocated luma/chroma plane buffers. The pointer is repositioned only when a sync marker introduces a new plane/row; between sync markers the run length is bounded solely by the input.\n\n\n\nA crafted PCD file that positions the pointer near the end of a plane and then supplies a long run of deltas with no intervening sync therefore walks the pointer past the end of the allocation and writes through it. Processing an untrusted PCD file — for example with gm convert or gm identify, or through any application linked against libGraphicsMagick — can corrupt heap memory beyond the buffers.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00131, EPSS Percentile is 0.03062 |
debian: CVE-2026-77118 was patched at 2026-08-25
2138.
Memory Corruption - Unknown Product (CVE-2026-79591) - Low [184]
Description: {'nvd_cve_data_all': 'A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00127, EPSS Percentile is 0.02678 |
debian: CVE-2026-79591 was patched at 2026-09-16
2139.
Memory Corruption - Unknown Product (CVE-2026-82623) - Low [184]
Description: {'nvd_cve_data_all': 'A vulnerability was detected in open62541 up to 1.5.5. Affected by this vulnerability is the function UA_DataValue_backend_copyRange of the file plugins/historydata/ua_history_data_backend_memory.c of the component History Backend. The manipulation results in use after free. The attack can be launched remotely. The exploit is now public and may be used. The project closed the issue report, stating that this is not the official way to report a security vulnerability.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A vulnerability was detected in open62541 up to 1.5.5. Affected by this vulnerability is the function UA_DataValue_backend_copyRange of the file plugins/historydata/ua_history_data_backend_memory.c of the component History Backend. The manipulation results in use after free. The attack can be launched remotely. The exploit is now public and may be used. The project closed the issue report, stating that this is not the official way to report a security vulnerability.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00405, EPSS Percentile is 0.3433 |
debian: CVE-2026-82623 was patched at 2026-09-16
2140.
Memory Corruption - Unknown Product (CVE-2026-86095) - Low [184]
Description: {'nvd_cve_data_all': 'Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribute names to overflow the destination buffer, causing memory corruption and crashes when applications enumerate attribute names.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribute names to overflow the destination buffer, causing memory corruption and crashes when applications enumerate attribute names.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.0264 |
debian: CVE-2026-86095 was patched at 2026-09-16
2141.
Memory Corruption - Unknown Product (CVE-2026-90556) - Low [184]
Description: {'nvd_cve_data_all': 'Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the entries array into adjacent heap-allocated struct fields, potentially corrupting memory when a user or server operator loads the file.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the entries array into adjacent heap-allocated struct fields, potentially corrupting memory when a user or server operator loads the file.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00139, EPSS Percentile is 0.03629 |
debian: CVE-2026-90556 was patched at 2026-09-16
2142.
Memory Corruption - Unknown Product (CVE-2026-90783) - Low [184]
Description: {'nvd_cve_data_all': 'MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.03843 |
debian: CVE-2026-90783 was patched at 2026-09-16
2143.
Security Feature Bypass - Unknown Product (CVE-2026-61634) - Low [184]
Description: {'nvd_cve_data_all': 'The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning path records the negotiated AMQP frame_max value, but src/main/java/com/rabbitmq/client/impl/SocketFrameHandler.java and NettyFrameHandlerFactory continue to validate broker-controlled frame payload lengths against maxInboundMessageBodySize because the negotiated limit is not applied consistently through setMaxInboundFramePayloadSize. A malicious or compromised broker can send a method frame larger than the negotiated frame_max during or after connection establishment, causing the client to allocate and decode a protocol-invalid frame instead of rejecting it with MalformedFrameException. The protocol violation can disrupt the affected connection and cause client-side denial of service. This issue is fixed in version 5.33.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning path records the negotiated AMQP frame_max value, but src/main/java/com/rabbitmq/client/impl/SocketFrameHandler.java and NettyFrameHandlerFactory continue to validate broker-controlled frame payload lengths against maxInboundMessageBodySize because the negotiated limit is not applied consistently through setMaxInboundFramePayloadSize. A malicious or compromised broker can send a method frame larger than the negotiated frame_max during or after connection establishment, causing the client to allocate and decode a protocol-invalid frame instead of rejecting it with MalformedFrameException. The protocol violation can disrupt the affected connection and cause client-side denial of service. This issue is fixed in version 5.33.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.2 | 10 | EPSS Probability is 0.00299, EPSS Percentile is 0.22612 |
debian: CVE-2026-61634 was patched at 2026-08-20
2144.
Information Disclosure - Unknown Product (CVE-2026-42393) - Low [183]
Description: {'nvd_cve_data_all': 'The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attacker with access to the same network as the doveadm service, able to make repeated requests and measure response timing accurately, can learn the length of the secret, which reduces the effort needed to guess it. The secret value itself is not disclosed. Restrict network access to the doveadm service to trusted clients. Update to non-vulnerable version. No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00145, EPSS Percentile is 0.04104 |
altlinux: CVE-2026-42393 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-42393 was patched at 2026-09-16
2145.
Unknown Vulnerability Type - ImageMagick (CVE-2026-70651) - Low [183]
Description: {'nvd_cve_data_all': 'libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick support can overflow the combined frame height while loading a crafted multi-page TIFF through VipsForeignLoadMagick. The vulnerable calculations in libvips/foreign/magick6load.c and libvips/foreign/magick7load.c multiply the per-page Ysize by n_frames without a checked bound, which can cause a heap buffer over-read and process crash. Most package-manager builds include libtiff and do not use this affected fallback path. This issue is fixed in version 8.18.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick support can overflow the combined frame height while loading a crafted multi-page TIFF through VipsForeignLoadMagick. The vulnerable calculations in libvips/foreign/magick6load.c and libvips/foreign/magick7load.c multiply the per-page Ysize by n_frames without a checked bound, which can cause a heap buffer over-read and process crash. Most package-manager builds include libtiff and do not use this affected fallback path. This issue is fixed in version 8.18.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02199 |
debian: CVE-2026-70651 was patched at 2026-08-25
2146.
Unknown Vulnerability Type - Nokogiri (CVE-2026-79769) - Low [183]
Description: {'nvd_cve_data_all': 'Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protected internal Node#initialize_copy_with_args helper behind Node#dup and #clone, which unwrapped its source argument as an xmlNode without a type check. If application code calls this protected method with a non-Node argument (e.g., a Namespace), it reads an xmlNs out of bounds, crashing the process. This is only triggerable by a programming error and cannot be triggered by untrusted input or normal use of the public API. Only CRuby is affected. Version 1.19.4 adds a type check and raises TypeError.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protected internal Node#initialize_copy_with_args helper behind Node#dup and #clone, which unwrapped its source argument as an xmlNode without a type check. If application code calls this protected method with a non-Node argument (e.g., a Namespace), it reads an xmlNs out of bounds, crashing the process. This is only triggerable by a programming error and cannot be triggered by untrusted input or normal use of the public API. Only CRuby is affected. Version 1.19.4 adds a type check and raises TypeError.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Nokogiri is an open source XML and HTML library for the Ruby programming language | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00181, EPSS Percentile is 0.07913 |
debian: CVE-2026-79769 was patched at 2026-09-16
2147.
Unknown Vulnerability Type - PHP Secure Communications Library (CVE-2026-84308) - Low [183]
Description: {'nvd_cve_data_all': 'phpseclib is a PHP secure communications library. Prior to 3.0.57 and 4.0.1, pure-PHP X25519 scalar multiplication in phpseclib/Math/PrimeField/Integer.php performs data-dependent conditional modular reductions in add() and subtract(). During the Montgomery ladder in phpseclib/Crypt/EC/BaseCurves/Montgomery.php, the reduction behavior of each step depends on the secret scalar prefix, creating per-step timing and libgmp call-count observations that can reveal a reused 251-bit clamped private scalar. The phpseclib/Crypt/EC/Formats/Keys/MontgomeryPrivate.php derivation path invokes the pure-PHP multiplication without a native-engine check, while phpseclib/Crypt/EC/Formats/Keys/PKCS8.php reaches it when ext-sodium is unavailable. Exploitation requires a reused or long-lived X25519 private key, knowledge of the corresponding public key, execution of the pure-PHP path, and a local observer capable of resolving individual ladder steps or libgmp entry-point calls. Ephemeral X25519 keys, including phpseclib's normal SSH exchange path, are not affected. Recovery of the scalar permanently compromises operations that reuse that key. This issue is fixed in versions 3.0.57 and 4.0.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'phpseclib is a PHP secure communications library. Prior to 3.0.57 and 4.0.1, pure-PHP X25519 scalar multiplication in phpseclib/Math/PrimeField/Integer.php performs data-dependent conditional modular reductions in add() and subtract(). During the Montgomery ladder in phpseclib/Crypt/EC/BaseCurves/Montgomery.php, the reduction behavior of each step depends on the secret scalar prefix, creating per-step timing and libgmp call-count observations that can reveal a reused 251-bit clamped private scalar. The phpseclib/Crypt/EC/Formats/Keys/MontgomeryPrivate.php derivation path invokes the pure-PHP multiplication without a native-engine check, while phpseclib/Crypt/EC/Formats/Keys/PKCS8.php reaches it when ext-sodium is unavailable. Exploitation requires a reused or long-lived X25519 private key, knowledge of the corresponding public key, execution of the pure-PHP path, and a local observer capable of resolving individual ladder steps or libgmp entry-point calls. Ephemeral X25519 keys, including phpseclib's normal SSH exchange path, are not affected. Recovery of the scalar permanently compromises operations that reuse that key. This issue is fixed in versions 3.0.57 and 4.0.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | phpseclib provides pure-PHP implementations of SSH2, SFTP, RSA, DSA, Elliptic Curves, AES, ChaCha20, X. 509, CSR, CRL, SPKAC | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00212, EPSS Percentile is 0.11658 |
debian: CVE-2026-84308 was patched at 2026-09-16
2148.
Unknown Vulnerability Type - libheif (CVE-2026-84451) - Low [183]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of unc_decoder::get_compressed_image_data_uncompressed() in libheif/codecs/uncompressed/unc_decoder.cc retains an addition-based range check that can wrap when a crafted uncompressed tile grid produces a large range_start_offset and range_size. The overflow makes the bounds comparison pass and allows heif_image_handle_decode_image_tile() to call memcpy() with an invalid source pointer and a very large length when decoding a valid high-index advertised tile. This incomplete remediation of CVE-2026-62292 can reliably crash tile-processing applications, while whole-image decoding is not claimed to reach the demonstrated path. This issue is fixed in version 1.23.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | libheif is an open source HEIF and AVIF image file format decoder and encoder library, supporting modern image codecs and container features. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-84451 was patched at 2026-09-16
2149.
Unknown Vulnerability Type - strongSwan (CVE-2026-78127) - Low [183]
Description: {'nvd_cve_data_all': 'libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | strongSwan is an open source IPsec-based VPN solution that provides secure network connectivity using IKEv1 and IKEv2 protocols, widely used on Linux systems for site-to-site and remote access VPN deployments. | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00354, EPSS Percentile is 0.28874 |
altlinux: CVE-2026-78127 was patched at 2026-09-11
debian: CVE-2026-78127 was patched at 2026-09-07, 2026-09-16
2150.
Unknown Vulnerability Type - Chromium (CVE-2026-87452) - Low [180]
Description: {'nvd_cve_data_all': 'Incorrect authorization in GPU in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in GPU in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00209, EPSS Percentile is 0.1124 |
altlinux: CVE-2026-87452 was patched at 2026-09-17
debian: CVE-2026-87452 was patched at 2026-09-16
2151.
Unknown Vulnerability Type - Chromium (CVE-2026-87456) - Low [180]
Description: {'nvd_cve_data_all': 'Uninitialized resource in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00236, EPSS Percentile is 0.14813 |
altlinux: CVE-2026-87456 was patched at 2026-09-17
debian: CVE-2026-87456 was patched at 2026-09-16
2152.
Unknown Vulnerability Type - Chromium (CVE-2026-87485) - Low [180]
Description: {'nvd_cve_data_all': 'Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00222, EPSS Percentile is 0.12892 |
altlinux: CVE-2026-87485 was patched at 2026-09-17
debian: CVE-2026-87485 was patched at 2026-09-16
2153.
Unknown Vulnerability Type - Chromium (CVE-2026-87498) - Low [180]
Description: {'nvd_cve_data_all': 'Missing authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0019, EPSS Percentile is 0.08876 |
altlinux: CVE-2026-87498 was patched at 2026-09-17
debian: CVE-2026-87498 was patched at 2026-09-16
2154.
Unknown Vulnerability Type - Chromium (CVE-2026-87517) - Low [180]
Description: {'nvd_cve_data_all': 'Race condition in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Race condition in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00174, EPSS Percentile is 0.07134 |
altlinux: CVE-2026-87517 was patched at 2026-09-17
debian: CVE-2026-87517 was patched at 2026-09-16
2155.
Unknown Vulnerability Type - Chromium (CVE-2026-87576) - Low [180]
Description: {'nvd_cve_data_all': 'Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09469 |
altlinux: CVE-2026-87576 was patched at 2026-09-17
debian: CVE-2026-87576 was patched at 2026-09-16
2156.
Unknown Vulnerability Type - Chromium (CVE-2026-87611) - Low [180]
Description: {'nvd_cve_data_all': 'Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.0692 |
altlinux: CVE-2026-87611 was patched at 2026-09-17
debian: CVE-2026-87611 was patched at 2026-09-16
2157.
Unknown Vulnerability Type - Chromium (CVE-2026-87614) - Low [180]
Description: {'nvd_cve_data_all': 'Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0019, EPSS Percentile is 0.08876 |
altlinux: CVE-2026-87614 was patched at 2026-09-17
debian: CVE-2026-87614 was patched at 2026-09-16
2158.
Unknown Vulnerability Type - Chromium (CVE-2026-87624) - Low [180]
Description: {'nvd_cve_data_all': 'UI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'UI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00139, EPSS Percentile is 0.03671 |
altlinux: CVE-2026-87624 was patched at 2026-09-17
debian: CVE-2026-87624 was patched at 2026-09-16
2159.
Unknown Vulnerability Type - Chromium (CVE-2026-87647) - Low [180]
Description: {'nvd_cve_data_all': 'Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00185, EPSS Percentile is 0.08298 |
altlinux: CVE-2026-87647 was patched at 2026-09-17
debian: CVE-2026-87647 was patched at 2026-09-16
2160.
Unknown Vulnerability Type - Chromium (CVE-2026-87652) - Low [180]
Description: {'nvd_cve_data_all': 'Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00218, EPSS Percentile is 0.12383 |
altlinux: CVE-2026-87652 was patched at 2026-09-17
debian: CVE-2026-87652 was patched at 2026-09-16
2161.
Unknown Vulnerability Type - Chromium (CVE-2026-91730) - Low [180]
Description: {'nvd_cve_data_all': 'Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00237, EPSS Percentile is 0.14921 |
altlinux: CVE-2026-91730 was patched at 2026-09-17
debian: CVE-2026-91730 was patched at 2026-09-16
2162.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92070) - Low [180]
Description: {'nvd_cve_data_all': 'Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04022 |
altlinux: CVE-2026-92070 was patched at 2026-09-16
2163.
Unknown Vulnerability Type - gitoxide (CVE-2026-82252) - Low [180]
Description: {'nvd_cve_data_all': 'gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked .gitmodules pointing outside the repository tree, causing gitoxide to parse arbitrary external files as submodule configuration and expose attacker-controlled name, path, and url values.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked .gitmodules pointing outside the repository tree, causing gitoxide to parse arbitrary external files as submodule configuration and expose attacker-controlled name, path, and url values.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.3 | 14 | gitoxide is an idiomatic, lean, fast & safe pure Rust implementation of Git, designed for correctness and performance, available both as a Rust library (gix crate) and command-line interface tools. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00387, EPSS Percentile is 0.32479 |
debian: CVE-2026-82252 was patched at 2026-09-16
2164.
Unknown Vulnerability Type - Morgan (CVE-2026-5078) - Low [178]
Description: {'nvd_cve_data_all': 'Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutralizing control characters. An unauthenticated attacker can send a crafted Authorization Basic header containing CR or LF bytes to inject forged log lines, breaking the one-request-per-line structure of access logs and enabling log forgery against downstream log consumers. The built-in combined, common, default, and short formats are affected, as well as any custom format that references :remote-user. Affected versions: morgan 1.2.0 through 1.10.1. Patches: upgrade to morgan 1.11.0, which neutralizes control characters in the :remote-user token output. Workarounds: use a custom format string that does not include :remote-user.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutralizing control characters. An unauthenticated attacker can send a crafted Authorization Basic header containing CR or LF bytes to inject forged log lines, breaking the one-request-per-line structure of access logs and enabling log forgery against downstream log consumers. The built-in combined, common, default, and short formats are affected, as well as any custom format that references :remote-user. Affected versions: morgan 1.2.0 through 1.10.1. Patches: upgrade to morgan 1.11.0, which neutralizes control characters in the :remote-user token output. Workarounds: use a custom format string that does not include :remote-user.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:morgan_project:morgan (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00332, EPSS Percentile is 0.26392 |
debian: CVE-2026-5078 was patched at 2026-09-16
2165.
Unknown Vulnerability Type - Pcre2 (CVE-2026-89161) - Low [178]
Description: {'nvd_cve_data_all': 'In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:pcre:pcre2 (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0011, EPSS Percentile is 0.01429 |
debian: CVE-2026-89161 was patched at 2026-09-16
2166.
Unknown Vulnerability Type - undici (CVE-2026-18149) - Low [178]
Description: {'nvd_cve_data_all': 'undici's retry handler can leave an already-exposed response body pending forever. When a server returns a successful response that declares a Content-Length, sends only part of the body, and closes the connection, the retry handler retries the request. If the retry returns a non-retryable status such as 400, the handler forwards that new response downstream and replaces its internal response stream, but the original response body that the application still holds is never ended or destroyed. As a result calls that read that body never settle, and the configured body timeout does not fire because its timer is tied to the connection parser rather than the orphaned body. An attacker-controlled server can trigger this with two short responses without keeping a connection open, and repeated requests accumulate pending promises and streams that can exhaust application concurrency or memory. This affects undici versions from 7.11.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'undici's retry handler can leave an already-exposed response body pending forever. When a server returns a successful response that declares a Content-Length, sends only part of the body, and closes the connection, the retry handler retries the request. If the retry returns a non-retryable status such as 400, the handler forwards that new response downstream and replaces its internal response stream, but the original response body that the application still holds is never ended or destroyed. As a result calls that read that body never settle, and the configured body timeout does not fire because its timer is tied to the connection parser rather than the orphaned body. An attacker-controlled server can trigger this with two short responses without keeping a connection open, and repeated requests accumulate pending promises and streams that can exhaust application concurrency or memory. This affects undici versions from 7.11.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:nodejs:undici (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00308, EPSS Percentile is 0.23637 |
debian: CVE-2026-18149 was patched at 2026-09-16
2167.
Unknown Vulnerability Type - undici (CVE-2026-85024) - Low [178]
Description: {'nvd_cve_data_all': 'undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, while that stream can still emit. When a remote peer sends a compressed payload that crosses the built-in 128 MiB decompressed-payload limit and then contains a malformed DEFLATE byte, the inflate stream emits a data error with no listener attached, which Node.js treats as a fatal unhandled error and terminates the entire process. Exploitation is remote and unauthenticated, requires no application mistake, and is asymmetric, since roughly 130 KB on the wire expands past the limit and crashes the process, and reconnecting can repeat the crash. This affects undici versions from 6.25.0 up to 6.28.1, from 7.28.0 up to 7.29.1, and from 8.1.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, while that stream can still emit. When a remote peer sends a compressed payload that crosses the built-in 128 MiB decompressed-payload limit and then contains a malformed DEFLATE byte, the inflate stream emits a data error with no listener attached, which Node.js treats as a fatal unhandled error and terminates the entire process. Exploitation is remote and unauthenticated, requires no application mistake, and is asymmetric, since roughly 130 KB on the wire expands past the limit and crashes the process, and reconnecting can repeat the crash. This affects undici versions from 6.25.0 up to 6.28.1, from 7.28.0 up to 7.29.1, and from 8.1.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:nodejs:undici (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.1732 |
debian: CVE-2026-85024 was patched at 2026-09-16
2168.
Unknown Vulnerability Type - Apache Tomcat (CVE-2026-73511) - Low [176]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy normally matches the raw request path, while servlet backends such as Apache Tomcat strip semicolon matrix parameters from each path segment before resolving the resource. Envoy's ignore_path_parameters_in_path_matching option instead truncates at the first semicolon and still does not match per-segment backend behavior. A remote client can use a parameterized protected segment, or a parameter on an earlier segment, to make Envoy select an unprotected fallback while the backend resolves the protected resource. The relevant scope boundary is that the bypass requires both a path-based Envoy decision and a backend that strips semicolon parameters per segment. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-73511 was patched at 2026-08-28, 2026-08-31
2169.
Unknown Vulnerability Type - Envoy (CVE-2026-73549) - Low [176]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's Utility::copyInternetAddressAndPort and QUIC client-address paths reconstruct scoped IPv6 addresses through addressAsString and Ipv6Instance. The string includes a percent scope identifier that inet_pton cannot parse, causing an exception or abort. Kernel-provided scoped IPv6 destinations in ORIGINAL_DST transparent-proxy deployments, and affected QUIC connection paths, can therefore terminate the process. The relevant scope boundary is that the HTTP use_http_header override rejects scoped addresses earlier; the advisory's crash path requires a kernel-provided original destination or the affected QUIC path. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-73549 was patched at 2026-08-28, 2026-08-31
2170.
Unknown Vulnerability Type - Envoy (CVE-2026-73551) - Low [176]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's URL normalization does not recognize dot and dotdot path segments when they carry semicolon parameters. A request such as /user/..;foo=bar/admin is therefore not canonicalized to /admin even when path normalization is enabled. If an upstream interprets the segment according to RFC 3986 while Envoy applies routing or RBAC to the uncollapsed path, a remote client can cause path confusion and bypass path-based security policy. The relevant scope boundary is that the security consequence depends on a downstream/upstream path interpretation mismatch or a path-based Envoy decision. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-73551 was patched at 2026-08-28, 2026-08-31
2171.
Denial of Service - Unknown Product (CVE-2026-79516) - Low [172]
Description: {'nvd_cve_data_all': 'An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted input.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted input.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00094, EPSS Percentile is 0.00692 |
debian: CVE-2026-79516 was patched at 2026-09-16
2172.
Denial of Service - Unknown Product (CVE-2026-88914) - Low [172]
Description: {'nvd_cve_data_all': 'A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes, which is then included in the downstream caption output. An attacker could exploit this by tricking a user into opening a malicious media file, potentially resulting in disclosure of adjacent heap memory or application crash.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes, which is then included in the downstream caption output. An attacker could exploit this by tricking a user into opening a malicious media file, potentially resulting in disclosure of adjacent heap memory or application crash.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.024 |
debian: CVE-2026-88914 was patched at 2026-09-16
2173.
Denial of Service - Unknown Product (CVE-2026-90994) - Low [172]
Description: {'nvd_cve_data_all': 'A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data(). A local client with access to the PAM responder's UNIX socket can exploit this by negotiating protocol v1 and sending an empty or truncated PAM request body. This can trigger an out-of-bounds read, potentially causing the PAM responder to terminate or restart, leading to a local denial of service.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data(). A local client with access to the PAM responder's UNIX socket can exploit this by negotiating protocol v1 and sending an empty or truncated PAM request body. This can trigger an out-of-bounds read, potentially causing the PAM responder to terminate or restart, leading to a local denial of service.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00118, EPSS Percentile is 0.01957 |
debian: CVE-2026-90994 was patched at 2026-09-16
2174.
Denial of Service - Unknown Product (CVE-2026-90996) - Low [172]
Description: {'nvd_cve_data_all': 'A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become unstable or terminate. This vulnerability affects the availability of the system responder.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become unstable or terminate. This vulnerability affects the availability of the system responder.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0011, EPSS Percentile is 0.01461 |
debian: CVE-2026-90996 was patched at 2026-09-16
2175.
Incorrect Calculation - Unknown Product (CVE-2026-90473) - Low [172]
Description: {'nvd_cve_data_all': 'msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000 that wraps when doubled, causing the parser cursor to desynchronize and attacker-controlled data to be returned in place of later fields.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000 that wraps when doubled, causing the parser cursor to desynchronize and attacker-controlled data to be returned in place of later fields.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0024, EPSS Percentile is 0.15315 |
debian: CVE-2026-90473 was patched at 2026-09-16
2176.
Memory Corruption - Unknown Product (CVE-2026-13732) - Low [172]
Description: {'nvd_cve_data_all': 'A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++ classes. The bug causes the destructor entries to remain in the main function list while the list length counter is decremented, resulting in an out-of-bounds write when the function list is copied to its final allocated array. An attacker can craft an ELF binary with malicious .stab and .stabstr sections that triggers this out-of-bounds write when a user opens the file in GDB and performs any symbol-inspection operation such as setting a breakpoint. The inferior process does not need to be executed. Under controlled conditions, this was demonstrated to achieve execution of arbitrary commands within the GDB process.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in GDB's STABS debug format parser. The\nread_member_functions() function in gdb/stabsread.c contains a linked\nlist removal bug in the code that separates destructor and non-destructor\nmember functions of C++ classes. The bug causes the destructor entries to\nremain in the main function list while the list length counter is\ndecremented, resulting in an out-of-bounds write when the function list\nis copied to its final allocated array. An attacker can craft an ELF\nbinary with malicious .stab and .stabstr sections that triggers this\nout-of-bounds write when a user opens the file in GDB and performs any\nsymbol-inspection operation such as setting a breakpoint. The inferior\nprocess does not need to be executed. Under controlled conditions, this\nwas demonstrated to achieve execution of arbitrary commands within the\nGDB process.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.01877 |
debian: CVE-2026-13732 was patched at 2026-09-16
2177.
Memory Corruption - Unknown Product (CVE-2026-82820) - Low [172]
Description: {'nvd_cve_data_all': 'A vulnerability was found in FLVMeta up to 1.2.2. Affected is the function amf_string_new of the file src/amf.c of the component AMF String Processing. The manipulation of the argument length results in heap-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as f412a33b9a84c2d1a9dee145a868feddbf64879e. A patch should be applied to remediate this issue. The project maintainer doubts the security impact: "While I acknowledged the bugs and provided fixes, I have yet to see any way to exploit these alleged vulnerabilities."', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A vulnerability was found in FLVMeta up to 1.2.2. Affected is the function amf_string_new of the file src/amf.c of the component AMF String Processing. The manipulation of the argument length results in heap-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as f412a33b9a84c2d1a9dee145a868feddbf64879e. A patch should be applied to remediate this issue. The project maintainer doubts the security impact: "While I acknowledged the bugs and provided fixes, I have yet to see any way to exploit these alleged vulnerabilities."', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00364, EPSS Percentile is 0.30009 |
debian: CVE-2026-82820 was patched at 2026-09-16
2178.
Memory Corruption - Unknown Product (CVE-2026-82821) - Low [172]
Description: {'nvd_cve_data_all': 'A vulnerability was determined in FLVMeta up to 1.2.2. Affected by this vulnerability is the function amf_object_get of the file src/amf.c of the component AMF Object Parsing. This manipulation causes null pointer dereference. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: 52642f7dfb76ec7334016622dde60b1ae963d79b. To fix this issue, it is recommended to deploy a patch. The project maintainer doubts the security impact: "While I acknowledged the bugs and provided fixes, I have yet to see any way to exploit these alleged vulnerabilities."', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A vulnerability was determined in FLVMeta up to 1.2.2. Affected by this vulnerability is the function amf_object_get of the file src/amf.c of the component AMF Object Parsing. This manipulation causes null pointer dereference. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: 52642f7dfb76ec7334016622dde60b1ae963d79b. To fix this issue, it is recommended to deploy a patch. The project maintainer doubts the security impact: "While I acknowledged the bugs and provided fixes, I have yet to see any way to exploit these alleged vulnerabilities."', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0033, EPSS Percentile is 0.26106 |
debian: CVE-2026-82821 was patched at 2026-09-16
2179.
Unknown Vulnerability Type - Bouncy Castle (CVE-2026-8149) - Low [171]
Description: {'nvd_cve_data_all': 'A vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on X86_64, AVX, AVX-512f, Linux, Legion of the Bouncy Castle Inc. BC-FJA bc-fips on Linux, X86_64, AVX, AVX-512f. This vulnerability is associated with program files gcm128w, gcm512w, gcm128w.C, gcm512w.C. This issue affects BC-LTS: from 2.73.0 before 2.73.11; BC-FJA: from 2.1.0 before 2.1.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on X86_64, AVX, AVX-512f, Linux, Legion of the Bouncy Castle Inc. BC-FJA bc-fips on Linux, X86_64, AVX, AVX-512f.\n\n This vulnerability is associated with program files gcm128w, gcm512w, gcm128w.C, gcm512w.C.\n\n\n\nThis issue affects BC-LTS: from 2.73.0 before 2.73.11; BC-FJA: from 2.1.0 before 2.1.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Bouncy Castle is a collection of APIs used in cryptography | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00158, EPSS Percentile is 0.05325 |
altlinux: CVE-2026-8149 was patched at 2026-09-12
2180.
Unknown Vulnerability Type - Libsoup (CVE-2026-77014) - Low [171]
Description: {'nvd_cve_data_all': 'A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | libsoup is an HTTP client/server library for GNOME. It uses GObjects and the glib main loop to integrate well with GNOME applications and also has a synchronous API for use in CLI tools. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00232, EPSS Percentile is 0.14271 |
debian: CVE-2026-77014 was patched at 2026-08-25
2181.
Unknown Vulnerability Type - MongoDB (CVE-2026-18698) - Low [171]
Description: {'nvd_cve_data_all': 'An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges. This could result in exposure of collection metadata and, on certain deployment configurations, unauthorized modification of system collection data.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges. This could result in exposure of collection metadata and, on certain deployment configurations, unauthorized modification of system collection data.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06402 |
altlinux: CVE-2026-18698 was patched at 2026-08-26
2182.
Unknown Vulnerability Type - MongoDB (CVE-2026-18709) - Low [171]
Description: {'nvd_cve_data_all': 'An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepared transaction, bypassing the intended transaction coordination process. This could result in cross-shard data inconsistency, cluster clock corruption, and violation of transaction atomicity guarantees.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepared transaction, bypassing the intended transaction coordination process. This could result in cross-shard data inconsistency, cluster clock corruption, and violation of transaction atomicity guarantees.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.6 | 10 | CVSS Base Score is 6.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00141, EPSS Percentile is 0.0381 |
altlinux: CVE-2026-18709 was patched at 2026-08-26
2183.
Unknown Vulnerability Type - MongoDB (CVE-2026-81524) - Low [171]
Description: {'nvd_cve_data_all': 'A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at a resource other than the one intended.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at a resource other than the one intended.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05165 |
debian: CVE-2026-81524 was patched at 2026-09-16
2184.
Unknown Vulnerability Type - MongoDB (CVE-2026-82060) - Low [171]
Description: {'nvd_cve_data_all': 'In MongoDB, insufficient validation of shard key values during document insertion allowed authenticated users to store documents with specially crafted, operator-shaped objects as shard key values in sharded collections. When change stream events for such documents were processed with the updateLookup full document mode, the crafted values were embedded into internal post-image lookup queries without proper sanitization, causing them to be interpreted as query operators rather than literal equality values. This could result in change stream consumers receiving incorrect post-image documents or encountering non-resumable fatal errors.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In MongoDB, insufficient validation of shard key values during document insertion allowed authenticated users to store documents with specially crafted, operator-shaped objects as shard key values in sharded collections. When change stream events for such documents were processed with the updateLookup full document mode, the crafted values were embedded into internal post-image lookup queries without proper sanitization, causing them to be interpreted as query operators rather than literal equality values. This could result in change stream consumers receiving incorrect post-image documents or encountering non-resumable fatal errors.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00236, EPSS Percentile is 0.14814 |
altlinux: CVE-2026-82060 was patched at 2026-09-09, 2026-09-10
2185.
Unknown Vulnerability Type - MongoDB (CVE-2026-84963) - Low [171]
Description: {'nvd_cve_data_all': 'An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing operation still reports success and returns no error. An unauthenticated party who can supply the input processed by an application that uses this component may cause that application to hold data that does not match what was submitted, which may result in unintended alteration of data.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing operation still reports success and returns no error. An unauthenticated party who can supply the input processed by an application that uses this component may cause that application to hold data that does not match what was submitted, which may result in unintended alteration of data.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00186, EPSS Percentile is 0.08395 |
debian: CVE-2026-84963 was patched at 2026-09-16
2186.
Unknown Vulnerability Type - Perl (CVE-2026-73638) - Low [171]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd.\n\ntiff_load_ifd() validates an IFD entry's data by checking that `entry->offset + entry->size` stays within the EXIF block, and never checks the start offset itself. Where that sum is not the real end of the data, the check passes with the entry starting outside the block.\n\nThrough 1.032 `entry->offset` is a plain int, so on the usual two's-complement implementations an offset with the high bit set converts to negative and the sum can land back inside the block. From 1.033 the field is a size_t and the addition wraps only where size_t is 32 bits. The IFD's own start offset is checked the same way and wraps where unsigned long is 32 bits, which includes 64-bit Windows.\n\nAny caller of Imager->read() on an attacker-supplied image may receive EXIF tags holding bytes from outside the block, or crash the process.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.6 | 10 | CVSS Base Score is 6.2. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-73638 was patched at 2026-08-26, 2026-08-27
debian: CVE-2026-73638 was patched at 2026-08-20
2187.
Unknown Vulnerability Type - ajv (CVE-2026-86472) - Low [171]
Description: {'nvd_cve_data_all': 'fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. In versions before 2.4.7, from 3.0.0 through 3.1.7, and from 4.0.0 through 4.1.4, fast-uri folds the host to lowercase before it percent-decodes the host, so a percent-encoded uppercase octet such as %41 decodes to a literal A that is never folded. For a scheme-relative reference such as //host there is no scheme, so the host canonicalization that would normally repair this does not run, and parse, normalize, and equal then disagree on the same host. An application that makes a case-sensitive host decision on fast-uri output, for example a host allowlist or denylist that compares the parsed host or uses equal, can be steered past the check with a percent-encoded uppercase octet, and because hostnames are case-insensitive in DNS and HTTP the evading spelling still reaches the host the check meant to gate. The issue is fixed in fast-uri 2.4.7, 3.1.8, and 4.1.5, and users should upgrade to one of those versions or later. As a workaround, compare hosts case-insensitively by lowercasing the parsed host before any allowlist or denylist decision.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. In versions before 2.4.7, from 3.0.0 through 3.1.7, and from 4.0.0 through 4.1.4, fast-uri folds the host to lowercase before it percent-decodes the host, so a percent-encoded uppercase octet such as %41 decodes to a literal A that is never folded. For a scheme-relative reference such as //host there is no scheme, so the host canonicalization that would normally repair this does not run, and parse, normalize, and equal then disagree on the same host. An application that makes a case-sensitive host decision on fast-uri output, for example a host allowlist or denylist that compares the parsed host or uses equal, can be steered past the check with a percent-encoded uppercase octet, and because hostnames are case-insensitive in DNS and HTTP the evading spelling still reaches the host the check meant to gate. The issue is fixed in fast-uri 2.4.7, 3.1.8, and 4.1.5, and users should upgrade to one of those versions or later. As a workaround, compare hosts case-insensitively by lowercasing the parsed host before any allowlist or denylist decision.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | ajv (Another JSON Schema Validator) is a high-performance JavaScript library for validating JSON data against JSON Schema specifications, widely used in Node.js applications and APIs. | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00161, EPSS Percentile is 0.05646 |
debian: CVE-2026-86472 was patched at 2026-09-16
2188.
Unknown Vulnerability Type - ajv (CVE-2026-86818) - Low [171]
Description: {'nvd_cve_data_all': 'fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parser in version 4.1.3. In versions 4.1.3 and 4.1.4, the mailto parser compares each query field name to the reserved names to, subject, and body while the name is still percent-encoded, and decodes it only when storing it as a generic header, so a percent-encoded spelling of a reserved field name is not recognized as that field at parse time but is re-emitted as the literal field name when the parsed URI is serialized. An application that validates, logs, or displays the recipient list from the first parse and then serializes the URI and sends it can silently gain an attacker-chosen recipient, and the subject and body fields can be smuggled across the same roundtrip. The issue is fixed in fast-uri 4.1.5, and users should upgrade to 4.1.5 or later. As a workaround, do not act on a mailto URI that fast-uri has re-serialized without first decoding and re-validating its recipient, subject, and body fields.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parser in version 4.1.3. In versions 4.1.3 and 4.1.4, the mailto parser compares each query field name to the reserved names to, subject, and body while the name is still percent-encoded, and decodes it only when storing it as a generic header, so a percent-encoded spelling of a reserved field name is not recognized as that field at parse time but is re-emitted as the literal field name when the parsed URI is serialized. An application that validates, logs, or displays the recipient list from the first parse and then serializes the URI and sends it can silently gain an attacker-chosen recipient, and the subject and body fields can be smuggled across the same roundtrip. The issue is fixed in fast-uri 4.1.5, and users should upgrade to 4.1.5 or later. As a workaround, do not act on a mailto URI that fast-uri has re-serialized without first decoding and re-validating its recipient, subject, and body fields.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | ajv (Another JSON Schema Validator) is a high-performance JavaScript library for validating JSON data against JSON Schema specifications, widely used in Node.js applications and APIs. | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00161, EPSS Percentile is 0.05646 |
debian: CVE-2026-86818 was patched at 2026-09-16
2189.
Unknown Vulnerability Type - Chromium (CVE-2026-84328) - Low [169]
Description: {'nvd_cve_data_all': 'Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00154, EPSS Percentile is 0.04913 |
altlinux: CVE-2026-84328 was patched at 2026-09-03
debian: CVE-2026-84328 was patched at 2026-09-03, 2026-09-16
2190.
Unknown Vulnerability Type - Chromium (CVE-2026-84331) - Low [169]
Description: {'nvd_cve_data_all': 'Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00154, EPSS Percentile is 0.04913 |
altlinux: CVE-2026-84331 was patched at 2026-09-03
debian: CVE-2026-84331 was patched at 2026-09-03, 2026-09-16
2191.
Unknown Vulnerability Type - Chromium (CVE-2026-84355) - Low [169]
Description: {'nvd_cve_data_all': 'Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00154, EPSS Percentile is 0.04913 |
altlinux: CVE-2026-84355 was patched at 2026-09-03
debian: CVE-2026-84355 was patched at 2026-09-03, 2026-09-16
2192.
Unknown Vulnerability Type - Chromium (CVE-2026-91708) - Low [169]
Description: {'nvd_cve_data_all': 'Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00151, EPSS Percentile is 0.04622 |
altlinux: CVE-2026-91708 was patched at 2026-09-17
debian: CVE-2026-91708 was patched at 2026-09-16
2193.
Unknown Vulnerability Type - JOSE (CVE-2026-53939) - Low [169]
Description: {'nvd_cve_data_all': 'OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A256CBC-HS512`) together with any key-management algorithm that generates a fresh content-encryption key (CEK), the CEK is all zero bytes instead of being randomly generated. The resulting JWE is therefore encrypted and authenticated under a fixed, publicly known key, so anyone who obtains the JWE can recover the plaintext and forge or modify the content. This is fixed in version 0.6.2.6 by `_cjose_jwe_set_cek_aes_cbc()` generating the CEK from `RAND_bytes`. A regression test asserts that the `encrypted_key` differs across two encryptions for each AES-CBC-HMAC variant. Until upgrading, for data encrypted with cjose, three options are available. Use an AES-GCM `enc` (`A128GCM` / `A192GCM` / `A256GCM`) instead of an AES-CBC-HMAC `enc`, use `alg=dir` with a caller-supplied CEK, or avoid using cjose for JWE encryption with the affected algorithm pair. These are mitigations for new ciphertexts only; data already encrypted under the zero key remains compromised and should be re-encrypted (and any secrets it contained rotated).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A256CBC-HS512`) together with any key-management algorithm that generates a fresh content-encryption key (CEK), the CEK is all zero bytes instead of being randomly generated. The resulting JWE is therefore encrypted and authenticated under a fixed, publicly known key, so anyone who obtains the JWE can recover the plaintext and forge or modify the content. This is fixed in version 0.6.2.6 by `_cjose_jwe_set_cek_aes_cbc()` generating the CEK from `RAND_bytes`. A regression test asserts that the `encrypted_key` differs across two encryptions for each AES-CBC-HMAC variant. Until upgrading, for data encrypted with cjose, three options are available. Use an AES-GCM `enc` (`A128GCM` / `A192GCM` / `A256GCM`) instead of an AES-CBC-HMAC `enc`, use `alg=dir` with a caller-supplied CEK, or avoid using cjose for JWE encryption with the affected algorithm pair. These are mitigations for new ciphertexts only; data already encrypted under the zero key remains compromised and should be re-encrypted (and any secrets it contained rotated).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.3 | 14 | JavaScript module for JSON Object Signing and Encryption (JOSE) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00196, EPSS Percentile is 0.09603 |
debian: CVE-2026-53939 was patched at 2026-09-15, 2026-09-16
2194.
Spoofing - Unknown Product (CVE-2026-63435) - Low [166]
Description: {'nvd_cve_data_all': 'Mail is an internet library for Ruby designed to handle email generation, parsing, and sending. Prior to 2.9.1, Mail::Utilities.q_value_decode and Mail::Utilities.b_value_decode used a single String#match and an overly greedy charset capture to decode only the first RFC 2047 encoded-word and mishandle surrounding or subsequent text. A crafted malformed encoded-word in an address display name or local part could cross ? delimiters and make decoded From, To, or Reply-To header values differ from the raw values inspected by a human reviewer or downstream parser, enabling apparent sender or recipient spoofing, phishing, or authorization-check bypass. This issue is fixed in version 2.9.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Mail is an internet library for Ruby designed to handle email generation, parsing, and sending. Prior to 2.9.1, Mail::Utilities.q_value_decode and Mail::Utilities.b_value_decode used a single String#match and an overly greedy charset capture to decode only the first RFC 2047 encoded-word and mishandle surrounding or subsequent text. A crafted malformed encoded-word in an address display name or local part could cross ? delimiters and make decoded From, To, or Reply-To header values differ from the raw values inspected by a human reviewer or downstream parser, enabling apparent sender or recipient spoofing, phishing, or authorization-check bypass. This issue is fixed in version 2.9.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00328, EPSS Percentile is 0.25942 |
debian: CVE-2026-63435 was patched at 2026-09-16
2195.
Unknown Vulnerability Type - FRRouting (CVE-2022-42917) - Low [166]
Description: {'nvd_cve_data_all': 'In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for example, symlinks to change the ownership of arbitrary files. This is a TOCTOU Race Condition caused by a combination of touch and chown.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for example, symlinks to change the ownership of arbitrary files. This is a TOCTOU Race Condition caused by a combination of touch and chown.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | FRRouting (FRR) is an IP routing protocol suite for Linux and Unix platforms, supporting BGP, OSPF, RIP, IS-IS, and other routing protocols for network infrastructure. | |
| 0.7 | 10 | CVSS Base Score is 6.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00131, EPSS Percentile is 0.03091 |
debian: CVE-2022-42917 was patched at 2026-09-16
2196.
Unknown Vulnerability Type - TLS (CVE-2026-75883) - Low [166]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf\n without checking the available space and without implementing outgoing \nPEAP fragmentation. Thus a pppd process connecting to a server which \nrequests PEAP authentication can be induced to corrupt global static \ndata following the outpacket_buf array, most likely causing incorrect behavior or a crash.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | TLS | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-75883 was patched at 2026-09-14, 2026-09-16
2197.
Unknown Vulnerability Type - nokogiri (CVE-2026-79772) - Low [166]
Description: {'nvd_cve_data_all': 'Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure instead of raising an exception. Attackers can exploit this to bypass signature validation in downstream SAML libraries by providing invalid canonicalized XML that is incorrectly accepted as valid.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure instead of raising an exception. Attackers can exploit this to bypass signature validation in downstream SAML libraries by providing invalid canonicalized XML that is incorrectly accepted as valid.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:nokogiri:nokogiri (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00246, EPSS Percentile is 0.16026 |
debian: CVE-2026-79772 was patched at 2026-09-16
2198.
Unknown Vulnerability Type - kin-openapi (CVE-2025-30153) - Low [162]
Description: {'nvd_cve_data_all': 'kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing the server to consume all available system memory. The root cause comes from the ZipFileBodyDecoder, which is registered automatically by the module (contrary to what the documentation says). This vulnerability is fixed in 0.131.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing the server to consume all available system memory. The root cause comes from the ZipFileBodyDecoder, which is registered automatically by the module (contrary to what the documentation says). This vulnerability is fixed in 0.131.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.12 | 14 | kin-openapi is a Go library for parsing, converting, validating, and working with OpenAPI and Swagger specifications and for validating HTTP requests and responses against OpenAPI schemas. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00518, EPSS Percentile is 0.42796 |
debian: CVE-2025-30153 was patched at 2026-08-20
2199.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63820) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: f2fs: fix missing read bio submission on large folio error f2fs_read_data_large_folio() can keep a read bio across multiple readahead folios. If a later folio hits an error before any of its blocks are added to the bio, folio_in_bio is false and the current error path returns immediately after ending that folio. This can leave the bio accumulated for earlier folios unsubmitted. Those folios then never receive read completion, and readers can wait indefinitely on the locked folios. Route errors through the common out path so any pending bio is submitted before returning. Stop consuming more readahead folios once an error is seen, and only wait on and clear the current folio when it was actually added to the bio.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix missing read bio submission on large folio error\n\nf2fs_read_data_large_folio() can keep a read bio across multiple\nreadahead folios. If a later folio hits an error before any of its\nblocks are added to the bio, folio_in_bio is false and the current error\npath returns immediately after ending that folio.\n\nThis can leave the bio accumulated for earlier folios unsubmitted. Those\nfolios then never receive read completion, and readers can wait\nindefinitely on the locked folios.\n\nRoute errors through the common out path so any pending bio is submitted\nbefore returning. Stop consuming more readahead folios once an error is\nseen, and only wait on and clear the current folio when it was actually\nadded to the bio.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00198, EPSS Percentile is 0.09779 |
ubuntu: CVE-2026-63820 was patched at 2026-09-07, 2026-09-16
2200.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63873) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix mm_struct reference leak in aie2_populate_range() aie2_populate_range() jumps back to the again label without calling mmput(mm), leaking a reference to the mm_struct. Add the missing mmput() before jumping to again.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\naccel/amdxdna: Fix mm_struct reference leak in aie2_populate_range()\n\naie2_populate_range() jumps back to the again label without calling\nmmput(mm), leaking a reference to the mm_struct.\n\nAdd the missing mmput() before jumping to again.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00206, EPSS Percentile is 0.10961 |
ubuntu: CVE-2026-63873 was patched at 2026-09-07, 2026-09-16
2201.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64464) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xhci: sideband: fix ring sg table pages leak xhci_ring_to_sgtable() allocates a temporary pages array and uses it to build the returned sg_table with sg_alloc_table_from_pages(). The error paths free the pages array, but the success path returns the sg_table without freeing it. This leaks the temporary array every time a sideband client gets an endpoint or event ring buffer. Free the pages array after sg_alloc_table_from_pages() succeeds. The returned sg_table has its own scatterlist entries and does not depend on the temporary array after construction.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxhci: sideband: fix ring sg table pages leak\n\nxhci_ring_to_sgtable() allocates a temporary pages array and\nuses it to build the returned sg_table with\nsg_alloc_table_from_pages().\n\nThe error paths free the pages array, but the success path\nreturns the sg_table without freeing it. This leaks the temporary\narray every time a sideband client gets an endpoint or event ring\nbuffer.\n\nFree the pages array after sg_alloc_table_from_pages() succeeds.\nThe returned sg_table has its own scatterlist entries and does not\ndepend on the temporary array after construction.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.07054 |
ubuntu: CVE-2026-64464 was patched at 2026-09-07, 2026-09-16
2202.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64491) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: usx2y: us144mkii: fix work UAF on disconnect tascam_disconnect() cancels capture_work and midi_in_work before usb_kill_anchored_urbs() kills the capture/MIDI-in URBs. Those URBs self-resubmit, and their completion handlers reschedule the work. A URB that completes in the small window between cancel_work_sync() and usb_kill_anchored_urbs() therefore re-arms the work after its only cancel. Nothing cancels it again before snd_card_free() frees the card-private tascam structure, so the work handler then runs on freed memory. Kill the anchored URBs before cancelling the work; once the work is cancelled no remaining URB can complete to re-arm it.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usx2y: us144mkii: fix work UAF on disconnect\n\ntascam_disconnect() cancels capture_work and midi_in_work before\nusb_kill_anchored_urbs() kills the capture/MIDI-in URBs. Those URBs\nself-resubmit, and their completion handlers reschedule the work.\n\nA URB that completes in the small window between cancel_work_sync() and\nusb_kill_anchored_urbs() therefore re-arms the work after its only\ncancel. Nothing cancels it again before snd_card_free() frees the\ncard-private tascam structure, so the work handler then runs on freed\nmemory.\n\nKill the anchored URBs before cancelling the work; once the work is\ncancelled no remaining URB can complete to re-arm it.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00174, EPSS Percentile is 0.07131 |
ubuntu: CVE-2026-64491 was patched at 2026-09-07, 2026-09-16
2203.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64492) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: iio: temperature: tmp006: use devm_iio_trigger_register tmp006_probe() allocates the DRDY trigger with devm_iio_trigger_alloc() but registers it with plain iio_trigger_register(). The driver has no .remove() callback, so on module unload the trigger stays in the global trigger list while its memory is freed by devm, leaving a dangling entry. Switch to devm_iio_trigger_register() so the registration is undone in the same devm scope as the allocation.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\niio: temperature: tmp006: use devm_iio_trigger_register\n\ntmp006_probe() allocates the DRDY trigger with devm_iio_trigger_alloc()\nbut registers it with plain iio_trigger_register(). The driver has no\n.remove() callback, so on module unload the trigger stays in the global\ntrigger list while its memory is freed by devm, leaving a dangling\nentry.\n\nSwitch to devm_iio_trigger_register() so the registration is undone in\nthe same devm scope as the allocation.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.07052 |
ubuntu: CVE-2026-64492 was patched at 2026-09-07, 2026-09-16
2204.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64591) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid WARNING in sva unbind path The Intel IOMMU driver allows SVA on devices even if they do not support PCI/PRI. Commit 39c20c4e83b9 ("iommu/vt-d: Only handle IOPF for SVA when PRI is supported") modified the SVA bind path to allow this configuration by skipping IOPF enablement when PRI is missing. However, it failed to update the unbind path. This creates an imbalance: the unbind path attempts to disable IOPF for a device that never had it enabled, triggering a WARNING in intel_iommu_disable_iopf(): WARNING: drivers/iommu/intel/iommu.c:3475 at intel_iommu_disable_iopf+0x4f/0x90d Call Trace: <TASK> blocking_domain_set_dev_pasid+0x50/0x70 iommu_detach_device_pasid+0x89/0xc0 iommu_sva_unbind_device+0x73/0x150 xe_vm_close_and_put+0x4d2/0x1200 [xe] Fix this by bypassing IOPF operations for SVA domains on non-PRI hardware in both the bind and unbind paths.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Avoid WARNING in sva unbind path\n\nThe Intel IOMMU driver allows SVA on devices even if they do not support\nPCI/PRI. Commit 39c20c4e83b9 ("iommu/vt-d: Only handle IOPF for SVA when\nPRI is supported") modified the SVA bind path to allow this configuration\nby skipping IOPF enablement when PRI is missing. However, it failed to\nupdate the unbind path.\n\nThis creates an imbalance: the unbind path attempts to disable IOPF for\na device that never had it enabled, triggering a WARNING in\nintel_iommu_disable_iopf():\n\n WARNING: drivers/iommu/intel/iommu.c:3475 at intel_iommu_disable_iopf+0x4f/0x90d\n Call Trace:\n <TASK>\n blocking_domain_set_dev_pasid+0x50/0x70\n iommu_detach_device_pasid+0x89/0xc0\n iommu_sva_unbind_device+0x73/0x150\n xe_vm_close_and_put+0x4d2/0x1200 [xe]\n\nFix this by bypassing IOPF operations for SVA domains on non-PRI hardware\nin both the bind and unbind paths.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.0602 |
ubuntu: CVE-2026-64591 was patched at 2026-09-07, 2026-09-16
2205.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-68087) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: HID: wacom: use GFP_ATOMIC in wacom_wac_queue_flush() wacom_wac_queue_flush() is called via the .raw_event callback (wacom_raw_event → wacom_wac_pen_serial_enforce → wacom_wac_queue_flush). For USB HID devices, this callback is invoked from hid_irq_in(), which is a URB completion handler running in atomic context. Using GFP_KERNEL in this path can sleep, leading to a "scheduling while atomic" bug. Use GFP_ATOMIC instead. The existing code already handles allocation failure by skipping the fifo entry and continuing.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nHID: wacom: use GFP_ATOMIC in wacom_wac_queue_flush()\n\nwacom_wac_queue_flush() is called via the .raw_event callback\n(wacom_raw_event → wacom_wac_pen_serial_enforce → wacom_wac_queue_flush).\nFor USB HID devices, this callback is invoked from hid_irq_in(), which\nis a URB completion handler running in atomic context. Using GFP_KERNEL\nin this path can sleep, leading to a "scheduling while atomic" bug.\n\nUse GFP_ATOMIC instead. The existing code already handles allocation\nfailure by skipping the fifo entry and continuing.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06244 |
ubuntu: CVE-2026-68087 was patched at 2026-09-07, 2026-09-16
2206.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-68089) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: iio: core: fix uninitialized data in debugfs If *ppos is non-zero then simple_write_to_buffer() will not initialize the start of buf[]. Non zero values for *ppos aren't going to work anyway. Test for them at the start of the function and return -EINVAL.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\niio: core: fix uninitialized data in debugfs\n\nIf *ppos is non-zero then simple_write_to_buffer() will not initialize\nthe start of buf[]. Non zero values for *ppos aren't going to work\nanyway. Test for them at the start of the function and return -EINVAL.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06248 |
ubuntu: CVE-2026-68089 was patched at 2026-09-07, 2026-09-16
2207.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-72333) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix tx ident leak for commands without a response Commit 6c3ea155e5ee ("Bluetooth: L2CAP: Fix not tracking outstanding TX ident") changed ident allocation to use an IDA, releasing idents in l2cap_put_ident() when the matching response command is received. But identifiers allocated for commands that have no response defined are never released. In particular L2CAP_LE_CREDITS is sent repeatedly for the lifetime of an LE CoC channel, so a peer streaming data to the host exhausts the 1-255 ident range after 254 credit packets. From then on l2cap_get_ident() fails: kernel: Bluetooth: Unable to allocate ident: -28 and every subsequent L2CAP_LE_CREDITS packet is sent with ident 0, which is invalid (Core Spec, Vol 3, Part A, Section 4: "Signaling identifier 0x00 is an invalid identifier and shall never be used in any command"). Remote stacks that validate the ident drop these commands, never receive new credits, and the channel stalls permanently. With default socket buffers this happens after roughly 0.5 MB of received data (the exact amount depends on the socket receive buffer): < ACL Data TX: Handle 2048 flags 0x00 dlen 12 LE L2CAP: LE Flow Control Credit (0x16) ident 0 len 4 Source CID: 64 Credits: 1 Release the ident immediately after sending L2CAP_LE_CREDITS since no response will ever release it. Use a local variable instead of chan->ident so that an ident that an EXT_FLOWCTL channel may be waiting on (e.g. a pending reconfigure) is not overwritten by a credit packet. Also add the missing L2CAP_LE_CONN_RSP case to l2cap_put_ident() so idents allocated for outgoing L2CAP_LE_CONN_REQ commands are released when the response arrives.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: fix tx ident leak for commands without a response\n\nCommit 6c3ea155e5ee ("Bluetooth: L2CAP: Fix not tracking outstanding\nTX ident") changed ident allocation to use an IDA, releasing idents in\nl2cap_put_ident() when the matching response command is received.\n\nBut identifiers allocated for commands that have no response defined\nare never released. In particular L2CAP_LE_CREDITS is sent repeatedly for\nthe lifetime of an LE CoC channel, so a peer streaming data to the\nhost exhausts the 1-255 ident range after 254 credit packets. From\nthen on l2cap_get_ident() fails:\n\n kernel: Bluetooth: Unable to allocate ident: -28\n\nand every subsequent L2CAP_LE_CREDITS packet is sent with ident 0,\nwhich is invalid (Core Spec, Vol 3, Part A, Section 4: "Signaling\nidentifier 0x00 is an invalid identifier and shall never be used in\nany command"). Remote stacks that validate the ident drop these\ncommands, never receive new credits, and the channel stalls\npermanently. With default socket buffers this happens after roughly 0.5 MB\nof received data (the exact amount depends on the socket receive buffer):\n\n < ACL Data TX: Handle 2048 flags 0x00 dlen 12\n LE L2CAP: LE Flow Control Credit (0x16) ident 0 len 4\n Source CID: 64\n Credits: 1\n\nRelease the ident immediately after sending L2CAP_LE_CREDITS since no\nresponse will ever release it. Use a local variable instead of\nchan->ident so that an ident that an EXT_FLOWCTL channel may be waiting on\n(e.g. a pending reconfigure) is not overwritten by a credit packet.\n\nAlso add the missing L2CAP_LE_CONN_RSP case to l2cap_put_ident() so\nidents allocated for outgoing L2CAP_LE_CONN_REQ commands are released\nwhen the response arrives.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00209, EPSS Percentile is 0.11264 |
oraclelinux: CVE-2026-72333 was patched at 2026-09-04
2208.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74486) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: use exe_file_deny_write_access() for the interpreter clone For MISC_FMT_OPEN_FILE entries load_misc_binary() clones the registered interpreter file and denies write access to the clone via plain deny_write_access(). The clone is installed as bprm->interpreter and later released by the exec machinery through exe_file_allow_write_access() which skips the i_writecount increment for files with FMODE_FSNOTIFY_HSM set. The deny and allow side can therefore come to different conclusions when pre-content watches are in play: if a pre-content watch is added to the interpreter after registration every subsequent exec through that entry takes a write denial on the clone that is never paired with a write allowance, driving the interpreter inode's i_writecount further down with each exec and leaving the interpreter unwritable even after the entry and all its users are gone. Take the write denial via exe_file_deny_write_access() so both sides of the pairing base their decision on the same file mode, and propagate failure instead of silently ignoring it: an interpreter that is concurrently open for writing now fails the exec with ETXTBSY, exactly like an interpreter freshly opened via open_exec() would.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_misc: use exe_file_deny_write_access() for the interpreter clone\n\nFor MISC_FMT_OPEN_FILE entries load_misc_binary() clones the\nregistered interpreter file and denies write access to the clone via\nplain deny_write_access(). The clone is installed as\nbprm->interpreter and later released by the exec machinery through\nexe_file_allow_write_access() which skips the i_writecount increment\nfor files with FMODE_FSNOTIFY_HSM set.\n\nThe deny and allow side can therefore come to different conclusions\nwhen pre-content watches are in play: if a pre-content watch is added\nto the interpreter after registration every subsequent exec through\nthat entry takes a write denial on the clone that is never paired\nwith a write allowance, driving the interpreter inode's i_writecount\nfurther down with each exec and leaving the interpreter unwritable\neven after the entry and all its users are gone.\n\nTake the write denial via exe_file_deny_write_access() so both sides\nof the pairing base their decision on the same file mode, and\npropagate failure instead of silently ignoring it: an interpreter\nthat is concurrently open for writing now fails the exec with\nETXTBSY, exactly like an interpreter freshly opened via open_exec()\nwould.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07456 |
oraclelinux: CVE-2026-74486 was patched at 2026-09-04
2209.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74585) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Bound the DROM dual link port number before indexing sw->ports tb_drom_parse_entry_port() validates the device-supplied header->index against sw->config.max_port_number before indexing sw->ports[], but the sibling field entry->dual_link_port_nr -- a 6-bit value also read from the DROM -- indexes the same array with no such check. A malicious or malformed Thunderbolt device can set dual_link_port_nr beyond the allocated sw->ports[] (max_port_number + 1 entries), producing an out-of-bounds tb_port pointer that is stored and later dereferenced. Reject a port entry whose dual_link_port_nr exceeds max_port_number, the same bound already applied to header->index.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: Bound the DROM dual link port number before indexing sw->ports\n\ntb_drom_parse_entry_port() validates the device-supplied header->index\nagainst sw->config.max_port_number before indexing sw->ports[], but the\nsibling field entry->dual_link_port_nr -- a 6-bit value also read from\nthe DROM -- indexes the same array with no such check. A malicious or\nmalformed Thunderbolt device can set dual_link_port_nr beyond the\nallocated sw->ports[] (max_port_number + 1 entries), producing an\nout-of-bounds tb_port pointer that is stored and later dereferenced.\n\nReject a port entry whose dual_link_port_nr exceeds max_port_number,\nthe same bound already applied to header->index.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07465 |
debian: CVE-2026-74585 was patched at 2026-08-25
oraclelinux: CVE-2026-74585 was patched at 2026-09-04
2210.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74600) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm/page_table_check: skip special zero mappings page_table_check_set() and page_table_check_clear() account mappings based on PageAnon(). Shared zero-page PTEs and huge zero PMDs are special mappings, but page_table_check can still account them as file-backed pages. An unprivileged process can populate enough zero mappings to overflow file_map_count and hit the existing BUG_ON(). The PTE path can do this with the shared zero page, and the PMD path can do the same with huge zero mappings. Skip special zero mappings in the user page-table accounting paths. Keep the PTE-side pte_special() check, and identify huge zero PMDs from the mapped folio instead of pmd_special(). That covers architectures where pmd_special() is a no-op without adding huge_zero_pfn checks to the generic counter helpers.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/page_table_check: skip special zero mappings\n\npage_table_check_set() and page_table_check_clear() account mappings based\non PageAnon(). Shared zero-page PTEs and huge zero PMDs are special\nmappings, but page_table_check can still account them as file-backed\npages.\n\nAn unprivileged process can populate enough zero mappings to overflow\nfile_map_count and hit the existing BUG_ON(). The PTE path can do this\nwith the shared zero page, and the PMD path can do the same with huge zero\nmappings.\n\nSkip special zero mappings in the user page-table accounting paths. Keep\nthe PTE-side pte_special() check, and identify huge zero PMDs from the\nmapped folio instead of pmd_special(). That covers architectures where\npmd_special() is a no-op without adding huge_zero_pfn checks to the\ngeneric counter helpers.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06243 |
debian: CVE-2026-74600 was patched at 2026-08-25
2211.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74602) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer() In rb_allocate_cpu_buffer(), bpage->order was omitted, leaving it as 0. This is an issue for a ring-buffer with subbufs bigger than PAGE_SIZE if when freed: free_buffer_page() relies on this value. Align the value with the actual allocation size (buffer::subbuf_order).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Initialise reader page order in rb_allocate_cpu_buffer()\n\nIn rb_allocate_cpu_buffer(), bpage->order was omitted, leaving it as 0.\nThis is an issue for a ring-buffer with subbufs bigger than PAGE_SIZE if\nwhen freed: free_buffer_page() relies on this value. Align the value\nwith the actual allocation size (buffer::subbuf_order).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06444 |
debian: CVE-2026-74602 was patched at 2026-08-25
2212.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74618) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: don't warn when the mount is completed from another user namespace fsopen() records the caller's user namespace in fc->user_ns and hands back an ordinary file descriptor. Nothing ties the task that calls fsconfig(FSCONFIG_CMD_CREATE) to the task that created the context. The fd is inherited across fork() and exec() and it can be passed over a unix socket. Completing a context from another user namespace is allowed on purpose. vfs_cmd_create() authorizes the create with mount_capable(), which for FS_USERNS_MOUNT checks ns_capable(fc->user_ns, CAP_SYS_ADMIN), and that succeeds for a task holding CAP_SYS_ADMIN in an ancestor of fc->user_ns. So an unprivileged task can reach the WARN_ON() in bm_fill_super(): create a user and a mount namespace in a child, call fsopen("binfmt_misc") there, send the fscontext fd to the parent and let the parent issue FSCONFIG_CMD_CREATE. Both namespaces come from a plain unshare(1) and no capability is needed anywhere: WARNING: fs/binfmt_misc.c:938 at bm_fill_super+0xa2/0xc0 [binfmt_misc] CPU: 15 UID: 1000 PID: 3243382 Comm: fswarn Call Trace: get_tree_keyed+0x7d/0xb0 bm_get_tree+0x34/0x90 [binfmt_misc] vfs_get_tree+0x2a/0x100 vfs_cmd_create+0x60/0xf0 __do_sys_fsconfig+0x4b2/0x500 The child needs the mount namespace because fsopen() itself gates on may_mount(), which asks for CAP_SYS_ADMIN in the user namespace owning the caller's mount namespace. fsconfig() doesn't repeat that check. It is a WARN_ON() and not a WARN_ON_ONCE(), so the condition can be raised in a loop to taint the kernel and flood the log, and it panics a kernel booted with panic_on_warn. Keep refusing the mount and stop warning about it. Nothing in bm_fill_super() depends on the two namespaces matching, it derives everything from sb->s_user_ns.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_misc: don't warn when the mount is completed from another user namespace\n\nfsopen() records the caller's user namespace in fc->user_ns and hands\nback an ordinary file descriptor. Nothing ties the task that calls\nfsconfig(FSCONFIG_CMD_CREATE) to the task that created the context. The\nfd is inherited across fork() and exec() and it can be passed over a\nunix socket.\n\nCompleting a context from another user namespace is allowed on purpose.\nvfs_cmd_create() authorizes the create with mount_capable(), which for\nFS_USERNS_MOUNT checks ns_capable(fc->user_ns, CAP_SYS_ADMIN), and that\nsucceeds for a task holding CAP_SYS_ADMIN in an ancestor of fc->user_ns.\nSo an unprivileged task can reach the WARN_ON() in bm_fill_super():\ncreate a user and a mount namespace in a child, call\nfsopen("binfmt_misc") there, send the fscontext fd to the parent and let\nthe parent issue FSCONFIG_CMD_CREATE. Both namespaces come from a plain\nunshare(1) and no capability is needed anywhere:\n\n WARNING: fs/binfmt_misc.c:938 at bm_fill_super+0xa2/0xc0 [binfmt_misc]\n CPU: 15 UID: 1000 PID: 3243382 Comm: fswarn\n Call Trace:\n get_tree_keyed+0x7d/0xb0\n bm_get_tree+0x34/0x90 [binfmt_misc]\n vfs_get_tree+0x2a/0x100\n vfs_cmd_create+0x60/0xf0\n __do_sys_fsconfig+0x4b2/0x500\n\nThe child needs the mount namespace because fsopen() itself gates on\nmay_mount(), which asks for CAP_SYS_ADMIN in the user namespace owning\nthe caller's mount namespace. fsconfig() doesn't repeat that check.\n\nIt is a WARN_ON() and not a WARN_ON_ONCE(), so the condition can be\nraised in a loop to taint the kernel and flood the log, and it panics a\nkernel booted with panic_on_warn.\n\nKeep refusing the mount and stop warning about it. Nothing in\nbm_fill_super() depends on the two namespaces matching, it derives\neverything from sb->s_user_ns.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06438 |
debian: CVE-2026-74618 was patched at 2026-08-25
oraclelinux: CVE-2026-74618 was patched at 2026-09-04
2213.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74619) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ovl: don't warn when the mount is completed from another user namespace fsopen() records the caller's user namespace in fc->user_ns and hands back an ordinary file descriptor. Nothing ties the task that calls fsconfig(FSCONFIG_CMD_CREATE) to the task that created the context. The fd is inherited across fork() and exec() and it can be passed over a unix socket. Completing a context from another user namespace is allowed on purpose. vfs_cmd_create() authorizes the create with mount_capable(), which for FS_USERNS_MOUNT checks ns_capable(fc->user_ns, CAP_SYS_ADMIN), and that succeeds for a task holding CAP_SYS_ADMIN in an ancestor of fc->user_ns. So an unprivileged task can reach the WARN_ON() in ovl_fill_super(): create a user and a mount namespace in a child, call fsopen("overlay") there, send the fscontext fd to the parent and let the parent issue FSCONFIG_CMD_CREATE. Both namespaces come from a plain unshare(1) and no capability is needed anywhere: WARNING: fs/overlayfs/super.c:1551 at ovl_fill_super+0x7b9/0x1e20 [overlay] CPU: 3 UID: 1000 PID: 3243376 Comm: fswarn Call Trace: get_tree_nodev+0x71/0xa0 ovl_get_tree+0x15/0x20 [overlay] vfs_get_tree+0x2a/0x100 vfs_cmd_create+0x60/0xf0 __do_sys_fsconfig+0x4b2/0x500 The child needs the mount namespace because fsopen() itself gates on may_mount(), which asks for CAP_SYS_ADMIN in the user namespace owning the caller's mount namespace. fsconfig() doesn't repeat that check. It is a WARN_ON() and not a WARN_ON_ONCE(), so the condition can be raised in a loop to taint the kernel and flood the log, and it panics a kernel booted with panic_on_warn. Keep refusing the mount and stop warning about it. ovl_parse_param() already spells a user namespace check this way for Opt_override_creds.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\novl: don't warn when the mount is completed from another user namespace\n\nfsopen() records the caller's user namespace in fc->user_ns and hands\nback an ordinary file descriptor. Nothing ties the task that calls\nfsconfig(FSCONFIG_CMD_CREATE) to the task that created the context. The\nfd is inherited across fork() and exec() and it can be passed over a\nunix socket.\n\nCompleting a context from another user namespace is allowed on purpose.\nvfs_cmd_create() authorizes the create with mount_capable(), which for\nFS_USERNS_MOUNT checks ns_capable(fc->user_ns, CAP_SYS_ADMIN), and that\nsucceeds for a task holding CAP_SYS_ADMIN in an ancestor of fc->user_ns.\nSo an unprivileged task can reach the WARN_ON() in ovl_fill_super():\ncreate a user and a mount namespace in a child, call fsopen("overlay")\nthere, send the fscontext fd to the parent and let the parent issue\nFSCONFIG_CMD_CREATE. Both namespaces come from a plain unshare(1) and no\ncapability is needed anywhere:\n\n WARNING: fs/overlayfs/super.c:1551 at ovl_fill_super+0x7b9/0x1e20 [overlay]\n CPU: 3 UID: 1000 PID: 3243376 Comm: fswarn\n Call Trace:\n get_tree_nodev+0x71/0xa0\n ovl_get_tree+0x15/0x20 [overlay]\n vfs_get_tree+0x2a/0x100\n vfs_cmd_create+0x60/0xf0\n __do_sys_fsconfig+0x4b2/0x500\n\nThe child needs the mount namespace because fsopen() itself gates on\nmay_mount(), which asks for CAP_SYS_ADMIN in the user namespace owning\nthe caller's mount namespace. fsconfig() doesn't repeat that check.\n\nIt is a WARN_ON() and not a WARN_ON_ONCE(), so the condition can be\nraised in a loop to taint the kernel and flood the log, and it panics a\nkernel booted with panic_on_warn.\n\nKeep refusing the mount and stop warning about it. ovl_parse_param()\nalready spells a user namespace check this way for Opt_override_creds.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06445 |
debian: CVE-2026-74619 was patched at 2026-08-25
oraclelinux: CVE-2026-74619 was patched at 2026-09-04
2214.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74620) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/sched: act_gact, act_police: range check the fallback control action tcf_action_check_ctrlact() range checks the primary control action: \tif (!opcode) \t\tret = action > TC_ACT_VALUE_MAX ? -EINVAL : 0; TC_ACT_VALUE_MAX is TC_ACT_TRAP, so kernel-internal verdicts above it cannot be set that way. But act_gact and act_police each carry a second, independent control action supplied by user space that never reaches that helper - TCA_GACT_PROB.paction and TCA_POLICE_RESULT. Both only reject TC_ACT_GOTO_CHAIN, so any other value is stored verbatim and returned verbatim from the action. In particular user space can store TC_ACT_CONSUMED, which is TC_ACT_VALUE_MAX + 1 and is deliberately not part of the UAPI value range. That verdict tells every caller the action took ownership of the skb, so nobody frees it: sch_handle_ingress(), sch_handle_egress() and tcf_qevent_handle() all deliberately skip the free for it. The result is one leaked sk_buff plus its data buffer per packet traversing the filter, unbounded, for all traffic on the chain including kernel-generated packets. Both are trivially deterministic. act_gact clamps tcfg_pval to >= 1, so with pval = 1 gact_determ() returns the fallback for every packet. act_police has no mandatory rate, so rate = 0 leaves tcfp_mtu = ~0 and tcf_police_mtu_check() always passes. TC_ACT_CONSUMED was added by commit 720f22fed81b ("net: sched: refactor reinsert action"), after both goto-chain guards were written: commit 9469f375ab09 ("net/sched: act_gact: disallow 'goto chain' on fallback control action") and commit c08f5ed5d625 ("net/sched: act_police: disallow 'goto chain' on fallback control action"). Neither guard was widened when the new verdict appeared. Factor the existing range test out of tcf_action_check_ctrlact() as tcf_action_valid() and apply it to both fallbacks. The helper cannot call tcf_action_check_ctrlact() directly because that also allocates a goto_chain, which is exactly what these two sites must not do. Reproduced on v7.2-rc6: kmemleak reports one leaked 232-byte skbuff_head_cache object plus its 704-byte data buffer per packet. With this patch both configurations are rejected with -EINVAL and kmemleak reports none.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_gact, act_police: range check the fallback control action\n\ntcf_action_check_ctrlact() range checks the primary control action:\n\n\tif (!opcode)\n\t\tret = action > TC_ACT_VALUE_MAX ? -EINVAL : 0;\n\nTC_ACT_VALUE_MAX is TC_ACT_TRAP, so kernel-internal verdicts above it\ncannot be set that way. But act_gact and act_police each carry a second,\nindependent control action supplied by user space that never reaches that\nhelper - TCA_GACT_PROB.paction and TCA_POLICE_RESULT. Both only reject\nTC_ACT_GOTO_CHAIN, so any other value is stored verbatim and returned\nverbatim from the action.\n\nIn particular user space can store TC_ACT_CONSUMED, which is\nTC_ACT_VALUE_MAX + 1 and is deliberately not part of the UAPI value\nrange. That verdict tells every caller the action took ownership of the\nskb, so nobody frees it: sch_handle_ingress(), sch_handle_egress() and\ntcf_qevent_handle() all deliberately skip the free for it. The result is\none leaked sk_buff plus its data buffer per packet traversing the filter,\nunbounded, for all traffic on the chain including kernel-generated\npackets.\n\nBoth are trivially deterministic. act_gact clamps tcfg_pval to >= 1, so\nwith pval = 1 gact_determ() returns the fallback for every packet.\nact_police has no mandatory rate, so rate = 0 leaves tcfp_mtu = ~0 and\ntcf_police_mtu_check() always passes.\n\nTC_ACT_CONSUMED was added by commit 720f22fed81b ("net: sched: refactor\nreinsert action"), after both goto-chain guards were written:\ncommit 9469f375ab09 ("net/sched: act_gact: disallow 'goto chain' on\nfallback control action") and\ncommit c08f5ed5d625 ("net/sched: act_police: disallow 'goto chain' on\nfallback control action"). Neither guard was widened when the new\nverdict appeared.\n\nFactor the existing range test out of tcf_action_check_ctrlact() as\ntcf_action_valid() and apply it to both fallbacks. The helper cannot call\ntcf_action_check_ctrlact() directly because that also allocates a\ngoto_chain, which is exactly what these two sites must not do.\n\nReproduced on v7.2-rc6: kmemleak reports one leaked 232-byte\nskbuff_head_cache object plus its 704-byte data buffer per packet. With\nthis patch both configurations are rejected with -EINVAL and kmemleak\nreports none.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07462 |
debian: CVE-2026-74620 was patched at 2026-08-25
oraclelinux: CVE-2026-74620 was patched at 2026-09-04
2215.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74622) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: atlantic: free RX pages of consumed but not refilled buffers aq_ring_rx_deinit() only walks [sw_head, sw_tail), the region posted to hardware. Since the page reuse strategy was added, a cleaned RX buffer keeps its page (and its DMA mapping) in the ring for reuse, and refill is batched: aq_ring_rx_fill() returns early until AQ_CFG_RX_REFILL_THRES slots are free. Slots that were consumed but not yet reposted therefore sit in the complementary [sw_tail, sw_head) gap with a live page, and the deinit walk never visits them: up to a refill batch worth of pages and DMA mappings leak on every interface down. Walk the whole ring instead and release whatever is still there. Also bail out if the buffer ring is already gone: a partial aq_ptp_ring_alloc() failure frees the ring but leaves aq_nic set, so aq_ptp_ring_deinit() still gets here on the unwind path.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: atlantic: free RX pages of consumed but not refilled buffers\n\naq_ring_rx_deinit() only walks [sw_head, sw_tail), the region posted to\nhardware. Since the page reuse strategy was added, a cleaned RX buffer\nkeeps its page (and its DMA mapping) in the ring for reuse, and refill\nis batched: aq_ring_rx_fill() returns early until AQ_CFG_RX_REFILL_THRES\nslots are free. Slots that were consumed but not yet reposted therefore\nsit in the complementary [sw_tail, sw_head) gap with a live page, and\nthe deinit walk never visits them: up to a refill batch worth of pages\nand DMA mappings leak on every interface down.\n\nWalk the whole ring instead and release whatever is still there. Also\nbail out if the buffer ring is already gone: a partial\naq_ptp_ring_alloc() failure frees the ring but leaves aq_nic set, so\naq_ptp_ring_deinit() still gets here on the unwind path.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07462 |
debian: CVE-2026-74622 was patched at 2026-08-25
oraclelinux: CVE-2026-74622 was patched at 2026-09-04
2216.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74636) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: tracing: Fix race between update_event_fields and, event_define_fields The following sequence may leads race between event_define_fields() and update_event_fields(): CPU0 (loads module A) CPU1 (loads module B) =============================== =============================== load_module(A) load_module(B) notifier_call_chain notifier_call_chain trace_module_notify trace_module_notify mutex_lock(&event_mutex) trace_event_update_all() trace_module_add_events(A) down_write(&trace_event_sem) __register_event(call_A) __add_event_to_tracers(call_A) event_define_fields(call_A) for each f: list_for_each_entry(field, list_add(&f->link, &class->fields, link) &class->fields) field = class->fields->next; Where access to the class->fields is not protected by the event_mutex in trace_event_update_all(). This produces the following panic: Unable to handle kernel access ... at virtual address 0000000000000018 pc : update_event_fields+0xf8/0x368 Call trace: update_event_fields+0xf8/0x368 trace_event_update_all+0x7c/0x2b4 trace_module_notify+0x4c/0x1dc notifier_call_chain+0x84/0x168 blocking_notifier_call_chain_robust+0x64/0xd4 load_module+0x10c8/0x123c __arm64_sys_finit_module+0x230/0x31c Fix by taking event_mutex in trace_event_update_all() before trace_event_sem.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix race between update_event_fields and, event_define_fields\n\nThe following sequence may leads race between event_define_fields()\nand update_event_fields():\n\n CPU0 (loads module A) CPU1 (loads module B)\n =============================== ===============================\n load_module(A) load_module(B)\n notifier_call_chain notifier_call_chain\n trace_module_notify trace_module_notify\n mutex_lock(&event_mutex) trace_event_update_all()\n trace_module_add_events(A) down_write(&trace_event_sem)\n __register_event(call_A)\n __add_event_to_tracers(call_A)\n event_define_fields(call_A)\n for each f: list_for_each_entry(field,\n list_add(&f->link, &class->fields, link)\n &class->fields) field = class->fields->next;\n\nWhere access to the class->fields is not protected by the event_mutex in\ntrace_event_update_all().\n\nThis produces the following panic:\n Unable to handle kernel access ... at virtual address 0000000000000018\n pc : update_event_fields+0xf8/0x368\n Call trace:\n update_event_fields+0xf8/0x368\n trace_event_update_all+0x7c/0x2b4\n trace_module_notify+0x4c/0x1dc\n notifier_call_chain+0x84/0x168\n blocking_notifier_call_chain_robust+0x64/0xd4\n load_module+0x10c8/0x123c\n __arm64_sys_finit_module+0x230/0x31c\n\nFix by taking event_mutex in trace_event_update_all() before\ntrace_event_sem.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06955 |
debian: CVE-2026-74636 was patched at 2026-08-25
oraclelinux: CVE-2026-74636 was patched at 2026-09-04
2217.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74638) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Serialize the scheduler timeout handlers V3D exposes several independent hardware queues (BIN, RENDER, TFU and CSD) but has only a single, global reset. A timeout on any one queue therefore has to stop, reset and restart the schedulers of every other queue as well. That makes concurrent timeout handlers unsafe. `reset_lock` was never able to make them safe, as a driver-side lock can only cover the driver's &drm_sched_backend_ops.timedout_job callback. The scheduler handles the timed out job and its pending list around that callback, outside of the driver's control, so a global reset triggered by one queue can still interfere with another queue that is in the middle of handling a timeout of its own. Consequently, if a reset happens in the CSD queue while a CL-intensive application is running, the global reset stops and restarts the CL queue's scheduler while that queue is handling a timeout of its own. As drm_sched_stop() and drm_sched_start() subtract and add the credits of every job sitting on the pending list of the scheduler they are called on, and as the CL queue's handler concurrently takes its job off that same list and puts it back, the stop and the start no longer see the same set of jobs. The CL queue is left with more credits in flight than its limit: [ 327.302739] ------------[ cut here ]------------ [ 327.302744] WARNING: CPU: 2 PID: 43 at drivers/gpu/drm/scheduler/sched_main.c:102 drm_sched_run_job_work+0x238/0x4d0 [gpu_sched] [ 327.302884] CPU: 2 UID: 0 PID: 43 Comm: kworker/u16:1 Not tainted 6.18.39-v8-16k+ #3 PREEMPT [ 327.302889] Hardware name: Raspberry Pi 5 Model B Rev 1.0 (DT) [ 327.302893] Workqueue: v3d_bin drm_sched_run_job_work [gpu_sched] [ 327.302984] Call trace: [ 327.302987] drm_sched_run_job_work+0x238/0x4d0 [gpu_sched] (P) [ 327.302997] process_scheduled_works+0x180/0x3d0 [ 327.303010] worker_thread+0x268/0x3e8 [ 327.303016] kthread+0x140/0x250 [ 327.303022] ret_from_fork+0x10/0x20 [ 327.303031] ---[ end trace 0000000000000000 ]--- From that point on, the credit count of the CL queue is broken, causing a complete GPU hang and UI freeze. The DRM scheduler already provides a mechanism to serialize the timeout handlers of different schedulers: an ordered workqueue passed as drm_sched_init()'s @timeout_wq parameter. By default, each scheduler queues its timeout work on the system workqueue, which runs the handlers concurrently. Give all of the queues a shared ordered workqueue instead, as recommended by the DRM scheduler documentation for hardware that has distinct queues but resets globally.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Serialize the scheduler timeout handlers\n\nV3D exposes several independent hardware queues (BIN, RENDER, TFU and\nCSD) but has only a single, global reset. A timeout on any one queue\ntherefore has to stop, reset and restart the schedulers of every other\nqueue as well. That makes concurrent timeout handlers unsafe.\n\n`reset_lock` was never able to make them safe, as a driver-side lock can\nonly cover the driver's &drm_sched_backend_ops.timedout_job callback.\nThe scheduler handles the timed out job and its pending list around that\ncallback, outside of the driver's control, so a global reset triggered\nby one queue can still interfere with another queue that is in the\nmiddle of handling a timeout of its own.\n\nConsequently, if a reset happens in the CSD queue while a CL-intensive\napplication is running, the global reset stops and restarts the CL\nqueue's scheduler while that queue is handling a timeout of its own. As\ndrm_sched_stop() and drm_sched_start() subtract and add the credits of\nevery job sitting on the pending list of the scheduler they are called\non, and as the CL queue's handler concurrently takes its job off that\nsame list and puts it back, the stop and the start no longer see the\nsame set of jobs. The CL queue is left with more credits in flight than\nits limit:\n\n[ 327.302739] ------------[ cut here ]------------\n[ 327.302744] WARNING: CPU: 2 PID: 43 at drivers/gpu/drm/scheduler/sched_main.c:102 drm_sched_run_job_work+0x238/0x4d0 [gpu_sched]\n[ 327.302884] CPU: 2 UID: 0 PID: 43 Comm: kworker/u16:1 Not tainted 6.18.39-v8-16k+ #3 PREEMPT\n[ 327.302889] Hardware name: Raspberry Pi 5 Model B Rev 1.0 (DT)\n[ 327.302893] Workqueue: v3d_bin drm_sched_run_job_work [gpu_sched]\n[ 327.302984] Call trace:\n[ 327.302987] drm_sched_run_job_work+0x238/0x4d0 [gpu_sched] (P)\n[ 327.302997] process_scheduled_works+0x180/0x3d0\n[ 327.303010] worker_thread+0x268/0x3e8\n[ 327.303016] kthread+0x140/0x250\n[ 327.303022] ret_from_fork+0x10/0x20\n[ 327.303031] ---[ end trace 0000000000000000 ]---\n\nFrom that point on, the credit count of the CL queue is broken, causing\na complete GPU hang and UI freeze.\n\nThe DRM scheduler already provides a mechanism to serialize the timeout\nhandlers of different schedulers: an ordered workqueue passed as\ndrm_sched_init()'s @timeout_wq parameter. By default, each scheduler\nqueues its timeout work on the system workqueue, which runs the handlers\nconcurrently. Give all of the queues a shared ordered workqueue instead,\nas recommended by the DRM scheduler documentation for hardware that has\ndistinct queues but resets globally.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06247 |
debian: CVE-2026-74638 was patched at 2026-08-25
2218.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74642) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: usb: Fix UAF at delayed release of MIDI2 EPs The recent fix for UAF in ump_to_endpoint() caused another UAF because it tries to dereference the UMP endpoint object, but this might be executed at a delayed context where the endpoint has been already released. Add private_free to clear the associated data for avoiding the further dereference for delayed releases.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb: Fix UAF at delayed release of MIDI2 EPs\n\nThe recent fix for UAF in ump_to_endpoint() caused another UAF because\nit tries to dereference the UMP endpoint object, but this might be\nexecuted at a delayed context where the endpoint has been already\nreleased.\n\nAdd private_free to clear the associated data for avoiding the further\ndereference for delayed releases.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06439 |
oraclelinux: CVE-2026-74642 was patched at 2026-09-04
2219.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74644) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm/damon/ops-common: putback folios on invalid migrate nid damon_pa_migrate() and damos_va_migrate() isolate folios into a local list and then call damon_migrate_pages(). When target_nid is invalid (including the scheme default NUMA_NO_NODE / -1), damon_migrate_pages() returns early without putting the folios back to the LRU. Callers then discard the list head while those folios remain isolated with an extra reference taken by folio_isolate_lru(). The pages stay off the LRU for as long as the mapping exists (anon active+inactive counts drop while RSS does not), and the leftover references can pin the pages after the mapping is gone. Put the folios back on the invalid-nid path so ignored migration requests still return them to the LRU.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/ops-common: putback folios on invalid migrate nid\n\ndamon_pa_migrate() and damos_va_migrate() isolate folios into a local list\nand then call damon_migrate_pages(). When target_nid is invalid\n(including the scheme default NUMA_NO_NODE / -1), damon_migrate_pages()\nreturns early without putting the folios back to the LRU.\n\nCallers then discard the list head while those folios remain isolated with\nan extra reference taken by folio_isolate_lru(). The pages stay off the\nLRU for as long as the mapping exists (anon active+inactive counts drop\nwhile RSS does not), and the leftover references can pin the pages after\nthe mapping is gone.\n\nPut the folios back on the invalid-nid path so ignored migration requests\nstill return them to the LRU.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06445 |
debian: CVE-2026-74644 was patched at 2026-08-25
oraclelinux: CVE-2026-74644 was patched at 2026-09-04
2220.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74653) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx The NXP LPC32xx UART (PORT_LPC3220) can latch an RX character-timeout interrupt while the RX FIFO is empty: IIR reports UART_IIR_RX_TIMEOUT (0x0c) but LSR.DR is clear. A character timeout is only cleared by reading RHR, but serial8250_rx_chars() reads RHR only when LSR.DR is set, so nothing ever clears the condition. The interrupt is level-triggered and re-fires immediately, so on a single-core ARM926 the resulting interrupt storm livelocks the CPU. It is reproducible when userspace repeatedly opens the front-panel port (ttyS1): serial8250_do_set_termios() re-enables interrupts on unlock and the handler then spins forever with iir=0xcc lsr=0x60 ier=0x05, tripping the soft-lockup detector in serial8250_handle_irq_locked(). LPC32xx has no dedicated 8250 glue driver, it's driven by the generic 8250_of. Add a hardware specific handle_irq for PORT_LPC3220, wired up in of_platform_serial_setup() the same way fsl8250_handle_irq is installed. The handler follows dw8250_handle_irq(): on an RX timeout with an empty FIFO (LSR.DR and LSR.BI clear) it does one throwaway RHR read to clear the condition, then calls serial8250_handle_irq_locked(). No real received data is ever discarded, and it is a no-op on healthy UARTs which never report a timeout with DR clear. This is the same class of bug already worked around in other 8250 drivers; see commit 424d79183af0 ("serial: 8250_dw: Avoid "too much work" from bogus rx timeout interrupt") which reports the identical iir=0xcc/lsr=0x60. See also UART_RX_TIMEOUT_QUIRK in 8250_omap, and the note in 8250_bcm7271.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nserial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx\n\nThe NXP LPC32xx UART (PORT_LPC3220) can latch an RX character-timeout\ninterrupt while the RX FIFO is empty: IIR reports UART_IIR_RX_TIMEOUT\n(0x0c) but LSR.DR is clear. A character timeout is only cleared by\nreading RHR, but serial8250_rx_chars() reads RHR only when LSR.DR is\nset, so nothing ever clears the condition. The interrupt is\nlevel-triggered and re-fires immediately, so on a single-core ARM926\nthe resulting interrupt storm livelocks the CPU.\n\nIt is reproducible when userspace repeatedly opens the front-panel port\n(ttyS1): serial8250_do_set_termios() re-enables interrupts on unlock and\nthe handler then spins forever with iir=0xcc lsr=0x60 ier=0x05, tripping\nthe soft-lockup detector in serial8250_handle_irq_locked().\n\nLPC32xx has no dedicated 8250 glue driver, it's driven by the generic\n8250_of. Add a hardware specific handle_irq for PORT_LPC3220, wired up\nin of_platform_serial_setup() the same way fsl8250_handle_irq is\ninstalled. The handler follows dw8250_handle_irq(): on an RX timeout\nwith an empty FIFO (LSR.DR and LSR.BI clear) it does one throwaway RHR\nread to clear the condition, then calls serial8250_handle_irq_locked().\nNo real received data is ever discarded, and it is a no-op on healthy\nUARTs which never report a timeout with DR clear.\n\nThis is the same class of bug already worked around in other 8250 drivers;\nsee commit 424d79183af0 ("serial: 8250_dw: Avoid "too much work" from bogus rx timeout interrupt")\nwhich reports the identical iir=0xcc/lsr=0x60. See also\nUART_RX_TIMEOUT_QUIRK in 8250_omap, and the note in 8250_bcm7271.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06438 |
debian: CVE-2026-74653 was patched at 2026-08-25, 2026-08-29
2221.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74654) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dma: Clear stale RX state on shutdown serial8250_release_dma() terminates RX DMA and releases the channel, but leaves rx_running set. If the port is closed while an RX transfer is active, the stale state remains while rxchan is NULL until the channel is requested again on the next open. The DesignWare BUSY workaround added by commit a7b9ce39fbe4 ("serial: 8250_dw: Ensure BUSY is deasserted") calls serial8250_rx_dma_flush() from the LCR write path during startup. This happens before serial8250_request_dma() obtains a new RX channel. On reopen, the stale rx_running state therefore makes the flush path pass a NULL channel to dmaengine_pause(), causing a kernel Oops. Clear rx_running after terminating RX DMA, matching the TX cleanup. Also make the flush helper return if the DMA object or RX channel is not available so startup and teardown paths cannot pass a NULL channel to the DMAengine API.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nserial: 8250_dma: Clear stale RX state on shutdown\n\nserial8250_release_dma() terminates RX DMA and releases the channel, but\nleaves rx_running set. If the port is closed while an RX transfer is\nactive, the stale state remains while rxchan is NULL until the channel is\nrequested again on the next open.\n\nThe DesignWare BUSY workaround added by commit a7b9ce39fbe4\n("serial: 8250_dw: Ensure BUSY is deasserted") calls\nserial8250_rx_dma_flush() from the LCR write path during startup. This\nhappens before serial8250_request_dma() obtains a new RX channel. On\nreopen, the stale rx_running state therefore makes the flush path pass a\nNULL channel to dmaengine_pause(), causing a kernel Oops.\n\nClear rx_running after terminating RX DMA, matching the TX cleanup. Also\nmake the flush helper return if the DMA object or RX channel is not\navailable so startup and teardown paths cannot pass a NULL channel to the\nDMAengine API.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07455 |
debian: CVE-2026-74654 was patched at 2026-08-25
oraclelinux: CVE-2026-74654 was patched at 2026-09-04
2222.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74657) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops fib_nlmsg_size() still estimates nexthop space as if every gateway is encoded as an IPv4 RTA_GATEWAY attribute. IPv4 routes can also carry an IPv6 gateway, which fib_nexthop_info() dumps as RTA_VIA. As a result, route notifications can allocate an skb that is too small. fib_dump_info() then fails with -EMSGSIZE and rtmsg_fib() hits the WARN_ON() that marks such failures as a fib_nlmsg_size() bug. With panic_on_warn set, this becomes a kernel panic. Mirror the actual nexthop dump layout in fib_nlmsg_size(): account for IPv6 nexthop gateways dumped as RTA_VIA, for the no-header rtnexthop layout used inside RTA_MULTIPATH, and for RTA_FLOW only when it is actually present.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops\n\nfib_nlmsg_size() still estimates nexthop space as if every gateway is\nencoded as an IPv4 RTA_GATEWAY attribute. IPv4 routes can also carry an\nIPv6 gateway, which fib_nexthop_info() dumps as RTA_VIA.\n\nAs a result, route notifications can allocate an skb that is too small.\nfib_dump_info() then fails with -EMSGSIZE and rtmsg_fib() hits the\nWARN_ON() that marks such failures as a fib_nlmsg_size() bug. With\npanic_on_warn set, this becomes a kernel panic.\n\nMirror the actual nexthop dump layout in fib_nlmsg_size(): account for\nIPv6 nexthop gateways dumped as RTA_VIA, for the no-header rtnexthop\nlayout used inside RTA_MULTIPATH, and for RTA_FLOW only when it is\nactually present.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07467 |
debian: CVE-2026-74657 was patched at 2026-08-25
oraclelinux: CVE-2026-74657 was patched at 2026-09-04
2223.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74658) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: futex: Prevent robust futex exit race some more A robust futex unlock stores 0 over the whole futex value - wiping FUTEX_WAITERS - and wakes a single waiter. That wakeup is a one-shot notification: the protocol relies on its recipient to either acquire the futex (and eventually unlock while aware of the remaining contention) or re-arm FUTEX_WAITERS before sleeping again. If the woken waiter is killed before it can do either, the kernel must jump in and wake the next task down the line. This is a known complication of the futex protocol with a previous partial fix in commit ca16d5bee598 ("futex: Prevent robust futex exit race"). Unfortunately, that fix is insufficient. If a third task re-acquired the futex through the uncontended fast path in the meantime, the notification is lost: robust exit processing sees that it is owned by another task and does nothing, while the new owner sees no FUTEX_WAITERS when it unlocks and wakes nobody. The remaining waiters sleep forever behind a free futex: A owns the futex, B and C sleep in FUTEX_WAIT uval == A | FUTEX_WAITERS A robust unlock: store 0, FUTEX_WAKE(1) wakes B uval == 0 D fast path acquire: cmpxchg(0 -> D) uval == D, no FUTEX_WAITERS B killed before acting on the wakeup B exit walk, pending op: owner D != B -> no action D unlock: no FUTEX_WAITERS -> no wake C sleeps forever This is clearly a shortcoming in the implementation, which fails to keep the FUTEX_WAITERS bit consistent. Work around this by augmenting the robust list exit processing to also perform the extra wakeup if the futex word is owned by another thread but FUTEX_WAITERS is not set. This does not fix the problem of a non-contended take over/release and free sequence, which has been discussed for years and has been addressed by commit 3ca9595d9fb6 ("futex: Add support for unlocking robust futexes") and subsequent changes, but failed to take the problem described above into account. A more complete solution which is based on the in kernel unlock of contended robust futexes has been discussed in the context of this change and should show up in mainline sooner than later. [ tglx: Amend change log slightly and fixup coding style ]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfutex: Prevent robust futex exit race some more\n\nA robust futex unlock stores 0 over the whole futex value - wiping\nFUTEX_WAITERS - and wakes a single waiter. That wakeup is a one-shot\nnotification: the protocol relies on its recipient to either acquire the\nfutex (and eventually unlock while aware of the remaining contention) or\nre-arm FUTEX_WAITERS before sleeping again. If the woken waiter is killed\nbefore it can do either, the kernel must jump in and wake the next task\ndown the line.\n\nThis is a known complication of the futex protocol with a previous\npartial fix in commit ca16d5bee598 ("futex: Prevent robust futex exit\nrace"). Unfortunately, that fix is insufficient.\n\nIf a third task re-acquired the futex through the uncontended fast\npath in the meantime, the notification is lost: robust exit processing\nsees that it is owned by another task and does nothing, while the new\nowner sees no FUTEX_WAITERS when it unlocks and wakes nobody.\nThe remaining waiters sleep forever behind a free futex:\n\n A owns the futex, B and C sleep in FUTEX_WAIT\n uval == A | FUTEX_WAITERS\n A robust unlock: store 0, FUTEX_WAKE(1) wakes B\n uval == 0\n D fast path acquire: cmpxchg(0 -> D)\n uval == D, no FUTEX_WAITERS\n B killed before acting on the wakeup\n B exit walk, pending op: owner D != B -> no action\n D unlock: no FUTEX_WAITERS -> no wake\n C sleeps forever\n\nThis is clearly a shortcoming in the implementation, which fails to keep\nthe FUTEX_WAITERS bit consistent.\n\nWork around this by augmenting the robust list exit processing to also\nperform the extra wakeup if the futex word is owned by another thread but\nFUTEX_WAITERS is not set.\n\nThis does not fix the problem of a non-contended take over/release and free\nsequence, which has been discussed for years and has been addressed by\ncommit 3ca9595d9fb6 ("futex: Add support for unlocking robust futexes") and\nsubsequent changes, but failed to take the problem described above into\naccount.\n\nA more complete solution which is based on the in kernel unlock of\ncontended robust futexes has been discussed in the context of this change\nand should show up in mainline sooner than later.\n\n[ tglx: Amend change log slightly and fixup coding style ]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07458 |
debian: CVE-2026-74658 was patched at 2026-08-25
oraclelinux: CVE-2026-74658 was patched at 2026-09-04
2224.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74659) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: bridge: mrp: fix uninitialised bytes on the wire br_mrp_alloc_test_skb() builds MRP test frames on an skb from dev_alloc_skb(), which does not clear the linear data area. On the MRA ring-role branch the sub-option TLV header is appended with \tsub_tlv = skb_put(skb, sizeof(*sub_tlv)); \tsub_tlv->type = BR_MRP_SUB_TLV_HEADER_TEST_AUTO_MGR; so sub_tlv->length is never written, and the two trailing alignment bytes are appended with a bare skb_put() that does not clear them either. The neighbouring oui and sub_opt regions are explicitly zeroed, so three uninitialised bytes are left in every MRA MRP_Test frame that goes out. Put the sub-option TLV header and the alignment padding in a single skb_put_zero(), which clears both. The AUTO_MGR sub-TLV carries no payload, so the zeroed length field is already the value it should have.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: mrp: fix uninitialised bytes on the wire\n\nbr_mrp_alloc_test_skb() builds MRP test frames on an skb from\ndev_alloc_skb(), which does not clear the linear data area. On the MRA\nring-role branch the sub-option TLV header is appended with\n\n\tsub_tlv = skb_put(skb, sizeof(*sub_tlv));\n\tsub_tlv->type = BR_MRP_SUB_TLV_HEADER_TEST_AUTO_MGR;\n\nso sub_tlv->length is never written, and the two trailing alignment bytes\nare appended with a bare skb_put() that does not clear them either. The\nneighbouring oui and sub_opt regions are explicitly zeroed, so three\nuninitialised bytes are left in every MRA MRP_Test frame that goes out.\n\nPut the sub-option TLV header and the alignment padding in a single\nskb_put_zero(), which clears both. The AUTO_MGR sub-TLV carries no\npayload, so the zeroed length field is already the value it should have.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06961 |
debian: CVE-2026-74659 was patched at 2026-08-25
2225.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74664) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reallocate update replies for mismatched IDs ovs_flow_cmd_new() preallocates the optional reply skb before it takes ovs_mutex and before it knows which existing flow will be updated. That is normally fine because the skb is sized from the request flow identifier. That identifier also becomes the inserted flow's identifier. For updates, however, a request with a UFID may miss the UFID lookup and then fall back to the flow key lookup. That lookup can legitimately find an existing key-identified flow. UFIDs are optional and the flow key is the primary identifier. For echoed replies, ovs_flow_cmd_fill_info() writes the matched flow's identifier, not the request identifier used for the preallocation. A short request UFID can therefore leave too little room for the key identifier. The fill can then fail with -EMSGSIZE and hit the BUG_ON(error < 0) in the update path. Once the update target has been resolved, reallocate the reply skb if the matched flow needs a larger reply than the request identifier allowed. Do this before replacing the actions so the request can still fail cleanly if the rare extra allocation fails.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: reallocate update replies for mismatched IDs\n\novs_flow_cmd_new() preallocates the optional reply skb before it takes\novs_mutex and before it knows which existing flow will be updated.\n\nThat is normally fine because the skb is sized from the request flow\nidentifier. That identifier also becomes the inserted flow's identifier.\nFor updates, however, a request with a UFID may miss the UFID lookup and\nthen fall back to the flow key lookup. That lookup can legitimately find\nan existing key-identified flow. UFIDs are optional and the flow key is\nthe primary identifier.\n\nFor echoed replies, ovs_flow_cmd_fill_info() writes the matched flow's\nidentifier, not the request identifier used for the preallocation. A short\nrequest UFID can therefore leave too little room for the key identifier.\nThe fill can then fail with -EMSGSIZE and hit the BUG_ON(error < 0) in the\nupdate path.\n\nOnce the update target has been resolved, reallocate the reply skb if the\nmatched flow needs a larger reply than the request identifier allowed. Do\nthis before replacing the actions so the request can still fail cleanly if\nthe rare extra allocation fails.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07461 |
debian: CVE-2026-74664 was patched at 2026-08-25
oraclelinux: CVE-2026-74664 was patched at 2026-09-04
2226.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74673) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Input: evdev - fix information leak in evdev_pass_values() In evdev_pass_values(), the input_event structure is allocated on the kernel stack and populated field-by-field. However, it is never fully initialized. On architectures where struct input_event contains explicit or implicit padding (such as the 32-bit __pad field on SPARC64), these padding bytes are left uninitialized. When this event structure is subsequently passed to the client buffer and later copied to userspace, the uninitialized padding bytes leak kernel stack memory, potentially exposing sensitive information. Similar issues exist in __evdev_queue_syn_dropped and __pass_event. Fix this by explicitly zeroing the entire event structure with memset() before populating its fields. This ensures all padding bytes are cleared before the data crosses the security boundary.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nInput: evdev - fix information leak in evdev_pass_values()\n\nIn evdev_pass_values(), the input_event structure is allocated on the\nkernel stack and populated field-by-field. However, it is never fully\ninitialized. On architectures where struct input_event contains explicit\nor implicit padding (such as the 32-bit __pad field on SPARC64), these\npadding bytes are left uninitialized.\n\nWhen this event structure is subsequently passed to the client buffer\nand later copied to userspace, the uninitialized padding bytes leak\nkernel stack memory, potentially exposing sensitive information.\n\nSimilar issues exist in __evdev_queue_syn_dropped and __pass_event.\n\nFix this by explicitly zeroing the entire event structure with memset()\nbefore populating its fields. This ensures all padding bytes are cleared\nbefore the data crosses the security boundary.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07457 |
debian: CVE-2026-74673 was patched at 2026-08-25
oraclelinux: CVE-2026-74673 was patched at 2026-09-04
2227.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74676) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: vt: add permission check for KDSKBMETA ioctl KDSKBMETA modifies keyboard meta mode but lacks the !perm check that all other keyboard setter ioctls in vt_k_ioctl() enforce, allowing a process to change meta mode on a non-controlling console without authorization.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvt: add permission check for KDSKBMETA ioctl\n\nKDSKBMETA modifies keyboard meta mode but lacks the !perm check that all\nother keyboard setter ioctls in vt_k_ioctl() enforce, allowing a process\nto change meta mode on a non-controlling console without authorization.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.0746 |
debian: CVE-2026-74676 was patched at 2026-08-25
oraclelinux: CVE-2026-74676 was patched at 2026-09-04
2228.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74680) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() If cxacru_cm() encounters an error while submitting or waiting for snd_urb, it aborts and returns the error without killing the already submitted rcv_urb. This leaves the rcv_urb active. When this happens during initialization (e.g., in cxacru_atm_start()), the driver may ignore the error and proceed to call cxacru_poll_status(), which invokes cxacru_cm() again. Attempting to submit the still-active rcv_urb triggers a warning in usb_submit_urb(): cxacru 1-1:1.0: send of cm 0x84 failed (-104) ATM dev 0: cxacru_atm_start: CHIP_ADSL_LINE_START returned -104 ------------[ cut here ]------------ URB ffff88812658d200 submitted while active WARNING: drivers/usb/core/urb.c:379 at usb_submit_urb+0x79/0x18b0 drivers/usb/core/urb.c:379 ... Call Trace: <TASK> cxacru_cm+0x21a/0xf10 drivers/usb/atm/cxacru.c:631 cxacru_cm_get_array drivers/usb/atm/cxacru.c:722 [inline] cxacru_poll_status+0x178/0x1110 drivers/usb/atm/cxacru.c:828 cxacru_atm_start+0x185/0x360 drivers/usb/atm/cxacru.c:814 usbatm_atm_init+0x144/0x3a0 drivers/usb/atm/usbatm.c:927 usbatm_usb_probe+0x15cb/0x1db0 drivers/usb/atm/usbatm.c:1178 cxacru_usb_probe+0x17f/0x220 drivers/usb/atm/cxacru.c:1370 ... To fix this, ensure that rcv_urb is properly killed if cxacru_cm() aborts early. We can safely call usb_kill_urb() on rcv_urb in the error path, as it is safe to call even if the URB is not active (e.g., if it failed to submit in the first place, or if it already completed).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()\n\nIf cxacru_cm() encounters an error while submitting or waiting for snd_urb,\nit aborts and returns the error without killing the already submitted\nrcv_urb. This leaves the rcv_urb active.\n\nWhen this happens during initialization (e.g., in cxacru_atm_start()), the\ndriver may ignore the error and proceed to call cxacru_poll_status(), which\ninvokes cxacru_cm() again. Attempting to submit the still-active rcv_urb\ntriggers a warning in usb_submit_urb():\n\ncxacru 1-1:1.0: send of cm 0x84 failed (-104)\nATM dev 0: cxacru_atm_start: CHIP_ADSL_LINE_START returned -104\n------------[ cut here ]------------\nURB ffff88812658d200 submitted while active\nWARNING: drivers/usb/core/urb.c:379 at usb_submit_urb+0x79/0x18b0\ndrivers/usb/core/urb.c:379\n...\nCall Trace:\n <TASK>\n cxacru_cm+0x21a/0xf10 drivers/usb/atm/cxacru.c:631\n cxacru_cm_get_array drivers/usb/atm/cxacru.c:722 [inline]\n cxacru_poll_status+0x178/0x1110 drivers/usb/atm/cxacru.c:828\n cxacru_atm_start+0x185/0x360 drivers/usb/atm/cxacru.c:814\n usbatm_atm_init+0x144/0x3a0 drivers/usb/atm/usbatm.c:927\n usbatm_usb_probe+0x15cb/0x1db0 drivers/usb/atm/usbatm.c:1178\n cxacru_usb_probe+0x17f/0x220 drivers/usb/atm/cxacru.c:1370\n...\n\nTo fix this, ensure that rcv_urb is properly killed if cxacru_cm() aborts\nearly. We can safely call usb_kill_urb() on rcv_urb in the error path, as\nit is safe to call even if the URB is not active (e.g., if it failed to\nsubmit in the first place, or if it already completed).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07525 |
debian: CVE-2026-74680 was patched at 2026-08-25
oraclelinux: CVE-2026-74680 was patched at 2026-09-04
2229.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74682) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix OOB write on Type II inbound URBs data_ep_set_params() sizes each URB transfer buffer before it adds the Format Type II transfer delimiter: \tu->packets = urb_packs; \tu->buffer_size = maxsize * u->packets; \tif (fmt->fmt_type == UAC_FORMAT_TYPE_II) \t\tu->packets++; /* for transfer delimiter */ \tu->urb = usb_alloc_urb(u->packets, GFP_KERNEL); buffer_size is computed from the pre-increment packet count and never recomputed, so for a Type II endpoint the buffer is one packet short of the packet count the URB is built with. prepare_inbound_urb() then lays out one iso frame per packet and never consults buffer_size: \toffs = 0; \tfor (i = 0; i < urb_ctx->packets; i++) { \t\turb->iso_frame_desc[i].offset = offs; \t\turb->iso_frame_desc[i].length = ep->curpacksize; \t\toffs += ep->curpacksize; \t} \turb->transfer_buffer_length = offs; \turb->number_of_packets = urb_ctx->packets; The last descriptor therefore points one packet past the end of the transfer buffer, where the host controller writes device data on every inbound transfer. prepare_silent_urb() and prepare_playback_urb() bound their fill loops by ctx->buffer_size, so only capture is affected. fmt_type comes from the device's audio streaming descriptors, so any device advertising a Type II capture format hits this once userspace sets hw_params on the stream. KASAN on 7.2.0-rc5 (arm64) with a dummy_hcd/raw-gadget device, one report per inbound transfer: BUG: KASAN: slab-out-of-bounds in dummy_timer Write of size 64 at addr ffff0000186171c0 by task cons02/166 __asan_memcpy dummy_timer hrtimer_run_softirq Allocated by task 166: usb_alloc_coherent snd_usb_endpoint_set_params The buggy address is located 0 bytes to the right of allocated 64-byte region [ffff000018617180, ffff0000186171c0) Compute buffer_size after the delimiter packet has been accounted for, and bound the fill loop by buffer_size, as prepare_silent_urb() already does on the outbound side. This grows every Type II URB allocation by one maxsize packet. Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: fix OOB write on Type II inbound URBs\n\ndata_ep_set_params() sizes each URB transfer buffer before it adds the\nFormat Type II transfer delimiter:\n\n\tu->packets = urb_packs;\n\tu->buffer_size = maxsize * u->packets;\n\n\tif (fmt->fmt_type == UAC_FORMAT_TYPE_II)\n\t\tu->packets++; /* for transfer delimiter */\n\tu->urb = usb_alloc_urb(u->packets, GFP_KERNEL);\n\nbuffer_size is computed from the pre-increment packet count and never\nrecomputed, so for a Type II endpoint the buffer is one packet short of\nthe packet count the URB is built with.\n\nprepare_inbound_urb() then lays out one iso frame per packet and never\nconsults buffer_size:\n\n\toffs = 0;\n\tfor (i = 0; i < urb_ctx->packets; i++) {\n\t\turb->iso_frame_desc[i].offset = offs;\n\t\turb->iso_frame_desc[i].length = ep->curpacksize;\n\t\toffs += ep->curpacksize;\n\t}\n\n\turb->transfer_buffer_length = offs;\n\turb->number_of_packets = urb_ctx->packets;\n\nThe last descriptor therefore points one packet past the end of the\ntransfer buffer, where the host controller writes device data on every\ninbound transfer. prepare_silent_urb() and prepare_playback_urb() bound\ntheir fill loops by ctx->buffer_size, so only capture is affected.\n\nfmt_type comes from the device's audio streaming descriptors, so any\ndevice advertising a Type II capture format hits this once userspace sets\nhw_params on the stream.\n\nKASAN on 7.2.0-rc5 (arm64) with a dummy_hcd/raw-gadget device, one report\nper inbound transfer:\n\n BUG: KASAN: slab-out-of-bounds in dummy_timer\n Write of size 64 at addr ffff0000186171c0 by task cons02/166\n __asan_memcpy\n dummy_timer\n hrtimer_run_softirq\n Allocated by task 166:\n usb_alloc_coherent\n snd_usb_endpoint_set_params\n The buggy address is located 0 bytes to the right of\n allocated 64-byte region [ffff000018617180, ffff0000186171c0)\n\nCompute buffer_size after the delimiter packet has been accounted for,\nand bound the fill loop by buffer_size, as prepare_silent_urb() already\ndoes on the outbound side. This grows every Type II URB allocation by\none maxsize packet.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07455 |
debian: CVE-2026-74682 was patched at 2026-08-25
oraclelinux: CVE-2026-74682 was patched at 2026-09-04
2230.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74683) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Input: evdev - sanitize event type index when fetching event masks The user-supplied event type index passed to EVIOCGMASK / EVIOCSMASK ioctls is used to index the static counts array in evdev_get_mask_cnt() and client evmasks array in evdev_get_mask(). While the event type is architecturally bounded by EV_CNT, speculative execution may mispredict bounds checks and perform out-of-bounds loads. Sanitize the event type index in evdev_get_mask_cnt() branchlessly using array_index_mask_nospec(). This clamps the index to 0 for safe array access and forces the returned count to 0 speculatively when the index is out of bounds. We do not need additional array_index_nospec() calls in evdev_get_mask() because evdev_get_mask_cnt() speculatively forces the count (and resulting xfer_size) to 0 for out-of-bounds types, preventing any speculative memory access to client evmasks array.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nInput: evdev - sanitize event type index when fetching event masks\n\nThe user-supplied event type index passed to EVIOCGMASK / EVIOCSMASK\nioctls is used to index the static counts array in evdev_get_mask_cnt()\nand client evmasks array in evdev_get_mask().\n\nWhile the event type is architecturally bounded by EV_CNT, speculative\nexecution may mispredict bounds checks and perform out-of-bounds loads.\n\nSanitize the event type index in evdev_get_mask_cnt() branchlessly using\narray_index_mask_nospec(). This clamps the index to 0 for safe array\naccess and forces the returned count to 0 speculatively when the index\nis out of bounds.\n\nWe do not need additional array_index_nospec() calls in evdev_get_mask()\nbecause evdev_get_mask_cnt() speculatively forces the count (and\nresulting xfer_size) to 0 for out-of-bounds types, preventing any\nspeculative memory access to client evmasks array.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0019, EPSS Percentile is 0.08887 |
debian: CVE-2026-74683 was patched at 2026-08-25
oraclelinux: CVE-2026-74683 was patched at 2026-09-04
2231.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74685) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: hwmon: (ltc4282) Clamp negative current limits When a negative value is passed to ltc4282_write_curr(), the signed long val is cast directly to u64: drivers/hwmon/ltc4282.c:ltc4282_write_curr() { /* need to pass it in millivolt */ u32 in = DIV_ROUND_CLOSEST_ULL((u64)val * st->rsense, DECA * MICRO); ... } This cast converts negative inputs into large positive values. The subsequent division result overflows the u32 in variable, truncating to a pseudo-random positive value. When this is passed to ltc4282_write_voltage_byte(), it is clamped to the maximum limit instead of zero. Clamp val to 0 and to the maximum supported upper limit before the cast and assign the result to a 64-bit temporary variable before the division to avoid the underflow and an also possible overflow.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (ltc4282) Clamp negative current limits\n\nWhen a negative value is passed to ltc4282_write_curr(), the signed long\nval is cast directly to u64:\n\ndrivers/hwmon/ltc4282.c:ltc4282_write_curr() {\n /* need to pass it in millivolt */\n u32 in = DIV_ROUND_CLOSEST_ULL((u64)val * st->rsense, DECA * MICRO);\n ...\n}\n\nThis cast converts negative inputs into large positive values. The\nsubsequent division result overflows the u32 in variable, truncating\nto a pseudo-random positive value. When this is passed to\nltc4282_write_voltage_byte(), it is clamped to the maximum limit instead\nof zero.\n\nClamp val to 0 and to the maximum supported upper limit before the cast\nand assign the result to a 64-bit temporary variable before the division\nto avoid the underflow and an also possible overflow.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06444 |
debian: CVE-2026-74685 was patched at 2026-08-25
2232.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74693) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: prestera: validate firmware header length prestera_fw_hdr_parse() reads the firmware header before checking that the firmware image contains that header. Reject images shorter than struct prestera_fw_header before decoding the magic and version fields.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: prestera: validate firmware header length\n\nprestera_fw_hdr_parse() reads the firmware header before checking\nthat the firmware image contains that header.\n\nReject images shorter than struct prestera_fw_header before decoding the\nmagic and version fields.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.0746 |
debian: CVE-2026-74693 was patched at 2026-08-25
2233.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74694) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length ncsi_send_cmd_nl() takes the number of bytes to copy from the attacker-controlled ncsi_pkt_hdr.length field of the in-band packet header, while the source buffer is the NCSI_ATTR_DATA netlink attribute whose readable size is nla_len() - sizeof(ncsi_pkt_hdr). The two length sources are never cross-checked: only nla_len() >= sizeof(struct ncsi_pkt_hdr) is enforced. With hdr->length set larger than the attribute payload (up to 65535 against at most 2032 readable bytes), ncsi_cmd_handler_oem() copies past the end of the netlink attribute buffer with unsafe_memcpy(), leaking up to ~64KB of kernel heap memory into the transmitted NCSI command packet. The destination skb is sized by the declared payload, so the write side does not overflow - this is a pure OOB read / information leak, reachable with CAP_NET_ADMIN on systems with a registered NCSI device (e.g. OpenBMC on Aspeed BMC SoCs, where NET_NCSI=y is standard). Reject commands whose declared payload extends past the end of the data attribute. The issue was found by the autokbug dynamic kernel fuzzer at Tencent Yunding Lab.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length\n\nncsi_send_cmd_nl() takes the number of bytes to copy from the\nattacker-controlled ncsi_pkt_hdr.length field of the in-band packet\nheader, while the source buffer is the NCSI_ATTR_DATA netlink\nattribute whose readable size is nla_len() - sizeof(ncsi_pkt_hdr).\nThe two length sources are never cross-checked: only\nnla_len() >= sizeof(struct ncsi_pkt_hdr) is enforced.\n\nWith hdr->length set larger than the attribute payload (up to 65535\nagainst at most 2032 readable bytes), ncsi_cmd_handler_oem() copies\npast the end of the netlink attribute buffer with unsafe_memcpy(),\nleaking up to ~64KB of kernel heap memory into the transmitted NCSI\ncommand packet. The destination skb is sized by the declared payload,\nso the write side does not overflow - this is a pure OOB read /\ninformation leak, reachable with CAP_NET_ADMIN on systems with a\nregistered NCSI device (e.g. OpenBMC on Aspeed BMC SoCs, where\nNET_NCSI=y is standard).\n\nReject commands whose declared payload extends past the end of the\ndata attribute.\n\nThe issue was found by the autokbug dynamic kernel fuzzer at Tencent\nYunding Lab.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.0746 |
debian: CVE-2026-74694 was patched at 2026-08-25
2234.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74718) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: devlink: fix net namespace reference leak in reload devlink_nl_reload_doit() calls devlink_netns_get(), which returns a net with a held reference. When the requested namespace differs from the current one and the reload action is not DRIVER_REINIT, the function returns -EOPNOTSUPP without releasing the reference. Add the missing put_net() on this error path.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndevlink: fix net namespace reference leak in reload\n\ndevlink_nl_reload_doit() calls devlink_netns_get(), which returns a net\nwith a held reference. When the requested namespace differs from the\ncurrent one and the reload action is not DRIVER_REINIT, the function\nreturns -EOPNOTSUPP without releasing the reference. Add the missing\nput_net() on this error path.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06438 |
debian: CVE-2026-74718 was patched at 2026-08-25
oraclelinux: CVE-2026-74718 was patched at 2026-09-04
2235.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74719) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() The SMC_LLC_CONFIRM_LINK / SMC_LLC_ADD_LINK_CONT branch in smc_llc_event_handler() stores an incoming qentry into the local LLC flow without first checking whether a qentry is already pending. If a malicious or buggy peer sends a second CONFIRM_LINK or ADD_LINK_CONT request while a flow is active and flow->qentry is already set, smc_llc_flow_qentry_set() overwrites the pointer without freeing the previous allocation, leaking one kmalloc-96 object per spurious message. The sibling SMC_LLC_DELETE_LINK branch already has the correct !flow->qentry guard. Apply the same guard to the CONFIRM_LINK/ADD_LINK_CONT branch so that a duplicate message when qentry is already occupied falls through to break and is freed by the kfree(qentry) at the out: label, rather than silently leaking the existing allocation. The response direction (smc_llc_rx_response()) is unaffected: it already guards with flow->qentry at the equivalent site and drops duplicate responses correctly.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler()\n\nThe SMC_LLC_CONFIRM_LINK / SMC_LLC_ADD_LINK_CONT branch in\nsmc_llc_event_handler() stores an incoming qentry into the local LLC flow\nwithout first checking whether a qentry is already pending. If a malicious or\nbuggy peer sends a second CONFIRM_LINK or ADD_LINK_CONT request while a flow is\nactive and flow->qentry is already set, smc_llc_flow_qentry_set() overwrites the\npointer without freeing the previous allocation, leaking one kmalloc-96 object\nper spurious message.\n\nThe sibling SMC_LLC_DELETE_LINK branch already has the correct !flow->qentry\nguard. Apply the same guard to the CONFIRM_LINK/ADD_LINK_CONT branch so that a\nduplicate message when qentry is already occupied falls through to break and is\nfreed by the kfree(qentry) at the out: label, rather than silently leaking the\nexisting allocation.\n\nThe response direction (smc_llc_rx_response()) is unaffected: it already guards\nwith flow->qentry at the equivalent site and drops duplicate responses\ncorrectly.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07464 |
debian: CVE-2026-74719 was patched at 2026-08-25
2236.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74728) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xfs: handle NULL b_addr in xfs_buf_free When xfs_buf_alloc_backing_mem() fails, xfs_buf_free() is called with bp->b_addr still NULL. The code falls through to the folio_put path which calls virt_to_folio(NULL), dereferencing an invalid address and causing a kernel crash. Call Trace: xfs_buf_free+0x25f/0x510 xfs_buf_alloc+0xc98/0x19b0 xfs_buf_find_insert+0x55/0x14d0 xfs_buf_get_map+0x122b/0x17c0 xfbtree_init_leaf_block+0x11c/0x4a0 xfbtree_init+0x1bb/0x460 xrep_rmap_setup_scan+0x100/0x1f0 xrep_rmapbt+0x41/0xc0 Fix this by skipping folio_put() when bp->b_addr is NULL.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: handle NULL b_addr in xfs_buf_free\n\nWhen xfs_buf_alloc_backing_mem() fails, xfs_buf_free() is called with\nbp->b_addr still NULL. The code falls through to the folio_put path\nwhich calls virt_to_folio(NULL), dereferencing an invalid address and\ncausing a kernel crash.\n\n Call Trace:\n xfs_buf_free+0x25f/0x510\n xfs_buf_alloc+0xc98/0x19b0\n xfs_buf_find_insert+0x55/0x14d0\n xfs_buf_get_map+0x122b/0x17c0\n xfbtree_init_leaf_block+0x11c/0x4a0\n xfbtree_init+0x1bb/0x460\n xrep_rmap_setup_scan+0x100/0x1f0\n xrep_rmapbt+0x41/0xc0\n\nFix this by skipping folio_put() when bp->b_addr is NULL.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0017, EPSS Percentile is 0.06649 |
debian: CVE-2026-74728 was patched at 2026-08-25
2237.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74729) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read put_fifo_with_discard() acts as both producer and consumer on the kfifo: it calls kfifo_skip() (advances out) and kfifo_put() (advances in) from the IRQ handler without synchronizing with snoop_file_read(), which also consumes via kfifo_to_user(). On SMP systems this concurrent access can leave (in - out) larger than the ring buffer, so __kfifo_to_user()'s clamp to (in - out) is ineffective and kfifo_copy_to_user() can attempt a copy_to_user() past the kmalloc-2k backing store: usercopy: Kernel memory exposure attempt detected from SLUB object 'kmalloc-2k' (offset 0, size 2049)! kernel BUG at mm/usercopy.c! Call trace: usercopy_abort __check_heap_object __check_object_size kfifo_copy_to_user __kfifo_to_user snoop_file_read vfs_read Serialize kfifo access with a per-channel spinlock shared between the IRQ handler (producer) and the file reader (consumer). Annotate @fifo with __guarded_by(&lock) and opt the driver into context analysis so the compiler enforces that all fifo access holds the lock.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read\n\nput_fifo_with_discard() acts as both producer and consumer on the kfifo:\nit calls kfifo_skip() (advances out) and kfifo_put() (advances in) from\nthe IRQ handler without synchronizing with snoop_file_read(), which also\nconsumes via kfifo_to_user(). On SMP systems this concurrent access can\nleave (in - out) larger than the ring buffer, so __kfifo_to_user()'s clamp\nto (in - out) is ineffective and kfifo_copy_to_user() can attempt a\ncopy_to_user() past the kmalloc-2k backing store:\n\n usercopy: Kernel memory exposure attempt detected from SLUB object\n 'kmalloc-2k' (offset 0, size 2049)!\n kernel BUG at mm/usercopy.c!\n Call trace:\n usercopy_abort\n __check_heap_object\n __check_object_size\n kfifo_copy_to_user\n __kfifo_to_user\n snoop_file_read\n vfs_read\n\nSerialize kfifo access with a per-channel spinlock shared between the\nIRQ handler (producer) and the file reader (consumer). Annotate @fifo\nwith __guarded_by(&lock) and opt the driver into context analysis so the\ncompiler enforces that all fifo access holds the lock.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0017, EPSS Percentile is 0.06685 |
debian: CVE-2026-74729 was patched at 2026-08-25
2238.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74735) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: l2tp: fix tunnel and session refcount leak on seq_file release In pppol2tp_proc_open() and l2tp_dfs_seq_open(), iteration state (pd->tunnel and pd->session) is kept in seq_file private data to allow iteration across multiple read() system calls. However, if userspace closes /proc/net/pppol2tp or /sys/kernel/debug/l2tp/tunnels before reading to end-of-file (EOF), any tunnel or session reference stored in pd->tunnel / pd->session is left un-dropped when seq_file private data is freed. Fix this by dropping any remaining pd->tunnel and pd->session references in pppol2tp_proc_release() and l2tp_dfs_seq_release() when closing the file.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nl2tp: fix tunnel and session refcount leak on seq_file release\n\nIn pppol2tp_proc_open() and l2tp_dfs_seq_open(), iteration state\n(pd->tunnel and pd->session) is kept in seq_file private data to allow\niteration across multiple read() system calls.\n\nHowever, if userspace closes /proc/net/pppol2tp or /sys/kernel/debug/l2tp/tunnels\nbefore reading to end-of-file (EOF), any tunnel or session reference stored in\npd->tunnel / pd->session is left un-dropped when seq_file private data is freed.\n\nFix this by dropping any remaining pd->tunnel and pd->session references in\npppol2tp_proc_release() and l2tp_dfs_seq_release() when closing the file.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00162, EPSS Percentile is 0.0583 |
debian: CVE-2026-74735 was patched at 2026-09-16
2239.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74740) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain tcf_action_exec() handles TC_ACT_GOTO_CHAIN by first checking rcu_access_pointer(a->goto_chain) and then calling tcf_action_goto_chain_exec(), which does a second, independent rcu_dereference_bh(a->goto_chain) read and immediately dereferences chain->filter_chain. A concurrent tcf_action_set_ctrlact() (e.g. the gact replace path) can clear a->goto_chain between the two reads, so the second read returns NULL and tcf_action_goto_chain_exec() dereferences NULL. Fix the race by doing a single rcu_dereference_bh() read of a->goto_chain in tcf_action_exec(), checking it once for NULL, and passing the resulting chain pointer into tcf_action_goto_chain_exec(). This turns the split check/use into a single check/use on one value.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_api: fix TOCTOU NULL deref on a->goto_chain\n\ntcf_action_exec() handles TC_ACT_GOTO_CHAIN by first checking\nrcu_access_pointer(a->goto_chain) and then calling\ntcf_action_goto_chain_exec(), which does a second, independent\nrcu_dereference_bh(a->goto_chain) read and immediately dereferences\nchain->filter_chain. A concurrent tcf_action_set_ctrlact() (e.g. the gact\nreplace path) can clear a->goto_chain between the two reads, so the second\nread returns NULL and tcf_action_goto_chain_exec() dereferences NULL.\n\nFix the race by doing a single rcu_dereference_bh() read of a->goto_chain\nin tcf_action_exec(), checking it once for NULL, and passing the resulting\nchain pointer into tcf_action_goto_chain_exec(). This turns the split\ncheck/use into a single check/use on one value.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00175, EPSS Percentile is 0.0728 |
debian: CVE-2026-74740 was patched at 2026-09-16
2240.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-74754) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: scsi: core: pair EH runtime PM get and put shost->eh_noresume is currently consulted twice in one error handling iteration: once before scsi_autopm_get_host() and once again before scsi_autopm_put_host(). That is racy when a PM-triggered error path flips shost->eh_noresume while the SCSI EH thread is still running. The problem flow looks like this: PM path ufshcd_set_dev_pwr_mode() shost->eh_noresume = 1 ufshcd_execute_start_stop <-- trigger EH ... shost->eh_noresume = 0 EH path scsi_error_handler() if (!shost->eh_noresume) scsi_autopm_get_host() <-- skipped ... if (!shost->eh_noresume) scsi_autopm_put_host() <-- executed later In that case one EH iteration can skip autoresume on entry and still drop a runtime PM reference on exit. That leaves an unmatched runtime PM put and can trigger a runtime PM usage count underflow. Fix this by making eh_noresume a regular bool so it can be accessed with READ_ONCE() and WRITE_ONCE(). Snapshot it once per EH iteration and use that snapshot for both runtime PM get and put decisions.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: core: pair EH runtime PM get and put\n\nshost->eh_noresume is currently consulted twice in one error handling\niteration: once before scsi_autopm_get_host() and once again before\nscsi_autopm_put_host().\n\nThat is racy when a PM-triggered error path flips shost->eh_noresume\nwhile the SCSI EH thread is still running.\n\nThe problem flow looks like this:\nPM path\n ufshcd_set_dev_pwr_mode()\n shost->eh_noresume = 1\n ufshcd_execute_start_stop <-- trigger EH\n ...\n shost->eh_noresume = 0\n\nEH path\n scsi_error_handler()\n if (!shost->eh_noresume)\n scsi_autopm_get_host() <-- skipped\n ...\n if (!shost->eh_noresume)\n scsi_autopm_put_host() <-- executed later\n\nIn that case one EH iteration can skip autoresume on entry and still\ndrop a runtime PM reference on exit. That leaves an unmatched runtime PM\nput and can trigger a runtime PM usage count underflow.\n\nFix this by making eh_noresume a regular bool so it can be accessed with\nREAD_ONCE() and WRITE_ONCE(). Snapshot it once per EH iteration and use\nthat snapshot for both runtime PM get and put decisions.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.05062 |
debian: CVE-2026-74754 was patched at 2026-09-16
2241.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80525) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup The ipc_config_data buffer for copier widgets is built once during ipc_prepare (called from sof_pcm_setup_connected_widgets) and cached for reuse. For host copiers this buffer contains the copier_data with gtw_cfg.node_id (host DMA ID). For DAI copiers it additionally includes a dma_config_tlv trailer with stream_id and dma_channel_id for HDA link DMA. On suspend/resume, both host and link DMA streams are released and re-allocated with potentially different stream tags. The underlying copier_data and dma_config_tlv structures are correctly updated by host_config and sdw_hda_dai_hw_params respectively. However, since the widget list (spcm->stream[].list) persists across suspend, sof_pcm_hw_params skips sof_pcm_setup_connected_widgets and ipc_prepare never runs again to rebuild ipc_config_data. The stale cached payload is then sent to firmware with boot-time DMA channel assignments, causing DMA channel conflicts that lead to firmware errors and crashes. Fix this by refreshing copier_data and dma_config_tlv portions of ipc_config_data in sof_ipc4_widget_setup right before the IPC message is sent. This ensures the payload always reflects the current DMA state regardless of whether ipc_prepare ran. For DAI copiers, the gtw_cfg.config_length in copier_data is temporarily inflated to include the TLV size (matching the ipc_config_data layout) before copying, then restored, mirroring what sof_ipc4_prepare_copier_module does when first building the buffer.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup\n\nThe ipc_config_data buffer for copier widgets is built once during\nipc_prepare (called from sof_pcm_setup_connected_widgets) and cached\nfor reuse. For host copiers this buffer contains the copier_data with\ngtw_cfg.node_id (host DMA ID). For DAI copiers it additionally includes\na dma_config_tlv trailer with stream_id and dma_channel_id for HDA link\nDMA.\n\nOn suspend/resume, both host and link DMA streams are released and\nre-allocated with potentially different stream tags. The underlying\ncopier_data and dma_config_tlv structures are correctly updated by\nhost_config and sdw_hda_dai_hw_params respectively. However, since the\nwidget list (spcm->stream[].list) persists across suspend,\nsof_pcm_hw_params skips sof_pcm_setup_connected_widgets and ipc_prepare\nnever runs again to rebuild ipc_config_data. The stale cached payload\nis then sent to firmware with boot-time DMA channel assignments, causing\nDMA channel conflicts that lead to firmware errors and crashes.\n\nFix this by refreshing copier_data and dma_config_tlv portions of\nipc_config_data in sof_ipc4_widget_setup right before the IPC message\nis sent. This ensures the payload always reflects the current DMA state\nregardless of whether ipc_prepare ran.\n\nFor DAI copiers, the gtw_cfg.config_length in copier_data is temporarily\ninflated to include the TLV size (matching the ipc_config_data layout)\nbefore copying, then restored, mirroring what\nsof_ipc4_prepare_copier_module does when first building the buffer.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06408 |
debian: CVE-2026-80525 was patched at 2026-09-16
2242.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80529) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xfs: don't swallow dquot recovery verification errors xlog_recover_dquot_commit_pass2() validates the recovered dquot with xfs_dqblk_verify() and, on failure, sets error = -EFSCORRUPTED and jumps to out_release. But out_release unconditionally returns 0, so the corruption error is discarded: the caller xlog_recover_items_pass2() sees success, log recovery proceeds as if the dquot were valid, and the corrupt quota buffer can be written back to disk.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: don't swallow dquot recovery verification errors\n\nxlog_recover_dquot_commit_pass2() validates the recovered dquot with\nxfs_dqblk_verify() and, on failure, sets error = -EFSCORRUPTED and jumps\nto out_release. But out_release unconditionally returns 0, so the\ncorruption error is discarded: the caller xlog_recover_items_pass2()\nsees success, log recovery proceeds as if the dquot were valid, and the\ncorrupt quota buffer can be written back to disk.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06934 |
debian: CVE-2026-80529 was patched at 2026-09-16
2243.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80532) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xfs: fix another iunlink infinite loop bug in online fsck xrep_iunlink_resolve_bucket is supposed to reconstruct as much of the incore prev and next unlinked list pointers based on what it finds on disk and in memory before we move on to relinking the truly lost inodes back into the unlinked list. However, it's still vulnerable to infinite loops that come in via the next_unlinked pointers. Fix this problem by remembering which inodes we've already seen and checking new agino pointers against that. If a bit is already set, either this is a loop or the inode has nonzero link count. We'll deal with the second case in a subsequent patch.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: fix another iunlink infinite loop bug in online fsck\n\nxrep_iunlink_resolve_bucket is supposed to reconstruct as much of the\nincore prev and next unlinked list pointers based on what it finds on\ndisk and in memory before we move on to relinking the truly lost inodes\nback into the unlinked list. However, it's still vulnerable to infinite\nloops that come in via the next_unlinked pointers.\n\nFix this problem by remembering which inodes we've already seen and\nchecking new agino pointers against that. If a bit is already set,\neither this is a loop or the inode has nonzero link count. We'll deal\nwith the second case in a subsequent patch.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06408 |
debian: CVE-2026-80532 was patched at 2026-09-16
2244.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80533) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair LOLLM noticed a longstanding bug where xrep_iunlink_walk_ondisk_bucket tries to walk ragi->sc->sa.agi_bp to rebuild the unlinked inode lists. Unfortunately, it's possible for agi_bp to be null if the buffer verifier fails, so we have to use ragi->agi_bp (which skips verifier checks) instead.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair\n\nLOLLM noticed a longstanding bug where xrep_iunlink_walk_ondisk_bucket\ntries to walk ragi->sc->sa.agi_bp to rebuild the unlinked inode lists.\nUnfortunately, it's possible for agi_bp to be null if the buffer\nverifier fails, so we have to use ragi->agi_bp (which skips verifier\nchecks) instead.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06419 |
debian: CVE-2026-80533 was patched at 2026-09-16
2245.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80534) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xfs: fix ilock leak on error in xfs_dq_get_next_id xfs_dq_get_next_id() takes the quota inode ILOCK before calling xfs_iread_extents(). If xfs_iread_extents() fails, the function returns immediately without releasing the lock, leaking the quota inode ILOCK. This can leave the quota inode locked and cause subsequent quota operations to hang. Fix this by jumping to a common unlock path on error instead of returning directly.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: fix ilock leak on error in xfs_dq_get_next_id\n\nxfs_dq_get_next_id() takes the quota inode ILOCK before calling\nxfs_iread_extents(). If xfs_iread_extents() fails, the function returns\nimmediately without releasing the lock, leaking the quota inode ILOCK.\nThis can leave the quota inode locked and cause subsequent quota\noperations to hang.\n\nFix this by jumping to a common unlock path on error instead of returning\ndirectly.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07431 |
debian: CVE-2026-80534 was patched at 2026-09-16
oraclelinux: CVE-2026-80534 was patched at 2026-09-04
2246.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80535) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xfs: don't double-lock when deleting a self-referential directory LOLLM notices that the dirtree scrubber can detect a directory that refers to itself. In this case, it's not correct for the directory tree repair code to try to iolock/ilock both sc->ip and dp, because they're the same inode. Fix this by detecting that corner case and handling it appropriately.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: don't double-lock when deleting a self-referential directory\n\nLOLLM notices that the dirtree scrubber can detect a directory that\nrefers to itself. In this case, it's not correct for the directory tree\nrepair code to try to iolock/ilock both sc->ip and dp, because they're\nthe same inode. Fix this by detecting that corner case and handling it\nappropriately.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06406 |
debian: CVE-2026-80535 was patched at 2026-09-16
2247.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80539) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: disallow multiple FENCE chunks in one submit amdgpu_cs_pass1() dispatches on chunk_id once per chunk without rejecting repeated ids. p->uf_bo is a single-slot field, so a submission carrying two AMDGPU_CHUNK_ID_FENCE chunks runs amdgpu_cs_p1_user_fence() twice, and the second run overwrites p->uf_bo with a freshly referenced BO without dropping the reference taken by the first. amdgpu_cs_parser_fini() only unrefs the final p->uf_bo, so every FENCE chunk but the last leaks a BO reference. The leaked BO outlives handle close and process exit. Reject duplicate FENCE chunks the same way commit fec5f8e8c6bc ("drm/amdgpu: disallow multiple BO_HANDLES chunks in one submit") did for p->bo_list. (cherry picked from commit 665b1fc2a1845206408f9a2c6da67101789edb82)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: disallow multiple FENCE chunks in one submit\n\namdgpu_cs_pass1() dispatches on chunk_id once per chunk without\nrejecting repeated ids. p->uf_bo is a single-slot field, so a\nsubmission carrying two AMDGPU_CHUNK_ID_FENCE chunks runs\namdgpu_cs_p1_user_fence() twice, and the second run overwrites\np->uf_bo with a freshly referenced BO without dropping the reference\ntaken by the first.\n\namdgpu_cs_parser_fini() only unrefs the final p->uf_bo, so every FENCE\nchunk but the last leaks a BO reference. The leaked BO outlives handle\nclose and process exit.\n\nReject duplicate FENCE chunks the same way commit fec5f8e8c6bc\n("drm/amdgpu: disallow multiple BO_HANDLES chunks in one submit") did\nfor p->bo_list.\n\n(cherry picked from commit 665b1fc2a1845206408f9a2c6da67101789edb82)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06936 |
debian: CVE-2026-80539 was patched at 2026-09-16
2248.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80562) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: gpio: ml-ioh: use raw_spinlock_t for the register lock ioh_irq_type() is registered as the irq_chip .irq_set_type callback and takes chip->spinlock with spin_lock_irqsave(). This callback is reached from __setup_irq() -> __irq_set_trigger() -> chip->irq_set_type() while the caller holds desc->lock, a raw_spinlock_t, with hardirqs disabled. That context is not sleepable, but on PREEMPT_RT a regular spinlock_t is an rtmutex-backed sleeping lock, so acquiring it there is invalid. ioh_irq_enable() and ioh_irq_disable() take the same lock from the .irq_enable/.irq_disable callbacks, which are likewise invoked with desc->lock held. Convert the register lock to raw_spinlock_t. The same lock also serializes the GPIO direction/value callbacks and the suspend/resume register save/restore, and those critical sections only perform short sequences of MMIO register accesses (ioread32()/iowrite32()); the .irq_set_type callback additionally emits a dev_warn() on an unsupported type. None of these are sleepable operations, so keeping this register lock non-sleeping is appropriate for the irqchip callbacks and does not change the GPIO-side locking contract. This is the same fix as commit a02b8950d619 ("gpio: pch: use raw_spinlock_t for the register lock"); this driver shares the same structure as gpio-pch.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: ml-ioh: use raw_spinlock_t for the register lock\n\nioh_irq_type() is registered as the irq_chip .irq_set_type callback and\ntakes chip->spinlock with spin_lock_irqsave(). This callback is reached\nfrom __setup_irq() -> __irq_set_trigger() -> chip->irq_set_type() while\nthe caller holds desc->lock, a raw_spinlock_t, with hardirqs disabled.\nThat context is not sleepable, but on PREEMPT_RT a regular spinlock_t is\nan rtmutex-backed sleeping lock, so acquiring it there is invalid.\nioh_irq_enable() and ioh_irq_disable() take the same lock from the\n.irq_enable/.irq_disable callbacks, which are likewise invoked with\ndesc->lock held.\n\nConvert the register lock to raw_spinlock_t. The same lock also\nserializes the GPIO direction/value callbacks and the suspend/resume\nregister save/restore, and those critical sections only perform short\nsequences of MMIO register accesses (ioread32()/iowrite32()); the\n.irq_set_type callback additionally emits a dev_warn() on an unsupported\ntype. None of these are sleepable operations, so keeping this register\nlock non-sleeping is appropriate for the irqchip callbacks and does not\nchange the GPIO-side locking contract.\n\nThis is the same fix as commit a02b8950d619 ("gpio: pch: use\nraw_spinlock_t for the register lock"); this driver shares the same\nstructure as gpio-pch.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.0743 |
debian: CVE-2026-80562 was patched at 2026-08-29, 2026-09-16
2249.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80566) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Input: hynitron_cstxxx - validate touch count and finger IDs The driver allocates max_touch_num input slots, which are indexed from zero through max_touch_num - 1. The current check allows a finger ID equal to max_touch_num to reach cst3xx_report_contact(). While the input core ignores out-of-range slot indices, reporting touch data without a valid slot change corrupts the touch state of the previously active slot. The touch count is read from the controller's report and is used to index the fixed-size report buffer without first checking its range. Reject counts larger than the supported number of touch slots before checking the trailing byte or parsing touch data. Reject finger IDs equal to or greater than max_touch_num, and return immediately when an invalid finger ID is encountered so that corrupt touch frames are discarded instead of reporting partial contact state. The V821 Avaota F1 board configures the vendor driver with one touch slot, so finger ID 1 is already invalid on that device.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nInput: hynitron_cstxxx - validate touch count and finger IDs\n\nThe driver allocates max_touch_num input slots, which are indexed from\nzero through max_touch_num - 1. The current check allows a finger ID\nequal to max_touch_num to reach cst3xx_report_contact(). While the input\ncore ignores out-of-range slot indices, reporting touch data without a\nvalid slot change corrupts the touch state of the previously active slot.\n\nThe touch count is read from the controller's report and is used to\nindex the fixed-size report buffer without first checking its range.\nReject counts larger than the supported number of touch slots before\nchecking the trailing byte or parsing touch data.\n\nReject finger IDs equal to or greater than max_touch_num, and return\nimmediately when an invalid finger ID is encountered so that corrupt\ntouch frames are discarded instead of reporting partial contact state.\n\nThe V821 Avaota F1 board configures the vendor driver with one touch\nslot, so finger ID 1 is already invalid on that device.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05188 |
debian: CVE-2026-80566 was patched at 2026-09-16
2250.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80567) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue Previously, rmi_f54_buffer_queue() waited for the worker thread to finish but ignored whether it succeeded. If the worker failed (e.g., due to a timeout or register read failure), the queue thread would silently return success, delivering stale or uninitialized memory to userspace. Add a 'report_error' field to struct f54_data to store the worker's exit status. Check this field in rmi_f54_buffer_queue() after the worker finishes, and mark the buffer as VB2_BUF_STATE_ERROR if an error occurred.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue\n\nPreviously, rmi_f54_buffer_queue() waited for the worker thread to\nfinish but ignored whether it succeeded. If the worker failed (e.g.,\ndue to a timeout or register read failure), the queue thread would\nsilently return success, delivering stale or uninitialized memory to\nuserspace.\n\nAdd a 'report_error' field to struct f54_data to store the worker's exit\nstatus. Check this field in rmi_f54_buffer_queue() after the worker\nfinishes, and mark the buffer as VB2_BUF_STATE_ERROR if an error\noccurred.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.06036 |
debian: CVE-2026-80567 was patched at 2026-09-16
2251.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80573) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Input: iforce - validate input packet lengths iforce_process_packet() reads fixed fields from joystick, wheel and status packets without first checking their lengths. In particular, the shared hats-and-buttons helper unconditionally reads data[6]. The status tail is a sequence of 16-bit effect addresses, but an incomplete final address is also consumed. A successful zero-length USB URB additionally reads the packet ID before the common parser is called. Reject the zero-length USB transfer, require the seven-byte joystick and wheel prefixes and the two-byte status prefix, and consume only complete status-tail addresses.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nInput: iforce - validate input packet lengths\n\niforce_process_packet() reads fixed fields from joystick, wheel and\nstatus packets without first checking their lengths. In particular, the\nshared hats-and-buttons helper unconditionally reads data[6]. The status\ntail is a sequence of 16-bit effect addresses, but an incomplete final\naddress is also consumed. A successful zero-length USB URB additionally\nreads the packet ID before the common parser is called.\n\nReject the zero-length USB transfer, require the seven-byte joystick and\nwheel prefixes and the two-byte status prefix, and consume only complete\nstatus-tail addresses.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.06036 |
debian: CVE-2026-80573 was patched at 2026-09-16
2252.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80581) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout Ignore IPC errors for pipeline state change if the firmware state is crashed or the IPC has timed out. If the firmware has crashed the kernel still needs to go through the state changes to reset its internal to be able to correctly work the next time the DSP is booted up. The case with IPC timeout is a bit more problematic, but it has been rootcaused to be the result of system scheduling blockage and the firmware did actually received and handled the message, but the reply handling got blocked by issues outside of the SOF stack. So far the best way to handle this is to continue with setting the state.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout\n\nIgnore IPC errors for pipeline state change if the firmware state is\ncrashed or the IPC has timed out.\n\nIf the firmware has crashed the kernel still needs to go through the state\nchanges to reset its internal to be able to correctly work the next time\nthe DSP is booted up.\n\nThe case with IPC timeout is a bit more problematic, but it has been\nrootcaused to be the result of system scheduling blockage and the firmware\ndid actually received and handled the message, but the reply handling got\nblocked by issues outside of the SOF stack.\nSo far the best way to handle this is to continue with setting the state.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05186 |
debian: CVE-2026-80581 was patched at 2026-09-16
2253.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80594) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing The driver parses CDC union descriptors in ims_pcu_get_cdc_union_desc() by iterating through the extra descriptor data. However, it does not verify that the bLength of each descriptor is at least 2. A malicious device could provide a descriptor with bLength = 0, leading to an infinite loop in the driver. Add a check to ensure bLength is at least 2 before proceeding with parsing.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ims-pcu - fix potential infinite loop in CDC union descriptor parsing\n\nThe driver parses CDC union descriptors in ims_pcu_get_cdc_union_desc()\nby iterating through the extra descriptor data. However, it does not\nverify that the bLength of each descriptor is at least 2. A malicious\ndevice could provide a descriptor with bLength = 0, leading to an\ninfinite loop in the driver.\n\nAdd a check to ensure bLength is at least 2 before proceeding with\nparsing.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07426 |
debian: CVE-2026-80594 was patched at 2026-09-16
redos: CVE-2026-80594 was patched at 2026-09-16
2254.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80595) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - add response length checks The driver processes response data from device buffers without verifying that the device actually sent enough data. This can lead to out-of-bounds reads or processing stale data. Add checks for the expected response length before accessing the buffers.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nInput: ims-pcu - add response length checks\n\nThe driver processes response data from device buffers without verifying\nthat the device actually sent enough data. This can lead to\nout-of-bounds reads or processing stale data.\n\nAdd checks for the expected response length before accessing the\nbuffers.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07426 |
debian: CVE-2026-80595 was patched at 2026-09-16
redos: CVE-2026-80595 was patched at 2026-09-16
2255.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80602) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: perf/x86/amd/lbr: Fix kernel address leakage A user-only branch stack can contain branches that originate from the kernel. As a result, kernel addresses are exposed to user space even when PERF_SAMPLE_BRANCH_USER is requested. On AMD processors supporting X86_FEATURE_AMD_LBR_V2, perf can still report SYSRET/ERET entries for which the branch-from addresses are in the kernel. E.g. $ perf record -e cycles -o - -j any,save_type,u -- \\ perf bench syscall basic --loop 1000 | \\ perf script -i - -F brstack|tr ' ' '\\n'| \\ grep -E '0x[89a-f][0-9a-f]{15}' ... 0xffffffff81001268/0x717a90a38f1a/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH 0xffffffff81001268/0x717a90a39157/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH 0xffffffff81001268/0x717a90a2c628/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH 0xffffffff81001268/0x717a90a41b60/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH 0xffffffff81001268/0x717a90a260db/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH 0xffffffff81001268/0x717a90a260db/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH 0xffffffff81001268/0x717a8bef1c30/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH 0xffffffff81001268/0x717a8e4d3c90/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH ... The reason is that the hardware filter only considers the privilege level applicable to the branch target. Extend software filtering to also validate the branch-from addresses against br_sel, so that any branch record whose branch-from address is in the kernel is dropped when PERF_SAMPLE_BRANCH_USER is requested.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/amd/lbr: Fix kernel address leakage\n\nA user-only branch stack can contain branches that originate from\nthe kernel. As a result, kernel addresses are exposed to user space\neven when PERF_SAMPLE_BRANCH_USER is requested. On AMD processors\nsupporting X86_FEATURE_AMD_LBR_V2, perf can still report SYSRET/ERET\nentries for which the branch-from addresses are in the kernel.\n\nE.g.\n\n $ perf record -e cycles -o - -j any,save_type,u -- \\\n perf bench syscall basic --loop 1000 | \\\n perf script -i - -F brstack|tr ' ' '\\n'| \\\n grep -E '0x[89a-f][0-9a-f]{15}'\n\n ...\n 0xffffffff81001268/0x717a90a38f1a/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n 0xffffffff81001268/0x717a90a39157/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n 0xffffffff81001268/0x717a90a2c628/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n 0xffffffff81001268/0x717a90a41b60/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n 0xffffffff81001268/0x717a90a260db/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n 0xffffffff81001268/0x717a90a260db/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n 0xffffffff81001268/0x717a8bef1c30/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n 0xffffffff81001268/0x717a8e4d3c90/M/-/-/0/ERET/NON_SPEC_CORRECT_PATH\n ...\n\nThe reason is that the hardware filter only considers the privilege\nlevel applicable to the branch target. Extend software filtering to\nalso validate the branch-from addresses against br_sel, so that any\nbranch record whose branch-from address is in the kernel is dropped\nwhen PERF_SAMPLE_BRANCH_USER is requested.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.0641 |
debian: CVE-2026-80602 was patched at 2026-09-16
2256.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80607) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg Sashiko found that user can cause this WARN_ON_ONCE() easily with adding a kprobe event based on a raw address with BTF parameter. Since this is not an unexpected condition, remove the WARN_ON_ONCE().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/probes: Remove WARN_ON_ONCE from parse_btf_arg\n\nSashiko found that user can cause this WARN_ON_ONCE() easily\nwith adding a kprobe event based on a raw address with BTF\nparameter.\n\nSince this is not an unexpected condition, remove the\nWARN_ON_ONCE().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06218 |
debian: CVE-2026-80607 was patched at 2026-09-16
2257.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80611) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ACPI: processor_idle: Mark LPI enter functions as __cpuidle When function tracing or Kprobes is enabled, entering an ACPI Low Power Idle (LPI) state triggers the following RCU splat: RCU not on for: acpi_idle_lpi_enter+0x4/0xd8 WARNING: CPU: 8 PID: 0 at include/linux/trace_recursion.h:162 function_trace_call+0x1e8/0x228 The acpi_idle_lpi_enter() function is invoked within the cpuidle path after RCU has already been disabled for the current local CPU. Consequently, ftrace's function_trace_call() expects RCU to be actively watching before recording trace data, emitting a warning if it is not. Fix this by annotating acpi_idle_lpi_enter(), the generic __weak stub, and the RISC-V implementation of acpi_processor_ffh_lpi_enter() with __cpuidle. This moves these functions into the '.cpuidle.text' section, implicitly disabling ftrace instrumentation (notrace) along this sensitive path and preventing trace-induced RCU warnings during idle entry.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: processor_idle: Mark LPI enter functions as __cpuidle\n\nWhen function tracing or Kprobes is enabled, entering an ACPI Low\nPower Idle (LPI) state triggers the following RCU splat:\n\n RCU not on for: acpi_idle_lpi_enter+0x4/0xd8\n WARNING: CPU: 8 PID: 0 at include/linux/trace_recursion.h:162 function_trace_call+0x1e8/0x228\n\nThe acpi_idle_lpi_enter() function is invoked within the cpuidle\npath after RCU has already been disabled for the current local CPU.\nConsequently, ftrace's function_trace_call() expects RCU to be\nactively watching before recording trace data, emitting a warning\nif it is not.\n\nFix this by annotating acpi_idle_lpi_enter(), the generic __weak\nstub, and the RISC-V implementation of acpi_processor_ffh_lpi_enter()\nwith __cpuidle. This moves these functions into the '.cpuidle.text'\nsection, implicitly disabling ftrace instrumentation (notrace) along\nthis sensitive path and preventing trace-induced RCU warnings during\nidle entry.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.0641 |
debian: CVE-2026-80611 was patched at 2026-09-16
2258.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80616) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns() It's pointless to call WARN_ON() in case of an allocation failure in dev_change_net_namespace() and device_rename(), since it only leads to useless splats caused by deliberate fault injections, so avoid it. Found by Linux Verification Center (linuxtesting.org) with Syzkaller.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns()\n\nIt's pointless to call WARN_ON() in case of an allocation failure in\ndev_change_net_namespace() and device_rename(), since it only leads to\nuseless splats caused by deliberate fault injections, so avoid it.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00178, EPSS Percentile is 0.07629 |
debian: CVE-2026-80616 was patched at 2026-09-16
2259.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80618) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free amdgpu_amdkfd_gpuvm_free_memory_of_gpu() unpinned DOORBELL and MMIO remap BOs (which are pinned at allocation time) before checking whether the BO is still mapped to the GPU. When the BO is still mapped, the function returns -EBUSY and leaves the BO alive, but it has already been unpinned. The BO is then unpinned again when it is finally freed during process teardown, triggering a ttm_bo_unpin() underflow warning: WARNING: CPU: 18 PID: 15066 at ttm/ttm_bo.c:650 amdttm_bo_unpin+0x6d/0x80 [amdttm] Workqueue: kfd_process_wq kfd_process_wq_release [amdgpu] RIP: 0010:amdttm_bo_unpin+0x6d/0x80 [amdttm] Call Trace: amdgpu_bo_unpin+0x1a/0x90 [amdgpu] amdgpu_amdkfd_gpuvm_unpin_bo+0x31/0xb0 [amdgpu] amdgpu_amdkfd_gpuvm_free_memory_of_gpu+0x3bf/0x460 [amdgpu] kfd_process_free_outstanding_kfd_bos+0xd4/0x170 [amdgpu] kfd_process_wq_release+0x109/0x1b0 [amdgpu] process_one_work+0x1e2/0x3b0 worker_thread+0x50/0x3a0 kthread+0xdd/0x100 ret_from_fork+0x29/0x50 Move the unpin after the mapped_to_gpu_memory check so it only happens once we are committed to freeing the BO. (cherry picked from commit 927c5b2defb9b09856444d94bebfd056a002bd75)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free\n\namdgpu_amdkfd_gpuvm_free_memory_of_gpu() unpinned DOORBELL and MMIO\nremap BOs (which are pinned at allocation time) before checking whether\nthe BO is still mapped to the GPU. When the BO is still mapped, the\nfunction returns -EBUSY and leaves the BO alive, but it has already\nbeen unpinned. The BO is then unpinned again when it is finally freed\nduring process teardown, triggering a ttm_bo_unpin() underflow warning:\n\n WARNING: CPU: 18 PID: 15066 at ttm/ttm_bo.c:650 amdttm_bo_unpin+0x6d/0x80 [amdttm]\n Workqueue: kfd_process_wq kfd_process_wq_release [amdgpu]\n RIP: 0010:amdttm_bo_unpin+0x6d/0x80 [amdttm]\n Call Trace:\n amdgpu_bo_unpin+0x1a/0x90 [amdgpu]\n amdgpu_amdkfd_gpuvm_unpin_bo+0x31/0xb0 [amdgpu]\n amdgpu_amdkfd_gpuvm_free_memory_of_gpu+0x3bf/0x460 [amdgpu]\n kfd_process_free_outstanding_kfd_bos+0xd4/0x170 [amdgpu]\n kfd_process_wq_release+0x109/0x1b0 [amdgpu]\n process_one_work+0x1e2/0x3b0\n worker_thread+0x50/0x3a0\n kthread+0xdd/0x100\n ret_from_fork+0x29/0x50\n\nMove the unpin after the mapped_to_gpu_memory check so it only happens\nonce we are committed to freeing the BO.\n\n(cherry picked from commit 927c5b2defb9b09856444d94bebfd056a002bd75)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06935 |
debian: CVE-2026-80618 was patched at 2026-09-16
redos: CVE-2026-80618 was patched at 2026-09-16
2260.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80623) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: coresight: ete: Always save state on power down System register ETMs and ETE are unlikely to be preserved on CPU power down. The ETE DT binding also never documented "arm,coresight-loses-context-with-cpu" so nobody would have legitimately been able to use that binding to fix it and ACPI has no such binding at all. Fix it by hard coding the setting for sysreg ETMs (ETE is always sysreg) or ACPI boots. Use a local variable when setting up save_state so that it's immune to concurrent probing when devices have different configurations which is an issue with modifying the global. This fixes the following error when using Coresight with ACPI on the FVP which supports CPU PM: coresight ete0: External agent took claim tag WARNING: drivers/hwtracing/coresight/coresight-core.c:248 at coresight_disclaim_device_unlocked+0xe0/0xe8, CPU#0: perf/117', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncoresight: ete: Always save state on power down\n\nSystem register ETMs and ETE are unlikely to be preserved on CPU power\ndown. The ETE DT binding also never documented\n"arm,coresight-loses-context-with-cpu" so nobody would have legitimately\nbeen able to use that binding to fix it and ACPI has no such binding at\nall.\n\nFix it by hard coding the setting for sysreg ETMs (ETE is always sysreg)\nor ACPI boots. Use a local variable when setting up save_state so that\nit's immune to concurrent probing when devices have different\nconfigurations which is an issue with modifying the global.\n\nThis fixes the following error when using Coresight with ACPI on the FVP\nwhich supports CPU PM:\n\n coresight ete0: External agent took claim tag\n WARNING: drivers/hwtracing/coresight/coresight-core.c:248 at coresight_disclaim_device_unlocked+0xe0/0xe8, CPU#0: perf/117', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06224 |
debian: CVE-2026-80623 was patched at 2026-09-16
2261.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80626) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del fsl_emb_pmu_del() unconditionally calls put_cpu_var(cpu_hw_events) at the 'out:' label, but only calls the matching get_cpu_var() after the 'i < 0' early-return check. When event->hw.idx is negative the function jumps to 'out:' without having taken get_cpu_var(), and the trailing put_cpu_var() then issues an unmatched preempt_enable(), underflowing preempt_count. On a CONFIG_PREEMPT=y kernel preempt_count would underflow and eventually present as a 'scheduling while atomic' BUG. Move put_cpu_var() to pair with get_cpu_var() so the percpu access is correctly bracketed and the 'out:' label only handles perf_pmu_enable.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/perf: fix preempt count underflow in fsl_emb_pmu_del\n\nfsl_emb_pmu_del() unconditionally calls put_cpu_var(cpu_hw_events) at\nthe 'out:' label, but only calls the matching get_cpu_var() after the\n'i < 0' early-return check. When event->hw.idx is negative the\nfunction jumps to 'out:' without having taken get_cpu_var(), and the\ntrailing put_cpu_var() then issues an unmatched preempt_enable(),\nunderflowing preempt_count.\n\nOn a CONFIG_PREEMPT=y kernel preempt_count would underflow and\neventually present as a 'scheduling while atomic' BUG.\n\nMove put_cpu_var() to pair with get_cpu_var() so the percpu access is\ncorrectly bracketed and the 'out:' label only handles perf_pmu_enable.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07429 |
debian: CVE-2026-80626 was patched at 2026-09-16
redos: CVE-2026-80626 was patched at 2026-09-16
2262.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80629) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: npc: Fix size of entry2cntr_map KASAN prints below splat. This is caused by allocating counter for reserved mcam entry for cpt 2nd pass entry. But mcam->entry2cntr_map is not allocated for reserved entries. BUG: KASAN: slab-out-of-bounds in npc_map_mcam_entry_and_cntr+0xb0/0x1a0 Write of size 2 at addr ffff0001033e7ffe by task kworker/0:1/14 CPU: 0 PID: 14 Comm: kworker/0:1 Not tainted 6.1.67 #1 Hardware name: Marvell CN106XX board (DT) Workqueue: events work_for_cpu_fn Call trace: dump_backtrace.part.0+0xe4/0xf0 show_stack+0x18/0x30 dump_stack_lvl+0x88/0xb4 print_report+0x154/0x458 kasan_report+0xb8/0x194 __asan_store2+0x7c/0xa0 npc_map_mcam_entry_and_cntr+0xb0/0x1a0 rvu_mbox_handler_npc_mcam_write_entry+0x268/0x280 npc_install_flow+0x840/0xfe0 rvu_npc_install_cpt_pass2_entry+0x138/0x190 rvu_nix_init+0x148c/0x2880 rvu_probe+0x1800/0x30b0 local_pci_probe+0x78/0xe0 work_for_cpu_fn+0x30/0x50 process_one_work+0x4cc/0x97c worker_thread+0x360/0x630 kthread+0x1a0/0x1b0 ret_from_fork+0x10/0x20', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-af: npc: Fix size of entry2cntr_map\n\nKASAN prints below splat. This is caused by allocating counter for\nreserved mcam entry for cpt 2nd pass entry. But mcam->entry2cntr_map\nis not allocated for reserved entries.\n\nBUG: KASAN: slab-out-of-bounds in npc_map_mcam_entry_and_cntr+0xb0/0x1a0\nWrite of size 2 at addr ffff0001033e7ffe by task kworker/0:1/14\n\nCPU: 0 PID: 14 Comm: kworker/0:1 Not tainted 6.1.67 #1\nHardware name: Marvell CN106XX board (DT)\nWorkqueue: events work_for_cpu_fn\nCall trace:\n dump_backtrace.part.0+0xe4/0xf0\n show_stack+0x18/0x30\n dump_stack_lvl+0x88/0xb4\n print_report+0x154/0x458\n kasan_report+0xb8/0x194\n __asan_store2+0x7c/0xa0\n npc_map_mcam_entry_and_cntr+0xb0/0x1a0\n rvu_mbox_handler_npc_mcam_write_entry+0x268/0x280\n npc_install_flow+0x840/0xfe0\n rvu_npc_install_cpt_pass2_entry+0x138/0x190\n rvu_nix_init+0x148c/0x2880\n rvu_probe+0x1800/0x30b0\n local_pci_probe+0x78/0xe0\n work_for_cpu_fn+0x30/0x50\n process_one_work+0x4cc/0x97c\n worker_thread+0x360/0x630\n kthread+0x1a0/0x1b0\n ret_from_fork+0x10/0x20', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.0642 |
debian: CVE-2026-80629 was patched at 2026-09-16
2263.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80643) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: EDAC/igen6: Fix call trace due to missing release() When unloading the igen6_edac driver, there is a call trace: Device '(null)' does not have a release() function, it is broken and must be fixed. See Documentation/core-api/kobject.rst. WARNING: drivers/base/core.c:2567 at device_release+0x84/0x90, CPU#5: rmmod/127209 ... RIP: 0010:device_release+0x84/0x90 Call Trace: <TASK> kobject_put+0x8c/0x220 put_device+0x17/0x30 igen6_unregister_mcis+0xa2/0xe0 [igen6_edac] igen6_remove+0x82/0xb0 [igen6_edac] ... Fix the call trace by providing empty release() functions for the memory controller devices.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nEDAC/igen6: Fix call trace due to missing release()\n\nWhen unloading the igen6_edac driver, there is a call trace:\n\n Device '(null)' does not have a release() function, it is broken and must be fixed.\n See Documentation/core-api/kobject.rst.\n WARNING: drivers/base/core.c:2567 at device_release+0x84/0x90, CPU#5: rmmod/127209\n ...\n RIP: 0010:device_release+0x84/0x90\n Call Trace:\n <TASK>\n kobject_put+0x8c/0x220\n put_device+0x17/0x30\n igen6_unregister_mcis+0xa2/0xe0 [igen6_edac]\n igen6_remove+0x82/0xb0 [igen6_edac]\n ...\n\nFix the call trace by providing empty release() functions for the\nmemory controller devices.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06223 |
debian: CVE-2026-80643 was patched at 2026-09-16
2264.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80644) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ocfs2: don't BUG_ON an invalid journal dinode [BUG] A fuzzed OCFS2 image can corrupt the current slot journal dinode while mount is still in progress. The mount path first reports the invalid journal block and then crashes in shutdown: kernel BUG at fs/ocfs2/journal.c:1034! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI RIP: 0010:ocfs2_journal_toggle_dirty+0x2d6/0x340 fs/ocfs2/journal.c:1034 Call Trace: ocfs2_journal_shutdown+0x414/0xc30 fs/ocfs2/journal.c:1116 ocfs2_mount_volume fs/ocfs2/super.c:1785 [inline] ocfs2_fill_super+0x30a9/0x3cd0 fs/ocfs2/super.c:1083 get_tree_bdev_flags+0x38b/0x640 fs/super.c:1698 get_tree_bdev+0x24/0x40 fs/super.c:1721 ocfs2_get_tree+0x21/0x30 fs/ocfs2/super.c:1184 vfs_get_tree+0x9a/0x370 fs/super.c:1758 fc_mount fs/namespace.c:1199 [inline] do_new_mount_fc fs/namespace.c:3642 [inline] do_new_mount fs/namespace.c:3718 [inline] path_mount+0x5b8/0x1ea0 fs/namespace.c:4028 do_mount fs/namespace.c:4041 [inline] __do_sys_mount fs/namespace.c:4229 [inline] __se_sys_mount fs/namespace.c:4206 [inline] __x64_sys_mount+0x282/0x320 fs/namespace.c:4206 ... [CAUSE] ocfs2_journal_toggle_dirty() used to return -EIO when journal->j_bh no longer contained a valid dinode, because the startup and shutdown paths already handled that failure. Commit 10995aa2451a ("ocfs2: Morph the haphazard OCFS2_IS_VALID_DINODE() checks.") changed the check to a BUG_ON() under the assumption that the journal dinode had already been validated. That turns an unexpected invalid journal dinode during mount teardown into a kernel crash instead of a normal mount failure. [FIX] Replace the BUG_ON() with WARN_ON() and return -EIO. This keeps the invariant warning for debugging, but restores the original behavior of failing startup or shutdown cleanly instead of panicking the kernel.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: don't BUG_ON an invalid journal dinode\n\n[BUG]\nA fuzzed OCFS2 image can corrupt the current slot journal dinode while\nmount is still in progress. The mount path first reports the invalid\njournal block and then crashes in shutdown:\n\nkernel BUG at fs/ocfs2/journal.c:1034!\nOops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\nRIP: 0010:ocfs2_journal_toggle_dirty+0x2d6/0x340 fs/ocfs2/journal.c:1034\nCall Trace:\n ocfs2_journal_shutdown+0x414/0xc30 fs/ocfs2/journal.c:1116\n ocfs2_mount_volume fs/ocfs2/super.c:1785 [inline]\n ocfs2_fill_super+0x30a9/0x3cd0 fs/ocfs2/super.c:1083\n get_tree_bdev_flags+0x38b/0x640 fs/super.c:1698\n get_tree_bdev+0x24/0x40 fs/super.c:1721\n ocfs2_get_tree+0x21/0x30 fs/ocfs2/super.c:1184\n vfs_get_tree+0x9a/0x370 fs/super.c:1758\n fc_mount fs/namespace.c:1199 [inline]\n do_new_mount_fc fs/namespace.c:3642 [inline]\n do_new_mount fs/namespace.c:3718 [inline]\n path_mount+0x5b8/0x1ea0 fs/namespace.c:4028\n do_mount fs/namespace.c:4041 [inline]\n __do_sys_mount fs/namespace.c:4229 [inline]\n __se_sys_mount fs/namespace.c:4206 [inline]\n __x64_sys_mount+0x282/0x320 fs/namespace.c:4206\n ...\n\n[CAUSE]\nocfs2_journal_toggle_dirty() used to return -EIO when journal->j_bh no\nlonger contained a valid dinode, because the startup and shutdown paths\nalready handled that failure. Commit 10995aa2451a\n("ocfs2: Morph the haphazard OCFS2_IS_VALID_DINODE() checks.") changed\nthe check to a BUG_ON() under the assumption that the journal dinode had\nalready been validated. That turns an unexpected invalid journal dinode\nduring mount teardown into a kernel crash instead of a normal mount\nfailure.\n\n[FIX]\nReplace the BUG_ON() with WARN_ON() and return -EIO. This keeps the\ninvariant warning for debugging, but restores the original behavior of\nfailing startup or shutdown cleanly instead of panicking the kernel.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07428 |
debian: CVE-2026-80644 was patched at 2026-09-16
oraclelinux: CVE-2026-80644 was patched at 2026-09-04
redos: CVE-2026-80644 was patched at 2026-09-16
2265.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80647) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix warning in poll cq direct mode CQs allocated by ib_alloc_cq() always have a comp_handler. Though in direct mode this handler is never expected to be called, it is still called when the driver is reset, triggering the following WARN_ONCE(): Call trace: ib_cq_completion_direct+0x38/0x60 hns_roce_cq_completion+0x54/0x90 (hns_roce_hw_v2] hns_roce_handle_device_err+Ox1c8/0x340 [hns_roce_hw_v2] hns_roce_hw_v2_uninit_instance.constprop.0+0x34/0x70 [hns_roce_hw_v2] hns_roce_hw_v2_reset_notify+0xc4/0xe0 [hns_roce_hw_v2] hclge_notify_roce_client+0x60/0xbc [hclge] hclge_reset_rebuild+0x48/0x34c [hclge] hclge_reset_subtask+0xcc/0xec [hclge] hclge_reset_service_task+0x80/0x160 [hclge] hclge_service_task+0x50/0x80 (hclge] process_one_work+0x1cc/0x4d0 worker_thread+0x154/0x414 kthread+0x104/0x144 ret_from_fork+0x10/0x18', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hns: Fix warning in poll cq direct mode\n\nCQs allocated by ib_alloc_cq() always have a comp_handler. Though\nin direct mode this handler is never expected to be called, it\nis still called when the driver is reset, triggering the following\nWARN_ONCE():\n\nCall trace:\nib_cq_completion_direct+0x38/0x60\nhns_roce_cq_completion+0x54/0x90 (hns_roce_hw_v2]\nhns_roce_handle_device_err+Ox1c8/0x340 [hns_roce_hw_v2]\nhns_roce_hw_v2_uninit_instance.constprop.0+0x34/0x70 [hns_roce_hw_v2]\nhns_roce_hw_v2_reset_notify+0xc4/0xe0 [hns_roce_hw_v2]\nhclge_notify_roce_client+0x60/0xbc [hclge]\nhclge_reset_rebuild+0x48/0x34c [hclge]\nhclge_reset_subtask+0xcc/0xec [hclge]\nhclge_reset_service_task+0x80/0x160 [hclge]\nhclge_service_task+0x50/0x80 (hclge]\nprocess_one_work+0x1cc/0x4d0\nworker_thread+0x154/0x414\nkthread+0x104/0x144\nret_from_fork+0x10/0x18', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07428 |
debian: CVE-2026-80647 was patched at 2026-09-16
redos: CVE-2026-80647 was patched at 2026-09-16
2266.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80652) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Treat zero-length cert chain as query for blob lengths When handling a PDH export, treat a zero-length userspace cert chain buffer as a request to query the length of the relevant blobs. Failure to account for the zero-length buffer trips a BUG_ON() when running with CONFIG_DEBUG_VIRTUAL=y due to trying to get the physical address of the ZERO_SIZE_PTR (returned by kzalloc() on the bogus allocation). kernel BUG at arch/x86/mm/physaddr.c:28 ! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI CPU: 30 UID: 0 PID: 28580 Comm: syz.2.18 Kdump: loaded Tainted: G W 6.18.16-smp-DEV #1 NONE Tainted: [W]=WARN Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 12.62.0-0 11/19/2025 RIP: 0010:__phys_addr+0x16a/0x180 arch/x86/mm/physaddr.c:28 RSP: 0018:ffffc9008329fc80 EFLAGS: 00010293 RAX: ffffffff8179110a RBX: 0000778000000010 RCX: ffff8884e6992600 RDX: 0000000000000000 RSI: 0000000080000010 RDI: 0000778000000010 RBP: ffffc9008329fdf0 R08: 0000000000000dc0 R09: 00000000ffffffff R10: dffffc0000000000 R11: fffffbfff126d297 R12: dffffc0000000000 R13: 1ffff92010653fc8 R14: 0000000080000010 R15: dffffc0000000000 FS: 0000555556bec9c0(0000) GS:ffff88aa4ce1c000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fd3159e7000 CR3: 00000004fbc44000 CR4: 0000000000350ef0 Call Trace: <TASK> [<ffffffff853d3869>] sev_ioctl_do_pdh_export+0x559/0x7a0 drivers/crypto/ccp/sev-dev.c:2308 [<ffffffff853d1fdd>] sev_ioctl+0x2cd/0x480 drivers/crypto/ccp/sev-dev.c:2556 [<ffffffff82549ebc>] vfs_ioctl fs/ioctl.c:52 [inline] [<ffffffff82549ebc>] __do_sys_ioctl fs/ioctl.c:598 [inline] [<ffffffff82549ebc>] __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:584 [<ffffffff8630115f>] do_syscall_x64 arch/x86/entry/syscall_64.c:64 [inline] [<ffffffff8630115f>] do_syscall_64+0x9f/0xf40 arch/x86/entry/syscall_64.c:98 [<ffffffff81000136>] entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7fd3158eac39 </TASK> Thankfully, the bug is benign outside of CONFIG_DEBUG_VIRTUAL=y as getting the physical address is just arithmetic, and the PSP errors out before trying to write to the garbage address (which it must, otherwise querying the blob lengths would clobber memory at pfn=0).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp - Treat zero-length cert chain as query for blob lengths\n\nWhen handling a PDH export, treat a zero-length userspace cert chain buffer\nas a request to query the length of the relevant blobs. Failure to account\nfor the zero-length buffer trips a BUG_ON() when running with\nCONFIG_DEBUG_VIRTUAL=y due to trying to get the physical address of the\nZERO_SIZE_PTR (returned by kzalloc() on the bogus allocation).\n\n kernel BUG at arch/x86/mm/physaddr.c:28 !\n Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\n CPU: 30 UID: 0 PID: 28580 Comm: syz.2.18 Kdump: loaded\n Tainted: G W 6.18.16-smp-DEV #1 NONE\n Tainted: [W]=WARN\n Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 12.62.0-0 11/19/2025\n RIP: 0010:__phys_addr+0x16a/0x180 arch/x86/mm/physaddr.c:28\n RSP: 0018:ffffc9008329fc80 EFLAGS: 00010293\n RAX: ffffffff8179110a RBX: 0000778000000010 RCX: ffff8884e6992600\n RDX: 0000000000000000 RSI: 0000000080000010 RDI: 0000778000000010\n RBP: ffffc9008329fdf0 R08: 0000000000000dc0 R09: 00000000ffffffff\n R10: dffffc0000000000 R11: fffffbfff126d297 R12: dffffc0000000000\n R13: 1ffff92010653fc8 R14: 0000000080000010 R15: dffffc0000000000\n FS: 0000555556bec9c0(0000) GS:ffff88aa4ce1c000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007fd3159e7000 CR3: 00000004fbc44000 CR4: 0000000000350ef0\n Call Trace:\n <TASK>\n [<ffffffff853d3869>] sev_ioctl_do_pdh_export+0x559/0x7a0 drivers/crypto/ccp/sev-dev.c:2308\n [<ffffffff853d1fdd>] sev_ioctl+0x2cd/0x480 drivers/crypto/ccp/sev-dev.c:2556\n [<ffffffff82549ebc>] vfs_ioctl fs/ioctl.c:52 [inline]\n [<ffffffff82549ebc>] __do_sys_ioctl fs/ioctl.c:598 [inline]\n [<ffffffff82549ebc>] __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:584\n [<ffffffff8630115f>] do_syscall_x64 arch/x86/entry/syscall_64.c:64 [inline]\n [<ffffffff8630115f>] do_syscall_64+0x9f/0xf40 arch/x86/entry/syscall_64.c:98\n [<ffffffff81000136>] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n RIP: 0033:0x7fd3158eac39\n </TASK>\n\nThankfully, the bug is benign outside of CONFIG_DEBUG_VIRTUAL=y as getting\nthe physical address is just arithmetic, and the PSP errors out before\ntrying to write to the garbage address (which it must, otherwise querying\nthe blob lengths would clobber memory at pfn=0).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07427 |
debian: CVE-2026-80652 was patched at 2026-09-16
oraclelinux: CVE-2026-80652 was patched at 2026-09-04
redos: CVE-2026-80652 was patched at 2026-09-16
2267.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80654) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: soc: xilinx: Shutdown and free rx mailbox channel A mbox rx channel is requested using mbox_request_channel_byname() in probe. In remove callback, the rx mailbox channel is cleaned up when the rx_chan is NULL due to incorrect condition check. The mailbox channel is not shutdown and it can receive messages even after the device removal. This leads to use after free. Also the channel resources are not freed. Fix this by checking the rx_chan correctly.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: xilinx: Shutdown and free rx mailbox channel\n\nA mbox rx channel is requested using mbox_request_channel_byname() in\nprobe. In remove callback, the rx mailbox channel is cleaned up when the\nrx_chan is NULL due to incorrect condition check. The mailbox channel is\nnot shutdown and it can receive messages even after the device removal.\nThis leads to use after free. Also the channel resources are not freed.\nFix this by checking the rx_chan correctly.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06415 |
debian: CVE-2026-80654 was patched at 2026-09-16
2268.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80659) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mmc: vub300: defer reset until cmd_mutex is unlocked vub300_cmndwork_thread() holds cmd_mutex while it sends a command and waits for the command response. If the response wait times out, __vub300_command_response() kills the command URBs and then synchronously resets the USB device through usb_reset_device(). That reset path re-enters the driver through vub300_pre_reset(), which also takes cmd_mutex. The worker therefore tries to acquire the same mutex recursively while it is still holding it from the command path. This issue was found by our static analysis tool and then manually reviewed against the current tree. The grounded PoC kept the real worker and timeout/reset carrier: vub300_cmndwork_thread() __vub300_command_response() usb_lock_device_for_reset() usb_reset_device() vub300_pre_reset() Lockdep reported the same-task recursive acquisition on cmd_mutex: WARNING: possible recursive locking detected ... (&test_vub300.cmd_mutex) ... at: usb_reset_device... [vuln_msv] ... (&test_vub300.cmd_mutex) ... at: vub300_cmndwork_thread+0x12/0x20 [vuln_msv] Workqueue: vub300_cmd_wq vub300_cmndwork_thread [vuln_msv] *** DEADLOCK *** Return a flag from __vub300_command_response() when the timeout path needs a device reset, then perform the reset after vub300_cmndwork_thread() has cleared the in-flight command state and dropped cmd_mutex. The reset is still attempted before mmc_request_done(), preserving the existing request completion ordering while avoiding the recursive lock.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: vub300: defer reset until cmd_mutex is unlocked\n\nvub300_cmndwork_thread() holds cmd_mutex while it sends a command and\nwaits for the command response. If the response wait times out,\n__vub300_command_response() kills the command URBs and then synchronously\nresets the USB device through usb_reset_device().\n\nThat reset path re-enters the driver through vub300_pre_reset(), which\nalso takes cmd_mutex. The worker therefore tries to acquire the same\nmutex recursively while it is still holding it from the command path.\n\nThis issue was found by our static analysis tool and then manually\nreviewed against the current tree.\n\nThe grounded PoC kept the real worker and timeout/reset carrier:\n\n vub300_cmndwork_thread()\n __vub300_command_response()\n usb_lock_device_for_reset()\n usb_reset_device()\n vub300_pre_reset()\n\nLockdep reported the same-task recursive acquisition on cmd_mutex:\n\n WARNING: possible recursive locking detected\n ... (&test_vub300.cmd_mutex) ... at: usb_reset_device... [vuln_msv]\n ... (&test_vub300.cmd_mutex) ... at: vub300_cmndwork_thread+0x12/0x20 [vuln_msv]\n Workqueue: vub300_cmd_wq vub300_cmndwork_thread [vuln_msv]\n *** DEADLOCK ***\n\nReturn a flag from __vub300_command_response() when the timeout path needs\na device reset, then perform the reset after vub300_cmndwork_thread() has\ncleared the in-flight command state and dropped cmd_mutex. The reset is\nstill attempted before mmc_request_done(), preserving the existing request\ncompletion ordering while avoiding the recursive lock.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07837 |
debian: CVE-2026-80659 was patched at 2026-09-16
oraclelinux: CVE-2026-80659 was patched at 2026-09-04
redos: CVE-2026-80659 was patched at 2026-09-16
2269.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80660) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: hwmon: (occ) unregister sysfs devices outside occ lock occ_active(false) and occ_shutdown() unregister sysfs-backed devices while occ->lock is held. hwmon_device_unregister() and sysfs_remove_group() can wait for active sysfs callbacks to drain, and those callbacks can enter the OCC update path and try to take occ->lock again. That gives the unregister paths the lock ordering occ->lock -> sysfs callback drain, while a callback has the opposite edge sysfs callback -> occ->lock. This issue was found by our static analysis tool and then manually reviewed against the current tree. The grounded PoC kept the real unregister and callback carrier: occ_shutdown() hwmon_device_unregister() occ_show_temp_1() occ_update_response() Lockdep reported the circular dependency with occ_shutdown() already holding the OCC mutex and hwmon_device_unregister() waiting on the sysfs side: WARNING: possible circular locking dependency detected ... (sysfs_lock) ... at: hwmon_device_unregister+0x12/0x30 [vuln_msv] ... (&test_occ.lock) ... at: occ_shutdown.constprop.0+0xe/0x40 [vuln_msv] occ_update_response.isra.0+0xb/0x20 [vuln_msv] occ_show_temp_1.constprop.0.isra.0+0x23/0x40 [vuln_msv] *** DEADLOCK *** Serialize hwmon registration and removal with a separate hwmon_lock. Under that lock, detach occ->hwmon and update occ->active while occ->lock is held so concurrent OCC state changes still see a stable state, then drop occ->lock before calling hwmon_device_unregister(). Remove the driver sysfs group before taking occ->lock in occ_shutdown(), so draining the driver attributes cannot wait while the OCC mutex is held. Also make OCC update callbacks return -ENODEV after deactivation, so callbacks that already passed sysfs active protection do not poll the hardware after teardown has detached the hwmon device.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (occ) unregister sysfs devices outside occ lock\n\nocc_active(false) and occ_shutdown() unregister sysfs-backed devices while\nocc->lock is held. hwmon_device_unregister() and sysfs_remove_group() can\nwait for active sysfs callbacks to drain, and those callbacks can enter the\nOCC update path and try to take occ->lock again. That gives the unregister\npaths the lock ordering occ->lock -> sysfs callback drain, while a callback\nhas the opposite edge sysfs callback -> occ->lock.\n\nThis issue was found by our static analysis tool and then manually\nreviewed against the current tree.\n\nThe grounded PoC kept the real unregister and callback carrier:\n\n occ_shutdown()\n hwmon_device_unregister()\n occ_show_temp_1()\n occ_update_response()\n\nLockdep reported the circular dependency with occ_shutdown() already\nholding the OCC mutex and hwmon_device_unregister() waiting on the sysfs\nside:\n\n WARNING: possible circular locking dependency detected\n ... (sysfs_lock) ... at: hwmon_device_unregister+0x12/0x30 [vuln_msv]\n ... (&test_occ.lock) ... at: occ_shutdown.constprop.0+0xe/0x40 [vuln_msv]\n occ_update_response.isra.0+0xb/0x20 [vuln_msv]\n occ_show_temp_1.constprop.0.isra.0+0x23/0x40 [vuln_msv]\n *** DEADLOCK ***\n\nSerialize hwmon registration and removal with a separate hwmon_lock.\nUnder that lock, detach occ->hwmon and update occ->active while occ->lock\nis held so concurrent OCC state changes still see a stable state, then\ndrop occ->lock before calling hwmon_device_unregister(). Remove the\ndriver sysfs group before taking occ->lock in occ_shutdown(), so draining\nthe driver attributes cannot wait while the OCC mutex is held. Also make\nOCC update callbacks return -ENODEV after deactivation, so callbacks that\nalready passed sysfs active protection do not poll the hardware after\nteardown has detached the hwmon device.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06936 |
debian: CVE-2026-80660 was patched at 2026-09-16
redos: CVE-2026-80660 was patched at 2026-09-16
2270.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80667) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/mlx5: LAG, MPESW, Fix missing complete() on devcom error mlx5_mpesw_work() returned without calling complete() when mlx5_lag_get_devcom_comp() returned NULL. A caller that queued the work and waited on mpesww->comp would block indefinitely. Funnel the early-return path through a new "complete" label so the waiter is always woken.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: LAG, MPESW, Fix missing complete() on devcom error\n\nmlx5_mpesw_work() returned without calling complete() when\nmlx5_lag_get_devcom_comp() returned NULL. A caller that queued the\nwork and waited on mpesww->comp would block indefinitely.\n\nFunnel the early-return path through a new "complete" label so the\nwaiter is always woken.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06418 |
debian: CVE-2026-80667 was patched at 2026-09-16
2271.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80669) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: bpf: Disable xfrm_decode_session hook attachment BPF LSM programs can currently attach to xfrm_decode_session(). That hook may return an error, but security_skb_classify_flow() calls it from a void path and triggers BUG_ON() if an error is returned. Disable BPF attachment to the hook to prevent a BPF LSM program from turning packet classification into a full panic.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Disable xfrm_decode_session hook attachment\n\nBPF LSM programs can currently attach to xfrm_decode_session(). That\nhook may return an error, but security_skb_classify_flow() calls it\nfrom a void path and triggers BUG_ON() if an error is returned.\n\nDisable BPF attachment to the hook to prevent a BPF LSM program from\nturning packet classification into a full panic.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06936 |
debian: CVE-2026-80669 was patched at 2026-09-16
redos: CVE-2026-80669 was patched at 2026-09-16
2272.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80676) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: use generic driver_override infrastructure When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF. Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally. Note that calling match() from __driver_attach() without the device lock held is intentional. [1]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nDrivers: hv: vmbus: use generic driver_override infrastructure\n\nWhen a driver is probed through __driver_attach(), the bus' match()\ncallback is called without the device lock held, thus accessing the\ndriver_override field without a lock, which can cause a UAF.\n\nFix this by using the driver-core driver_override infrastructure taking\ncare of proper locking internally.\n\nNote that calling match() from __driver_attach() without the device lock\nheld is intentional. [1]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06418 |
debian: CVE-2026-80676 was patched at 2026-09-16
2273.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80686) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE pte_pfn() and pte_dirty() have undefined behaviour when called on a non-present PTE. In migrate_vma_collect_pmd(), these functions may be invoked on non-present entries (e.g., device-private entries), leading to potential crashes from pte_pfn() or incorrect dirty folio accounting from pte_dirty(). Fix both by guarding with pte_present() checks.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE\n\npte_pfn() and pte_dirty() have undefined behaviour when called on a\nnon-present PTE. In migrate_vma_collect_pmd(), these functions may be\ninvoked on non-present entries (e.g., device-private entries), leading\nto potential crashes from pte_pfn() or incorrect dirty folio accounting\nfrom pte_dirty(). Fix both by guarding with pte_present() checks.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06935 |
debian: CVE-2026-80686 was patched at 2026-09-16
2274.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80695) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: hwmon: (sht3x) Fix unaligned accesses Sashiko reports: In sht3x_update_client(), the 16-bit temperature and humidity values are extracted from a stack-allocated byte array using be16_to_cpup(). The pointers passed to this function are calculated as buf and buf + 3. Since the difference between the two pointers is an odd number of bytes, at least one of them is guaranteed to be at an unaligned offset. This will trigger an alignment fault on strict-alignment architectures such as ARMv5 or SPARC, resulting in a kernel panic. Fix the problem by using get_unaligned_be16() instead of be16_to_cpup(), and put_unaligned_be16() instead of cpu_to_be16().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (sht3x) Fix unaligned accesses\n\nSashiko reports:\n\nIn sht3x_update_client(), the 16-bit temperature and humidity values are\nextracted from a stack-allocated byte array using be16_to_cpup(). The\npointers passed to this function are calculated as buf and buf + 3. Since\nthe difference between the two pointers is an odd number of bytes, at\nleast one of them is guaranteed to be at an unaligned offset.\n\nThis will trigger an alignment fault on strict-alignment architectures\nsuch as ARMv5 or SPARC, resulting in a kernel panic.\n\nFix the problem by using get_unaligned_be16() instead of be16_to_cpup(),\nand put_unaligned_be16() instead of cpu_to_be16().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06414 |
debian: CVE-2026-80695 was patched at 2026-09-16
2275.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80698) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix double free of wq, engine, and group structs The release callbacks for wq, engine, and group devices (idxd_conf_wq_release, idxd_conf_engine_release, idxd_conf_group_release) each call kfree() on the enclosing struct. The setup error paths and cleanup functions also call kfree() explicitly after put_device(), producing a double free whenever put_device() drops the reference count to zero and fires the release. In the setup functions, device_initialize() is called before device_add(), so the reference count is exactly 1 at the error sites. put_device() unconditionally fires the release, which frees the struct; the subsequent explicit kfree() then operates on freed memory. For idxd_setup_wqs(), the wq release callback also owns opcap_bmap and wqcfg. The error unwind additionally freed those fields explicitly before calling put_device(), causing further double frees on both. Remove the redundant explicit kfree() calls from all setup error paths and cleanup functions for wq, engine, and group structs, delegating sole ownership of those allocations to the release callbacks.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: fix double free of wq, engine, and group structs\n\nThe release callbacks for wq, engine, and group devices\n(idxd_conf_wq_release, idxd_conf_engine_release,\nidxd_conf_group_release) each call kfree() on the enclosing struct.\nThe setup error paths and cleanup functions also call kfree()\nexplicitly after put_device(), producing a double free whenever\nput_device() drops the reference count to zero and fires the release.\n\nIn the setup functions, device_initialize() is called before\ndevice_add(), so the reference count is exactly 1 at the error sites.\nput_device() unconditionally fires the release, which frees the struct;\nthe subsequent explicit kfree() then operates on freed memory.\n\nFor idxd_setup_wqs(), the wq release callback also owns opcap_bmap\nand wqcfg. The error unwind additionally freed those fields explicitly\nbefore calling put_device(), causing further double frees on both.\n\nRemove the redundant explicit kfree() calls from all setup error paths\nand cleanup functions for wq, engine, and group structs, delegating\nsole ownership of those allocations to the release callbacks.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.05059 |
debian: CVE-2026-80698 was patched at 2026-09-16
2276.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80703) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE Prevent unauthorized termination of active GPU debug sessions. Previously, users with /dev/kfd access could terminate another process's debug session without proper ownership or ptrace authorization. (cherry picked from commit 4db4c5ffd5585b72622ecf6ffedf2da258ee23f5)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE\n\nPrevent unauthorized termination of active GPU debug sessions.\nPreviously, users with /dev/kfd access could terminate another process's\ndebug session without proper ownership or ptrace authorization.\n\n(cherry picked from commit 4db4c5ffd5585b72622ecf6ffedf2da258ee23f5)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05187 |
debian: CVE-2026-80703 was patched at 2026-09-16
2277.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80708) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() The helper function _ip_cprb_helper() uses internal buffer memory for building and processing CPRBs. After use this buffer was never scrubbed which could lead to leaving for example clear key material in memory which could be exposed via tricky reuse of this same memory. Extend the _ip_cprb_helper() function with another parameter 'scrub' used to steer scrubbing of this buffer. So now the caller has the opportunity to decide if scrubbing is needed or not. Extend the clear key to secure key token import process in function cca_clr2cipherkey() to tell the helper function from above to scrub the cprb buffer when the clear key value is part of the request data. Add explicit scrubbing on return from function cca_clr2cipherkey() for the random EXOR buffer and the cprb buffer. Overall this cleans the internal used buffer in case of clear key import to prevent sensitive data to get exposed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey()\n\nThe helper function _ip_cprb_helper() uses internal buffer memory for\nbuilding and processing CPRBs. After use this buffer was never\nscrubbed which could lead to leaving for example clear key material in\nmemory which could be exposed via tricky reuse of this same memory.\n\nExtend the _ip_cprb_helper() function with another parameter 'scrub'\nused to steer scrubbing of this buffer. So now the caller has the\nopportunity to decide if scrubbing is needed or not.\n\nExtend the clear key to secure key token import process in function\ncca_clr2cipherkey() to tell the helper function from above to scrub\nthe cprb buffer when the clear key value is part of the request data.\n\nAdd explicit scrubbing on return from function cca_clr2cipherkey() for\nthe random EXOR buffer and the cprb buffer.\n\nOverall this cleans the internal used buffer in case of clear key\nimport to prevent sensitive data to get exposed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.06037 |
debian: CVE-2026-80708 was patched at 2026-09-16
2278.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80711) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: power: supply: max17040: handle missing status supplier MAX17040 does not report charger state itself, so the driver forwards POWER_SUPPLY_PROP_STATUS to a supplier power supply. If no supplier is registered, power_supply_get_property_from_supplier() returns -ENODEV and leaves the output value untouched. max17040_get_property() currently ignores that error and returns success, so userspace can read an uninitialized status value from the battery power supply. This happens on systems that use the fuel gauge without a charger supplier relationship in firmware. Return POWER_SUPPLY_STATUS_UNKNOWN when no supplier provides STATUS, and propagate other supplier lookup errors.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: max17040: handle missing status supplier\n\nMAX17040 does not report charger state itself, so the driver forwards\nPOWER_SUPPLY_PROP_STATUS to a supplier power supply. If no supplier is\nregistered, power_supply_get_property_from_supplier() returns -ENODEV and\nleaves the output value untouched.\n\nmax17040_get_property() currently ignores that error and returns success,\nso userspace can read an uninitialized status value from the battery power\nsupply. This happens on systems that use the fuel gauge without a charger\nsupplier relationship in firmware.\n\nReturn POWER_SUPPLY_STATUS_UNKNOWN when no supplier provides STATUS, and\npropagate other supplier lookup errors.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05187 |
debian: CVE-2026-80711 was patched at 2026-09-16
2279.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80715) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: igc: remove napi_synchronize() in igc_down() When an AF_XDP zero-copy application is killed abruptly, the XSK pool is torn down but NAPI keeps polling. igc_clean_rx_irq_zc() then returns the full budget on every poll, so napi_complete_done() never clears NAPI_STATE_SCHED. igc_down() calls napi_synchronize() before napi_disable(), so it spins forever waiting for that bit and the interface never goes down. Drop the napi_synchronize() and let napi_disable() do the job -- it sets NAPI_STATE_DISABLE, which forces the stuck poll to complete. Reorder it ahead of igc_set_queue_napi() so the NAPI mapping is cleared only after polling has stopped, matching the recent igb fix b1e067240379.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nigc: remove napi_synchronize() in igc_down()\n\nWhen an AF_XDP zero-copy application is killed abruptly, the XSK pool is\ntorn down but NAPI keeps polling. igc_clean_rx_irq_zc() then returns the\nfull budget on every poll, so napi_complete_done() never clears\nNAPI_STATE_SCHED.\n\nigc_down() calls napi_synchronize() before napi_disable(), so it spins\nforever waiting for that bit and the interface never goes down. Drop the\nnapi_synchronize() and let napi_disable() do the job -- it sets\nNAPI_STATE_DISABLE, which forces the stuck poll to complete. Reorder it\nahead of igc_set_queue_napi() so the NAPI mapping is cleared only after\npolling has stopped, matching the recent igb fix b1e067240379.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00161, EPSS Percentile is 0.0564 |
debian: CVE-2026-80715 was patched at 2026-09-16
oraclelinux: CVE-2026-80715 was patched at 2026-09-04
2280.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80727) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: x86/mce: Set up the polling timer before CMCI discovery I hit the following on one of my machines: mce: CPU0 BANK15 CMCI inherited storm ------------[ cut here ]------------ ODEBUG: assert_init not available (active state 0) object: (____ptrval____) object type: timer_list hint: 0x0 WARNING: lib/debugobjects.c:632 at debug_object_assert_init+0x178/0x230, CPU#0: swapper/0/0 CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 7.2.0-rc5 #3 PREEMPTLAZY RIP: 0010:debug_object_assert_init+0x18f/0x230 Call Trace: <TASK> __mod_timer mce_timer_kick cmci_discover intel_init_cmci mce_intel_feature_init mcheck_cpu_init identify_cpu identify_boot_cpu arch_cpu_finalize_init start_kernel A second splat follows right after, from timer_setup() finding that same timer already queued: ODEBUG: init active (active state 0) object: (____ptrval____) object type: timer_list hint: stub_timer+0x0/0x10 This is happening because CMCI storm detection is trying to modify the timer before latter was properly set up. Set up the timer first. __mcheck_cpu_setup_timer() only calls timer_setup(), and depends on neither the generic nor the vendor init. [ bp: Massage commit message. ]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mce: Set up the polling timer before CMCI discovery\n\nI hit the following on one of my machines:\n\n mce: CPU0 BANK15 CMCI inherited storm\n ------------[ cut here ]------------\n ODEBUG: assert_init not available (active state 0) object: (____ptrval____) object type: timer_list hint: 0x0\n WARNING: lib/debugobjects.c:632 at debug_object_assert_init+0x178/0x230, CPU#0: swapper/0/0\n CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 7.2.0-rc5 #3 PREEMPTLAZY\n RIP: 0010:debug_object_assert_init+0x18f/0x230\n Call Trace:\n <TASK>\n __mod_timer\n mce_timer_kick\n cmci_discover\n intel_init_cmci\n mce_intel_feature_init\n mcheck_cpu_init\n identify_cpu\n identify_boot_cpu\n arch_cpu_finalize_init\n start_kernel\n\nA second splat follows right after, from timer_setup() finding that same\ntimer already queued:\n\n ODEBUG: init active (active state 0) object: (____ptrval____) object type: timer_list hint: stub_timer+0x0/0x10\n\nThis is happening because CMCI storm detection is trying to modify the timer\nbefore latter was properly set up.\n\nSet up the timer first. __mcheck_cpu_setup_timer() only calls timer_setup(),\nand depends on neither the generic nor the vendor init.\n\n [ bp: Massage commit message. ]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10042 |
debian: CVE-2026-80727 was patched at 2026-09-16
2281.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80728) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Revert "drm/amdgpu: fix aperture mapping leak" devres teardown is LIFO. The aperture devres node was registered after the DRM device node, so devres_release_all() unmaps the aperture before the DRM device release callback fires amdgpu_device_fini_sw(). IP sw_fini callbacks (e.g. vcn_v4_0_sw_fini) write to fw_shared through a pointer derived from aper_base_kaddr, causing a kernel page fault on probe failure / rollback: BUG: unable to handle page fault ... PMD 0 RIP: vcn_v4_0_sw_fini+0x7b/0x170 [amdgpu] Call Trace: amdgpu_device_fini_sw amdgpu_driver_release_kms devm_drm_dev_init_release devres_release_all This reverts commit d871e99879cb5fd1fa798b006b4888887e63a17a. (cherry picked from commit 336e0cd576817ac64a4b394ca2b3680029f3e37f)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRevert "drm/amdgpu: fix aperture mapping leak"\n\ndevres teardown is LIFO. The aperture devres node was registered after\nthe DRM device node, so devres_release_all() unmaps the aperture before\nthe DRM device release callback fires amdgpu_device_fini_sw(). IP\nsw_fini callbacks (e.g. vcn_v4_0_sw_fini) write to fw_shared through a\npointer derived from aper_base_kaddr, causing a kernel page fault on\nprobe failure / rollback:\n\n BUG: unable to handle page fault ... PMD 0\n RIP: vcn_v4_0_sw_fini+0x7b/0x170 [amdgpu]\n Call Trace:\n amdgpu_device_fini_sw\n amdgpu_driver_release_kms\n devm_drm_dev_init_release\n devres_release_all\n\nThis reverts commit d871e99879cb5fd1fa798b006b4888887e63a17a.\n\n(cherry picked from commit 336e0cd576817ac64a4b394ca2b3680029f3e37f)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06417 |
debian: CVE-2026-80728 was patched at 2026-09-16
2282.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80733) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: remove WARN_ON_ONCE() from sk_mc_loop() sk_mc_loop() can be called for sockets that are neither AF_INET nor AF_INET6 (e.g. AF_PACKET sockets when sending packets via raw/packet socket over virtual devices such as VRF or ipvlan). In such cases, sk_family is not AF_INET/AF_INET6 and sk_mc_loop() falls through the switch statement and triggers WARN_ON_ONCE(1). Non-INET sockets do not support IP_MULTICAST_LOOP or IPV6_MULTICAST_LOOP options, so loopback should default to true without generating a warning.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: remove WARN_ON_ONCE() from sk_mc_loop()\n\nsk_mc_loop() can be called for sockets that are neither AF_INET\nnor AF_INET6 (e.g. AF_PACKET sockets when sending packets via raw/packet\nsocket over virtual devices such as VRF or ipvlan).\n\nIn such cases, sk_family is not AF_INET/AF_INET6 and sk_mc_loop() falls\nthrough the switch statement and triggers WARN_ON_ONCE(1).\n\nNon-INET sockets do not support IP_MULTICAST_LOOP or IPV6_MULTICAST_LOOP\noptions, so loopback should default to true without generating a warning.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11447 |
debian: CVE-2026-80733 was patched at 2026-09-16
oraclelinux: CVE-2026-80733 was patched at 2026-09-04
2283.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80739) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock In case __mlx5e_add_fdb_flow() fails in lower levels, the flow is deleted via mlx5e_tc_del_flow(), and mlx5e_tc_del_flow() is acquiring ESW devcom lock without condition. In addition, in case of peer_flow, __mlx5e_add_fdb_flow() is called while holding ESW devcom comp lock. This results in an AA deadlock. To fix this, introduce a new PEER flag that is set on flows created as peer flows (the duplicate flows on peer devices), and check it in mlx5e_tc_del_flow() before acquiring ESW devcom lock. Lockdep splat: ============================================ WARNING: possible recursive locking detected ============================================ Possible unsafe locking scenario: CPU0 ---- lock(&comp->lock_key#2); lock(&comp->lock_key#2); *** DEADLOCK *** Call Trace: <TASK> dump_stack_lvl+0x69/0xa0 print_deadlock_bug.cold+0xbd/0xca __lock_acquire+0x1671/0x2ec0 lock_acquire+0x10e/0x2e0 down_read+0x95/0x430 mlx5_devcom_for_each_peer_begin+0x4e/0xe0 [mlx5_core] mlx5e_tc_del_flow+0x11d/0xa70 [mlx5_core] mlx5e_flow_put+0x99/0x100 [mlx5_core] __mlx5e_add_fdb_flow+0x409/0xf00 [mlx5_core] mlx5e_configure_flower+0x2a86/0x4100 [mlx5_core] mlx5e_rep_setup_tc_cls_flower+0x12f/0x1b0 [mlx5_core] mlx5e_rep_setup_tc_cb+0x153/0x750 [mlx5_core] tc_setup_cb_add+0x1dc/0x470 fl_change+0x2f4d/0x626d [cls_flower] tc_new_tfilter+0x79b/0x2310 rtnetlink_rcv_msg+0x778/0xad0 do_syscall_64+0x70/0x960 entry_SYSCALL_64_after_hwframe+0x4b/0x53 </TASK>', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: TC, Check if flow is PEER before acquiring devcom lock\n\nIn case __mlx5e_add_fdb_flow() fails in lower levels, the flow is\ndeleted via mlx5e_tc_del_flow(), and mlx5e_tc_del_flow() is acquiring\nESW devcom lock without condition. In addition, in case of peer_flow,\n__mlx5e_add_fdb_flow() is called while holding ESW devcom comp lock.\nThis results in an AA deadlock.\n\nTo fix this, introduce a new PEER flag that is set on flows created as\npeer flows (the duplicate flows on peer devices), and check it in\nmlx5e_tc_del_flow() before acquiring ESW devcom lock.\n\nLockdep splat:\n============================================\nWARNING: possible recursive locking detected\n============================================\n Possible unsafe locking scenario:\n CPU0\n ----\n lock(&comp->lock_key#2);\n lock(&comp->lock_key#2);\n *** DEADLOCK ***\nCall Trace:\n <TASK>\n dump_stack_lvl+0x69/0xa0\n print_deadlock_bug.cold+0xbd/0xca\n __lock_acquire+0x1671/0x2ec0\n lock_acquire+0x10e/0x2e0\n down_read+0x95/0x430\n mlx5_devcom_for_each_peer_begin+0x4e/0xe0 [mlx5_core]\n mlx5e_tc_del_flow+0x11d/0xa70 [mlx5_core]\n mlx5e_flow_put+0x99/0x100 [mlx5_core]\n __mlx5e_add_fdb_flow+0x409/0xf00 [mlx5_core]\n mlx5e_configure_flower+0x2a86/0x4100 [mlx5_core]\n mlx5e_rep_setup_tc_cls_flower+0x12f/0x1b0 [mlx5_core]\n mlx5e_rep_setup_tc_cb+0x153/0x750 [mlx5_core]\n tc_setup_cb_add+0x1dc/0x470\n fl_change+0x2f4d/0x626d [cls_flower]\n tc_new_tfilter+0x79b/0x2310\n rtnetlink_rcv_msg+0x778/0xad0\n do_syscall_64+0x70/0x960\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n </TASK>', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10043 |
debian: CVE-2026-80739 was patched at 2026-09-16
2284.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80742) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: af_packet: Don't send zero-byte data in tpacket_snd(). syzbot reported a WARNING in __dev_queue_xmit() triggered via tpacket_snd(): skb_assert_len WARNING: at include/linux/skbuff.h:2753 skb_assert_len WARNING: at __dev_queue_xmit+0x21bc/0x4970 net/core/dev.c:4781 Call Trace: <TASK> dev_queue_xmit include/linux/netdevice.h:3448 [inline] packet_xmit+0x243/0x310 net/packet/af_packet.c:276 tpacket_snd net/packet/af_packet.c:2907 [inline] packet_sendmsg+0x28d6/0x4eb0 net/packet/af_packet.c:3134 When sending 0-byte packets via TPACKET ring buffer on devices with no hard header (e.g. dev->hard_header_len == 0), tpacket_fill_skb() populates an skb with skb->len == 0 and returns 0. tpacket_snd() then forwards this empty skb to packet_xmit(), causing __dev_queue_xmit() to hit skb_assert_len(skb). Similar checks exist in packet_snd() via commit dc633700f00f ("net/af_packet: check len when min_header_len equals to 0") and in packet_sendmsg_spkt() via commit 6a341729fb31 ("af_packet: Don't send zero-byte data in packet_sendmsg_spkt()."). Return -EINVAL in tpacket_fill_skb() when skb->len is zero to reject zero-length packets in tpacket_snd().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\naf_packet: Don't send zero-byte data in tpacket_snd().\n\nsyzbot reported a WARNING in __dev_queue_xmit() triggered via tpacket_snd():\n\nskb_assert_len\nWARNING: at include/linux/skbuff.h:2753 skb_assert_len\nWARNING: at __dev_queue_xmit+0x21bc/0x4970 net/core/dev.c:4781\n\nCall Trace:\n <TASK>\n dev_queue_xmit include/linux/netdevice.h:3448 [inline]\n packet_xmit+0x243/0x310 net/packet/af_packet.c:276\n tpacket_snd net/packet/af_packet.c:2907 [inline]\n packet_sendmsg+0x28d6/0x4eb0 net/packet/af_packet.c:3134\n\nWhen sending 0-byte packets via TPACKET ring buffer on devices with no\nhard header (e.g. dev->hard_header_len == 0), tpacket_fill_skb()\npopulates an skb with skb->len == 0 and returns 0. tpacket_snd() then\nforwards this empty skb to packet_xmit(), causing __dev_queue_xmit() to\nhit skb_assert_len(skb).\n\nSimilar checks exist in packet_snd() via commit dc633700f00f\n("net/af_packet: check len when min_header_len equals to 0") and in\npacket_sendmsg_spkt() via commit 6a341729fb31 ("af_packet: Don't send\nzero-byte data in packet_sendmsg_spkt().").\n\nReturn -EINVAL in tpacket_fill_skb() when skb->len is zero to reject\nzero-length packets in tpacket_snd().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11445 |
debian: CVE-2026-80742 was patched at 2026-09-16
oraclelinux: CVE-2026-80742 was patched at 2026-09-04
2285.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80744) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path In nft_flow_rule_offload_abort(), WARN_ON_ONCE(err) is triggered on every error during rollback, including -ENOMEM. Memory allocation failures are expected under low-memory conditions and do not indicate a kernel bug. Trace for example: nft_flow_offload_chain() // FLOW_BLOCK_BIND nft_flow_block_chain() nft_chain_offload_cmd() nft_block_offload_cmd() ->ndo_setup_tc() nsim_setup_tc() flow_block_cb_setup_simple() flow_block_cb_alloc() // fails to -ENOMEM The warning was reproduced on the 5.10 stable kernel under memory pressure via fault injection, but the underlying bug exists in mainline as well, as demonstrated by the ENOMEM trace above. The following splat was triggered during nf_tables transaction processing: WARNING: CPU: 0 PID: 8567 at net/netfilter/nf_tables_offload.c:532 nft_flow_rule_offload_abort net/netfilter/nf_tables_offload.c:532 [inline] WARNING: CPU: 0 PID: 8567 at net/netfilter/nf_tables_offload.c:532 nft_flow_rule_offload_commit+0x971/0xcd0 net/netfilter/nf_tables_offload.c:591 Modules linked in: CPU: 0 PID: 8567 Comm: syz-executor.0 Not tainted 5.10.260-syzkaller #0 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014 RIP: 0010:nft_flow_rule_offload_abort net/netfilter/nf_tables_offload.c:532 [inline] RIP: 0010:nft_flow_rule_offload_commit+0x971/0xcd0 net/netfilter/nf_tables_offload.c:591 Call Trace: nf_tables_commit+0x3bd/0x4bd0 net/netfilter/nf_tables_api.c:8604 nfnetlink_rcv_batch+0xb1e/0x1f20 net/netfilter/nfnetlink.c:509 nfnetlink_rcv_skb_batch net/netfilter/nfnetlink.c:579 [inline] nfnetlink_rcv+0x3b3/0x420 net/netfilter/nfnetlink.c:597 netlink_unicast_kernel net/netlink/af_netlink.c:1314 [inline] netlink_unicast+0x6cd/0xa00 net/netfilter/af_netlink.c:1340 netlink_sendmsg+0x906/0xe10 net/netfilter/af_netlink.c:1919 sock_sendmsg_nosec net/socket.c:651 [inline] __sock_sendmsg+0x155/0x190 net/socket.c:663 ____sys_sendmsg+0x705/0x870 net/socket.c:2379 ___sys_sendmsg+0x100/0x170 net/socket.c:2433 __sys_sendmsg+0xe9/0x1c0 net/socket.c:2462 do_syscall_64+0x33/0x40 arch/x86/entry/common.c:46 entry_SYSCALL_64_after_hwframe+0x67/0xd1 Change the condition to WARN_ON_ONCE(err && err != -ENOMEM) so that warnings are only emitted for unexpected errors. This aligns with the common kernel practice of not warning on -ENOMEM. Found by Linux Verification Center (linuxtesting.org) with Syzkaller.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path\n\nIn nft_flow_rule_offload_abort(), WARN_ON_ONCE(err) is triggered on every\nerror during rollback, including -ENOMEM. Memory allocation failures are\nexpected under low-memory conditions and do not indicate a kernel bug.\n\nTrace for example:\nnft_flow_offload_chain() // FLOW_BLOCK_BIND\n nft_flow_block_chain()\n nft_chain_offload_cmd()\n nft_block_offload_cmd()\n ->ndo_setup_tc()\n nsim_setup_tc()\n flow_block_cb_setup_simple()\n flow_block_cb_alloc() // fails to -ENOMEM\n\nThe warning was reproduced on the 5.10 stable kernel under memory pressure\nvia fault injection, but the underlying bug exists in mainline as well,\nas demonstrated by the ENOMEM trace above. The following splat was\ntriggered during nf_tables transaction processing:\n\nWARNING: CPU: 0 PID: 8567 at net/netfilter/nf_tables_offload.c:532 nft_flow_rule_offload_abort net/netfilter/nf_tables_offload.c:532 [inline]\nWARNING: CPU: 0 PID: 8567 at net/netfilter/nf_tables_offload.c:532 nft_flow_rule_offload_commit+0x971/0xcd0 net/netfilter/nf_tables_offload.c:591\nModules linked in:\nCPU: 0 PID: 8567 Comm: syz-executor.0 Not tainted 5.10.260-syzkaller #0\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014\nRIP: 0010:nft_flow_rule_offload_abort net/netfilter/nf_tables_offload.c:532 [inline]\nRIP: 0010:nft_flow_rule_offload_commit+0x971/0xcd0 net/netfilter/nf_tables_offload.c:591\nCall Trace:\n nf_tables_commit+0x3bd/0x4bd0 net/netfilter/nf_tables_api.c:8604\n nfnetlink_rcv_batch+0xb1e/0x1f20 net/netfilter/nfnetlink.c:509\n nfnetlink_rcv_skb_batch net/netfilter/nfnetlink.c:579 [inline]\n nfnetlink_rcv+0x3b3/0x420 net/netfilter/nfnetlink.c:597\n netlink_unicast_kernel net/netlink/af_netlink.c:1314 [inline]\n netlink_unicast+0x6cd/0xa00 net/netfilter/af_netlink.c:1340\n netlink_sendmsg+0x906/0xe10 net/netfilter/af_netlink.c:1919\n sock_sendmsg_nosec net/socket.c:651 [inline]\n __sock_sendmsg+0x155/0x190 net/socket.c:663\n ____sys_sendmsg+0x705/0x870 net/socket.c:2379\n ___sys_sendmsg+0x100/0x170 net/socket.c:2433\n __sys_sendmsg+0xe9/0x1c0 net/socket.c:2462\n do_syscall_64+0x33/0x40 arch/x86/entry/common.c:46\n entry_SYSCALL_64_after_hwframe+0x67/0xd1\n\nChange the condition to WARN_ON_ONCE(err && err != -ENOMEM) so that\nwarnings are only emitted for unexpected errors. This aligns with the\ncommon kernel practice of not warning on -ENOMEM.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00226, EPSS Percentile is 0.1348 |
debian: CVE-2026-80744 was patched at 2026-09-16
oraclelinux: CVE-2026-80744 was patched at 2026-09-04
2286.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80755) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: selinux: reject a permission value exceeding the class permission count perm_read() bounds a permission value by SEL_VEC_MAX but never by the nprim of the owning class or common, which is taken verbatim from the policy image. security_get_permissions() then writes perms[value - 1] into an nprim-sized kcalloc() array, so a class declaring fewer permissions than its largest permission value drives an out-of-bounds heap write. The top-level symbol tables are validated this way; the nested per-class permission table is not. Reject a permission whose value exceeds nprim, which is already set when perm_read() runs. Well-formed policies are unaffected. [PM: tweak comment for line length]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: reject a permission value exceeding the class permission count\n\nperm_read() bounds a permission value by SEL_VEC_MAX but never by the\nnprim of the owning class or common, which is taken verbatim from the\npolicy image. security_get_permissions() then writes perms[value - 1]\ninto an nprim-sized kcalloc() array, so a class declaring fewer\npermissions than its largest permission value drives an out-of-bounds\nheap write. The top-level symbol tables are validated this way; the\nnested per-class permission table is not.\n\nReject a permission whose value exceeds nprim, which is already set when\nperm_read() runs. Well-formed policies are unaffected.\n\n[PM: tweak comment for line length]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10041 |
debian: CVE-2026-80755 was patched at 2026-09-16
2287.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80756) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: selinux: do not cancel a policy conversion that never started sel_write_load() calls selinux_policy_cancel() when sel_make_policy_nodes() fails, and that helper dereferences the outgoing policy to cancel its sidtab conversion. On the first policy load there is no outgoing policy: security_load_policy() returns early for that case, before it converts anything, and state->policy is still NULL. A first load that fails while building the selinuxfs tree therefore takes a NULL dereference in selinux_policy_cancel(), reached from a write(2) to /sys/fs/selinux/load. Skip the cancel when there is no old policy, mirroring the check security_load_policy() already makes before it converts.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: do not cancel a policy conversion that never started\n\nsel_write_load() calls selinux_policy_cancel() when sel_make_policy_nodes()\nfails, and that helper dereferences the outgoing policy to cancel its\nsidtab conversion. On the first policy load there is no outgoing policy:\nsecurity_load_policy() returns early for that case, before it converts\nanything, and state->policy is still NULL. A first load that fails while\nbuilding the selinuxfs tree therefore takes a NULL dereference in\nselinux_policy_cancel(), reached from a write(2) to /sys/fs/selinux/load.\n\nSkip the cancel when there is no old policy, mirroring the check\nsecurity_load_policy() already makes before it converts.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11444 |
debian: CVE-2026-80756 was patched at 2026-09-16
oraclelinux: CVE-2026-80756 was patched at 2026-09-04
2288.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80757) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: selinux: reject a class permission count below its inherited common security_get_permissions() maps an inherited common's permissions into an array sized by the class's own permissions.nprim, but class_read() takes that nprim verbatim from the policy image and never checks that it covers the common. A class that inherits a common of N permissions while declaring a smaller nprim is accepted, and on load the common's permissions are written past the class-sized array -- an out-of-bounds heap write. Reject a class whose permission count is below its inherited common's. Well-formed policies, where the class count already includes the inherited permissions, are unaffected.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: reject a class permission count below its inherited common\n\nsecurity_get_permissions() maps an inherited common's permissions into\nan array sized by the class's own permissions.nprim, but class_read()\ntakes that nprim verbatim from the policy image and never checks that it\ncovers the common. A class that inherits a common of N permissions while\ndeclaring a smaller nprim is accepted, and on load the common's\npermissions are written past the class-sized array -- an out-of-bounds\nheap write.\n\nReject a class whose permission count is below its inherited common's.\nWell-formed policies, where the class count already includes the\ninherited permissions, are unaffected.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11443 |
debian: CVE-2026-80757 was patched at 2026-09-16
oraclelinux: CVE-2026-80757 was patched at 2026-09-04
2289.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80759) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_aml: validate firmware segment lengths aml_download_firmware() reads two lengths from the firmware header and uses them to build pointers before checking that the header and segment data are present. A truncated or inconsistent firmware image can make the driver read past firmware->data while constructing TCI commands. Reject images shorter than the header and ensure that the ICCM and DCCM ranges fit within the loaded firmware before downloading either segment.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_aml: validate firmware segment lengths\n\naml_download_firmware() reads two lengths from the firmware header and\nuses them to build pointers before checking that the header and segment\ndata are present. A truncated or inconsistent firmware image can make\nthe driver read past firmware->data while constructing TCI commands.\n\nReject images shorter than the header and ensure that the ICCM and DCCM\nranges fit within the loaded firmware before downloading either segment.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06416 |
debian: CVE-2026-80759 was patched at 2026-09-16
2290.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80761) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: zero the sockaddr before returning it in getname iso_sock_getname() fills a struct sockaddr_iso in place and returns its size without clearing it first, so bytes it does not write are copied to user space from the kernel stack. The getsockname(2) and getpeername(2) paths both run through do_getsockname(), which hands getname() an uninitialized sockaddr_storage on the stack and copies back up to the number of bytes getname() returns, so the driver has to initialize every byte it accounts for. Two ranges are left uninitialized: - struct sockaddr_iso is 10 bytes but only 9 are written (family, iso_bdaddr, iso_bdaddr_type), leaking the trailing pad byte on every call. - for a broadcast peer (BIS_LINK or PA_LINK) the returned length grows by sizeof(struct sockaddr_iso_bc), but only bc_sid, bc_num_bis and bc_bis are filled; bc_bdaddr and bc_bdaddr_type, the first 7 bytes of that structure, are never written. An unprivileged process can open a BTPROTO_ISO socket and reach the pad leak with getsockname(); the broadcast leak needs an established BIS/PA connection. l2cap and rfcomm already memset their sockaddr in getname for the same reason; do the same here.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: zero the sockaddr before returning it in getname\n\niso_sock_getname() fills a struct sockaddr_iso in place and returns its\nsize without clearing it first, so bytes it does not write are copied to\nuser space from the kernel stack. The getsockname(2) and getpeername(2)\npaths both run through do_getsockname(), which hands getname() an\nuninitialized sockaddr_storage on the stack and copies back up to the\nnumber of bytes getname() returns, so the driver has to initialize every\nbyte it accounts for.\n\nTwo ranges are left uninitialized:\n\n - struct sockaddr_iso is 10 bytes but only 9 are written (family,\n iso_bdaddr, iso_bdaddr_type), leaking the trailing pad byte on every\n call.\n\n - for a broadcast peer (BIS_LINK or PA_LINK) the returned length grows\n by sizeof(struct sockaddr_iso_bc), but only bc_sid, bc_num_bis and\n bc_bis are filled; bc_bdaddr and bc_bdaddr_type, the first 7 bytes of\n that structure, are never written.\n\nAn unprivileged process can open a BTPROTO_ISO socket and reach the pad\nleak with getsockname(); the broadcast leak needs an established BIS/PA\nconnection. l2cap and rfcomm already memset their sockaddr in getname\nfor the same reason; do the same here.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.0645 |
debian: CVE-2026-80761 was patched at 2026-09-16
2291.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80763) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: validate LE Set CIG Parameters response The Command Complete dispatch validates only the fixed part of the LE Set CIG Parameters response. After that part is pulled from the skb, hci_cc_le_set_cig_params() trusts num_handles and reads each entry in the trailing handle array. Matching num_handles against the command's num_cis does not guarantee that the response contains the advertised handles. A truncated response from a malfunctioning controller can therefore make the handler read beyond the skb data. Validate that the remaining skb data contains all advertised handles. Include this in the existing response validation so malformed responses also follow the established CIG failure handling.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_event: validate LE Set CIG Parameters response\n\nThe Command Complete dispatch validates only the fixed part of the LE Set\nCIG Parameters response. After that part is pulled from the skb,\nhci_cc_le_set_cig_params() trusts num_handles and reads each entry in the\ntrailing handle array.\n\nMatching num_handles against the command's num_cis does not guarantee\nthat the response contains the advertised handles. A truncated response\nfrom a malfunctioning controller can therefore make the handler read\nbeyond the skb data.\n\nValidate that the remaining skb data contains all advertised handles.\nInclude this in the existing response validation so malformed responses\nalso follow the established CIG failure handling.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06964 |
debian: CVE-2026-80763 was patched at 2026-09-16
2292.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80768) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: HID: ft260: fix stack-use-after-return write in I2C read race ft260_i2c_read() points dev->read_buf at a caller-supplied buffer (often an on-stack variable), arms a completion and waits up to five seconds for the device to return the data. The HID input callback ft260_raw_event() runs in the input/IRQ path, independent of the dev->lock mutex held by the read path, and copies the device-supplied payload into dev->read_buf after a plain NULL check. These two paths share read_buf, read_idx and read_len with no serialization. If the device delays its response until the read times out, ft260_i2c_read() resets the controller, clears read_buf and returns, unwinding the stack frame the buffer lived in. A response that arrives at that moment lets ft260_raw_event() pass the NULL check and then memcpy() the device-controlled payload into the now-freed stack location, a bounded but attacker-influenced stack-use-after-return write triggerable by malicious or malfunctioning hardware. Add a dedicated spinlock that serializes every access to read_buf, read_idx and read_len. ft260_raw_event() now holds it across the NULL check, the memcpy and the index update, while the read path takes it when arming and when clearing the buffer, so the teardown can no longer slip between the check and the copy.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nHID: ft260: fix stack-use-after-return write in I2C read race\n\nft260_i2c_read() points dev->read_buf at a caller-supplied buffer\n(often an on-stack variable), arms a completion and waits up to five\nseconds for the device to return the data. The HID input callback\nft260_raw_event() runs in the input/IRQ path, independent of the\ndev->lock mutex held by the read path, and copies the device-supplied\npayload into dev->read_buf after a plain NULL check.\n\nThese two paths share read_buf, read_idx and read_len with no\nserialization. If the device delays its response until the read\ntimes out, ft260_i2c_read() resets the controller, clears read_buf\nand returns, unwinding the stack frame the buffer lived in. A\nresponse that arrives at that moment lets ft260_raw_event() pass the\nNULL check and then memcpy() the device-controlled payload into the\nnow-freed stack location, a bounded but attacker-influenced\nstack-use-after-return write triggerable by malicious or\nmalfunctioning hardware.\n\nAdd a dedicated spinlock that serializes every access to read_buf,\nread_idx and read_len. ft260_raw_event() now holds it across the\nNULL check, the memcpy and the index update, while the read path\ntakes it when arming and when clearing the buffer, so the teardown\ncan no longer slip between the check and the copy.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07459 |
debian: CVE-2026-80768 was patched at 2026-09-16
2293.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80771) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: HID: nintendo: register input device after capabilities are set input_register_device() exposes the device to userspace immediately. In joycon_input_create() it was called before joycon_config_rumble() configures the FF_RUMBLE capability and the memless force-feedback device, so a concurrent EVIOCSFF could dereference a NULL dev->ff. Registering early also means the initial udev event lacks button and axis information, which can make input managers ignore the device. Move input_register_device() to the end of joycon_input_create(), after all capabilities, the IMU input device and the force-feedback callbacks have been configured.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nHID: nintendo: register input device after capabilities are set\n\ninput_register_device() exposes the device to userspace immediately.\nIn joycon_input_create() it was called before joycon_config_rumble()\nconfigures the FF_RUMBLE capability and the memless force-feedback\ndevice, so a concurrent EVIOCSFF could dereference a NULL dev->ff.\n\nRegistering early also means the initial udev event lacks button and\naxis information, which can make input managers ignore the device.\n\nMove input_register_device() to the end of joycon_input_create(), after\nall capabilities, the IMU input device and the force-feedback callbacks\nhave been configured.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.0644 |
debian: CVE-2026-80771 was patched at 2026-09-16
2294.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80774) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: HID: asus: fix missing hid_is_usb() check to_usb_interface() can only be used on a hid_device whose parent is really USB; uhid can create devices that identify as being on BUS_USB, but don't actually have a USB parent. Fix the use of to_usb_interface() without a hid_is_usb() check. I have verified that it is currently possible to trigger a kernel splat due to this bug in an ASAN build, and that this commit fixes the issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nHID: asus: fix missing hid_is_usb() check\n\nto_usb_interface() can only be used on a hid_device whose parent is really\nUSB; uhid can create devices that identify as being on BUS_USB, but don't\nactually have a USB parent.\nFix the use of to_usb_interface() without a hid_is_usb() check.\n\nI have verified that it is currently possible to trigger a kernel splat due\nto this bug in an ASAN build, and that this commit fixes the issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06441 |
debian: CVE-2026-80774 was patched at 2026-09-16
2295.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80779) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/ionic: avoid OOB TX partner lookup for hwstamp RXQ The dedicated hardware timestamp RX queue is allocated with q->index equal to lif->ionic->nrxqs_per_lif. The normal txqcqs array only contains the regular queue pairs, so using that index to set rxq->partner can read one entry past txqcqs[] and then write through the derived pointer. Only link RX/TX partners for normal queue-pair indexes. Leave the hwstamp RX queue unpaired, and make the XDP_TX path abort cleanly if an RX queue has no TX partner.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/ionic: avoid OOB TX partner lookup for hwstamp RXQ\n\nThe dedicated hardware timestamp RX queue is allocated with q->index\nequal to lif->ionic->nrxqs_per_lif. The normal txqcqs array only\ncontains the regular queue pairs, so using that index to set rxq->partner\ncan read one entry past txqcqs[] and then write through the derived\npointer.\nOnly link RX/TX partners for normal queue-pair indexes. Leave the hwstamp\nRX queue unpaired, and make the XDP_TX path abort cleanly if an RX queue\nhas no TX partner.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06411 |
debian: CVE-2026-80779 was patched at 2026-09-16
2296.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80782) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: HID: magicmouse: do not keep a stale msc->input if no input is claimed magicmouse_input_mapping() caches the first hid_input's input_dev in msc->input while the report descriptor is parsed, and the rest of the driver treats a non-NULL msc->input as proof that an input device was registered. That does not hold on the hid-input error path. If hidinput_connect() fails -- for instance because input_register_device() returns an error -- it unwinds through hidinput_disconnect(), which frees every input_dev it created, including the one cached in msc->input. The failure does not abort the probe. hid_connect() only skips the claim: \tif ((connect_mask & HID_CONNECT_HIDINPUT) && !hidinput_connect(hdev, \t\t\t\tconnect_mask & HID_CONNECT_HIDINPUT_FORCE)) \t\thdev->claimed |= HID_CLAIMED_INPUT; and the "device has no listeners" bailout below it does not fire for this driver, which sets ->raw_event; on the USB Magic Mouse 2 / Magic Trackpad 2 paths hidraw and hiddev are claimed as well. hid_hw_start() therefore returns 0 and magicmouse_probe() continues with msc->input pointing at freed memory. Being non-NULL, it passes the "input not registered" check in probe and the NULL checks in ->raw_event and ->event, so the next input report dereferences freed memory. Clear msc->input when the HID core did not claim an input device, so the existing NULL checks cover this case as well.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nHID: magicmouse: do not keep a stale msc->input if no input is claimed\n\nmagicmouse_input_mapping() caches the first hid_input's input_dev in\nmsc->input while the report descriptor is parsed, and the rest of the\ndriver treats a non-NULL msc->input as proof that an input device was\nregistered.\n\nThat does not hold on the hid-input error path. If hidinput_connect()\nfails -- for instance because input_register_device() returns an error --\nit unwinds through hidinput_disconnect(), which frees every input_dev it\ncreated, including the one cached in msc->input.\n\nThe failure does not abort the probe. hid_connect() only skips the claim:\n\n\tif ((connect_mask & HID_CONNECT_HIDINPUT) && !hidinput_connect(hdev,\n\t\t\t\tconnect_mask & HID_CONNECT_HIDINPUT_FORCE))\n\t\thdev->claimed |= HID_CLAIMED_INPUT;\n\nand the "device has no listeners" bailout below it does not fire for this\ndriver, which sets ->raw_event; on the USB Magic Mouse 2 / Magic Trackpad\n2 paths hidraw and hiddev are claimed as well. hid_hw_start() therefore\nreturns 0 and magicmouse_probe() continues with msc->input pointing at\nfreed memory. Being non-NULL, it passes the "input not registered" check\nin probe and the NULL checks in ->raw_event and ->event, so the next\ninput report dereferences freed memory.\n\nClear msc->input when the HID core did not claim an input device, so the\nexisting NULL checks cover this case as well.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09463 |
debian: CVE-2026-80782 was patched at 2026-09-16
2297.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80785) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fbdev: serialize mode sysfs access with lock_fb_info() show_mode(), show_modes(), and store_mode() access fb_info->modelist and fb_info->mode without holding lock_fb_info(). store_modes() takes lock_fb_info() while replacing the modelist and freeing the old one. A concurrent reader or writer can load a pointer to an old modelist entry before store_modes() frees it, then dereference freed memory or store a stale freed pointer in fb_info->mode. Take lock_fb_info() in show_mode(), show_modes(), and store_mode() to serialize with store_modes(). In show_mode(), copy the mode to the stack and format after dropping the lock. In store_mode(), split activate() into a _locked variant to avoid double-locking, and hold the locks for the modelist walk, mode conversion, activation, and fb_info->mode assignment together.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: serialize mode sysfs access with lock_fb_info()\n\nshow_mode(), show_modes(), and store_mode() access fb_info->modelist\nand fb_info->mode without holding lock_fb_info(). store_modes() takes\nlock_fb_info() while replacing the modelist and freeing the old one.\n\nA concurrent reader or writer can load a pointer to an old modelist\nentry before store_modes() frees it, then dereference freed memory or\nstore a stale freed pointer in fb_info->mode.\n\nTake lock_fb_info() in show_mode(), show_modes(), and store_mode() to\nserialize with store_modes(). In show_mode(), copy the mode to the\nstack and format after dropping the lock. In store_mode(), split\nactivate() into a _locked variant to avoid double-locking, and hold\nthe locks for the modelist walk, mode conversion, activation, and\nfb_info->mode assignment together.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.05092 |
debian: CVE-2026-80785 was patched at 2026-09-16
2298.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80786) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fbdev: Wrap user-invoked calls to fb_set_var() in helper Handle fbcon during display updates in fb_set_var_from_user(). Check with fbcon if the mode change is possible, update hardware state and finally update fbcon. Update all callers. Only the FBIOPUT_VSCREENINFO ioctl currently does all steps. Other mode-changes callers in sysfs and driver code are missing fbcon-related steps. With the new helper, ps3fb and sh_mobile_lcdcfb no longer maintain fbcon state themselves.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: Wrap user-invoked calls to fb_set_var() in helper\n\nHandle fbcon during display updates in fb_set_var_from_user(). Check\nwith fbcon if the mode change is possible, update hardware state and\nfinally update fbcon. Update all callers.\n\nOnly the FBIOPUT_VSCREENINFO ioctl currently does all steps. Other\nmode-changes callers in sysfs and driver code are missing fbcon-related\nsteps.\n\nWith the new helper, ps3fb and sh_mobile_lcdcfb no longer maintain\nfbcon state themselves.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.05092 |
debian: CVE-2026-80786 was patched at 2026-09-16
2299.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80788) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations When fuzzing the nvme target code, I tripped a kernel warning in nvmet_tcp_map_data() because the length passed into the allocator is controlled by the remote initiator. A remote initiator that sends a command with an SGL claiming a huge number, can create a scatterlist and iovec allocation of over 1 million entries, which causes the backing kmalloc call to exceed MAX_PAGE_ORDER and then the page allocator will trip on a WARN_ON_ONCE_GFP() message: WARNING: mm/page_alloc.c:5280 __alloc_frozen_pages_noprof Workqueue: nvmet_tcp_wq nvmet_tcp_io_work ... sgl_alloc_order nvmet_tcp_map_data nvmet_tcp_try_recv_pdu As it's never good to trip a kernel warning remotely due to many systems having panic-on-warn enabled, let's silence it by just add GFP_NOWARN to the allocation flags.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations\n\nWhen fuzzing the nvme target code, I tripped a kernel warning in\nnvmet_tcp_map_data() because the length passed into the allocator is\ncontrolled by the remote initiator.\n\nA remote initiator that sends a command with an SGL claiming a huge\nnumber, can create a scatterlist and iovec allocation of over 1 million\nentries, which causes the backing kmalloc call to exceed MAX_PAGE_ORDER\nand then the page allocator will trip on a WARN_ON_ONCE_GFP() message:\n\n WARNING: mm/page_alloc.c:5280 __alloc_frozen_pages_noprof\n Workqueue: nvmet_tcp_wq nvmet_tcp_io_work\n ...\n sgl_alloc_order\n nvmet_tcp_map_data\n nvmet_tcp_try_recv_pdu\n\nAs it's never good to trip a kernel warning remotely due to many systems\nhaving panic-on-warn enabled, let's silence it by just add GFP_NOWARN to\nthe allocation flags.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09462 |
debian: CVE-2026-80788 was patched at 2026-09-16
2300.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80789) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: bound SGL data length before allocating command buffers nvmet_tcp_map_data() reads the host-controlled 32-bit sgl->length and, for the in-capsule offset descriptor (type 0x01), checks it against port->inline_data_size before use. Any other SGL descriptor type -- including the non-inline transport SGL data-block descriptor (type (NVME_TRANSPORT_SGL_DATA_DESC << 4) | NVME_SGL_FMT_TRANSPORT_A, the type a real host uses for out-of-capsule writes) skips that check entirely and falls straight through to: \tcmd->req.sg = sgl_alloc(len, GFP_KERNEL, &cmd->req.sg_cnt); with len taken directly from the wire, unbounded up to 4 GiB. nvmet_req_init() only parses the command and never inspects sgl->length, and nvmet_check_transfer_len() -- the only other place transfer_len is validated -- runs later, from req->execute(), after the allocation has already happened. For a write command the target responds with an R2T and parks the command waiting for the host to send the data; if the host (or an unauthenticated peer that simply never follows up) never does, the sgl_alloc() buffer stays resident for the life of the command. NVMe/TCP has no mandatory authentication in the default configuration, so any peer able to reach the target portal and complete a Fabrics connect can drive this with a single crafted command, repeatable across queues and connections for amplification. This is unbounded kernel memory allocation triggered by a remote, effectively unauthenticated peer. Validate len against the same NVMET_TCP_MAXH2CDATA ceiling this file already uses to bound per-PDU H2C data, for every SGL descriptor type, before doing any allocation. This closes the gap for the non-inline descriptor while leaving the existing, tighter inline_data_size check in place for the in-capsule case. Runtime-verified on a v6.19 KASAN stand: with this bound in place, a crafted write command carrying an oversized non-inline SGL length is rejected before sgl_alloc() runs, where the same request previously drove an unbounded ~256 MiB kernel allocation (up to 4 GiB) that stayed resident pending an R2T the host never satisfies.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: bound SGL data length before allocating command buffers\n\nnvmet_tcp_map_data() reads the host-controlled 32-bit sgl->length\nand, for the in-capsule offset descriptor (type 0x01), checks it\nagainst port->inline_data_size before use. Any other SGL descriptor\ntype -- including the non-inline transport SGL data-block descriptor\n(type (NVME_TRANSPORT_SGL_DATA_DESC << 4) | NVME_SGL_FMT_TRANSPORT_A,\nthe type a real host uses for out-of-capsule writes) skips that check\nentirely and falls straight through to:\n\n\tcmd->req.sg = sgl_alloc(len, GFP_KERNEL, &cmd->req.sg_cnt);\n\nwith len taken directly from the wire, unbounded up to 4 GiB.\n\nnvmet_req_init() only parses the command and never inspects\nsgl->length, and nvmet_check_transfer_len() -- the only other place\ntransfer_len is validated -- runs later, from req->execute(), after\nthe allocation has already happened. For a write command the target\nresponds with an R2T and parks the command waiting for the host to\nsend the data; if the host (or an unauthenticated peer that simply\nnever follows up) never does, the sgl_alloc() buffer stays resident\nfor the life of the command. NVMe/TCP has no mandatory authentication\nin the default configuration, so any peer able to reach the target\nportal and complete a Fabrics connect can drive this with a single\ncrafted command, repeatable across queues and connections for\namplification. This is unbounded kernel memory allocation\ntriggered by a remote, effectively unauthenticated peer.\n\nValidate len against the same NVMET_TCP_MAXH2CDATA ceiling this file\nalready uses to bound per-PDU H2C data, for every SGL descriptor type,\nbefore doing any allocation. This closes the gap for the non-inline\ndescriptor while leaving the existing, tighter inline_data_size check\nin place for the in-capsule case.\n\nRuntime-verified on a v6.19 KASAN stand: with this bound in place, a\ncrafted write command carrying an oversized non-inline SGL length is\nrejected before sgl_alloc() runs, where the same request previously\ndrove an unbounded ~256 MiB kernel allocation (up to 4 GiB) that\nstayed resident pending an R2T the host never satisfies.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00234, EPSS Percentile is 0.14471 |
debian: CVE-2026-80789 was patched at 2026-09-16
2301.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80790) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: fix invalid free in LS IOD error path nvmet_fc_alloc_ls_iodlist() advances iod while initializing the LS IOD array. If an rqstbuf allocation or response buffer DMA mapping fails, the unwind loop decrements iod past the start of the array. The final kfree(iod) therefore frees an address before the allocated object. This can be reproduced with nvme-fcloop and failslab by setting fail-nth to 6 before creating a target port. KASAN reports: BUG: KASAN: invalid-free in nvmet_fc_register_targetport Free of addr ffff88816cf8ff48 by task nvmet_fail_nth/9552 Free the original allocation base stored in tgtport->iod instead. With this fix applied, the same sysfs write with fail-nth=6 returns -ENOMEM without any KASAN report.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-fc: fix invalid free in LS IOD error path\n\nnvmet_fc_alloc_ls_iodlist() advances iod while initializing the LS IOD\narray. If an rqstbuf allocation or response buffer DMA mapping fails,\nthe unwind loop decrements iod past the start of the array. The final\nkfree(iod) therefore frees an address before the allocated object.\n\nThis can be reproduced with nvme-fcloop and failslab by setting\nfail-nth to 6 before creating a target port. KASAN reports:\n\n BUG: KASAN: invalid-free in nvmet_fc_register_targetport\n Free of addr ffff88816cf8ff48 by task nvmet_fail_nth/9552\n\nFree the original allocation base stored in tgtport->iod instead. With\nthis fix applied, the same sysfs write with fail-nth=6 returns -ENOMEM\nwithout any KASAN report.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09464 |
debian: CVE-2026-80790 was patched at 2026-09-16
2302.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80791) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: zero the AUTH_RECEIVE response buffer nvmet_execute_auth_receive() allocates the response buffer with kmalloc() sized by the host-supplied AUTH_RECEIVE allocation length, but the DH-HMAC-CHAP builders write only a fixed-size message into it. The full allocation length is then copied to the wire by nvmet_copy_to_sgl(), so a remote initiator receives the bytes past the built message -- up to nearly a page of uninitialized slab -- during the pre-authentication handshake. Allocate the buffer with kzalloc() so the unwritten tail is zeroed before it is sent; conforming responses are unaffected.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-auth: zero the AUTH_RECEIVE response buffer\n\nnvmet_execute_auth_receive() allocates the response buffer with kmalloc()\nsized by the host-supplied AUTH_RECEIVE allocation length, but the\nDH-HMAC-CHAP builders write only a fixed-size message into it. The full\nallocation length is then copied to the wire by nvmet_copy_to_sgl(), so a\nremote initiator receives the bytes past the built message -- up to nearly\na page of uninitialized slab -- during the pre-authentication handshake.\n\nAllocate the buffer with kzalloc() so the unwritten tail is zeroed before\nit is sent; conforming responses are unaffected.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00207, EPSS Percentile is 0.11026 |
debian: CVE-2026-80791 was patched at 2026-09-16
2303.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80793) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipv4: reject undersized MTUs in ip_do_fragment() ip_do_fragment() subtracts the IPv4 header length from the effective MTU and passes the resulting payload MTU to ip_frag_next(). If the effective MTU is smaller than hlen + 8, ip_frag_next() rounds the fragment payload length down to zero. The fragmentation state then never makes forward progress: state->left, state->ptr and state->offset stay unchanged while ip_do_fragment() keeps allocating and transmitting header-only fragments until the softlockup detector fires. This is reproducible with a route installed using "mtu lock 20", but it is also reproducible without route MTU lock, for example by forwarding a packet to a device whose MTU is 20. Fix it in ip_do_fragment() by rejecting mtu < hlen + 8 with -EMSGSIZE, matching the existing IPv6 fragmentation check.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: reject undersized MTUs in ip_do_fragment()\n\nip_do_fragment() subtracts the IPv4 header length from the effective\nMTU and passes the resulting payload MTU to ip_frag_next().\n\nIf the effective MTU is smaller than hlen + 8, ip_frag_next() rounds\nthe fragment payload length down to zero. The fragmentation state then\nnever makes forward progress: state->left, state->ptr and state->offset\nstay unchanged while ip_do_fragment() keeps allocating and transmitting\nheader-only fragments until the softlockup detector fires.\n\nThis is reproducible with a route installed using "mtu lock 20", but it\nis also reproducible without route MTU lock, for example by forwarding a\npacket to a device whose MTU is 20.\n\nFix it in ip_do_fragment() by rejecting mtu < hlen + 8 with -EMSGSIZE,\nmatching the existing IPv6 fragmentation check.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09456 |
debian: CVE-2026-80793 was patched at 2026-09-16
2304.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80794) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix uninit-value in the RF discover/activated NTF handlers nci_rf_discover_ntf_packet() and nci_rf_intf_activated_ntf_packet() each parse a notification into an on-stack struct (nci_rf_discover_ntf / nci_rf_intf_activated_ntf) that is not initialised. The RF technology-specific parameters are only extracted when rf_tech_specific_params_len is non-zero, so a notification that reports a zero length leaves the rf_tech_specific_params union uninitialised - and both handlers then pass it to nci_add_new_protocol(), which reads it: - discover: nci_add_new_target() -> nci_add_new_protocol(); - activated: nci_target_auto_activated() -> nci_add_new_protocol(). nci_add_new_protocol() uses nfca_poll->nfcid1_len as both a branch condition and a memcpy() length and copies nfcid1/sens_res/sel_res into ndev->targets, which is later exposed to user space via NFC_CMD_GET_TARGET. BUG: KMSAN: uninit-value in nci_add_new_protocol+0x624/0x6c0 nci_add_new_protocol+0x624/0x6c0 nci_ntf_packet+0x25b2/0x3c30 nci_rx_work+0x318/0x5d0 process_scheduled_works+0x84b/0x17a0 worker_thread+0xc10/0x11b0 kthread+0x376/0x500 Local variable ntf.i created at: nci_ntf_packet+0xbc2/0x3c30 Zero-initialise both on-stack notifications so the union reads back as zero when no technology-specific parameters are present.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: fix uninit-value in the RF discover/activated NTF handlers\n\nnci_rf_discover_ntf_packet() and nci_rf_intf_activated_ntf_packet() each\nparse a notification into an on-stack struct (nci_rf_discover_ntf /\nnci_rf_intf_activated_ntf) that is not initialised. The RF\ntechnology-specific parameters are only extracted when\nrf_tech_specific_params_len is non-zero, so a notification that reports a\nzero length leaves the rf_tech_specific_params union uninitialised - and\nboth handlers then pass it to nci_add_new_protocol(), which reads it:\n\n - discover: nci_add_new_target() -> nci_add_new_protocol();\n - activated: nci_target_auto_activated() -> nci_add_new_protocol().\n\nnci_add_new_protocol() uses nfca_poll->nfcid1_len as both a branch\ncondition and a memcpy() length and copies nfcid1/sens_res/sel_res into\nndev->targets, which is later exposed to user space via NFC_CMD_GET_TARGET.\n\n BUG: KMSAN: uninit-value in nci_add_new_protocol+0x624/0x6c0\n nci_add_new_protocol+0x624/0x6c0\n nci_ntf_packet+0x25b2/0x3c30\n nci_rx_work+0x318/0x5d0\n process_scheduled_works+0x84b/0x17a0\n worker_thread+0xc10/0x11b0\n kthread+0x376/0x500\n Local variable ntf.i created at:\n nci_ntf_packet+0xbc2/0x3c30\n\nZero-initialise both on-stack notifications so the union reads back as\nzero when no technology-specific parameters are present.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09457 |
debian: CVE-2026-80794 was patched at 2026-09-16
2305.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80797) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: purge fragmented skbs during cleanup pn53x_common_clean() purges resp_q before freeing the common PN533 state, but it leaves fragment_skb untouched. The fragmentation helpers queue transmit fragments there while sending large initiator or target-mode frames, and those skbs remain owned by the driver until they are sent or discarded. If the device is removed while fragments are still queued, the common cleanup path frees the PN533 state without releasing the queued fragment skbs, leaking them. Purge fragment_skb during cleanup alongside resp_q.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: pn533: purge fragmented skbs during cleanup\n\npn53x_common_clean() purges resp_q before freeing the common PN533 state,\nbut it leaves fragment_skb untouched. The fragmentation helpers queue\ntransmit fragments there while sending large initiator or target-mode\nframes, and those skbs remain owned by the driver until they are sent or\ndiscarded.\n\nIf the device is removed while fragments are still queued, the common\ncleanup path frees the PN533 state without releasing the queued fragment\nskbs, leaking them.\n\nPurge fragment_skb during cleanup alongside resp_q.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09459 |
debian: CVE-2026-80797 was patched at 2026-09-16
2306.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80799) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers nfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv() contain three related bugs in their TLV parsing loops: 1. 'offset' is declared u8 but tlv_array_len is u16. When TLV data advances offset past 255 it silently wraps to zero, causing infinite loops or double-processing of buffer data. 2. Before reading tlv[0] (type) and tlv[1] (length) there is no check that offset+2 <= tlv_array_len. A truncated TLV causes an OOB read of one byte past the buffer end. 3. After reading the length field, the value bytes are accessed without checking offset+2+length <= tlv_array_len. A crafted length=0xFF on a short buffer causes up to 255 bytes of OOB read past the buffer end. Both functions are reachable without authentication via nfc_llcp_set_remote_gb() which feeds remote LLCP general bytes directly into nfc_llcp_parse_gb_tlv() with no additional validation. Fix all three issues by widening offset from u8 to u16 and adding bounds checks for both the TLV header and value field before each access.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: fix OOB read and u8 offset wrap in TLV parsers\n\nnfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv() contain\nthree related bugs in their TLV parsing loops:\n\n1. 'offset' is declared u8 but tlv_array_len is u16. When TLV data\n advances offset past 255 it silently wraps to zero, causing\n infinite loops or double-processing of buffer data.\n\n2. Before reading tlv[0] (type) and tlv[1] (length) there is no\n check that offset+2 <= tlv_array_len. A truncated TLV causes\n an OOB read of one byte past the buffer end.\n\n3. After reading the length field, the value bytes are accessed\n without checking offset+2+length <= tlv_array_len. A crafted\n length=0xFF on a short buffer causes up to 255 bytes of OOB\n read past the buffer end.\n\nBoth functions are reachable without authentication via\nnfc_llcp_set_remote_gb() which feeds remote LLCP general bytes\ndirectly into nfc_llcp_parse_gb_tlv() with no additional\nvalidation.\n\nFix all three issues by widening offset from u8 to u16 and adding\nbounds checks for both the TLV header and value field before each\naccess.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00234, EPSS Percentile is 0.14471 |
debian: CVE-2026-80799 was patched at 2026-09-16
2307.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80800) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: bound the connect_sn TLV walk to the skb Commit 27256cdb290e ("nfc: llcp: bound SNL TLV parsing to the skb and add length checks") fixed the unbounded TLV walk in nfc_llcp_recv_snl(), and commit d8bd2dedbde5 ("nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers") subsequently bounded nfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv(). One sibling parser sharing the same pattern remains unbounded: nfc_llcp_connect_sn(). nfc_llcp_connect_sn() walks a TLV list, reading a two-byte header (type, length) followed by length bytes of value, without checking that the two header bytes or the declared length stay within the buffer. It returns a pointer to a service name of up to 255 bytes that may point past the end of the skb; it is subsequently consumed by memcmp() in nfc_llcp_sock_from_sn(). In addition tlv_array_len was computed as "skb->len - LLCP_HEADER_SIZE" in size_t, so a CONNECT/CC frame shorter than the LLCP header underflows to a huge length and the walk runs far past the buffer. nfc_llcp_connect_sn() is reachable from nfc_llcp_recv_connect() and nfc_llcp_recv_cc(), i.e. from received CONNECT and CC PDUs. A nearby NFC device can reach this without authentication; LLCP link activation happens automatically after NFC-DEP, and the nfc_llcp_rx_skb() dispatcher applies no minimum-length guard. Walk the TLV list by pointer, bounded by skb_tail_pointer(skb), and validate each declared length before use, matching the approach already used for nfc_llcp_recv_snl(). Starting the walk at &skb->data[LLCP_HEADER_SIZE] against the tail pointer also removes the size_t underflow for short frames. Found by 0sec automated security-research tooling (https://0sec.ai).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: bound the connect_sn TLV walk to the skb\n\nCommit 27256cdb290e ("nfc: llcp: bound SNL TLV parsing to the skb and\nadd length checks") fixed the unbounded TLV walk in nfc_llcp_recv_snl(),\nand commit d8bd2dedbde5 ("nfc: llcp: fix OOB read and u8 offset wrap in\nTLV parsers") subsequently bounded nfc_llcp_parse_gb_tlv() and\nnfc_llcp_parse_connection_tlv(). One sibling parser sharing the same\npattern remains unbounded: nfc_llcp_connect_sn().\n\nnfc_llcp_connect_sn() walks a TLV list, reading a two-byte header\n(type, length) followed by length bytes of value, without checking that\nthe two header bytes or the declared length stay within the buffer. It\nreturns a pointer to a service name of up to 255 bytes that may point\npast the end of the skb; it is subsequently consumed by memcmp() in\nnfc_llcp_sock_from_sn(). In addition tlv_array_len was computed as\n"skb->len - LLCP_HEADER_SIZE" in size_t, so a CONNECT/CC frame shorter\nthan the LLCP header underflows to a huge length and the walk runs far\npast the buffer.\n\nnfc_llcp_connect_sn() is reachable from nfc_llcp_recv_connect() and\nnfc_llcp_recv_cc(), i.e. from received CONNECT and CC PDUs. A nearby\nNFC device can reach this without authentication; LLCP link activation\nhappens automatically after NFC-DEP, and the nfc_llcp_rx_skb()\ndispatcher applies no minimum-length guard.\n\nWalk the TLV list by pointer, bounded by skb_tail_pointer(skb), and\nvalidate each declared length before use, matching the approach already\nused for nfc_llcp_recv_snl(). Starting the walk at\n&skb->data[LLCP_HEADER_SIZE] against the tail pointer also removes the\nsize_t underflow for short frames.\n\nFound by 0sec automated security-research tooling (https://0sec.ai).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00234, EPSS Percentile is 0.14472 |
debian: CVE-2026-80800 was patched at 2026-09-16
2308.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80801) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfc: microread: validate target discovery payload lengths microread_target_discovered() parses target discovery payloads from skb->data according to the HCI gate. The fixed field offsets and UID copies were checked only against the destination nfc_target buffers, not against the actual skb length. Validate that each gate-specific payload contains the fixed fields and UID bytes before reading or copying them.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: microread: validate target discovery payload lengths\n\nmicroread_target_discovered() parses target discovery payloads from\nskb->data according to the HCI gate. The fixed field offsets and UID\ncopies were checked only against the destination nfc_target buffers, not\nagainst the actual skb length.\n\nValidate that each gate-specific payload contains the fixed fields and\nUID bytes before reading or copying them.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09458 |
debian: CVE-2026-80801 was patched at 2026-09-16
2309.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80803) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfc: digital: clamp SENSF_RES length to the destination buffer digital_in_recv_sensf_res() memcpy()s resp->len bytes from a remote NFC-F device response into the NFC_SENSF_RES_MAXSIZE-byte target.sensf_res field without an upper-bound check. A nearby malicious NFC-F device can send an oversized SENSF_RES response to overflow the stack-local struct nfc_target. Clamp resp->len to NFC_SENSF_RES_MAXSIZE before the copy. Found by 0sec automated security-research tooling (https://0sec.ai).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: digital: clamp SENSF_RES length to the destination buffer\n\ndigital_in_recv_sensf_res() memcpy()s resp->len bytes from a remote\nNFC-F device response into the NFC_SENSF_RES_MAXSIZE-byte target.sensf_res\nfield without an upper-bound check. A nearby malicious NFC-F device can\nsend an oversized SENSF_RES response to overflow the stack-local struct\nnfc_target.\n\nClamp resp->len to NFC_SENSF_RES_MAXSIZE before the copy.\n\nFound by 0sec automated security-research tooling (https://0sec.ai).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09457 |
debian: CVE-2026-80803 was patched at 2026-09-16
2310.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80805) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xfs: validate attr entry pointer before field access xfs_attr3_leaf_verify_entry() accesses lentry/rentry fields (namelen, valuelen) before checking if the entry pointer itself is within bounds. If nameidx is crafted to point near the end of the buffer, these field accesses can read out-of-bounds before the bounds check at name_end > buf_end is performed. Add explicit bounds checks for entry pointers before accessing their fields. Use offsetof() to check that the start of the flexible array member (nameval/name) is within bounds, which ensures all preceding fields are safe to access.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: validate attr entry pointer before field access\n\nxfs_attr3_leaf_verify_entry() accesses lentry/rentry fields (namelen,\nvaluelen) before checking if the entry pointer itself is within bounds.\nIf nameidx is crafted to point near the end of the buffer, these field\naccesses can read out-of-bounds before the bounds check at\nname_end > buf_end is performed.\n\nAdd explicit bounds checks for entry pointers before accessing their\nfields. Use offsetof() to check that the start of the flexible array\nmember (nameval/name) is within bounds, which ensures all preceding\nfields are safe to access.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09458 |
debian: CVE-2026-80805 was patched at 2026-09-16
2311.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80806) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ext4: don't enable DAX on new encrypted files Currently, when a new encrypted regular file is created, the call to ext4_set_inode_flags(inode, init=true) in __ext4_new_inode() is made before EXT4_INODE_ENCRYPT is set. As a result, it can set S_DAX if the filesystem is mounted with "-o dax=always". EXT4_INODE_ENCRYPT then actually gets set a bit later in __ext4_new_inode(), when it calls fscrypt_set_context() which calls ext4_set_context(). ext4_set_context() sets EXT4_INODE_ENCRYPT and calls ext4_set_inode_flags(inode, init=false) to set S_ENCRYPTED too. This was intended to clear S_DAX as well. However, this was broken by commit 043546e46dc7 ("fs/ext4: Only change S_DAX on inode load"). This causes data written to the file to bypass encryption, also causing xfstests failures such as generic/548 (when "-o dax=always" is used). Fix this by simplifying the flow by making __ext4_new_inode() set EXT4_INODE_ENCRYPT earlier. This makes it take effect in ext4_set_inode_flags(inode, init=true), making S_DAX never be set. Similarly, make EXT4_STATE_MAY_INLINE_DATA never be set in the first place on new encrypted inodes. Then it doesn't need to be cleared. As a result of these simplifications, ext4_set_context() no longer needs to change inode flags or state when 'handle != NULL'. Remove that too.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\next4: don't enable DAX on new encrypted files\n\nCurrently, when a new encrypted regular file is created, the call to\next4_set_inode_flags(inode, init=true) in __ext4_new_inode() is made\nbefore EXT4_INODE_ENCRYPT is set. As a result, it can set S_DAX if the\nfilesystem is mounted with "-o dax=always".\n\nEXT4_INODE_ENCRYPT then actually gets set a bit later in\n__ext4_new_inode(), when it calls fscrypt_set_context() which calls\next4_set_context(). ext4_set_context() sets EXT4_INODE_ENCRYPT and\ncalls ext4_set_inode_flags(inode, init=false) to set S_ENCRYPTED too.\n\nThis was intended to clear S_DAX as well. However, this was broken by\ncommit 043546e46dc7 ("fs/ext4: Only change S_DAX on inode load"). This\ncauses data written to the file to bypass encryption, also causing\nxfstests failures such as generic/548 (when "-o dax=always" is used).\n\nFix this by simplifying the flow by making __ext4_new_inode() set\nEXT4_INODE_ENCRYPT earlier. This makes it take effect in\next4_set_inode_flags(inode, init=true), making S_DAX never be set.\n\nSimilarly, make EXT4_STATE_MAY_INLINE_DATA never be set in the first\nplace on new encrypted inodes. Then it doesn't need to be cleared.\n\nAs a result of these simplifications, ext4_set_context() no longer needs\nto change inode flags or state when 'handle != NULL'. Remove that too.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.07023 |
debian: CVE-2026-80806 was patched at 2026-09-16
2312.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80807) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nilfs2: reject invalid block index in GC ioctl Syzbot reported list corruption caused by a double list_add_tail() call on bh->b_assoc_buffers within nilfs_lookup_dirty_data_buffers(). Analysis revealed that the root cause was the insertion of a page/folio with a page index of ULONG_MAX into the page cache via the GC ioctl. filemap_get_folios_tag(), called by nilfs_lookup_dirty_data_buffers(), repeatedly detects a dirty folio with a page index of ULONG_MAX due to index wrap-around, leading to duplicate processing of dirty buffers. As a preparatory step, the GC ioctl loads the page/folio of the block to be moved during GC and inserts it into the page cache based on information in the nilfs_vdesc structure passed as an argument. Normally, this does not cause issues because the user-space GC library configures the nilfs_vdesc structure properly. However, since there is no range check on the parameters determining the page index, a request with artificially crafted parameters -- such as those generated by Syzbot -- can result in a page/folio being inserted with a page index of ULONG_MAX, triggering the above problem. This resolves the issue by checking the ranges of 'vd_offset' and 'vd_vblocknr' in the nilfs_vdesc structure that determine the page index, thereby preventing the invalid page/folio insertions.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: reject invalid block index in GC ioctl\n\nSyzbot reported list corruption caused by a double list_add_tail() call on\nbh->b_assoc_buffers within nilfs_lookup_dirty_data_buffers().\n\nAnalysis revealed that the root cause was the insertion of a page/folio\nwith a page index of ULONG_MAX into the page cache via the GC ioctl.\nfilemap_get_folios_tag(), called by nilfs_lookup_dirty_data_buffers(),\nrepeatedly detects a dirty folio with a page index of ULONG_MAX due to\nindex wrap-around, leading to duplicate processing of dirty buffers.\n\nAs a preparatory step, the GC ioctl loads the page/folio of the block to\nbe moved during GC and inserts it into the page cache based on information\nin the nilfs_vdesc structure passed as an argument. Normally, this does\nnot cause issues because the user-space GC library configures the\nnilfs_vdesc structure properly. However, since there is no range check on\nthe parameters determining the page index, a request with artificially\ncrafted parameters -- such as those generated by Syzbot -- can result in a\npage/folio being inserted with a page index of ULONG_MAX, triggering the\nabove problem.\n\nThis resolves the issue by checking the ranges of 'vd_offset' and\n'vd_vblocknr' in the nilfs_vdesc structure that determine the page index,\nthereby preventing the invalid page/folio insertions.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00201, EPSS Percentile is 0.10145 |
debian: CVE-2026-80807 was patched at 2026-09-16
2313.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80808) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ext4: stop retrying saturated xattr cache entries ext4_xattr_block_set() retries when a cache entry selected for reuse has a saturated reference count after taking the buffer lock. The retry returns to the mbcache lookup without making that entry ineligible, so it can select the same unusable entry indefinitely. A task spinning there can hold the parent directory's i_rwsem and leave concurrent rmdir callers blocked. Normally a reusable entry has a reference count below EXT4_XATTR_REFCOUNT_MAX because the count and MBE_REUSABLE_B are updated under the same buffer lock. A corrupted filesystem can violate that invariant. The syzbot reproducer reports allocator and xattr corruption before triggering this retry loop. Check the untrusted on-disk count before incrementing it, avoiding overflow, and clear MBE_REUSABLE_B when it is already saturated. The next lookup then skips the entry that was just proven unusable. This mirrors the normal transition at EXT4_XATTR_REFCOUNT_MAX; the release path marks the entry reusable again on the exact 1024-to-1023 transition. Using the same QEMU harness and guest parameters, current unpatched Linux hung in 6 of 8 420-second trials with the do_rmdir signature; representative NMI backtraces caught the owner spinning in ext4_xattr_block_set(). The patched kernel completed 28 of 28 trials without a hung-task report; the final twelve trials exercised the reviewed overflow-safe form of the change. syzbot's patch testing also completed without reproducing the hang.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\next4: stop retrying saturated xattr cache entries\n\next4_xattr_block_set() retries when a cache entry selected for reuse\nhas a saturated reference count after taking the buffer lock. The retry\nreturns to the mbcache lookup without making that entry ineligible, so\nit can select the same unusable entry indefinitely. A task spinning\nthere can hold the parent directory's i_rwsem and leave concurrent\nrmdir callers blocked.\n\nNormally a reusable entry has a reference count below\nEXT4_XATTR_REFCOUNT_MAX because the count and MBE_REUSABLE_B are\nupdated under the same buffer lock. A corrupted filesystem can violate\nthat invariant. The syzbot reproducer reports allocator and xattr\ncorruption before triggering this retry loop.\n\nCheck the untrusted on-disk count before incrementing it, avoiding\noverflow, and clear MBE_REUSABLE_B when it is already saturated. The\nnext lookup then skips the entry that was just proven unusable. This\nmirrors the normal transition at EXT4_XATTR_REFCOUNT_MAX; the release\npath marks the entry reusable again on the exact 1024-to-1023\ntransition.\n\nUsing the same QEMU harness and guest parameters, current unpatched\nLinux hung in 6 of 8 420-second trials with the do_rmdir signature;\nrepresentative NMI backtraces caught the owner spinning in\next4_xattr_block_set(). The patched kernel completed 28 of 28 trials\nwithout a hung-task report; the final twelve trials exercised the\nreviewed overflow-safe form of the change. syzbot's patch testing also\ncompleted without reproducing the hang.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09462 |
debian: CVE-2026-80808 was patched at 2026-09-16
2314.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80809) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix missing metadata reservation for large xattrs [BUG] lsetxattr() panics the kernel when setting a large xattr value on a fragmented filesystem where the file already has an external xattr block. [CAUSE] ocfs2_calc_xattr_set_need() never reserves metadata blocks for a new xattr value's extent tree when the file already has an external xattr block. The not_found path leaves meta_add at zero, so meta_ac is NULL when ocfs2_xattr_extend_allocation() runs. A new value root has room for a single extent record. On a fragmented filesystem, the allocator cannot satisfy the xattr value in one contiguous run, so each non-contiguous run requires its own extent record. When the value root's extent list is full and meta_ac is NULL, ocfs2_add_clusters_in_btree() returns RESTART_META, and ocfs2_xattr_extend_allocation() hits BUG_ON(why == RESTART_META). [FIX] The case where no xattr block exists yet already calls ocfs2_extend_meta_needed(&def_xv.xv.xr_list) to reserve value tree metadata. Add the same reservation to the case where an xattr block already exists, making the two cases consistent. Replace the BUG_ON with a -ENOSPC return so that if RESTART_META is returned despite the reservation, the error propagates to userspace instead of panicking the kernel.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix missing metadata reservation for large xattrs\n\n[BUG]\nlsetxattr() panics the kernel when setting a large xattr value on a\nfragmented filesystem where the file already has an external xattr\nblock.\n\n[CAUSE]\nocfs2_calc_xattr_set_need() never reserves metadata blocks for a new\nxattr value's extent tree when the file already has an external xattr\nblock. The not_found path leaves meta_add at zero, so meta_ac is NULL\nwhen ocfs2_xattr_extend_allocation() runs.\n\nA new value root has room for a single extent record. On a fragmented\nfilesystem, the allocator cannot satisfy the xattr value in one\ncontiguous run, so each non-contiguous run requires its own extent\nrecord. When the value root's extent list is full and meta_ac is NULL,\nocfs2_add_clusters_in_btree() returns RESTART_META, and\nocfs2_xattr_extend_allocation() hits BUG_ON(why == RESTART_META).\n\n[FIX]\nThe case where no xattr block exists yet already calls\nocfs2_extend_meta_needed(&def_xv.xv.xr_list) to reserve value tree\nmetadata. Add the same reservation to the case where an xattr block\nalready exists, making the two cases consistent.\n\nReplace the BUG_ON with a -ENOSPC return so that if RESTART_META is\nreturned despite the reservation, the error propagates to userspace\ninstead of panicking the kernel.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.0946 |
debian: CVE-2026-80809 was patched at 2026-09-16
2315.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80812) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: dummy: Check card index validity at probe snd_dummy_probe() blindly trusts that the given devptr->id value is within the proper card index range. It's OK for the devices the driver itself creates at the module probe time, but if the device is bound manually via sysfs interface, this could be -1 as "none", and this leads to OOB access for index[] and other parameters. Add a sanity check for the card index and warn/correct it if it's a value out of the range.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: dummy: Check card index validity at probe\n\nsnd_dummy_probe() blindly trusts that the given devptr->id value is\nwithin the proper card index range. It's OK for the devices the\ndriver itself creates at the module probe time, but if the device is\nbound manually via sysfs interface, this could be -1 as "none", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07459 |
debian: CVE-2026-80812 was patched at 2026-09-16
2316.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80814) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: rndis_host: add overflow check in rndis_rx_fixup() Add an overflow check to ensure that data_offset + data_len + 8 does not wrap, which would enable an OOB read of the USB data buffer.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nrndis_host: add overflow check in rndis_rx_fixup()\n\nAdd an overflow check to ensure that data_offset + data_len + 8 does not\nwrap, which would enable an OOB read of the USB data buffer.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09457 |
debian: CVE-2026-80814 was patched at 2026-09-16
2317.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80815) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Use a private URB for the notification endpoint scarlett2_init_notify() used mixer->urb, which snd_usb_mixer_status_create() allocates for the UAC2 status interrupt endpoint and mixer.c manages. On a device with that endpoint, the "already in use" check fires on the status URB and returns 0 for success without doing anything. No notification URB is submitted, and cmd_done is left zeroed because it is initialised past that check and nowhere else. scarlett2_usb_init() then issues SCARLETT2_USB_INIT_1 and wait_for_completion_timeout() would crash adding to the zeroed wait.head. Use a separate URB in scarlett2_data, as done for FCP, and initialise cmd_done in scarlett2_init_private(). mixer.c was also freeing the URB in snd_usb_mixer_free() and resubmitting it in snd_usb_mixer_activate(), so scarlett2 must now do both: add scarlett2_cleanup_urb(), called from private_free and private_suspend, and a private_resume callback to re-establish the URB after resume. scarlett2_init_notify() is reached from there, and the URB kill path in scarlett2_notify() completes cmd_done, leaving a stale count that would satisfy the next command's wait before the device ACKs. Use reinit_completion() to clear it. Also free the URB if the transfer buffer allocation fails, and both if usb_submit_urb() fails. Move scarlett2_init_notify() up next to scarlett2_cleanup_urb() so scarlett2_init_private() can reference it without a forward declaration.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: scarlett2: Use a private URB for the notification endpoint\n\nscarlett2_init_notify() used mixer->urb, which\nsnd_usb_mixer_status_create() allocates for the UAC2 status interrupt\nendpoint and mixer.c manages. On a device with that endpoint, the\n"already in use" check fires on the status URB and returns 0 for\nsuccess without doing anything. No notification URB is submitted, and\ncmd_done is left zeroed because it is initialised past that check and\nnowhere else. scarlett2_usb_init() then issues SCARLETT2_USB_INIT_1\nand wait_for_completion_timeout() would crash adding to the zeroed\nwait.head.\n\nUse a separate URB in scarlett2_data, as done for FCP, and initialise\ncmd_done in scarlett2_init_private(). mixer.c was also freeing the URB\nin snd_usb_mixer_free() and resubmitting it in\nsnd_usb_mixer_activate(), so scarlett2 must now do both: add\nscarlett2_cleanup_urb(), called from private_free and private_suspend,\nand a private_resume callback to re-establish the URB after resume.\nscarlett2_init_notify() is reached from there, and the URB kill path\nin scarlett2_notify() completes cmd_done, leaving a stale count that\nwould satisfy the next command's wait before the device ACKs. Use\nreinit_completion() to clear it.\n\nAlso free the URB if the transfer buffer allocation fails, and both if\nusb_submit_urb() fails. Move scarlett2_init_notify() up next to\nscarlett2_cleanup_urb() so scarlett2_init_private() can reference it\nwithout a forward declaration.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06406 |
debian: CVE-2026-80815 was patched at 2026-09-16
2318.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80819) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept rfcomm_sock_recvmsg() completes a deferred setup by calling rfcomm_dlc_accept() without holding any RFCOMM lock: \tif (test_and_clear_bit(RFCOMM_DEFER_SETUP, &d->flags)) { \t\trfcomm_dlc_accept(d); \t\treturn 0; \t} and rfcomm_dlc_accept() dereferences the session on its first line: \tstruct sock *sk = d->session->sock->sk; Every other path that touches d->session runs under rfcomm_mutex: rfcomm_dlc_open(), rfcomm_dlc_close(), rfcomm_dlc_exists(), rfcomm_dlc_send_rpn(), and the RFCOMM thread through rfcomm_process_sessions(). rfcomm_connect_ind() is even documented as "called under rfcomm_lock()". This call site is the only one that skips it. The RFCOMM_DEFER_SETUP bit looks like it serialises the accept against teardown, since __rfcomm_dlc_close() returns early when it wins the test_and_clear. But rfcomm_recv_disc() forces the state first: \td->state = BT_CLOSED; \t__rfcomm_dlc_close(d, err); and the early return only covers BT_CONNECT, BT_CONFIG, BT_OPEN and BT_CONNECT2. With the state already BT_CLOSED that switch does not match, the bit is never consulted, and __rfcomm_dlc_close() falls through to rfcomm_dlc_unlink(), which sets d->session = NULL. So a remote DISC on a deferred dlc clears the session while leaving RFCOMM_DEFER_SETUP set. The next recvmsg() then passes the test_and_clear and dereferences a NULL session. No timing window is needed: once the DISC has been processed, the dereference is unconditional. Give rfcomm_dlc_accept() the same shape as rfcomm_dlc_open() and rfcomm_dlc_close(): an exported wrapper that takes rfcomm_mutex and re-checks the session, around a __rfcomm_dlc_accept() that the two in-core callers, which already hold the mutex, keep using. Reproduced on a KASAN + PROVE_LOCKING kernel with a BR/EDR peer emulated over /dev/vhci: the peer brings up an ACL link, opens L2CAP on the RFCOMM PSM, starts a session, opens a dlc on a channel bound with BT_DEFER_SETUP, and sends DISC after the socket is accepted. recv() on the accepted socket then hits: Oops: general protection fault KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017] RIP: 0010:rfcomm_dlc_accept+0x54/0x350 Call Trace: rfcomm_sock_recvmsg+0x1cd/0x230 sock_recvmsg+0x166/0x1c0 __sys_recvfrom+0x20d/0x300 0x10 is the offset of sock in struct rfcomm_session. With this patch the same run completes with recv() returning 0 and no report, and lockdep stays quiet, confirming rfcomm_mutex is still taken before lock_sock on this path as it is on the thread side.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept\n\nrfcomm_sock_recvmsg() completes a deferred setup by calling\nrfcomm_dlc_accept() without holding any RFCOMM lock:\n\n\tif (test_and_clear_bit(RFCOMM_DEFER_SETUP, &d->flags)) {\n\t\trfcomm_dlc_accept(d);\n\t\treturn 0;\n\t}\n\nand rfcomm_dlc_accept() dereferences the session on its first line:\n\n\tstruct sock *sk = d->session->sock->sk;\n\nEvery other path that touches d->session runs under rfcomm_mutex:\nrfcomm_dlc_open(), rfcomm_dlc_close(), rfcomm_dlc_exists(),\nrfcomm_dlc_send_rpn(), and the RFCOMM thread through\nrfcomm_process_sessions(). rfcomm_connect_ind() is even documented as\n"called under rfcomm_lock()". This call site is the only one that skips\nit.\n\nThe RFCOMM_DEFER_SETUP bit looks like it serialises the accept against\nteardown, since __rfcomm_dlc_close() returns early when it wins the\ntest_and_clear. But rfcomm_recv_disc() forces the state first:\n\n\td->state = BT_CLOSED;\n\t__rfcomm_dlc_close(d, err);\n\nand the early return only covers BT_CONNECT, BT_CONFIG, BT_OPEN and\nBT_CONNECT2. With the state already BT_CLOSED that switch does not\nmatch, the bit is never consulted, and __rfcomm_dlc_close() falls\nthrough to rfcomm_dlc_unlink(), which sets d->session = NULL.\n\nSo a remote DISC on a deferred dlc clears the session while leaving\nRFCOMM_DEFER_SETUP set. The next recvmsg() then passes the\ntest_and_clear and dereferences a NULL session. No timing window is\nneeded: once the DISC has been processed, the dereference is\nunconditional.\n\nGive rfcomm_dlc_accept() the same shape as rfcomm_dlc_open() and\nrfcomm_dlc_close(): an exported wrapper that takes rfcomm_mutex and\nre-checks the session, around a __rfcomm_dlc_accept() that the two\nin-core callers, which already hold the mutex, keep using.\n\nReproduced on a KASAN + PROVE_LOCKING kernel with a BR/EDR peer emulated\nover /dev/vhci: the peer brings up an ACL link, opens L2CAP on the\nRFCOMM PSM, starts a session, opens a dlc on a channel bound with\nBT_DEFER_SETUP, and sends DISC after the socket is accepted. recv() on\nthe accepted socket then hits:\n\n Oops: general protection fault\n KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]\n RIP: 0010:rfcomm_dlc_accept+0x54/0x350\n Call Trace:\n rfcomm_sock_recvmsg+0x1cd/0x230\n sock_recvmsg+0x166/0x1c0\n __sys_recvfrom+0x20d/0x300\n\n0x10 is the offset of sock in struct rfcomm_session. With this patch the\nsame run completes with recv() returning 0 and no report, and lockdep\nstays quiet, confirming rfcomm_mutex is still taken before lock_sock on\nthis path as it is on the thread side.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.0946 |
debian: CVE-2026-80819 was patched at 2026-09-16
2319.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80820) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xfs: don't livelock in scrub on a circular unlinked list LOLLM points out that online fsck can livelock if an unlinked inode list contains a loop. Use a bitmap to detect cycles.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: don't livelock in scrub on a circular unlinked list\n\nLOLLM points out that online fsck can livelock if an unlinked inode list\ncontains a loop. Use a bitmap to detect cycles.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06443 |
debian: CVE-2026-80820 was patched at 2026-09-16
2320.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80825) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb mt7925_usb_sdio_tx_prepare_skb() pushes a TX descriptor and a USB header onto every skb and assumes the headroom for them is already there. That holds for locally generated traffic, where mac80211 reserves hw->extra_tx_headroom, but forwarded frames are sent through ieee80211_8023_xmit(), which does not reserve it. Bridge a wired interface to an mt7925u AP and the first forwarded frame that arrives short panics the kernel: skbuff: skb_under_panic: len:415 put:4 tail:0x19b end:0x640 dev:wlan1 kernel BUG at net/core/skbuff.c:212! Call trace: skb_panic+0x58/0x60 (P) skb_push+0x58/0x60 mt7925_usb_sdio_tx_prepare_skb+0xf8/0x1b8 [mt7925_common] mt76u_tx_queue_skb+0xa0/0x1f8 [mt76_usb] __mt76_tx_queue_skb+0x54/0xe8 [mt76] mt76_txq_schedule.part.0+0x204/0x478 [mt76] mt76_txq_schedule_all+0x50/0x80 [mt76] mt792x_tx_worker+0x68/0x100 [mt792x_lib] __mt76_worker_fn+0x84/0x150 [mt76] Whether a given setup hits it depends on how much headroom the ingress netdev leaves in its rx skbs. Reproduced on a Raspberry Pi 5 bridging onboard ethernet to a Netgear A9000; originally reported on an MT7986 router running OpenWrt. Nick Morrow's testing on a Pi 4 (bcmgenet), which leaves more headroom, helped narrow the trigger to the ingress path. The same bug was fixed on mt7921 by commit 98c4d0abf5c4 ("mt76: mt7921: don't assume adequate headroom for SDIO headers"), but mt7925 was copied from mt7921 without the fix. Add the same guard here.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb\n\nmt7925_usb_sdio_tx_prepare_skb() pushes a TX descriptor and a USB\nheader onto every skb and assumes the headroom for them is already\nthere. That holds for locally generated traffic, where mac80211\nreserves hw->extra_tx_headroom, but forwarded frames are sent through\nieee80211_8023_xmit(), which does not reserve it. Bridge a wired\ninterface to an mt7925u AP and the first forwarded frame that arrives\nshort panics the kernel:\n\n skbuff: skb_under_panic: len:415 put:4 tail:0x19b end:0x640 dev:wlan1\n kernel BUG at net/core/skbuff.c:212!\n Call trace:\n skb_panic+0x58/0x60 (P)\n skb_push+0x58/0x60\n mt7925_usb_sdio_tx_prepare_skb+0xf8/0x1b8 [mt7925_common]\n mt76u_tx_queue_skb+0xa0/0x1f8 [mt76_usb]\n __mt76_tx_queue_skb+0x54/0xe8 [mt76]\n mt76_txq_schedule.part.0+0x204/0x478 [mt76]\n mt76_txq_schedule_all+0x50/0x80 [mt76]\n mt792x_tx_worker+0x68/0x100 [mt792x_lib]\n __mt76_worker_fn+0x84/0x150 [mt76]\n\nWhether a given setup hits it depends on how much headroom the ingress\nnetdev leaves in its rx skbs. Reproduced on a Raspberry Pi 5 bridging\nonboard ethernet to a Netgear A9000; originally reported on an MT7986\nrouter running OpenWrt. Nick Morrow's testing on a Pi 4 (bcmgenet),\nwhich leaves more headroom, helped narrow the trigger to the ingress\npath.\n\nThe same bug was fixed on mt7921 by commit 98c4d0abf5c4 ("mt76:\nmt7921: don't assume adequate headroom for SDIO headers"), but mt7925\nwas copied from mt7921 without the fix. Add the same guard here.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.0644 |
debian: CVE-2026-80825 was patched at 2026-09-16
2321.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80828) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Complete cleanup after system-resume errors A failed system resume can leave the card unusable until reboot. usb_audio_resume() jumps to err_out when snd_usb_pcm_resume() or snd_usb_mixer_resume() fails. The error path skips the out: block, which restores D0 and decrements chip->num_suspended_intf. The card stays in SNDRV_CTL_POWER_D3hot, so later control access blocks in snd_power_ref_and_wait(). USB core logs an interface resume callback error. It does not retry that callback, so a later callback cannot complete the skipped cleanup. usb_audio_suspend() increments num_suspended_intf before returning success. A system-resume callback must consume the system-suspend count even if a component resume fails. Otherwise, the stranded count skews later suspend and resume cycles. Do not apply this cleanup to runtime-resume errors. Runtime PM can retry -EAGAIN or -EBUSY without another suspend callback. The count must continue to describe that suspended interface. Other runtime-resume errors latch runtime_error in the PM core and do not cause an immediate callback retry. Both parts of the system-resume error path are longstanding. Commit 88a8516a2128a ("ALSA: usbaudio: implement USB autosuspend") introduced err_out past the D0 restore. Commit 862b2509d157c ("ALSA: usb-audio: Fix inconsistent card PM state after resume") later moved num_suspended_intf-- into the out: block. The error path now skips both operations. No third-party code is needed to reach the error path. snd_usb_mixer_resume() ends in snd_usb_mixer_activate(), which returns the result of usb_submit_urb() for devices that have a mixer status URB. Its mixer->private_resume hook can also fail through scarlett2_init_notify(). snd_usb_pcm_resume() issues a SET_CUR request to a UAC3 power domain. It can return -EPIPE or -EIO when the device stalls the request. Route a component error through out: only when system_suspend is nonzero. Continue to return runtime-resume errors through err_out. Later component resume stages remain skipped. The original error still reaches USB core. A later transfer can fail if the device did not recover. I reproduced the system-resume failure on an Audient iD14 MkI with an out-of-tree diagnostic mixer resume hook. An injected -EIO on the unpatched core left control readers in uninterruptible sleep in snd_power_ref_and_wait() until a reboot. With this patch, the same failure restored control access. A second system suspend and resume also succeeded after I disabled fault injection.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Complete cleanup after system-resume errors\n\nA failed system resume can leave the card unusable until reboot.\nusb_audio_resume() jumps to err_out when snd_usb_pcm_resume() or\nsnd_usb_mixer_resume() fails. The error path skips the out: block, which\nrestores D0 and decrements chip->num_suspended_intf.\n\nThe card stays in SNDRV_CTL_POWER_D3hot, so later control access blocks in\nsnd_power_ref_and_wait(). USB core logs an interface resume callback error.\nIt does not retry that callback, so a later callback cannot complete the\nskipped cleanup.\n\nusb_audio_suspend() increments num_suspended_intf before returning success.\nA system-resume callback must consume the system-suspend count even if a\ncomponent resume fails. Otherwise, the stranded count skews later suspend\nand resume cycles.\n\nDo not apply this cleanup to runtime-resume errors. Runtime PM can retry\n-EAGAIN or -EBUSY without another suspend callback. The count must continue\nto describe that suspended interface. Other runtime-resume errors latch\nruntime_error in the PM core and do not cause an immediate callback retry.\n\nBoth parts of the system-resume error path are longstanding. Commit\n88a8516a2128a ("ALSA: usbaudio: implement USB autosuspend") introduced\nerr_out past the D0 restore. Commit 862b2509d157c ("ALSA: usb-audio: Fix\ninconsistent card PM state after resume") later moved\nnum_suspended_intf-- into the out: block. The error path now skips both\noperations.\n\nNo third-party code is needed to reach the error path.\nsnd_usb_mixer_resume() ends in snd_usb_mixer_activate(), which returns the\nresult of usb_submit_urb() for devices that have a mixer status URB. Its\nmixer->private_resume hook can also fail through scarlett2_init_notify().\nsnd_usb_pcm_resume() issues a SET_CUR request to a UAC3 power domain. It\ncan return -EPIPE or -EIO when the device stalls the request.\n\nRoute a component error through out: only when system_suspend is nonzero.\nContinue to return runtime-resume errors through err_out. Later component\nresume stages remain skipped. The original error still reaches USB core.\nA later transfer can fail if the device did not recover.\n\nI reproduced the system-resume failure on an Audient iD14 MkI with an\nout-of-tree diagnostic mixer resume hook. An injected -EIO on the unpatched\ncore left control readers in uninterruptible sleep in\nsnd_power_ref_and_wait() until a reboot. With this patch, the same failure\nrestored control access. A second system suspend and resume also succeeded\nafter I disabled fault injection.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0019, EPSS Percentile is 0.08884 |
debian: CVE-2026-80828 was patched at 2026-09-16
2322.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80829) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() snd_usbmidi_novation_output() lays out a two-byte header at transfer_buffer[0..1] and passes &transfer_buffer[2] together with a length of ep->max_transfer - 2 to snd_rawmidi_transmit(): \tcount = snd_rawmidi_transmit(ep->ports[0].substream, \t\t\t\t &transfer_buffer[2], \t\t\t\t ep->max_transfer - 2); ep->max_transfer comes from the output endpoint's wMaxPacketSize via usb_maxpacket(). A malformed or malicious device can advertise a bulk OUT endpoint with a wMaxPacketSize of 1 - the USB core only clamps this value downwards - so ep->max_transfer becomes 1 and the count argument becomes -1. snd_rawmidi_transmit() passes the negative count on to __snd_rawmidi_transmit_peek(), where "if (count1 > count) count1 = count" leaves count1 negative; get_aligned_size() keeps it negative for a byte-stream substream, so the following memcpy(buffer, ..., count1) runs with a (size_t)-1 length and writes far past the transfer buffer, which was allocated with usb_alloc_coherent(ep->max_transfer). This is the same class of bug that was fixed for snd_usbmidi_akai_output() in commit 0970274613fb ("ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()"); the novation output routine was left unguarded. Bail out when the endpoint cannot hold the two-byte header plus at least one payload byte.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()\n\nsnd_usbmidi_novation_output() lays out a two-byte header at\ntransfer_buffer[0..1] and passes &transfer_buffer[2] together with a\nlength of ep->max_transfer - 2 to snd_rawmidi_transmit():\n\n\tcount = snd_rawmidi_transmit(ep->ports[0].substream,\n\t\t\t\t &transfer_buffer[2],\n\t\t\t\t ep->max_transfer - 2);\n\nep->max_transfer comes from the output endpoint's wMaxPacketSize via\nusb_maxpacket(). A malformed or malicious device can advertise a bulk\nOUT endpoint with a wMaxPacketSize of 1 - the USB core only clamps this\nvalue downwards - so ep->max_transfer becomes 1 and the count argument\nbecomes -1.\n\nsnd_rawmidi_transmit() passes the negative count on to\n__snd_rawmidi_transmit_peek(), where "if (count1 > count) count1 = count"\nleaves count1 negative; get_aligned_size() keeps it negative for a\nbyte-stream substream, so the following memcpy(buffer, ..., count1) runs\nwith a (size_t)-1 length and writes far past the transfer buffer, which\nwas allocated with usb_alloc_coherent(ep->max_transfer).\n\nThis is the same class of bug that was fixed for snd_usbmidi_akai_output()\nin commit 0970274613fb ("ALSA: usb-audio: fix OOB write in\nsnd_usbmidi_akai_output()"); the novation output routine was left\nunguarded. Bail out when the endpoint cannot hold the two-byte header\nplus at least one payload byte.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09461 |
debian: CVE-2026-80829 was patched at 2026-09-16
2323.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80831) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: crypto: mxs-dcp - fix source scatterlist length access mxs_dcp_aes_block_crypt() uses sg_dma_len() without mapping the source scatterlist with dma_map_sg() first. Therefore, sg_dma_len() is invalid and could return zero or a stale DMA length, causing encryption and decryption to process the wrong number of bytes when CONFIG_NEED_SG_DMA_LENGTH=y. Use the original scatterlist length instead.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: mxs-dcp - fix source scatterlist length access\n\nmxs_dcp_aes_block_crypt() uses sg_dma_len() without mapping the source\nscatterlist with dma_map_sg() first. Therefore, sg_dma_len() is invalid\nand could return zero or a stale DMA length, causing encryption and\ndecryption to process the wrong number of bytes when\nCONFIG_NEED_SG_DMA_LENGTH=y.\n\nUse the original scatterlist length instead.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06111 |
debian: CVE-2026-80831 was patched at 2026-09-16
2324.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80832) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: crypto: qce - fix CCM AAD buffer underallocation The AAD buffer allocated in qce_aead_ccm_prepare_buf_assoclen() can be smaller than the length later programmed into the DMA scatterlist. The allocation size is currently calculated as: ALIGN(assoclen, 16) + MAX_CCM_ADATA_HEADER_LEN while the DMA length is set to: ALIGN(assoclen + adata_header_len, 16) Since ALIGN() does not distribute over addition, the allocation can be smaller than the DMA length. For example, when assoclen = 32 and adata_header_len = 2: allocation = ALIGN(32, 16) + 6 = 38 DMA length = ALIGN(32 + 2, 16) = 48 As a result, the QCE hardware can read beyond the allocated buffer while computing the CBC-MAC over the associated data. The extra bytes are folded into the authentication tag, resulting in an incorrect tag and causing CCM self-test failures such as: alg: aead: ccm-aes-qce encryption test failed (wrong result) on test vector 8 Fix the allocation by adding the maximum possible AAD header length before alignment: ALIGN(assoclen + MAX_CCM_ADATA_HEADER_LEN, 16) This guarantees that the allocated buffer is large enough for the fully padded AAD data for all supported header sizes.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qce - fix CCM AAD buffer underallocation\n\nThe AAD buffer allocated in qce_aead_ccm_prepare_buf_assoclen()\ncan be smaller than the length later programmed into the DMA\nscatterlist.\n\nThe allocation size is currently calculated as:\n\n ALIGN(assoclen, 16) + MAX_CCM_ADATA_HEADER_LEN\n\nwhile the DMA length is set to:\n\n ALIGN(assoclen + adata_header_len, 16)\n\nSince ALIGN() does not distribute over addition, the allocation\ncan be smaller than the DMA length. For example, when\nassoclen = 32 and adata_header_len = 2:\n\n allocation = ALIGN(32, 16) + 6 = 38\n DMA length = ALIGN(32 + 2, 16) = 48\n\nAs a result, the QCE hardware can read beyond the allocated\nbuffer while computing the CBC-MAC over the associated data.\nThe extra bytes are folded into the authentication tag,\nresulting in an incorrect tag and causing CCM self-test\nfailures such as:\n\n alg: aead: ccm-aes-qce encryption test failed (wrong result)\n on test vector 8\n\nFix the allocation by adding the maximum possible AAD header\nlength before alignment:\n\n ALIGN(assoclen + MAX_CCM_ADATA_HEADER_LEN, 16)\n\nThis guarantees that the allocated buffer is large enough\nfor the fully padded AAD data for all supported header sizes.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00178, EPSS Percentile is 0.07586 |
debian: CVE-2026-80832 was patched at 2026-09-16
2325.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80835) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - Remove crypto_rng interface qcom-rng.c exposes the same hardware through two completely separate interfaces, crypto_rng and hwrng. However, the implementation of this is buggy because it permits generation operations from these interfaces to run concurrently with each other, accessing the same registers. That is, qcom_rng_generate() synchronizes with itself but not with qcom_hwrng_read(). This results in potential repetition of output from the RNG, output of non-random values, etc. Fortunately, there's actually no point in hardware RNG drivers implementing the crypto_rng interface. It's not actually used by anything besides the "rng" algorithm type of AF_ALG, which in turn is not actually used in practice. Other crypto_rng hardware drivers are likewise being phased out, leaving just the hwrng support. Thus, remove it to simplify the code and avoid conflict (and confusion) with the hwrng interface which is the one that actually matters.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qcom-rng - Remove crypto_rng interface\n\nqcom-rng.c exposes the same hardware through two completely separate\ninterfaces, crypto_rng and hwrng. However, the implementation of this\nis buggy because it permits generation operations from these interfaces\nto run concurrently with each other, accessing the same registers. That\nis, qcom_rng_generate() synchronizes with itself but not with\nqcom_hwrng_read(). This results in potential repetition of output from\nthe RNG, output of non-random values, etc.\n\nFortunately, there's actually no point in hardware RNG drivers\nimplementing the crypto_rng interface. It's not actually used by\nanything besides the "rng" algorithm type of AF_ALG, which in turn is\nnot actually used in practice. Other crypto_rng hardware drivers are\nlikewise being phased out, leaving just the hwrng support.\n\nThus, remove it to simplify the code and avoid conflict (and confusion)\nwith the hwrng interface which is the one that actually matters.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06448 |
debian: CVE-2026-80835 was patched at 2026-09-16
2326.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80838) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: vxlan: keep the last remote linked during FDB flush A non-nexthop FDB entry is expected to have at least one remote while it remains reachable through the FDB hash table. A filtered bulk flush violates this invariant when every remote matches: It unlinks the last remote in vxlan_fdb_dst_destroy() and only afterwards tells vxlan_flush() to destroy the parent FDB entry. An RCU reader can find the parent during this interval. first_remote_rcu() then applies list_entry_rcu() to the empty list head, producing an invalid remote pointer that the receive learning path can read from and write to. When a matching remote is the sole remaining remote, leave it linked and ask the caller to destroy the entire FDB entry. vxlan_fdb_destroy() keeps the remote attached while sending the deletion notification and removing the parent from the lookup structures.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: keep the last remote linked during FDB flush\n\nA non-nexthop FDB entry is expected to have at least one remote while it\nremains reachable through the FDB hash table. A filtered bulk flush\nviolates this invariant when every remote matches: It unlinks the last\nremote in vxlan_fdb_dst_destroy() and only afterwards tells vxlan_flush()\nto destroy the parent FDB entry.\n\nAn RCU reader can find the parent during this interval.\nfirst_remote_rcu() then applies list_entry_rcu() to the empty list head,\nproducing an invalid remote pointer that the receive learning path can\nread from and write to.\n\nWhen a matching remote is the sole remaining remote, leave it linked and\nask the caller to destroy the entire FDB entry. vxlan_fdb_destroy() keeps\nthe remote attached while sending the deletion notification and removing\nthe parent from the lookup structures.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06449 |
debian: CVE-2026-80838 was patched at 2026-09-16
2327.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80839) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject unrepresentable multicast TVLV offsets The network and transport header fields in struct sk_buff are 16-bit offsets from skb->head, and U16_MAX is reserved as the unset transport header value. batadv_tvlv_call_handler() sets both fields from a received multicast TVLV without checking whether the TVLV end is representable. If the end offset exceeds the field's range, skb_set_transport_header() truncates it so that the transport header precedes the network header. The negative difference is then returned by skb_network_header_len() as a large u32. batadv_mcast_forw_packet() consequently accepts an oversized multicast tracker and accesses memory beyond the skb data. Add skb_set_transport_header_careful(), an offset-aware counterpart to skb_reset_transport_header_careful(), which validates the final head-relative offset before assigning it. Use the new helper in batadv_tvlv_call_handler() and reject unrepresentable TVLVs before setting the network header.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: reject unrepresentable multicast TVLV offsets\n\nThe network and transport header fields in struct sk_buff are 16-bit\noffsets from skb->head, and U16_MAX is reserved as the unset transport\nheader value. batadv_tvlv_call_handler() sets both fields from a received\nmulticast TVLV without checking whether the TVLV end is representable.\n\nIf the end offset exceeds the field's range, skb_set_transport_header()\ntruncates it so that the transport header precedes the network header.\nThe negative difference is then returned by skb_network_header_len() as\na large u32. batadv_mcast_forw_packet() consequently accepts an oversized\nmulticast tracker and accesses memory beyond the skb data.\n\nAdd skb_set_transport_header_careful(), an offset-aware counterpart to\nskb_reset_transport_header_careful(), which validates the final\nhead-relative offset before assigning it. Use the new helper in\nbatadv_tvlv_call_handler() and reject unrepresentable TVLVs before\nsetting the network header.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06446 |
debian: CVE-2026-80839 was patched at 2026-09-16
2328.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80840) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipv6: seg6: clear IPv4 control block on IPIP decapsulation End.DX4 and End.DT4 decapsulate an IPv4 packet through decap_and_validate() and send it directly to IPv4 routing. The inner packet therefore bypasses ip_rcv_core(), which normally clears IPCB before IPv4 interprets skb->cb. The skb instead retains IP6CB data from the outer packet. IP6CB and IPCB use the same skb->cb storage, so IP6CB(skb)->lastopt overlaps IPCB(skb)->opt.optlen and srr, while IP6CB(skb)->nhoff overlaps rr and ts. The sender can make the stale optlen byte nonzero with a valid outer extension-header chain. The reproducers put an eight-byte Destination Options header immediately after the 40-byte IPv6 header and before the Segment Routing Header. ipv6_destopt_rcv() records the sender-controlled Destination Options offset in both lastopt and nhoff, setting them to 40. On the reproduced little-endian x86-64 kernel, IPv4 therefore sees optlen = 40 and rr = 40. Both tcp_v4_save_options() and __ip_options_echo() skip option copying when optlen is zero. Here optlen is 40, so the TCP SYN path allocates room for 40 bytes of option data and calls __ip_options_echo(). The stale rr value makes that function read inner packet byte 41 as the Record Route option length. The reproducers set that sender-controlled byte to 255, so __ip_options_echo() copies 255 bytes into the 40-byte option-data area. Separate End.DX4 and End.DT4 reproducers on the unpatched v7.2-rc5 kernel both produced: BUG: KASAN: slab-out-of-bounds in __ip_options_echo() Write of size 255 The relevant End.DX4 call path is: __ip_options_echo tcp_v4_route_req tcp_conn_request tcp_v4_conn_request tcp_rcv_state_process tcp_v4_do_rcv tcp_v4_rcv ip_protocol_deliver_rcu ip_local_deliver_finish ip_local_deliver input_action_end_dx4_finish input_action_end_dx4 The relevant End.DT4 call path is: __ip_options_echo tcp_v4_route_req tcp_conn_request tcp_v4_conn_request tcp_rcv_state_process tcp_v4_do_rcv tcp_v4_rcv ip_protocol_deliver_rcu ip_local_deliver_finish ip_local_deliver input_action_end_dt4 tcp_v4_save_options() is inlined into the tcp_v4_route_req() path, so it does not appear as a separate frame. When decap_and_validate() handles IPPROTO_IPIP, save the ingress interface from IP6CB, clear IPCB, and restore the saved value. Doing this in the common decapsulation path covers End.DX4, End.DT4, and End.DT46's IPv4 arm. Use IP6CB(skb)->iif rather than skb->skb_iif. These actions run after l3mdev processing, which can replace skb_iif with the L3 master; IP6CB iif still records the receiving interface set at IPv6 ingress.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: seg6: clear IPv4 control block on IPIP decapsulation\n\nEnd.DX4 and End.DT4 decapsulate an IPv4 packet through\ndecap_and_validate() and send it directly to IPv4 routing. The inner\npacket therefore bypasses ip_rcv_core(), which normally clears IPCB\nbefore IPv4 interprets skb->cb.\n\nThe skb instead retains IP6CB data from the outer packet. IP6CB and\nIPCB use the same skb->cb storage, so IP6CB(skb)->lastopt overlaps\nIPCB(skb)->opt.optlen and srr, while IP6CB(skb)->nhoff overlaps rr and\nts.\n\nThe sender can make the stale optlen byte nonzero with a valid outer\nextension-header chain. The reproducers put an eight-byte Destination\nOptions header immediately after the 40-byte IPv6 header and before the\nSegment Routing Header. ipv6_destopt_rcv() records the sender-controlled\nDestination Options offset in both lastopt and nhoff, setting them to\n40. On the reproduced little-endian x86-64 kernel, IPv4 therefore sees\noptlen = 40 and rr = 40.\n\nBoth tcp_v4_save_options() and __ip_options_echo() skip option copying\nwhen optlen is zero. Here optlen is 40, so the TCP SYN path allocates\nroom for 40 bytes of option data and calls __ip_options_echo(). The\nstale rr value makes that function read inner packet byte 41 as the\nRecord Route option length. The reproducers set that sender-controlled\nbyte to 255, so __ip_options_echo() copies 255 bytes into the 40-byte\noption-data area.\n\nSeparate End.DX4 and End.DT4 reproducers on the unpatched v7.2-rc5\nkernel both produced:\n\n BUG: KASAN: slab-out-of-bounds in __ip_options_echo()\n Write of size 255\n\nThe relevant End.DX4 call path is:\n\n __ip_options_echo\n tcp_v4_route_req\n tcp_conn_request\n tcp_v4_conn_request\n tcp_rcv_state_process\n tcp_v4_do_rcv\n tcp_v4_rcv\n ip_protocol_deliver_rcu\n ip_local_deliver_finish\n ip_local_deliver\n input_action_end_dx4_finish\n input_action_end_dx4\n\nThe relevant End.DT4 call path is:\n\n __ip_options_echo\n tcp_v4_route_req\n tcp_conn_request\n tcp_v4_conn_request\n tcp_rcv_state_process\n tcp_v4_do_rcv\n tcp_v4_rcv\n ip_protocol_deliver_rcu\n ip_local_deliver_finish\n ip_local_deliver\n input_action_end_dt4\n\ntcp_v4_save_options() is inlined into the tcp_v4_route_req() path, so\nit does not appear as a separate frame.\n\nWhen decap_and_validate() handles IPPROTO_IPIP, save the ingress\ninterface from IP6CB, clear IPCB, and restore the saved value. Doing\nthis in the common decapsulation path covers End.DX4, End.DT4, and\nEnd.DT46's IPv4 arm.\n\nUse IP6CB(skb)->iif rather than skb->skb_iif. These actions run after\nl3mdev processing, which can replace skb_iif with the L3 master;\nIP6CB iif still records the receiving interface set at IPv6 ingress.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10698 |
debian: CVE-2026-80840 was patched at 2026-09-16
2329.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80843) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xfrm: fix xfrm_state_construct() auth-trunc leak attach_auth_trunc() can allocate x->aalg while leaving x->props.aalgo at zero when the selected auth algorithm has no sadb_alg_id. One real case is cmac(aes). xfrm_state_construct() then treats !x->props.aalgo as "no auth algorithm attached yet" and calls attach_auth(). That overwrites x->aalg and loses the first allocation. Any later failure or teardown only frees the replacement pointer. Check whether x->aalg is already attached instead of inferring that state from x->props.aalgo.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: fix xfrm_state_construct() auth-trunc leak\n\nattach_auth_trunc() can allocate x->aalg while leaving\nx->props.aalgo at zero when the selected auth algorithm has no\nsadb_alg_id. One real case is cmac(aes).\n\nxfrm_state_construct() then treats !x->props.aalgo as "no auth\nalgorithm attached yet" and calls attach_auth(). That overwrites\nx->aalg and loses the first allocation. Any later failure or teardown\nonly frees the replacement pointer.\n\nCheck whether x->aalg is already attached instead of inferring that\nstate from x->props.aalgo.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09459 |
debian: CVE-2026-80843 was patched at 2026-09-16
2330.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80845) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xfrm: avoid lock inversion in nat keepalive work nat_keepalive_work() walks the state table while xfrm_state_walk() holds net->xfrm.xfrm_state_lock. Its callback then acquires x->lock, which conflicts with the delete path taking the same locks in reverse order via xfrm_state_delete() and __xfrm_state_delete(). This creates an AB-BA deadlock that is reported by lockdep when a NAT keepalive worker races with SA deletion. Fix this by splitting the keepalive walk into two phases. First, collect the candidate states while the walk holds xfrm_state_lock and take a reference on each state. Then, after the walk completes, process each collected state and acquire x->lock without nesting it under xfrm_state_lock.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: avoid lock inversion in nat keepalive work\n\nnat_keepalive_work() walks the state table while xfrm_state_walk()\nholds net->xfrm.xfrm_state_lock. Its callback then acquires x->lock,\nwhich conflicts with the delete path taking the same locks in reverse\norder via xfrm_state_delete() and __xfrm_state_delete(). This creates\nan AB-BA deadlock that is reported by lockdep when a NAT keepalive\nworker races with SA deletion.\n\nFix this by splitting the keepalive walk into two phases. First,\ncollect the candidate states while the walk holds xfrm_state_lock and\ntake a reference on each state. Then, after the walk completes, process\neach collected state and acquire x->lock without nesting it under\nxfrm_state_lock.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06446 |
debian: CVE-2026-80845 was patched at 2026-09-16
2331.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80846) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xfrm: drop ESP-in-TCP packets with no ingress device ESP-in-TCP receives records through the TCP strparser. handle_esp() restores skb->dev from the saved skb_iif before passing the packet into the XFRM input path. Queued TCP data can be processed after the original ingress device has been removed, for example during veth or net namespace teardown. In that case dev_get_by_index_rcu() returns NULL. The XFRM IPv4 and IPv6 input paths both expect skb->dev to be valid while building the route lookup, so queued ESP-in-TCP data can dereference a NULL device. Drop the packet if the saved ingress device can no longer be resolved. Such a packet can no longer be routed through the normal XFRM receive path, and this preserves the existing behaviour for packets whose ingress device still exists.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: drop ESP-in-TCP packets with no ingress device\n\nESP-in-TCP receives records through the TCP strparser. handle_esp()\nrestores skb->dev from the saved skb_iif before passing the packet into\nthe XFRM input path.\n\nQueued TCP data can be processed after the original ingress device has\nbeen removed, for example during veth or net namespace teardown. In that\ncase dev_get_by_index_rcu() returns NULL. The XFRM IPv4 and IPv6 input\npaths both expect skb->dev to be valid while building the route lookup,\nso queued ESP-in-TCP data can dereference a NULL device.\n\nDrop the packet if the saved ingress device can no longer be resolved.\nSuch a packet can no longer be routed through the normal XFRM receive\npath, and this preserves the existing behaviour for packets whose ingress\ndevice still exists.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.0946 |
debian: CVE-2026-80846 was patched at 2026-09-16
2332.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80847) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: tcp: clamp route advmss to TCP_MIN_MSS tcp_select_initial_window() assumes that callers never pass an MSS smaller than 1, but route-derived advmss values can violate that assumption. A too-small explicit RTAX_ADVMSS is one way to get there, but it is not the only one. The same divide-by-zero can also be reached through the "default advmss" path when RTAX_ADVMSS is left at 0 and the effective advmss is later driven down by route MTU and min_adv_mss. Introduce a tcp_dst_advmss() helper that clamps route advmss to TCP_MIN_MSS before TCP consumes it, and use it in the TCP paths that derive advmss from dst metrics. This keeps the effective MSS from dropping to zero before tcp_select_initial_window() rounds the receive window.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: clamp route advmss to TCP_MIN_MSS\n\ntcp_select_initial_window() assumes that callers never pass an MSS\nsmaller than 1, but route-derived advmss values can violate that\nassumption.\n\nA too-small explicit RTAX_ADVMSS is one way to get there, but it is not\nthe only one. The same divide-by-zero can also be reached through the\n"default advmss" path when RTAX_ADVMSS is left at 0 and the effective\nadvmss is later driven down by route MTU and min_adv_mss.\n\nIntroduce a tcp_dst_advmss() helper that clamps route advmss to\nTCP_MIN_MSS before TCP consumes it, and use it in the TCP paths that\nderive advmss from dst metrics. This keeps the effective MSS from\ndropping to zero before tcp_select_initial_window() rounds the receive\nwindow.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06447 |
debian: CVE-2026-80847 was patched at 2026-09-16
2333.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80851) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: gtp: serialize PDP context updates PDP contexts can be deleted through GTP_CMD_DELPDP or while the GTP network device is being unregistered. The latter is serialized by RTNL, but the generic-netlink delete path only holds RCU. Running both paths concurrently can therefore make both paths delete the same PDP context. The issue was found through static analysis and reproduced on a KASAN-enabled kernel by a simple two-thread program racing GTP_CMD_DELPDP against RTM_DELLINK: Oops: general protection fault, probably for non-canonical address KASAN: maybe wild-memory-access in range [0xdead000000000120-0xdead000000000127] RIP: gtp_genl_del_pdp+0x1c1/0x420 [gtp] RBP: dead000000000122 The second deletion dereferenced the poisoned hlist pprev pointer. Serialize gtp_pdp_add(), gtp_genl_del_pdp(), and gtp_dellink() with a shared mutex. Keep the mutex held until the final use of a PDP context in the NEWPDP path, and keep the RCU read-side section around the complete PDP context use in the DELPDP path.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: serialize PDP context updates\n\nPDP contexts can be deleted through GTP_CMD_DELPDP or while the GTP\nnetwork device is being unregistered. The latter is serialized by RTNL,\nbut the generic-netlink delete path only holds RCU.\n\nRunning both paths concurrently can therefore make both paths delete the\nsame PDP context. The issue was found through static analysis and\nreproduced on a KASAN-enabled kernel by a simple two-thread program\nracing GTP_CMD_DELPDP against RTM_DELLINK:\n\n Oops: general protection fault, probably for non-canonical address\n KASAN: maybe wild-memory-access in range\n [0xdead000000000120-0xdead000000000127]\n RIP: gtp_genl_del_pdp+0x1c1/0x420 [gtp]\n RBP: dead000000000122\n\nThe second deletion dereferenced the poisoned hlist pprev pointer.\n\nSerialize gtp_pdp_add(), gtp_genl_del_pdp(), and gtp_dellink() with a\nshared mutex. Keep the mutex held until the final use of a PDP context in\nthe NEWPDP path, and keep the RCU read-side section around the complete\nPDP context use in the DELPDP path.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06446 |
debian: CVE-2026-80851 was patched at 2026-09-16
2334.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80854) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: keep port count until LUN teardown completes tcm_usbg_drop_nexus() permits session removal once tpg_port_count reaches zero. However, usbg_port_unlink() currently decrements that count from the fabric_pre_unlink() callback, before core_dev_del_lun() waits for active se_lun references to drain. If removal of the last LUN races a nexus removal, the latter can observe a zero port count and call target_remove_session(). This frees sess_cmd_map while an in-flight struct usbg_cmd, including its work item, can still be accessed. Overlapping the last-LUN unlink with nexus removal reproduces this lifetime violation as a DEBUG_OBJECTS "free active" warning for usbg_cmd_work, followed by a target-core BUG/Oops. The generic target-core unlink path has no callback after core_dev_del_lun() completes. Add an optional fabric_post_unlink() callback and use it for the f_tcm port count. The count now remains nonzero until core_dev_del_lun() has finished draining active LUN references, preventing nexus removal from freeing the session during command completion.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_tcm: keep port count until LUN teardown completes\n\ntcm_usbg_drop_nexus() permits session removal once tpg_port_count\nreaches zero. However, usbg_port_unlink() currently decrements that\ncount from the fabric_pre_unlink() callback, before core_dev_del_lun()\nwaits for active se_lun references to drain.\n\nIf removal of the last LUN races a nexus removal, the latter can observe\na zero port count and call target_remove_session(). This frees\nsess_cmd_map while an in-flight struct usbg_cmd, including its work item,\ncan still be accessed.\n\nOverlapping the last-LUN unlink with nexus removal reproduces this\nlifetime violation as a DEBUG_OBJECTS "free active" warning for\nusbg_cmd_work, followed by a target-core BUG/Oops.\n\nThe generic target-core unlink path has no callback after\ncore_dev_del_lun() completes. Add an optional fabric_post_unlink()\ncallback and use it for the f_tcm port count. The count now remains\nnonzero until core_dev_del_lun() has finished draining active LUN\nreferences, preventing nexus removal from freeing the session during\ncommand completion.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00182, EPSS Percentile is 0.08003 |
debian: CVE-2026-80854 was patched at 2026-09-16
2335.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80855) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fuse: fix invalidate lock leak on open O_TRUNC DAX failure fuse_open() takes filemap_invalidate_lock() for a DAX truncate (dax_truncate = true) and releases it before the out_inode_unlock label. But when fuse_dax_break_layouts() fails, the goto out_inode_unlock skips the unlock and leaks the rwsem, so any later fault or truncate on the file stalls on the stale lock. fuse_dax_break_layouts() can fail with -ERESTARTSYS when a signal interrupts the wait for busy DAX pages to drain: open("file", O_RDWR | O_TRUNC) └─ fuse_open() ├─ filemap_invalidate_lock() # dax_truncate └─ fuse_dax_break_layouts() └─ dax_break_layout() └─ wait_page_idle() # TASK_INTERRUPTIBLE └─ fuse_wait_dax_page() # unlock, schedule, re-lock └─ signal → -ERESTARTSYS goto out_inode_unlock # <- lock leaked Fix this by moving filemap_invalidate_unlock() below the label so that all error paths release the lock, and rename the label to out_unlock as it now covers more than just the inode lock.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: fix invalidate lock leak on open O_TRUNC DAX failure\n\nfuse_open() takes filemap_invalidate_lock() for a DAX truncate\n(dax_truncate = true) and releases it before the out_inode_unlock\nlabel. But when fuse_dax_break_layouts() fails, the goto\nout_inode_unlock skips the unlock and leaks the rwsem, so any later\nfault or truncate on the file stalls on the stale lock.\n\nfuse_dax_break_layouts() can fail with -ERESTARTSYS when a signal\ninterrupts the wait for busy DAX pages to drain:\n\n open("file", O_RDWR | O_TRUNC)\n └─ fuse_open()\n ├─ filemap_invalidate_lock() # dax_truncate\n └─ fuse_dax_break_layouts()\n └─ dax_break_layout()\n └─ wait_page_idle() # TASK_INTERRUPTIBLE\n └─ fuse_wait_dax_page() # unlock, schedule, re-lock\n └─ signal → -ERESTARTSYS\n goto out_inode_unlock # <- lock leaked\n\nFix this by moving filemap_invalidate_unlock() below the label so\nthat all error paths release the lock, and rename the label to\nout_unlock as it now covers more than just the inode lock.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06066 |
debian: CVE-2026-80855 was patched at 2026-09-16
2336.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80856) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fuse: fix invalidate lock leak on setattr writeback failure fuse_do_setattr() takes filemap_invalidate_lock() for a DAX truncate (fault_blocked = true) and releases it at the out:/error: labels. But when a writeback flush is also needed, a write_inode_now() failure returns directly and leaks the lock, so any later fault or truncate on the file stalls on the stale rwsem. For example, truncate(2) on a setuid file reaches fuse_do_setattr() with both ATTR_SIZE and ATTR_MODE set: truncate(2) └─ do_truncate() ├─ dentry_needs_remove_privs() # S_ISUID └─ notify_change() # KILL_SUID -> ATTR_MODE └─ fuse_setattr() # no killpriv: │ # ia_valid |= ATTR_MODE └─ fuse_do_setattr() ├─ filemap_invalidate_lock() # IS_DAX && is_truncate └─ write_inode_now() # is_wb && ATTR_MODE └─ if (err) # e.g. daemon -> -EIO return err # <- lock leaked Fix this by adding an unlock label that releases the lock before returning the error, and use it for the fuse_dax_break_layouts() failure path as well.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: fix invalidate lock leak on setattr writeback failure\n\nfuse_do_setattr() takes filemap_invalidate_lock() for a DAX truncate\n(fault_blocked = true) and releases it at the out:/error: labels. But\nwhen a writeback flush is also needed, a write_inode_now() failure\nreturns directly and leaks the lock, so any later fault or truncate on\nthe file stalls on the stale rwsem.\n\nFor example, truncate(2) on a setuid file reaches fuse_do_setattr()\nwith both ATTR_SIZE and ATTR_MODE set:\n\n truncate(2)\n └─ do_truncate()\n ├─ dentry_needs_remove_privs() # S_ISUID\n └─ notify_change() # KILL_SUID -> ATTR_MODE\n └─ fuse_setattr() # no killpriv:\n │ # ia_valid |= ATTR_MODE\n └─ fuse_do_setattr()\n ├─ filemap_invalidate_lock() # IS_DAX && is_truncate\n └─ write_inode_now() # is_wb && ATTR_MODE\n └─ if (err) # e.g. daemon -> -EIO\n return err # <- lock leaked\n\nFix this by adding an unlock label that releases the lock before\nreturning the error, and use it for the fuse_dax_break_layouts()\nfailure path as well.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06062 |
debian: CVE-2026-80856 was patched at 2026-09-16
2337.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80861) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: usb: xhci: bail out of setup if the controller is inaccessible xhci_gen_setup() locates the operational registers using the capability length read from the very first register: \txhci->op_regs = hcd->regs + \t\tHC_LENGTH(readl(&xhci->cap_regs->hc_capbase)); If the controller is dead or has dropped off the bus, that read returns ~0, HC_LENGTH() truncates it to 0xff, and op_regs ends up 0xff bytes past the page-aligned MMIO base, i.e. unaligned. The first access through it, xhci_halt() -> xhci_handshake() reading op_regs->status, is then an unaligned readl() on device memory. arm64 faults on unaligned device accesses, so instead of xhci_handshake() catching the all-ones value and returning -ENODEV, setup oopses: xhci-pci-renesas 0005:08:00.0: Unable to change power state from D3cold to D0, device inaccessible xhci-pci-renesas 0005:08:00.0: xHCI Host Controller xhci-pci-renesas 0005:08:00.0: new USB bus registered, assigned bus number 1 Unable to handle kernel paging request at virtual address ffff80030a770103 ESR = 0x0000000096000021 FSC = 0x21: alignment fault Internal error: Oops: 0000000096000021 [#1] SMP pc : xhci_halt [xhci_hcd] Call trace: xhci_halt xhci_gen_setup xhci_pci_setup usb_add_hcd usb_hcd_pci_probe xhci_pci_common_probe xhci_pci_renesas_probe This was hit with a Renesas uPD720201 that failed to power up ("Unable to change power state from D3cold to D0, device inaccessible") yet still reached the HCD probe path. Read the capability register once, and if it reads back the all-ones value (as xhci_handshake() and xhci_reset() already test for), abort setup with -ENODEV before op_regs is derived from it. Reading it once also avoids re-reading a register that may change under a concurrent hot-removal.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci: bail out of setup if the controller is inaccessible\n\nxhci_gen_setup() locates the operational registers using the capability\nlength read from the very first register:\n\n\txhci->op_regs = hcd->regs +\n\t\tHC_LENGTH(readl(&xhci->cap_regs->hc_capbase));\n\nIf the controller is dead or has dropped off the bus, that read returns\n~0, HC_LENGTH() truncates it to 0xff, and op_regs ends up 0xff bytes\npast the page-aligned MMIO base, i.e. unaligned. The first access\nthrough it, xhci_halt() -> xhci_handshake() reading op_regs->status, is\nthen an unaligned readl() on device memory. arm64 faults on unaligned\ndevice accesses, so instead of xhci_handshake() catching the all-ones\nvalue and returning -ENODEV, setup oopses:\n\n xhci-pci-renesas 0005:08:00.0: Unable to change power state from D3cold to D0, device inaccessible\n xhci-pci-renesas 0005:08:00.0: xHCI Host Controller\n xhci-pci-renesas 0005:08:00.0: new USB bus registered, assigned bus number 1\n Unable to handle kernel paging request at virtual address ffff80030a770103\n ESR = 0x0000000096000021\n FSC = 0x21: alignment fault\n Internal error: Oops: 0000000096000021 [#1] SMP\n pc : xhci_halt [xhci_hcd]\n Call trace:\n xhci_halt\n xhci_gen_setup\n xhci_pci_setup\n usb_add_hcd\n usb_hcd_pci_probe\n xhci_pci_common_probe\n xhci_pci_renesas_probe\n\nThis was hit with a Renesas uPD720201 that failed to power up ("Unable\nto change power state from D3cold to D0, device inaccessible") yet still\nreached the HCD probe path.\n\nRead the capability register once, and if it reads back the all-ones\nvalue (as xhci_handshake() and xhci_reset() already test for), abort\nsetup with -ENODEV before op_regs is derived from it. Reading it once\nalso avoids re-reading a register that may change under a concurrent\nhot-removal.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05203 |
debian: CVE-2026-80861 was patched at 2026-09-16
2338.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80862) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix usage of page_frag_cache nvme uses page_frag_cache to preallocate PDU for each preallocated request of block device. Block devices are created in parallel threads, consequently page_frag_cache is used in not thread-safe manner. That leads to incorrect refcounting of backstore pages and premature free. That can be catched by !sendpage_ok inside network stack: WARNING: CPU: 7 PID: 467 at ../net/core/skbuff.c:6931 skb_splice_from_iter+0xfa/0x310. \ttcp_sendmsg_locked+0x782/0xce0 \ttcp_sendmsg+0x27/0x40 \tsock_sendmsg+0x8b/0xa0 \tnvme_tcp_try_send_cmd_pdu+0x149/0x2a0 Then random panic may occur. Fix that by serializing the usage of page_frag_cache.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-tcp: fix usage of page_frag_cache\n\nnvme uses page_frag_cache to preallocate PDU for each preallocated request\nof block device. Block devices are created in parallel threads,\nconsequently page_frag_cache is used in not thread-safe manner.\nThat leads to incorrect refcounting of backstore pages and premature free.\n\nThat can be catched by !sendpage_ok inside network stack:\n\nWARNING: CPU: 7 PID: 467 at ../net/core/skbuff.c:6931 skb_splice_from_iter+0xfa/0x310.\n\ttcp_sendmsg_locked+0x782/0xce0\n\ttcp_sendmsg+0x27/0x40\n\tsock_sendmsg+0x8b/0xa0\n\tnvme_tcp_try_send_cmd_pdu+0x149/0x2a0\nThen random panic may occur.\n\nFix that by serializing the usage of page_frag_cache.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05202 |
debian: CVE-2026-80862 was patched at 2026-09-16
2339.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80865) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: bpf: Add missing access_ok call to copy_user_syms As reported by sashiko we use __get_user without prior access_ok call on the user space pointer. Adding the missing call for the whole pointer array. Plus removing the err check in the error path, because it's not needed and also we can return -ENOMEM directly from the first kvmalloc_array fail path. [1] https://lore.kernel.org/bpf/20260611115503.AC16D1F00893@smtp.kernel.org/', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Add missing access_ok call to copy_user_syms\n\nAs reported by sashiko we use __get_user without prior access_ok call on the\nuser space pointer. Adding the missing call for the whole pointer array.\n\nPlus removing the err check in the error path, because it's not needed and\nalso we can return -ENOMEM directly from the first kvmalloc_array fail path.\n\n[1] https://lore.kernel.org/bpf/20260611115503.AC16D1F00893@smtp.kernel.org/', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00161, EPSS Percentile is 0.0564 |
debian: CVE-2026-80865 was patched at 2026-09-16
redos: CVE-2026-80865 was patched at 2026-09-16
2340.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80867) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: alpha/PCI: Add security_locked_down() check to pci_mmap_resource() Currently, Alpha's pci_mmap_resource() does not check security_locked_down(LOCKDOWN_PCI_ACCESS) before allowing userspace to mmap PCI BARs. The generic version has had this check since commit eb627e17727e ("PCI: Lock down BAR access when the kernel is locked down") to prevent DMA attacks when the kernel is locked down. Add the same check to Alpha's pci_mmap_resource().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nalpha/PCI: Add security_locked_down() check to pci_mmap_resource()\n\nCurrently, Alpha's pci_mmap_resource() does not check\nsecurity_locked_down(LOCKDOWN_PCI_ACCESS) before allowing userspace to mmap\nPCI BARs.\n\nThe generic version has had this check since commit eb627e17727e ("PCI:\nLock down BAR access when the kernel is locked down") to prevent DMA\nattacks when the kernel is locked down.\n\nAdd the same check to Alpha's pci_mmap_resource().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.06036 |
debian: CVE-2026-80867 was patched at 2026-09-16
redos: CVE-2026-80867 was patched at 2026-09-16
2341.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80875) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipvs: use parsed transport offset in TCP state lookup TCP state handling reparses the skb to find the TCP header. For IPv6 it uses sizeof(struct ipv6hdr), while the surrounding IPVS code already parsed the packet with ip_vs_fill_iph_skb() and has the real transport-header offset in iph.len. This makes TCP state handling look at the wrong bytes when an IPv6 packet carries extension headers. Use the parsed transport offset passed down from ip_vs_set_state() when reading the TCP header. For IPv4 and for IPv6 packets without extension headers, the passed offset matches the previous value.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: use parsed transport offset in TCP state lookup\n\nTCP state handling reparses the skb to find the TCP header. For IPv6 it\nuses sizeof(struct ipv6hdr), while the surrounding IPVS code already\nparsed the packet with ip_vs_fill_iph_skb() and has the real\ntransport-header offset in iph.len.\n\nThis makes TCP state handling look at the wrong bytes when an IPv6\npacket carries extension headers. Use the parsed transport offset passed\ndown from ip_vs_set_state() when reading the TCP header.\n\nFor IPv4 and for IPv6 packets without extension headers, the passed\noffset matches the previous value.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.06038 |
debian: CVE-2026-80875 was patched at 2026-09-16
redos: CVE-2026-80875 was patched at 2026-09-16
2342.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80876) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix event length with forced 8-byte alignment When RB_FORCE_8BYTE_ALIGNMENT is true, rb_calculate_event_length() reserves the space of event->array[0] for placing the data length and rb_update_event() stores the data length in event->array[0] accordingly. As a result the whole event length will add extra 4 bytes for sizeof(event.array[0]) unconditionally. But ring_buffer_event_length() only subtracts the sizeof(event->array[0]) for events larger than RB_MAX_SMALL_DATA + sizeof(event->array[0]). As a result, small events on architectures with RB_FORCE_8BYTE_ALIGNMENT=true report a data length that is 4 bytes larger than expected. To fix it, add the RB_FORCE_8BYTE_ALIGNMENT as a condition to subtract the size of that length field whenever RB_FORCE_8BYTE_ALIGNMENT is true. This issue is observed in a riscv64 kernel with CONFIG_HAVE_64BIT_ALIGNED_ACCESS set to y, when we run ftrace selftest trace_marker_raw.tc, we get the weird log: for cases where the id is 1..100, the number of data field is 8*N, but once id exceeds 100, the number of data field becomes 8*N+4: # 1 buf: 58 00 00 00 80 5e d1 63 (number of data field is 8*1) ... # a buf: 58 ... (number of data field is 8*2) ... # 64 buf: 58 ... (number of data field is 8*13) # 65 buf: 58 ... (number of data field is 8*13+4) After applying this change, the number of data field keeps being 8*N+4 consistently.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Fix event length with forced 8-byte alignment\n\nWhen RB_FORCE_8BYTE_ALIGNMENT is true, rb_calculate_event_length()\nreserves the space of event->array[0] for placing the data length and\nrb_update_event() stores the data length in event->array[0]\naccordingly. As a result the whole event length will add extra 4 bytes\nfor sizeof(event.array[0]) unconditionally.\n\nBut ring_buffer_event_length() only subtracts the\nsizeof(event->array[0]) for events larger than RB_MAX_SMALL_DATA +\nsizeof(event->array[0]). As a result, small events on architectures\nwith RB_FORCE_8BYTE_ALIGNMENT=true report a data length that is 4\nbytes larger than expected.\n\nTo fix it, add the RB_FORCE_8BYTE_ALIGNMENT as a condition to subtract\nthe size of that length field whenever RB_FORCE_8BYTE_ALIGNMENT is\ntrue.\n\nThis issue is observed in a riscv64 kernel with\nCONFIG_HAVE_64BIT_ALIGNED_ACCESS set to y, when we run ftrace selftest\ntrace_marker_raw.tc, we get the weird log: for cases where the id is\n1..100, the number of data field is 8*N, but once id exceeds 100, the\nnumber of data field becomes 8*N+4:\n # 1 buf: 58 00 00 00 80 5e d1 63 (number of data field is 8*1)\n ...\n # a buf: 58 ... (number of data field is 8*2)\n ...\n # 64 buf: 58 ... (number of data field is 8*13)\n # 65 buf: 58 ... (number of data field is 8*13+4)\n\nAfter applying this change, the number of data field keeps being 8*N+4\nconsistently.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.06037 |
debian: CVE-2026-80876 was patched at 2026-09-16
redos: CVE-2026-80876 was patched at 2026-09-16
2343.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80877) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: afs: Fix vllist leak Fix a leak of the new vllist in afs_update_cell() in the event that it is an empty list (nr_servers == 0), in which case the old list isn't displaced unless the old list is also empty.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix vllist leak\n\nFix a leak of the new vllist in afs_update_cell() in the event that it is an\nempty list (nr_servers == 0), in which case the old list isn't displaced\nunless the old list is also empty.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.06037 |
debian: CVE-2026-80877 was patched at 2026-09-16
redos: CVE-2026-80877 was patched at 2026-09-16
2344.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80878) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: afs: Fix leak of ungot volume Fix afs_lookup_volume_rcu() so that it doesn't leak a dying volume if afs_try_get_volume() fails.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix leak of ungot volume\n\nFix afs_lookup_volume_rcu() so that it doesn't leak a dying volume if\nafs_try_get_volume() fails.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05203 |
debian: CVE-2026-80878 was patched at 2026-09-16
2345.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80879) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write A circular locking dependency involves INODE_ALLOC_SYSTEM_INODE, EXTENT_ALLOC_SYSTEM_INODE, and ORPHAN_DIR_SYSTEM_INODE. 1. ocfs2_mknod() acquires INODE_ALLOC then EXTENT_ALLOC. 2. ocfs2_dio_end_io_write() acquires EXTENT_ALLOC for unwritten extents, then ORPHAN_DIR via ocfs2_del_inode_from_orphan() while still holding EXTENT_ALLOC. 3. ocfs2_wipe_inode() acquires ORPHAN_DIR then INODE_ALLOC via ocfs2_remove_inode. Break the cycle in ocfs2_dio_end_io_write() by freeing the allocation contexts (releasing EXTENT_ALLOC) before acquiring ORPHAN_DIR. WARNING: possible circular locking dependency detected ------------------------------------------------------ is trying to acquire lock: ffff8881e78b33a0 (&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}, at: ocfs2_evict_inode+0x1539/0x43b0 fs/ocfs2/inode.c:1299 but task is already holding lock: ffff8881e78b4fa0 (&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]){+.+.}-{4:4}, at: ocfs2_evict_inode+0xe97/0x43b0 fs/ocfs2/inode.c:1299 the existing dependency chain (in reverse order) is: -> #2 (&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]){+.+.}-{4:4}: inode_lock include/linux/fs.h:1029 [inline] ocfs2_del_inode_from_orphan+0x12e/0x7a0 fs/ocfs2/namei.c:2728 ocfs2_dio_end_io+0xf9c/0x1370 fs/ocfs2/aops.c:2418 dio_complete+0x25b/0x790 fs/direct-io.c:281 -> #1 (&ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}: inode_lock include/linux/fs.h:1029 [inline] ocfs2_reserve_suballoc_bits+0x16d/0x4840 fs/ocfs2/suballoc.c:882 ocfs2_reserve_new_metadata_blocks+0x415/0x9a0 fs/ocfs2/suballoc.c:1078 ocfs2_mknod+0x10f3/0x2260 fs/ocfs2/namei.c:351 -> #0 (&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}: __lock_acquire+0x15a5/0x2cf0 kernel/locking/lockdep.c:5237 lock_acquire+0x106/0x350 kernel/locking/lockdep.c:5868 down_write+0x96/0x200 kernel/locking/rwsem.c:1625 inode_lock include/linux/fs.h:1029 [inline] ocfs2_remove_inode fs/ocfs2/inode.c:733 [inline] ocfs2_wipe_inode fs/ocfs2/inode.c:896 [inline] ocfs2_delete_inode fs/ocfs2/inode.c:1157 [inline] ocfs2_evict_inode+0x1539/0x43b0 fs/ocfs2/inode.c:1299 Chain exists of: &ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE] --> &ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE] --> &ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE] Possible unsafe locking scenario: CPU0 CPU1 ---- ---- lock(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]); lock(&ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE]); lock(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]); lock(&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]); *** DEADLOCK ***', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix circular locking dependency in ocfs2_dio_end_io_write\n\nA circular locking dependency involves INODE_ALLOC_SYSTEM_INODE,\nEXTENT_ALLOC_SYSTEM_INODE, and ORPHAN_DIR_SYSTEM_INODE.\n\n1. ocfs2_mknod() acquires INODE_ALLOC then EXTENT_ALLOC.\n\n2. ocfs2_dio_end_io_write() acquires EXTENT_ALLOC for unwritten\n extents, then ORPHAN_DIR via ocfs2_del_inode_from_orphan() while still\n holding EXTENT_ALLOC.\n\n3. ocfs2_wipe_inode() acquires ORPHAN_DIR then INODE_ALLOC via\n ocfs2_remove_inode.\n\nBreak the cycle in ocfs2_dio_end_io_write() by freeing the allocation\ncontexts (releasing EXTENT_ALLOC) before acquiring ORPHAN_DIR.\n\nWARNING: possible circular locking dependency detected\n------------------------------------------------------\nis trying to acquire lock:\nffff8881e78b33a0\n(&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}, at:\nocfs2_evict_inode+0x1539/0x43b0 fs/ocfs2/inode.c:1299\n\nbut task is already holding lock:\nffff8881e78b4fa0\n(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]){+.+.}-{4:4}, at:\nocfs2_evict_inode+0xe97/0x43b0 fs/ocfs2/inode.c:1299\n\nthe existing dependency chain (in reverse order) is:\n\n-> #2 (&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]){+.+.}-{4:4}:\n inode_lock include/linux/fs.h:1029 [inline]\n ocfs2_del_inode_from_orphan+0x12e/0x7a0 fs/ocfs2/namei.c:2728\n ocfs2_dio_end_io+0xf9c/0x1370 fs/ocfs2/aops.c:2418\n dio_complete+0x25b/0x790 fs/direct-io.c:281\n\n-> #1 (&ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}:\n inode_lock include/linux/fs.h:1029 [inline]\n ocfs2_reserve_suballoc_bits+0x16d/0x4840 fs/ocfs2/suballoc.c:882\n ocfs2_reserve_new_metadata_blocks+0x415/0x9a0\n fs/ocfs2/suballoc.c:1078\n ocfs2_mknod+0x10f3/0x2260 fs/ocfs2/namei.c:351\n\n-> #0 (&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}:\n __lock_acquire+0x15a5/0x2cf0 kernel/locking/lockdep.c:5237\n lock_acquire+0x106/0x350 kernel/locking/lockdep.c:5868\n down_write+0x96/0x200 kernel/locking/rwsem.c:1625\n inode_lock include/linux/fs.h:1029 [inline]\n ocfs2_remove_inode fs/ocfs2/inode.c:733 [inline]\n ocfs2_wipe_inode fs/ocfs2/inode.c:896 [inline]\n ocfs2_delete_inode fs/ocfs2/inode.c:1157 [inline]\n ocfs2_evict_inode+0x1539/0x43b0 fs/ocfs2/inode.c:1299\n\nChain exists of:\n &ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE] -->\n &ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE] -->\n &ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]\n\n Possible unsafe locking scenario:\n\n CPU0 CPU1\n ---- ----\n lock(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]);\n lock(&ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE]);\n lock(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]);\n lock(&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]);\n\n *** DEADLOCK ***', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06105 |
debian: CVE-2026-80879 was patched at 2026-09-16
redos: CVE-2026-80879 was patched at 2026-09-16
2346.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80880) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: IB/mlx5: Properly support implicit ODP rereg_mr Due to all the child mkeys in the implicit ODP configuration we cannot change anything in place for the parent mkey. Instead the whole thing needs to be rebuilt if any change is requested. If the user does not specify a translation then force the implicit values which will then fall through the logic into mlx5_ib_reg_user_mr() to allocate a completely new MR. Since implicit children were also touching the mr->pd, this removes another case where the access was racy.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nIB/mlx5: Properly support implicit ODP rereg_mr\n\nDue to all the child mkeys in the implicit ODP configuration we cannot\nchange anything in place for the parent mkey. Instead the whole thing\nneeds to be rebuilt if any change is requested. If the user does not\nspecify a translation then force the implicit values which will then fall\nthrough the logic into mlx5_ib_reg_user_mr() to allocate a completely new\nMR.\n\nSince implicit children were also touching the mr->pd, this removes\nanother case where the access was racy.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00161, EPSS Percentile is 0.05703 |
debian: CVE-2026-80880 was patched at 2026-09-16
redos: CVE-2026-80880 was patched at 2026-09-16
2347.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80881) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix buffer head management in ocfs2_read_blocks() In ocfs2_read_blocks(), caller should't assume that buffer head returned by 'sb_getblk()' is exclusively owned and so 'put_bh()' always drops b_count from 1 to 0. If it is not so, buffer head remains on hold and likely to be returned by the next call to 'sb_getblk()' unchanged - that is, with BH_Uptodate bit set even if it has failed validation previously, thus allowing to insert that buffer head into OCFS2 metadata cache and submit it to upper layers. To avoid such a scenario, BH_Uptodate should be cleared immediately after 'validate()' callback has detected some data inconsistency.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix buffer head management in ocfs2_read_blocks()\n\nIn ocfs2_read_blocks(), caller should't assume that buffer head returned\nby 'sb_getblk()' is exclusively owned and so 'put_bh()' always drops\nb_count from 1 to 0. If it is not so, buffer head remains on hold and\nlikely to be returned by the next call to 'sb_getblk()' unchanged - that\nis, with BH_Uptodate bit set even if it has failed validation previously,\nthus allowing to insert that buffer head into OCFS2 metadata cache and\nsubmit it to upper layers. To avoid such a scenario, BH_Uptodate should\nbe cleared immediately after 'validate()' callback has detected some data\ninconsistency.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06106 |
debian: CVE-2026-80881 was patched at 2026-09-16
redos: CVE-2026-80881 was patched at 2026-09-16
2348.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80882) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm Ensure the ENOMEM error value is set when the input buffer allocation fails in tegra_ccm_do_one_req.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: tegra - Return ENOMEM when input buffer allocation fails for ccm\n\nEnsure the ENOMEM error value is set when the input buffer allocation\nfails in tegra_ccm_do_one_req.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05187 |
debian: CVE-2026-80882 was patched at 2026-09-16
2349.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80883) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered The host1x_client_register() function is called just prior to register map initialization loop, making the device available to userspace. This may result in userspace attempting to submits a job before the register map is initialized. Address this by moving register initialization before host1x client registration.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered\n\nThe host1x_client_register() function is called just prior to register map\ninitialization loop, making the device available to userspace. This may\nresult in userspace attempting to submits a job before the register map is\ninitialized. Address this by moving register initialization before host1x\nclient registration.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00157, EPSS Percentile is 0.05248 |
debian: CVE-2026-80883 was patched at 2026-09-16
2350.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80884) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ntb: Store original DMA address for future release The DMA API requires that dma_free_attrs receive the exact dma_handle originally returned by the allocation function. Do not modify it.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nntb: Store original DMA address for future release\n\nThe DMA API requires that dma_free_attrs receive the exact dma_handle\noriginally returned by the allocation function. Do not modify it.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00158, EPSS Percentile is 0.05381 |
debian: CVE-2026-80884 was patched at 2026-09-16
2351.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80887) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: use check_add_overflow for shader size+offset bound vmw_shader_define() validates the user-supplied shader window against its backing buffer with \t(u64)buffer->tbo.base.size < (u64)size + (u64)offset drm_vmw_shader_create_arg::offset is __u64 in the uapi; when it is near U64_MAX the unsigned addition wraps and the resulting tiny value passes the check. The unbounded offset is then stored in res->guest_memory_offset and forwarded to host SVGA shader-create commands. Use check_add_overflow() to detect the wrap and compare the resulting endpoint against the buffer size.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: use check_add_overflow for shader size+offset bound\n\nvmw_shader_define() validates the user-supplied shader window against\nits backing buffer with\n\n\t(u64)buffer->tbo.base.size < (u64)size + (u64)offset\n\ndrm_vmw_shader_create_arg::offset is __u64 in the uapi; when it is\nnear U64_MAX the unsigned addition wraps and the resulting tiny value\npasses the check. The unbounded offset is then stored in\nres->guest_memory_offset and forwarded to host SVGA shader-create\ncommands.\n\nUse check_add_overflow() to detect the wrap and compare the resulting\nendpoint against the buffer size.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06406 |
debian: CVE-2026-80887 was patched at 2026-09-16
2352.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80888) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: drop dma_buf reference on foreign-fd prime import ttm_prime_fd_to_handle() returns -ENOSYS when the imported fd's dma_buf->ops do not match the ttm_object_device's ops, but does so without releasing the reference acquired by dma_buf_get(). Any unprivileged renderD client passing a non-vmwgfx prime fd through the DRM_VMW_GB_SURFACE_REF{,_EXT} path leaks one dma_buf reference per call and indefinitely pins the foreign exporter's GEM resources. Funnel the error path through the existing dma_buf_put() so the reference is always dropped.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: drop dma_buf reference on foreign-fd prime import\n\nttm_prime_fd_to_handle() returns -ENOSYS when the imported fd's\ndma_buf->ops do not match the ttm_object_device's ops, but does so\nwithout releasing the reference acquired by dma_buf_get(). Any\nunprivileged renderD client passing a non-vmwgfx prime fd through the\nDRM_VMW_GB_SURFACE_REF{,_EXT} path leaks one dma_buf reference per\ncall and indefinitely pins the foreign exporter's GEM resources.\n\nFunnel the error path through the existing dma_buf_put() so the\nreference is always dropped.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07524 |
debian: CVE-2026-80888 was patched at 2026-09-16
2353.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80889) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: can: isotp: fix timer drain order, wakeup handling and tx_gen ordering This patch is a follow-up to commit cf070fe33bfb ("can: isotp: serialize TX state transitions under so->rx_lock") which addresses following sashiko-bot findings: - isotp_sendmsg(): drain so->txfrtimer first so a stale callback can't re-arm echotimer after the claim - isotp_release(): wake so->wait after forcing ISOTP_SHUTDOWN so a sleeping sendmsg() claim isn't stranded - isotp_sendmsg(): have both wait_event_interruptible() calls in isotp_sendmsg() also wake on ISOTP_SHUTDOWN and do not return claim to IDLE to avoid corrupting a concurrent isotp_release() process. - isotp_sendmsg(): handle potential claim of a new transfer when the wait_event_interruptible() call returns in CAN_ISOTP_WAIT_TX_DONE mode. Don't touch timers and states of the new transfer if a new thread incremented so->tx_gen before getting the lock at err_event_drop. - isotp_sendmsg(): handle a stuck can_send() and omit timer and state changes if a new transfer was claimed. wait_tx_done() returns the error recorded in so->tx_result[], tagged with the caller's own generation. - isotp_tx_timeout(): on a claimed timeout, record the ECOMM error for the timed-out transfer's own generation in so->tx_result[]; sk->sk_err is raised unconditionally, same as every other error path here. - isotp_tx_gen_done()/isotp_tx_timeout(): always read tx.state (acquire) before tx_gen - the reverse order let a weakly ordered CPU pair a fresh tx.state with a stale tx_gen/tx_result slot. - isotp_sendmsg(): wait_tx_done: drain sk_err via sock_error() once we have read the result from so->tx_result[], so an already-reported error doesn't stay latched for a later poll()/SO_ERROR. Also align the remaining lock-free so->tx.state/rx.state/cfecho accesses and use skb->hash as unique loopback echo frame indicator.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncan: isotp: fix timer drain order, wakeup handling and tx_gen ordering\n\nThis patch is a follow-up to commit cf070fe33bfb ("can: isotp: serialize\nTX state transitions under so->rx_lock") which addresses following\nsashiko-bot findings:\n\n- isotp_sendmsg(): drain so->txfrtimer first so a stale callback can't\n re-arm echotimer after the claim\n\n- isotp_release(): wake so->wait after forcing ISOTP_SHUTDOWN so a\n sleeping sendmsg() claim isn't stranded\n\n- isotp_sendmsg(): have both wait_event_interruptible() calls in\n isotp_sendmsg() also wake on ISOTP_SHUTDOWN and do not return claim to\n IDLE to avoid corrupting a concurrent isotp_release() process.\n\n- isotp_sendmsg(): handle potential claim of a new transfer when\n the wait_event_interruptible() call returns in CAN_ISOTP_WAIT_TX_DONE\n mode. Don't touch timers and states of the new transfer if a new thread\n incremented so->tx_gen before getting the lock at err_event_drop.\n\n- isotp_sendmsg(): handle a stuck can_send() and omit timer and state\n changes if a new transfer was claimed. wait_tx_done() returns the error\n recorded in so->tx_result[], tagged with the caller's own generation.\n\n- isotp_tx_timeout(): on a claimed timeout, record the ECOMM error for\n the timed-out transfer's own generation in so->tx_result[]; sk->sk_err\n is raised unconditionally, same as every other error path here.\n\n- isotp_tx_gen_done()/isotp_tx_timeout(): always read tx.state (acquire)\n before tx_gen - the reverse order let a weakly ordered CPU pair a fresh\n tx.state with a stale tx_gen/tx_result slot.\n\n- isotp_sendmsg(): wait_tx_done: drain sk_err via sock_error() once we\n have read the result from so->tx_result[], so an already-reported error\n doesn't stay latched for a later poll()/SO_ERROR.\n\nAlso align the remaining lock-free so->tx.state/rx.state/cfecho accesses\nand use skb->hash as unique loopback echo frame indicator.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07499 |
debian: CVE-2026-80889 was patched at 2026-09-16
2354.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80890) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: sctp: reject stale cookies with mismatched verification tags sctp_unpack_cookie() skips cookie expiration checks whenever an association already exists. This is broader than the exception in RFC 9260 Section 5.2.4. For an existing association, Section 5.2.4 permits an expired State Cookie only when both Verification Tags in the cookie match the current association. Otherwise, the packet SHOULD be discarded and a Stale Cookie ERROR MUST be sent. The broad check lets an expired Action A restart cookie reach sctp_sf_do_dupcook_a(). In a runtime test with the default 60 second cookie lifetime, replaying such a cookie after 65 seconds returned a COOKIE-ACK and restarted the association. Check cookie expiration unless both Verification Tags match. This preserves the Action D exception for a lost COOKIE ACK while rejecting expired cookies in all other cases.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: reject stale cookies with mismatched verification tags\n\nsctp_unpack_cookie() skips cookie expiration checks whenever an\nassociation already exists. This is broader than the exception in\nRFC 9260 Section 5.2.4.\n\nFor an existing association, Section 5.2.4 permits an expired State\nCookie only when both Verification Tags in the cookie match the current\nassociation. Otherwise, the packet SHOULD be discarded and a Stale\nCookie ERROR MUST be sent.\n\nThe broad check lets an expired Action A restart cookie reach\nsctp_sf_do_dupcook_a(). In a runtime test with the default 60 second\ncookie lifetime, replaying such a cookie after 65 seconds returned a\nCOOKIE-ACK and restarted the association.\n\nCheck cookie expiration unless both Verification Tags match. This\npreserves the Action D exception for a lost COOKIE ACK while rejecting\nexpired cookies in all other cases.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07525 |
debian: CVE-2026-80890 was patched at 2026-09-16
2355.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80891) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Validate AIBV and AISB before pinning guest pages The AIBV holds one bit per MSI-X vector for a given function. The size of the bit vector is derived from the NOI and the AIBVO. If the size of the AIBV exceeds a single page boundary, then reject the request as we cannot safely pin the guest AIBV. Similarly reject the request if the AISB address is not 8-byte aligned as the architecture requires doubleword alignment for the summary bit address. Since the AISBO can address up to 64 bits, the size of the AISB can only be 8 bytes for the function. This also ensures the AISB doesn't exceed a single page boundary.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: pci: Validate AIBV and AISB before pinning guest pages\n\nThe AIBV holds one bit per MSI-X vector for a given function. The size of\nthe bit vector is derived from the NOI and the AIBVO. If the size of the\nAIBV exceeds a single page boundary, then reject the request as we cannot\nsafely pin the guest AIBV.\n\nSimilarly reject the request if the AISB address is not 8-byte aligned as\nthe architecture requires doubleword alignment for the summary bit address.\nSince the AISBO can address up to 64 bits, the size of the AISB can only be\n8 bytes for the function. This also ensures the AISB doesn't exceed a\nsingle page boundary.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.0702 |
debian: CVE-2026-80891 was patched at 2026-09-16
2356.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80892) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: erofs: cap LZMA stream pool size fs/erofs/decompressor_lzma.c sizes the module-global MicroLZMA stream pool from num_possible_cpus() when the lzma_streams module parameter is unset, then z_erofs_load_lzma_config() preallocates one image-supplied dictionary per stream, accepting dictionaries up to 8 MiB. On high-CPU systems, a small EROFS image can pin hundreds of MiB of vmalloc-backed decoder state until the erofs module is unloaded. Impact: An EROFS image mounted by the system can pin up to 8 MiB of vmalloc memory per LZMA stream, either as intended or unexpectedly. Bound the default stream count by a new CONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS option, default 16, so the worst-case default preallocation is 128 MiB if the number of CPUs is no less than 16 while preserving the existing per-image dictionary limit. An explicit lzma_streams module parameter is still honoured as-is, so administrators who deliberately size the pool are not affected.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: cap LZMA stream pool size\n\nfs/erofs/decompressor_lzma.c sizes the module-global MicroLZMA stream\npool from num_possible_cpus() when the lzma_streams module parameter is\nunset, then z_erofs_load_lzma_config() preallocates one image-supplied\ndictionary per stream, accepting dictionaries up to 8 MiB. On high-CPU\nsystems, a small EROFS image can pin hundreds of MiB of vmalloc-backed\ndecoder state until the erofs module is unloaded.\n\nImpact: An EROFS image mounted by the system can pin up to 8 MiB of\nvmalloc memory per LZMA stream, either as intended or unexpectedly.\n\nBound the default stream count by a new\nCONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS option, default 16, so the\nworst-case default preallocation is 128 MiB if the number of CPUs is no\nless than 16 while preserving the existing per-image dictionary limit.\nAn explicit lzma_streams module parameter is still honoured as-is, so\nadministrators who deliberately size the pool are not affected.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06963 |
debian: CVE-2026-80892 was patched at 2026-09-16
2357.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80893) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() copy_hugetlb_page_range() clears the uffd-wp bit of migration and hwpoison entries with huge_pte_clear_uffd_wp(), which operates on the present-PTE bit position. Swap entries keep the uffd-wp state elsewhere -- the migration branch reads and sets it with pte_swp_uffd_wp() and pte_swp_mkuffd_wp() -- and the present-PTE position falls into the swap payload. On x86-64 it lands in the inverted swap offset, where a naturally-aligned hugetlb PFN always has the affected bit set, so the clear advances the encoded PFN by two pages. No userfaultfd needs to be involved: the clear is guarded only by the child VMA not being uffd-wp registered, so a plain fork() with an in-flight hugetlb migration entry (or a poisoned hugetlb page) corrupts the entry copied into the child. Instrumenting the clear and forking after MADV_HWPOISON on a 2MB anon hugetlb page shows: offset before=120e00 offset after =120e02 The fallout is mostly latent: rmap walks match migration entries by folio range and remove_migration_pte() rebuilds the PTE from the folio, so a within-folio PFN skew heals once migration completes. But any path that re-encodes the corrupted offset -- e.g. hugetlb_change_protection() rewriting a writable migration entry via make_readable_migration_entry(swp_offset(entry)) -- propagates it. Migration entries legitimately carry uffd-wp, so clear it with pte_swp_clear_uffd_wp(), matching copy_nonpresent_pte() and move_huge_pte(). A hwpoison entry, on the other hand, never carries the uffd-wp bit: it is installed fresh by make_hwpoison_entry() (try_to_unmap_one() does not preserve uffd-wp on the hwpoison path) and hugetlb_change_protection() leaves hwpoison entries untouched. There was nothing to clear there, only the corruption, so drop the clear entirely.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()\n\ncopy_hugetlb_page_range() clears the uffd-wp bit of migration and hwpoison\nentries with huge_pte_clear_uffd_wp(), which operates on the present-PTE\nbit position. Swap entries keep the uffd-wp state elsewhere -- the\nmigration branch reads and sets it with pte_swp_uffd_wp() and\npte_swp_mkuffd_wp() -- and the present-PTE position falls into the swap\npayload. On x86-64 it lands in the inverted swap offset, where a\nnaturally-aligned hugetlb PFN always has the affected bit set, so the\nclear advances the encoded PFN by two pages.\n\nNo userfaultfd needs to be involved: the clear is guarded only by the\nchild VMA not being uffd-wp registered, so a plain fork() with an\nin-flight hugetlb migration entry (or a poisoned hugetlb page) corrupts\nthe entry copied into the child. Instrumenting the clear and forking\nafter MADV_HWPOISON on a 2MB anon hugetlb page shows:\n\n offset before=120e00\n offset after =120e02\n\nThe fallout is mostly latent: rmap walks match migration entries by folio\nrange and remove_migration_pte() rebuilds the PTE from the folio, so a\nwithin-folio PFN skew heals once migration completes. But any path that\nre-encodes the corrupted offset -- e.g. hugetlb_change_protection()\nrewriting a writable migration entry via\nmake_readable_migration_entry(swp_offset(entry)) -- propagates it.\n\nMigration entries legitimately carry uffd-wp, so clear it with\npte_swp_clear_uffd_wp(), matching copy_nonpresent_pte() and\nmove_huge_pte().\n\nA hwpoison entry, on the other hand, never carries the uffd-wp bit: it is\ninstalled fresh by make_hwpoison_entry() (try_to_unmap_one() does not\npreserve uffd-wp on the hwpoison path) and hugetlb_change_protection()\nleaves hwpoison entries untouched. There was nothing to clear there, only\nthe corruption, so drop the clear entirely.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06965 |
debian: CVE-2026-80893 was patched at 2026-09-16
2358.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80894) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace iommufd_hwpt_replace_device() calls: \tiommufd_auto_response_faults(hwpt, old_handle); passing the *new* hwpt together with the handle of the device's *old* domain. This should be a parameter mismatch: 1. Semantically, iommufd_auto_response_faults(x, handle) scans x->fault's deliver list and response xarray for groups matching "handle". A group is queued under the hwpt that was attached at fault-delivery time. old_handle is fetched *before* the domain switch, so its group lives on old->fault, not on the new hwpt->fault. 2. Historically, the first argument was "old". The routine was introduced by commit b7d8833677ba ("iommufd: Fault-capable hwpt attach/detach/replace") as __fault_domain_replace_dev() in fault.c, correctly calling iommufd_auto_response_faults(old, curr). Commit fb21b1568ada ("iommufd: Make attach_handle generic than fault specific") moved this into iommufd_hwpt_replace_device() in device.c and swapped it to "hwpt". This should be a refactor regression, not an intentional change. Fix this by passing "old" instead.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace\n\niommufd_hwpt_replace_device() calls:\n\n\tiommufd_auto_response_faults(hwpt, old_handle);\n\npassing the *new* hwpt together with the handle of\nthe device's *old* domain. This should be a parameter mismatch:\n\n1. Semantically, iommufd_auto_response_faults(x, handle) scans\n x->fault's deliver list and response xarray for groups matching\n "handle". A group is queued under the hwpt that was attached at\n fault-delivery time. old_handle is fetched *before* the domain switch,\n so its group lives on old->fault, not on the new hwpt->fault.\n\n2. Historically, the first argument was "old". The routine was\n introduced by commit b7d8833677ba ("iommufd: Fault-capable hwpt\n attach/detach/replace") as __fault_domain_replace_dev() in\n fault.c, correctly calling iommufd_auto_response_faults(old, curr).\n Commit fb21b1568ada ("iommufd: Make attach_handle generic than\n fault specific") moved this into iommufd_hwpt_replace_device() in\n device.c and swapped it to "hwpt". This should be a refactor regression,\n not an intentional change.\n\nFix this by passing "old" instead.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06415 |
debian: CVE-2026-80894 was patched at 2026-09-16
2359.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80901) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipvs: fix the checksum validations ip_vs_in_icmp_v6() is missing checksum validation for ICMPv6 packets from clients. In fact, as for TCP/UDP we should validate the checksum for ICMP packets only when we mangle the packets on MASQ or on reply for tunnel. Also, Sashiko points out that handle_response_icmp() being common for IPv4 and IPv6 is missing the pseudo-header calculation while validating ICMPv6 messages from real servers which is a problem if checksum is not validated by the hardware. Fix the problems by creating ip_vs_checksum_common_check() helper and use it for TCP/UDP/ICMP both for IPv4 and IPv6. Rely on the nf_checksum() for validating the ICMP messages but use it also for TCP and UDP. Use correct IP offset for IP_VS_DBG_RL_PKT for TCP/UDP/SCTP. IPVS packets (TCP/UDP/SCTP/ICMP) do not need checksum validation on LOCAL_OUT (local clients or local real servers) and on FORWARD (traffic from servers on LAN). Do it only on LOCAL_IN, in case nf_checksum() is not called on PRE_ROUTING. Also, ip_vs_checksum_complete() can be marked static.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: fix the checksum validations\n\nip_vs_in_icmp_v6() is missing checksum validation for ICMPv6\npackets from clients. In fact, as for TCP/UDP we should\nvalidate the checksum for ICMP packets only when we\nmangle the packets on MASQ or on reply for tunnel.\n\nAlso, Sashiko points out that handle_response_icmp() being\ncommon for IPv4 and IPv6 is missing the pseudo-header\ncalculation while validating ICMPv6 messages from real\nservers which is a problem if checksum is not validated\nby the hardware.\n\nFix the problems by creating ip_vs_checksum_common_check()\nhelper and use it for TCP/UDP/ICMP both for IPv4 and IPv6.\nRely on the nf_checksum() for validating the ICMP messages\nbut use it also for TCP and UDP.\n\nUse correct IP offset for IP_VS_DBG_RL_PKT for TCP/UDP/SCTP.\n\nIPVS packets (TCP/UDP/SCTP/ICMP) do not need checksum\nvalidation on LOCAL_OUT (local clients or local real\nservers) and on FORWARD (traffic from servers on LAN).\nDo it only on LOCAL_IN, in case nf_checksum() is not\ncalled on PRE_ROUTING.\n\nAlso, ip_vs_checksum_complete() can be marked static.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00161, EPSS Percentile is 0.05673 |
debian: CVE-2026-80901 was patched at 2026-09-16
2360.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80902) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA When terminating DMA transfers, active descriptors are not properly reclaimed. Only cyclic descriptors were handled, leaving non-cyclic descriptors and their LLI chains to be permanently leaked. Fix by using vchan_terminate_vdesc() which handles both cyclic and non-cyclic descriptors by adding them to desc_terminated queue for proper cleanup. Add pchan->desc != pchan->done check to prevent double-adding completed descriptors, which would corrupt the list.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA\n\nWhen terminating DMA transfers, active descriptors are not properly\nreclaimed. Only cyclic descriptors were handled, leaving non-cyclic\ndescriptors and their LLI chains to be permanently leaked.\n\nFix by using vchan_terminate_vdesc() which handles both cyclic and\nnon-cyclic descriptors by adding them to desc_terminated queue for\nproper cleanup.\n\nAdd pchan->desc != pchan->done check to prevent double-adding completed\ndescriptors, which would corrupt the list.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06062 |
debian: CVE-2026-80902 was patched at 2026-09-16
2361.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80903) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Fix sync entry leak on OA config emit failure xe_oa_emit_oa_config() releases the sync entries and the syncs array only on its success path. When it fails before the point of no return (fence allocation, config buffer allocation or batch submission), it returns without touching stream->syncs. The stream open path handles such failures in the caller, but xe_oa_config_locked() propagates the error without any cleanup, so the syncs array and the fence references held by the parsed entries are leaked. The next config ioctl overwrites stream->syncs, making the memory unreachable for good. Clean up the parsed syncs when xe_oa_emit_oa_config() fails, matching the cleanup done by the stream open error path. (cherry picked from commit 8af97b3da2cfce04e6b457c6eb17ed3c1daf912b)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/oa: Fix sync entry leak on OA config emit failure\n\nxe_oa_emit_oa_config() releases the sync entries and the syncs array\nonly on its success path. When it fails before the point of no return\n(fence allocation, config buffer allocation or batch submission), it\nreturns without touching stream->syncs.\n\nThe stream open path handles such failures in the caller, but\nxe_oa_config_locked() propagates the error without any cleanup, so the\nsyncs array and the fence references held by the parsed entries are\nleaked. The next config ioctl overwrites stream->syncs, making the\nmemory unreachable for good.\n\nClean up the parsed syncs when xe_oa_emit_oa_config() fails, matching\nthe cleanup done by the stream open error path.\n\n(cherry picked from commit 8af97b3da2cfce04e6b457c6eb17ed3c1daf912b)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05188 |
debian: CVE-2026-80903 was patched at 2026-09-16
2362.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80904) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/tls: Fail tls_sw_splice_read() after a failed async decrypt When an async decrypt fails, tls_decrypt_done() records the error in ctx->async_wait.err and calls tls_err_abort(), which stores it in sk_err. tls_sw_recvmsg() and tls_sw_read_sock() each read async_wait.err once they hold the reader lock and fail the call: a record that did not authenticate breaks the connection. tls_sw_splice_read() has no such check, and sk_err does not stand in for one. tls_rx_rec_wait() tests sk_err only inside the loop it skips whenever a record is already parsed, and the first reader to reach sock_error() clears it, while async_wait.err persists. A splice therefore keeps delivering records on a connection that recvmsg() and read_sock() refuse to read. Read async_wait.err in tls_sw_splice_read() as the other two readers do.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/tls: Fail tls_sw_splice_read() after a failed async decrypt\n\nWhen an async decrypt fails, tls_decrypt_done() records the error in\nctx->async_wait.err and calls tls_err_abort(), which stores it in\nsk_err. tls_sw_recvmsg() and tls_sw_read_sock() each read\nasync_wait.err once they hold the reader lock and fail the call: a\nrecord that did not authenticate breaks the connection.\n\ntls_sw_splice_read() has no such check, and sk_err does not stand in\nfor one. tls_rx_rec_wait() tests sk_err only inside the loop it\nskips whenever a record is already parsed, and the first reader to\nreach sock_error() clears it, while async_wait.err persists. A\nsplice therefore keeps delivering records on a connection that\nrecvmsg() and read_sock() refuse to read.\n\nRead async_wait.err in tls_sw_splice_read() as the other two readers\ndo.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00161, EPSS Percentile is 0.05672 |
debian: CVE-2026-80904 was patched at 2026-09-16
2363.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80906) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: packet: fix wrong transport_header when sending VLAN-tagged frame In packet_parse_headers(), when processing a VLAN-tagged frame, skb_set_network_header() is called to advance network_header past the VLAN tag to the inner protocol header. skb_probe_transport_header() is then called with skb->protocol still set to the outer VLAN EtherType (e.g. ETH_P_8021Q), while nhoff (derived from skb_network_offset()) already points past the VLAN tag to the inner protocol header. In __skb_flow_dissect(), proto is initialized to ETH_P_8021Q and nhoff points past the VLAN tag. When the dissector hits case ETH_P_8021Q, it reads a struct vlan_hdr at nhoff via __skb_header_pointer(), but that offset contains the inner protocol header (e.g. an IP header). The bytes are misinterpreted as a VLAN header, yielding a garbage encapsulated EtherType that matches no known protocol. The dissector returns false, so skb_probe_transport_header() never calls skb_set_transport_header(), leaving transport_header at its uninitialized sentinel value (~0U). Move skb_probe_transport_header() to before skb_set_network_header(). At the time skb_probe_transport_header() is called, network_header still points to the VLAN header, so nhoff correctly points to the VLAN header. The flow dissector can then parse the VLAN header, extract the inner EtherType, and advance nhoff to the inner protocol header, allowing transport_header to be set correctly.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: packet: fix wrong transport_header when sending VLAN-tagged frame\n\nIn packet_parse_headers(), when processing a VLAN-tagged frame,\nskb_set_network_header() is called to advance network_header past the\nVLAN tag to the inner protocol header. skb_probe_transport_header() is\nthen called with skb->protocol still set to the outer VLAN EtherType\n(e.g. ETH_P_8021Q), while nhoff (derived from skb_network_offset())\nalready points past the VLAN tag to the inner protocol header.\n\nIn __skb_flow_dissect(), proto is initialized to ETH_P_8021Q and nhoff\npoints past the VLAN tag. When the dissector hits case ETH_P_8021Q, it\nreads a struct vlan_hdr at nhoff via __skb_header_pointer(), but that\noffset contains the inner protocol header (e.g. an IP header). The bytes\nare misinterpreted as a VLAN header, yielding a garbage encapsulated\nEtherType that matches no known protocol. The dissector returns false,\nso skb_probe_transport_header() never calls skb_set_transport_header(),\nleaving transport_header at its uninitialized sentinel value (~0U).\n\nMove skb_probe_transport_header() to before skb_set_network_header(). At\nthe time skb_probe_transport_header() is called, network_header still\npoints to the VLAN header, so nhoff correctly points to the VLAN header.\nThe flow dissector can then parse the VLAN header, extract the inner\nEtherType, and advance nhoff to the inner protocol header, allowing\ntransport_header to be set correctly.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06064 |
debian: CVE-2026-80906 was patched at 2026-09-16
2364.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80907) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix UVD dpb min size calculation for H264 This should use actual number of references from the decode message, instead of maximum derived from level. (cherry picked from commit 64b525edb7e7bdfcdc77883c5e413804e2396856)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix UVD dpb min size calculation for H264\n\nThis should use actual number of references from the decode\nmessage, instead of maximum derived from level.\n\n(cherry picked from commit 64b525edb7e7bdfcdc77883c5e413804e2396856)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05203 |
debian: CVE-2026-80907 was patched at 2026-09-16
2365.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80908) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Reject UVD message with dimensions above 4096 Fixes potential overflow in DPB size calculations. (cherry picked from commit 05e1387d151f71569fbe122d2c89f9db0c21dc10)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Reject UVD message with dimensions above 4096\n\nFixes potential overflow in DPB size calculations.\n\n(cherry picked from commit 05e1387d151f71569fbe122d2c89f9db0c21dc10)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06063 |
debian: CVE-2026-80908 was patched at 2026-09-16
2366.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80909) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Reject UVD message with invalid number of h265 refs Same change as for h264, avoids overflow later when calculating min dpb size. (cherry picked from commit a4b0720e4f1601f97f59a2be9c1b4b94fa6527d5)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Reject UVD message with invalid number of h265 refs\n\nSame change as for h264, avoids overflow later when calculating\nmin dpb size.\n\n(cherry picked from commit a4b0720e4f1601f97f59a2be9c1b4b94fa6527d5)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06064 |
debian: CVE-2026-80909 was patched at 2026-09-16
2367.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80910) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses EAR SPKR PA Gain" and the four "WSA RX* Mux" controls are enumerated, but their get and put callbacks access the value through ucontrol->value.integer.value[0] (a long) instead of ucontrol->value.enumerated.item[0] (an unsigned int). This same pattern was fixed in the sibling drivers by commit bcfe5f76cc40 ("ASoC: codecs: rx-macro: fix accessing array out of bounds for enum type") and commit 0ea5eff7c606 ("ASoC: codecs: va-macro: fix accessing array out of bounds for enum type"), but wsa-macro was missed. On 64-bit kernels with CONFIG_SND_CTL_DEBUG this trips the elem value sanity check and every read of these controls fails with -EINVAL.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses\n\nEAR SPKR PA Gain" and the four "WSA RX* Mux" controls are enumerated,\nbut their get and put callbacks access the value through\nucontrol->value.integer.value[0] (a long) instead of\nucontrol->value.enumerated.item[0] (an unsigned int).\n\nThis same pattern was fixed in the sibling drivers by\ncommit bcfe5f76cc40 ("ASoC: codecs: rx-macro: fix accessing array\nout of bounds for enum type") and\ncommit 0ea5eff7c606 ("ASoC: codecs: va-macro: fix accessing array\nout of bounds for enum type"), but wsa-macro was missed.\n\nOn 64-bit kernels with CONFIG_SND_CTL_DEBUG this trips the elem value\nsanity check and every read of these controls fails with -EINVAL.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00161, EPSS Percentile is 0.05672 |
debian: CVE-2026-80910 was patched at 2026-09-16
2368.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80911) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() If either tplg_ops->dai_config or widget_kcontrol_setup fail during widget setup we would double decrement the use_count of the widget because the sof_widget_free_unlocked() would be called twice, similarly the core_put would be invoked twice as well. Since the use_count and core_put() is handled within the widget_free function we need to return without falling through the pipe_widget_free label. The fixes tag is picked to the last change around this part of the code which is adequately old enough for backporting purposes.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked()\n\nIf either tplg_ops->dai_config or widget_kcontrol_setup fail during widget\nsetup we would double decrement the use_count of the widget because the\nsof_widget_free_unlocked() would be called twice, similarly the core_put\nwould be invoked twice as well.\n\nSince the use_count and core_put() is handled within the widget_free\nfunction we need to return without falling through the pipe_widget_free\nlabel.\n\nThe fixes tag is picked to the last change around this part of the code\nwhich is adequately old enough for backporting purposes.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05188 |
debian: CVE-2026-80911 was patched at 2026-09-16
2369.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80912) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: selinux: reject an unclaimed class value in security_get_classes() security_get_classes() sizes an array by p_classes.nprim and fills it at value - 1, so a class value the policy never defines leaves a NULL. sel_make_classes() passes every entry to sel_make_dir(), reaching the same d_alloc_name() dereference as the permission array. The class symbol table is allowed to be sparse (policydb_class_isvalid() exists to absorb that), but this getter builds its own array straight from the hash table and has no such predicate. Fail the lookup when a value went unclaimed instead of handing out the NULL. Conforming policies define every class they declare and are unaffected.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: reject an unclaimed class value in security_get_classes()\n\nsecurity_get_classes() sizes an array by p_classes.nprim and fills it at\nvalue - 1, so a class value the policy never defines leaves a NULL.\nsel_make_classes() passes every entry to sel_make_dir(), reaching the same\nd_alloc_name() dereference as the permission array. The class symbol table\nis allowed to be sparse (policydb_class_isvalid() exists to absorb that),\nbut this getter builds its own array straight from the hash table and has\nno such predicate.\n\nFail the lookup when a value went unclaimed instead of handing out the\nNULL. Conforming policies define every class they declare and are\nunaffected.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06064 |
debian: CVE-2026-80912 was patched at 2026-09-16
2370.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80913) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: selinux: require every boolean value to be defined p_bools.nprim comes from the policy image independently of how many booleans follow it, and cond_index_bool() fills bool_val_to_struct[] at value - 1, so a count larger than the values present leaves NULL entries. Every user of that array then walks it by index and dereferences each entry: cond_evaluate_expr() on the access-vector path, security_get_bools() and security_get_bool_value() behind selinuxfs, and security_set_bools(). A sparse class value is absorbed by policydb_class_isvalid() and its siblings; booleans have no such predicate, and no consumer that could use one. Reject a boolean value that no boolean defines, once, where the array is built. Conforming policies define every boolean they declare and are unaffected.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: require every boolean value to be defined\n\np_bools.nprim comes from the policy image independently of how many\nbooleans follow it, and cond_index_bool() fills bool_val_to_struct[] at\nvalue - 1, so a count larger than the values present leaves NULL entries.\nEvery user of that array then walks it by index and dereferences each\nentry: cond_evaluate_expr() on the access-vector path,\nsecurity_get_bools() and security_get_bool_value() behind selinuxfs, and\nsecurity_set_bools(). A sparse class value is absorbed by\npolicydb_class_isvalid() and its siblings; booleans have no such\npredicate, and no consumer that could use one.\n\nReject a boolean value that no boolean defines, once, where the array is\nbuilt. Conforming policies define every boolean they declare and are\nunaffected.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06064 |
debian: CVE-2026-80913 was patched at 2026-09-16
2371.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80915) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix DPT allocation paths. Remove the fallback for VRAM to system memory, I tested it and that doesn't work at all, only a black screen with pipe fault errors were observed. On systems with media GT, extra latency is added when accessing stolen memory when the GT is in MC6. Since we additionally aren't counting how much memory is used for stolen and we could in theory fill up the entire stolen area with DPT's, avoid using stolen and only use the default memory region. Using stolen may also result in random system hangs under load. (cherry picked from commit a196406a3831291598fe8e73245914f7acffdfe0)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Fix DPT allocation paths.\n\nRemove the fallback for VRAM to system memory, I tested it and that\ndoesn't work at all, only a black screen with pipe fault errors were\nobserved.\n\nOn systems with media GT, extra latency is added when accessing stolen\nmemory when the GT is in MC6. Since we additionally aren't counting how\nmuch memory is used for stolen and we could in theory fill up the\nentire stolen area with DPT's, avoid using stolen and only use the\ndefault memory region.\n\nUsing stolen may also result in random system hangs under load.\n\n(cherry picked from commit a196406a3831291598fe8e73245914f7acffdfe0)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05188 |
debian: CVE-2026-80915 was patched at 2026-09-16
2372.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80916) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: kcov: fix data corruption and race conditions on PREEMPT_RT syzbot is reporting KCOV state corruption on PREEMPT_RT kernels, for the temporary storage used for saving/restoring remote KCOV state is currently allocated as the per-CPU area. On PREEMPT_RT kernels, softirq handlers run as preemptible task threads (e.g., ksoftirqd). If a softirq context preempts a task running a remote KCOV session, it safely saves the task's state into the per-CPU area. However, if that softirq thread is subsequently preempted by a higher- priority softirq thread on the same CPU, the second softirq will overwrite the same per-CPU area, permanently destroying the original task's KCOV state. Fix this data corruption by moving the temporary storage from the per-CPU area to the per-thread area. Since each softirq thread now owns its own task context, nested softirq preemption no longer causes data overwrites. Note that while the temporary storage is now on a per-thread basis, the per-CPU kcov_percpu_data.lock must be retained, for we need to ensure that kcov_remote_start() and kcov_remote_stop() operate atomically without racing against asynchronous interrupts that manipulate the current task's KCOV state. It is likely that GFP_KERNEL allocation by vmalloc_node() in kcov_init() has already called panic() before returning NULL, for there will be no OOM-killable userspace processes when __init function of built-in module runs. But this patch also fixes crashing the kernel when vmalloc_node() in kcov_init() returned NULL, for kcov_init() left per-CPU irq_area == NULL but kcov_remote_start() depends on per-CPU irq_area != NULL, resulting in (1) doing vmalloc() in kcov_remote_start() despite !in_task() context (2) out-of-array-bounds access if (1) succeeded but kcov->remote_size < CONFIG_KCOV_IRQ_AREA_SIZE (3) always leak memory allocated by (1), eventually killing all OOM-killable userspace processes problems.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nkcov: fix data corruption and race conditions on PREEMPT_RT\n\nsyzbot is reporting KCOV state corruption on PREEMPT_RT kernels, for the\ntemporary storage used for saving/restoring remote KCOV state is currently\nallocated as the per-CPU area.\n\nOn PREEMPT_RT kernels, softirq handlers run as preemptible task threads\n(e.g., ksoftirqd). If a softirq context preempts a task running a remote\nKCOV session, it safely saves the task's state into the per-CPU area.\nHowever, if that softirq thread is subsequently preempted by a higher-\npriority softirq thread on the same CPU, the second softirq will overwrite\nthe same per-CPU area, permanently destroying the original task's KCOV\nstate.\n\nFix this data corruption by moving the temporary storage from the per-CPU\narea to the per-thread area. Since each softirq thread now owns its own\ntask context, nested softirq preemption no longer causes data overwrites.\n\nNote that while the temporary storage is now on a per-thread basis, the\nper-CPU kcov_percpu_data.lock must be retained, for we need to ensure that\nkcov_remote_start() and kcov_remote_stop() operate atomically without\nracing against asynchronous interrupts that manipulate the current task's\nKCOV state.\n\nIt is likely that GFP_KERNEL allocation by vmalloc_node() in kcov_init()\nhas already called panic() before returning NULL, for there will be no\nOOM-killable userspace processes when __init function of built-in module\nruns. But this patch also fixes crashing the kernel when vmalloc_node()\nin kcov_init() returned NULL, for kcov_init() left per-CPU irq_area == NULL\nbut kcov_remote_start() depends on per-CPU irq_area != NULL, resulting in\n\n (1) doing vmalloc() in kcov_remote_start() despite !in_task() context\n\n (2) out-of-array-bounds access if (1) succeeded but\n kcov->remote_size < CONFIG_KCOV_IRQ_AREA_SIZE\n\n (3) always leak memory allocated by (1), eventually killing all\n OOM-killable userspace processes\n\nproblems.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00182, EPSS Percentile is 0.07976 |
debian: CVE-2026-80916 was patched at 2026-09-16
2373.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80918) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: HID: core: fix number/pointer type confusion on long items When fetch_item() is called by hid_scan_report() on an item with HID_ITEM_TAG_LONG, it stores a pointer to the item data in item->data.longdata instead of storing a value directly in item->data.{u8/u16/u32}. When item_udata() or item_sdata() encounters such an item, it incorrectly assumes that the item is in short format, and therefore returns the lower part of a kernel pointer reinterpreted as a number. When a HID device is connected whose descriptor contains a HID_GLOBAL_ITEM_TAG_REPORT_SIZE encoded in long format with size=4, this causes the lower half of a kernel pointer to be printed into dmesg as a number, like this: hid (null): invalid report_size 107953555 To fix it, let item_udata() and item_sdata() verify that the item is in short format. Note that this bug only affects hid_scan_report(), while the main parsing pass hid_parse_collections() will always bail out when encountering a long item. Sidenote: There are currently no users of data.longdata; maybe we should just remove any parsing of long-format descriptors as a follow-up.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: fix number/pointer type confusion on long items\n\nWhen fetch_item() is called by hid_scan_report() on an item with\nHID_ITEM_TAG_LONG, it stores a pointer to the item data in\nitem->data.longdata instead of storing a value directly in\nitem->data.{u8/u16/u32}.\n\nWhen item_udata() or item_sdata() encounters such an item, it incorrectly\nassumes that the item is in short format, and therefore returns the lower\npart of a kernel pointer reinterpreted as a number.\n\nWhen a HID device is connected whose descriptor contains a\nHID_GLOBAL_ITEM_TAG_REPORT_SIZE encoded in long format with size=4, this\ncauses the lower half of a kernel pointer to be printed into dmesg as a\nnumber, like this:\n\n hid (null): invalid report_size 107953555\n\nTo fix it, let item_udata() and item_sdata() verify that the item is in\nshort format.\n\nNote that this bug only affects hid_scan_report(), while the main parsing\npass hid_parse_collections() will always bail out when encountering a long\nitem.\n\nSidenote: There are currently no users of data.longdata; maybe we should\njust remove any parsing of long-format descriptors as a follow-up.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00182, EPSS Percentile is 0.07976 |
debian: CVE-2026-80918 was patched at 2026-09-16
2374.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80920) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: io_uring: defer eventfd signaling when queued from a wakeup handler io_req_local_work_add() signals the CQ ring eventfd inline when it is the one to push the first entry onto ->work_list. For DEFER_TASKRUN rings that add is frequently done from a waitqueue wakeup handler, where an arbitrary waitqueue lock is held. eventfd_signal_mask() only refuses to recurse when current->in_eventfd is set, but that bit is set by eventfd_signal_mask() itself. If the wake chain starts somewhere else, signal goes out inline and can feed back into epoll. Add IOU_F_TWQ_IN_WAKE, set it on the task_work add done from the three waitqueue callbacks, and use it to force io_eventfd_signal() down the existing call_rcu_hurry() deferral instead of signaling inline.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: defer eventfd signaling when queued from a wakeup handler\n\nio_req_local_work_add() signals the CQ ring eventfd inline when it is the\none to push the first entry onto ->work_list. For DEFER_TASKRUN rings that\nadd is frequently done from a waitqueue wakeup handler, where an\narbitrary waitqueue lock is held.\n\neventfd_signal_mask() only refuses to recurse when current->in_eventfd\nis set, but that bit is set by eventfd_signal_mask() itself. If the wake\nchain starts somewhere else, signal goes out inline and can feed back\ninto epoll.\n\nAdd IOU_F_TWQ_IN_WAKE, set it on the task_work add done from the three\nwaitqueue callbacks, and use it to force io_eventfd_signal() down the\nexisting call_rcu_hurry() deferral instead of signaling inline.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05203 |
debian: CVE-2026-80920 was patched at 2026-09-16
2375.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80922) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - Allow zero as a random number Zero is a valid random number and needs to be allowed. Otherwise the output is distinguishable from random.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qcom-rng - Allow zero as a random number\n\nZero is a valid random number and needs to be allowed. Otherwise the\noutput is distinguishable from random.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05204 |
debian: CVE-2026-80922 was patched at 2026-09-16
2376.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80930) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout i2c_nuvoton_wait_for_stat() enables the IRQ before waiting for the interrupt handler to report a status change. If the wait times out, or is interrupted before the handler runs, the function returns without balancing the enable_irq() call. Disable the IRQ before leaving the failed wait path. Also preserve an interrupted wait's original error code instead of converting it to -ETIMEDOUT inside the helper.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntpm: tpm_i2c_nuvoton: disable IRQ on wait timeout\n\ni2c_nuvoton_wait_for_stat() enables the IRQ before waiting for the\ninterrupt handler to report a status change. If the wait times out, or is\ninterrupted before the handler runs, the function returns without\nbalancing the enable_irq() call.\n\nDisable the IRQ before leaving the failed wait path. Also preserve an\ninterrupted wait's original error code instead of converting it to\n-ETIMEDOUT inside the helper.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07432 |
debian: CVE-2026-80930 was patched at 2026-09-16
2377.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80938) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex mt7615_suspend() acquired the mt76 mutex and then called cancel_delayed_work_sync() on mac_work. mt7615_mac_work() acquires the same mutex via mt7615_mutex_acquire() at the top of the worker, so if mac_work is already running and blocked on the mutex, the suspend path deadlocks waiting for the work it holds the mutex against. Flush scan_work and mac_work before taking the mutex, matching the suspend paths in mt7921 and mt7925. scan_work only takes the mt76 spinlock, but moving it keeps the sequence consistent. This also keeps mac_work from running over an already suspended HIF, which the previous split (async cancel under the lock, sync cancel after release) would have allowed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex\n\nmt7615_suspend() acquired the mt76 mutex and then called\ncancel_delayed_work_sync() on mac_work. mt7615_mac_work() acquires the\nsame mutex via mt7615_mutex_acquire() at the top of the worker, so if\nmac_work is already running and blocked on the mutex, the suspend path\ndeadlocks waiting for the work it holds the mutex against.\n\nFlush scan_work and mac_work before taking the mutex, matching the\nsuspend paths in mt7921 and mt7925. scan_work only takes the mt76\nspinlock, but moving it keeps the sequence consistent. This also keeps\nmac_work from running over an already suspended HIF, which the previous\nsplit (async cancel under the lock, sync cancel after release) would\nhave allowed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06931 |
debian: CVE-2026-80938 was patched at 2026-09-16
2378.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80939) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot Since the hardware rfkill polling was introduced, arm64 platforms can panic with an asynchronous SError during warm reboot: SError Interrupt on CPU8, code 0x00000000be000011 -- SError Workqueue: events_power_efficient rfkill_poll [rfkill] rtw89_pci_ops_read8+0x94/0x160 [rtw89_pci] rtw89_core_rfkill_poll+0x50/0x1e0 [rtw89_core] rtw89_ops_rfkill_poll+0x40/0x68 [rtw89_core] ieee80211_rfkill_poll+0x3c/0x70 [mac80211] cfg80211_rfkill_poll+0x40/0x2a0 [cfg80211] rfkill_poll+0x30/0x88 [rfkill] Kernel panic - not syncing: Asynchronous SError Interrupt On the reboot path the kernel only runs device_shutdown(), which calls each driver's .shutdown callback; .remove is not invoked. The rtw89 PCI driver had no .shutdown callback, so nothing stopped the rfkill polling work while the platform was tearing the PCIe link down. Once the link is gone, the next MMIO read from the poll handler targets a non-responding device and is reported as a fatal asynchronous SError on arm64. Add rtw89_pci_shutdown(), wired to all rtw89 PCI device drivers, which sets a new RTW89_FLAG_SHUTDOWN flag (mirroring the USB RTW89_FLAG_UNPLUGGED pattern). When the flag is set, rtw89_ops_rfkill_poll() returns early, so no MMIO read is issued to the chip after shutdown begins and the SError no longer occurs. This does not call the full .remove path from .shutdown, to keep the shutdown handler minimal and avoid running the non-idempotent teardown twice.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot\n\nSince the hardware rfkill polling was introduced, arm64 platforms can\npanic with an asynchronous SError during warm reboot:\n\n SError Interrupt on CPU8, code 0x00000000be000011 -- SError\n Workqueue: events_power_efficient rfkill_poll [rfkill]\n rtw89_pci_ops_read8+0x94/0x160 [rtw89_pci]\n rtw89_core_rfkill_poll+0x50/0x1e0 [rtw89_core]\n rtw89_ops_rfkill_poll+0x40/0x68 [rtw89_core]\n ieee80211_rfkill_poll+0x3c/0x70 [mac80211]\n cfg80211_rfkill_poll+0x40/0x2a0 [cfg80211]\n rfkill_poll+0x30/0x88 [rfkill]\n Kernel panic - not syncing: Asynchronous SError Interrupt\n\nOn the reboot path the kernel only runs device_shutdown(), which calls\neach driver's .shutdown callback; .remove is not invoked. The rtw89 PCI\ndriver had no .shutdown callback, so nothing stopped the rfkill polling\nwork while the platform was tearing the PCIe link down. Once the link\nis gone, the next MMIO read from the poll handler targets a\nnon-responding device and is reported as a fatal asynchronous SError on\narm64.\n\nAdd rtw89_pci_shutdown(), wired to all rtw89 PCI device drivers, which\nsets a new RTW89_FLAG_SHUTDOWN flag (mirroring the USB\nRTW89_FLAG_UNPLUGGED pattern). When the flag is set,\nrtw89_ops_rfkill_poll() returns early, so no MMIO read is issued to the\nchip after shutdown begins and the SError no longer occurs.\n\nThis does not call the full .remove path from .shutdown, to keep the\nshutdown handler minimal and avoid running the non-idempotent teardown\ntwice.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06219 |
debian: CVE-2026-80939 was patched at 2026-09-16
2379.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80940) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: pci: fix resource leak on failed NAPI setup rtw_pci_probe() allocates PCI resources through rtw_pci_setup_resource() before it sets up NAPI. If rtw_pci_napi_init() fails, the error path jumps straight to err_pci_declaim and skips rtw_pci_destroy(), leaving the PCI resources allocated by rtw_pci_setup_resource() behind. Add a dedicated cleanup label for the NAPI setup failure path so probe destroys the PCI resources. The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing current mainline kernels. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1-rc7. An x86_64 allyesconfig build showed no new warnings. As we do not have a suitable rtw88 PCI board to test with, no runtime testing was able to be performed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw88: pci: fix resource leak on failed NAPI setup\n\nrtw_pci_probe() allocates PCI resources through\nrtw_pci_setup_resource() before it sets up NAPI. If\nrtw_pci_napi_init() fails, the error path jumps straight to\nerr_pci_declaim and skips rtw_pci_destroy(), leaving the PCI\nresources allocated by rtw_pci_setup_resource() behind.\n\nAdd a dedicated cleanup label for the NAPI setup failure path so probe\ndestroys the PCI resources.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing current\nmainline kernels. The tool is still under development and is not yet\npublicly available. Manual inspection confirms that the bug is still\npresent in v7.1-rc7.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have a\nsuitable rtw88 PCI board to test with, no runtime testing was able to be\nperformed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06407 |
debian: CVE-2026-80940 was patched at 2026-09-16
2380.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80964) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: virmidi: Check card index validity at probe virmidi driver blindly trusts that the given devptr->id value is within the proper card index range at probe. It's OK for the devices the driver itself creates at the module probe time, but if the device is bound manually via sysfs interface, this could be -1 as "none", and this leads to OOB access for index[] and other parameters. Add a sanity check for the card index and warn/correct it if it's a value out of the range.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: virmidi: Check card index validity at probe\n\nvirmidi driver blindly trusts that the given devptr->id value is\nwithin the proper card index range at probe. It's OK for the devices\nthe driver itself creates at the module probe time, but if the device\nis bound manually via sysfs interface, this could be -1 as "none", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06929 |
debian: CVE-2026-80964 was patched at 2026-09-16
2381.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80965) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: serial-u16550: Check card index validity at probe serial-u16550 driver blindly trusts that the given devptr->id value is within the proper card index range at probe. It's OK for the devices the driver itself creates at the module probe time, but if the device is bound manually via sysfs interface, this could be -1 as "none", and this leads to OOB access for index[] and other parameters. Add a sanity check for the card index and warn/correct it if it's a value out of the range.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: serial-u16550: Check card index validity at probe\n\nserial-u16550 driver blindly trusts that the given devptr->id value is\nwithin the proper card index range at probe. It's OK for the devices\nthe driver itself creates at the module probe time, but if the device\nis bound manually via sysfs interface, this could be -1 as "none", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07432 |
debian: CVE-2026-80965 was patched at 2026-09-16
2382.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80966) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: portman2x4: Check card index validity at probe Although portman2x4 driver has a check of the given devptr->id value, it doesn't check for a negative id, which is often given as "none" or such value when bound via sysfs. This may lead to OOB access for index[] and other parameters. Add a sanity check for the card index and warn/correct it if it's a value out of the range.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: portman2x4: Check card index validity at probe\n\nAlthough portman2x4 driver has a check of the given devptr->id value,\nit doesn't check for a negative id, which is often given as "none" or\nsuch value when bound via sysfs. This may lead to OOB access for\nindex[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11449 |
debian: CVE-2026-80966 was patched at 2026-09-16
2383.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80968) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: mts64: Check card index validity at probe Although mts64 driver has a check of the given devptr->id value, it doesn't check for a negative id, which is often given as "none" or such value when bound via sysfs. This may lead to OOB access for index[] and other parameters. Add a sanity check for the card index and warn/correct it if it's a value out of the range.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: mts64: Check card index validity at probe\n\nAlthough mts64 driver has a check of the given devptr->id value, it\ndoesn't check for a negative id, which is often given as "none" or\nsuch value when bound via sysfs. This may lead to OOB access for\nindex[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11448 |
debian: CVE-2026-80968 was patched at 2026-09-16
2384.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80969) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: mpu401: Check card index validity at probe mpu401 driver blindly trusts that the given devptr->id value is within the proper card index range at probe. It's OK for the devices the driver itself creates at the module probe time, but if the device is bound manually via sysfs interface, this could be -1 as "none", and this leads to OOB access for index[] and other parameters. Add a sanity check for the card index and warn/correct it if it's a value out of the range.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: mpu401: Check card index validity at probe\n\nmpu401 driver blindly trusts that the given devptr->id value is within\nthe proper card index range at probe. It's OK for the devices the\ndriver itself creates at the module probe time, but if the device is\nbound manually via sysfs interface, this could be -1 as "none", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.1145 |
debian: CVE-2026-80969 was patched at 2026-09-16
2385.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80972) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Check card index validity at probe aloop driver blindly trusts that the given devptr->id value is within the proper card index range at probe. It's OK for the devices the driver itself creates at the module probe time, but if the device is bound manually via sysfs interface, this could be -1 as "none", and this leads to OOB access for index[] and other parameters. Add a sanity check for the card index and warn/correct it if it's a value out of the range.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: aloop: Check card index validity at probe\n\naloop driver blindly trusts that the given devptr->id value is within\nthe proper card index range at probe. It's OK for the devices the\ndriver itself creates at the module probe time, but if the device is\nbound manually via sysfs interface, this could be -1 as "none", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.0693 |
debian: CVE-2026-80972 was patched at 2026-09-16
2386.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80973) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: 6fire: bound the MIDI event length from the device usb6fire_comm_receiver_handler() forwards a MIDI event using a length byte the device supplies, with no bound and no check that the transfer delivered that many bytes: \tif (!urb->status) { \t\tif (rt->receiver_buffer[0] == 0x10) /* midi in event */ \t\t\tif (midi_rt) \t\t\t\tmidi_rt->in_received(midi_rt, \t\t\t\t\t\trt->receiver_buffer + 2, \t\t\t\t\t\trt->receiver_buffer[1]); \t} receiver_buffer is a 64-byte kzalloc() buffer (COMM_RECEIVER_BUFSIZE), so only 62 bytes follow the two-byte header. receiver_buffer[1] is a u8 the device chooses, so a device that answers with 0x10 and a length of 0xFF makes snd_rawmidi_receive() read 255 bytes starting two bytes into a 64-byte object. The bytes past the buffer are handed to userspace through the rawmidi read path. urb->actual_length is not consulted either, so a short transfer leaves both the type byte and the length byte at their previous values and the handler acts on stale data. The receiver URB is submitted from usb6fire_comm_init() at probe, so the read happens on plug with no user action; forwarding to userspace also needs a MIDI input substream open, since usb6fire_midi_in_received() only calls snd_rawmidi_receive() when rt->in is set. KASAN on 7.2.0-rc5 (arm64), single packet from an emulated device: BUG: KASAN: slab-out-of-bounds in snd_rawmidi_receive Read of size 255 at addr ffff000009f64682 by task bash/183 __asan_memcpy snd_rawmidi_receive usb6fire_midi_in_received [snd_usb_6fire] usb6fire_comm_receiver_handler [snd_usb_6fire] Allocated by task 11: usb6fire_comm_init [snd_usb_6fire] usb6fire_chip_probe [snd_usb_6fire] The buggy address is located 2 bytes inside of allocated 64-byte region [ffff000009f64680, ffff000009f646c0) Reject the event when the length exceeds the bytes that follow the header, and require the transfer to have delivered the header plus that many bytes. The receiver URB is submitted with a 64-byte transfer_buffer_length, so a genuine device cannot deliver an event longer than those 62 bytes and nothing valid is dropped. Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: 6fire: bound the MIDI event length from the device\n\nusb6fire_comm_receiver_handler() forwards a MIDI event using a length\nbyte the device supplies, with no bound and no check that the transfer\ndelivered that many bytes:\n\n\tif (!urb->status) {\n\t\tif (rt->receiver_buffer[0] == 0x10) /* midi in event */\n\t\t\tif (midi_rt)\n\t\t\t\tmidi_rt->in_received(midi_rt,\n\t\t\t\t\t\trt->receiver_buffer + 2,\n\t\t\t\t\t\trt->receiver_buffer[1]);\n\t}\n\nreceiver_buffer is a 64-byte kzalloc() buffer (COMM_RECEIVER_BUFSIZE), so\nonly 62 bytes follow the two-byte header. receiver_buffer[1] is a u8 the\ndevice chooses, so a device that answers with 0x10 and a length of 0xFF\nmakes snd_rawmidi_receive() read 255 bytes starting two bytes into a\n64-byte object. The bytes past the buffer are handed to userspace\nthrough the rawmidi read path.\n\nurb->actual_length is not consulted either, so a short transfer leaves\nboth the type byte and the length byte at their previous values and the\nhandler acts on stale data.\n\nThe receiver URB is submitted from usb6fire_comm_init() at probe, so the\nread happens on plug with no user action; forwarding to userspace also\nneeds a MIDI input substream open, since usb6fire_midi_in_received()\nonly calls snd_rawmidi_receive() when rt->in is set.\n\nKASAN on 7.2.0-rc5 (arm64), single packet from an emulated device:\n\n BUG: KASAN: slab-out-of-bounds in snd_rawmidi_receive\n Read of size 255 at addr ffff000009f64682 by task bash/183\n __asan_memcpy\n snd_rawmidi_receive\n usb6fire_midi_in_received [snd_usb_6fire]\n usb6fire_comm_receiver_handler [snd_usb_6fire]\n Allocated by task 11:\n usb6fire_comm_init [snd_usb_6fire]\n usb6fire_chip_probe [snd_usb_6fire]\n The buggy address is located 2 bytes inside of\n allocated 64-byte region [ffff000009f64680, ffff000009f646c0)\n\nReject the event when the length exceeds the bytes that follow the\nheader, and require the transfer to have delivered the header plus that\nmany bytes. The receiver URB is submitted with a 64-byte\ntransfer_buffer_length, so a genuine device cannot deliver an event\nlonger than those 62 bytes and nothing valid is dropped.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.1145 |
debian: CVE-2026-80973 was patched at 2026-09-16
2387.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80974) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mfd: sm501: Fix potential memory leaks during remove The memory allocated for struct sm501_devdata in sm501_pci_probe() and sm501_plat_probe() is not freed by the corresponding remove functions sm501_pci_remove() and sm501_plat_remove(). Fix that by adding a call to kfree().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmfd: sm501: Fix potential memory leaks during remove\n\nThe memory allocated for struct sm501_devdata in sm501_pci_probe() and\nsm501_plat_probe() is not freed by the corresponding remove functions\nsm501_pci_remove() and sm501_plat_remove(). Fix that by adding a call to\nkfree().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10047 |
debian: CVE-2026-80974 was patched at 2026-09-16
2388.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80983) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/smc: fix socket refcount leak in smc_switch_conns() smc_switch_conns() takes a reference on the SMC socket before dropping lgr->conns_lock, so the connection stays alive while the CDC slot is fetched: sock_hold(&smc->sk); read_unlock_bh(&lgr->conns_lock); /* pre-fetch buffer outside of send_lock, might sleep */ rc = smc_cdc_get_free_slot(conn, to_lnk, &wr_buf, NULL, &pend); if (rc) goto err_out; The err_out label only drops the wr_tx link reference, so this early exit returns without the matching sock_put(). The second error exit is not affected, because sock_put() has already run by then. A leaked sk_refcnt means the smc_sock is never destroyed. Its send and receive buffers stay allocated, and for a user socket the reference held on the network namespace is never released, so the netns can no longer be torn down. smc_cdc_get_free_slot() fails when the target link goes down or when the connection has been killed while the switch is in progress. Both are reachable during the link failover this function implements, so the leak is triggered by the same hardware events that make smc_switch_conns() run in the first place. Restructure so there is a single sock_put() covering both outcomes, instead of adding a second one to the error path.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix socket refcount leak in smc_switch_conns()\n\nsmc_switch_conns() takes a reference on the SMC socket before dropping\nlgr->conns_lock, so the connection stays alive while the CDC slot is\nfetched:\n\n sock_hold(&smc->sk);\n read_unlock_bh(&lgr->conns_lock);\n /* pre-fetch buffer outside of send_lock, might sleep */\n rc = smc_cdc_get_free_slot(conn, to_lnk, &wr_buf, NULL, &pend);\n if (rc)\n goto err_out;\n\nThe err_out label only drops the wr_tx link reference, so this early exit\nreturns without the matching sock_put(). The second error exit is not\naffected, because sock_put() has already run by then.\n\nA leaked sk_refcnt means the smc_sock is never destroyed. Its send and\nreceive buffers stay allocated, and for a user socket the reference held\non the network namespace is never released, so the netns can no longer be\ntorn down.\n\nsmc_cdc_get_free_slot() fails when the target link goes down or when the\nconnection has been killed while the switch is in progress. Both are\nreachable during the link failover this function implements, so the leak\nis triggered by the same hardware events that make smc_switch_conns() run\nin the first place.\n\nRestructure so there is a single sock_put() covering both outcomes,\ninstead of adding a second one to the error path.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.0693 |
debian: CVE-2026-80983 was patched at 2026-09-16
2389.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80984) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/smc: do not dereference an unset send buffer on the SMC-D teardown path smc_close_stream_wait() calls smc_tx_prepared_sends() from inside its sk_wait_event() condition, and sk_wait_event() evaluates that condition once with the socket lock released. smcd_buf_detach() clears conn->sndbuf_desc from smc_conn_kill() under lock_sock(), so a link group terminating while a socket waits there leaves the helper dereferencing NULL, faulting out of close(). SIOCOUTQ reads the field by hand, and smc_close_cancel_work() drops the lock across two cancel_*_sync() calls. Sample the pointer once in the helper, report nothing prepared while it is unset, and bound the ioctl the same way. The receive tasklet dereferences the field directly in smc_cdc_msg_recv_action(), not through this helper; 1/2 is what keeps it from running that late.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: do not dereference an unset send buffer on the SMC-D teardown path\n\nsmc_close_stream_wait() calls smc_tx_prepared_sends() from inside its\nsk_wait_event() condition, and sk_wait_event() evaluates that condition\nonce with the socket lock released. smcd_buf_detach() clears\nconn->sndbuf_desc from smc_conn_kill() under lock_sock(), so a link group\nterminating while a socket waits there leaves the helper dereferencing\nNULL, faulting out of close(). SIOCOUTQ reads the field by hand, and\nsmc_close_cancel_work() drops the lock across two cancel_*_sync() calls.\n\nSample the pointer once in the helper, report nothing prepared while it is\nunset, and bound the ioctl the same way. The receive tasklet dereferences\nthe field directly in smc_cdc_msg_recv_action(), not through this helper;\n1/2 is what keeps it from running that late.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10047 |
debian: CVE-2026-80984 was patched at 2026-09-16
2390.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80988) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_transport: Fail TX enqueue when the QP link is down Commit f195a1a6fe41 ("ntb: Drop packets when qp link is down") meant to make ntb_transport_tx_enqueue() drop packets submitted while the QP link is down, but it only returns 0 without consuming the packet. Zero means success by this function's contract, so ntb_netdev reports NETDEV_TX_OK and forgets the skb: nothing queued it, nothing frees it, and it leaks, one skb for every transmit racing a link-down. Return -ENOLINK instead, restoring the contract that a non-zero return leaves the buffer owned by the caller. With the preceding patch, ntb_netdev frees the skb on non-retryable enqueue failures and returns NETDEV_TX_OK, so a packet racing with link-down is dropped without leaking or entering a busy retry loop.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nNTB: ntb_transport: Fail TX enqueue when the QP link is down\n\nCommit f195a1a6fe41 ("ntb: Drop packets when qp link is down") meant to\nmake ntb_transport_tx_enqueue() drop packets submitted while the QP link\nis down, but it only returns 0 without consuming the packet. Zero means\nsuccess by this function's contract, so ntb_netdev reports NETDEV_TX_OK\nand forgets the skb: nothing queued it, nothing frees it, and it leaks,\none skb for every transmit racing a link-down.\n\nReturn -ENOLINK instead, restoring the contract that a non-zero return\nleaves the buffer owned by the caller. With the preceding patch,\nntb_netdev frees the skb on non-retryable enqueue failures and returns\nNETDEV_TX_OK, so a packet racing with link-down is dropped without leaking\nor entering a busy retry loop.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07432 |
debian: CVE-2026-80988 was patched at 2026-09-16
2391.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80990) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Release the Rx HopID that was handed out on mismatch tb_xdomain_alloc_in_hopid() passes the wanted HopID to ida_alloc_range() as the lower bound, so a taken id is not an error there: the allocator returns the next free one above it. tbnet_connected_work() asks for the peer's transmit path, treats any other id as a failure and returns without releasing what it got, so that allocation stays live for the rest of the XDomain connection with nothing left holding a reference to it. Release the id when it is not the one we asked for, the same way the error unwind at the end of the function releases the expected one.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: thunderbolt: Release the Rx HopID that was handed out on mismatch\n\ntb_xdomain_alloc_in_hopid() passes the wanted HopID to ida_alloc_range()\nas the lower bound, so a taken id is not an error there: the allocator\nreturns the next free one above it. tbnet_connected_work() asks for the\npeer's transmit path, treats any other id as a failure and returns\nwithout releasing what it got, so that allocation stays live for the rest\nof the XDomain connection with nothing left holding a reference to it.\n\nRelease the id when it is not the one we asked for, the same way the\nerror unwind at the end of the function releases the expected one.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10044 |
debian: CVE-2026-80990 was patched at 2026-09-16
2392.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80996) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: l2tp: do not propagate multicast notification errors The tunnel create, tunnel modify, session create, and session modify netlink handlers send multicast notifications through helpers that can fail while allocating or encoding a message, or while multicasting it. For tunnel and session create/modify, a notification is sent after the live operation has completed. Returning a best-effort notification error as the command result can therefore report failure for an operation that already committed and can cause callers to retry and accumulate live objects. Keep sending notifications for listener visibility, but do not propagate their best-effort status as the command result. This also keeps the tunnel modify command consistent with the other notification-only paths.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: l2tp: do not propagate multicast notification errors\n\nThe tunnel create, tunnel modify, session create, and session modify\nnetlink handlers send multicast notifications through helpers that can fail\nwhile allocating or encoding a message, or while multicasting it.\n\nFor tunnel and session create/modify, a notification is sent after the live\noperation has completed. Returning a best-effort notification error as the\ncommand result can therefore report failure for an operation that already\ncommitted and can cause callers to retry and accumulate live objects.\n\nKeep sending notifications for listener visibility, but do not propagate\ntheir best-effort status as the command result. This also keeps the tunnel\nmodify command consistent with the other notification-only paths.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06408 |
debian: CVE-2026-80996 was patched at 2026-09-16
2393.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80999) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO rtl83xx_reset_assert() and rtl83xx_reset_deassert() are only called from the probe path, which may sleep and is not timing-critical. When the reset GPIO is provided by a sleeping controller such as an I2C I/O expander, gpiod_set_value() warns: WARNING: drivers/gpio/gpiolib.c:4030 at gpiod_set_value+0x44/0x80, CPU#1: kworker/u16:4/61 Hardware name: B&O MAP CA33 Rev f (UNKNOWN) (DT) Workqueue: events_unbound deferred_probe_work_func pc : gpiod_set_value+0x44/0x80 lr : rtl83xx_probe+0x1d8/0x3a0 Call trace: gpiod_set_value+0x44/0x80 (P) rtl83xx_probe+0x1d8/0x3a0 realtek_mdio_probe+0x24/0xa0 mdio_probe+0x38/0x78 really_probe+0xc4/0x3e0 __driver_probe_device+0x15c/0x1b8 driver_probe_device+0xb4/0x120 __device_attach_driver+0xb8/0x1a0 bus_for_each_drv+0x88/0xf0 __device_attach+0xa0/0x1d8 device_initial_probe+0x54/0x68 bus_probe_device+0x38/0xa0 deferred_probe_work_func+0xb8/0x120 process_one_work+0x184/0x4e8 worker_thread+0x188/0x308 kthread+0x130/0x150 ret_from_fork+0x10/0x20 Switch both helpers to gpiod_set_value_cansleep() so such a reset GPIO can be used without triggering the warning. The reset GPIO has been driven with the non-sleeping gpiod_set_value() since the driver was added in v4.19. The call has since been refactored across several files - from realtek-smi.c / realtek-mdio.c into the common rtl83xx.c module and then into the rtl83xx_reset_assert() and rtl83xx_reset_deassert() helpers (both in v6.9). This patch therefore applies as-is only to kernels that carry those helpers (v6.9+); older stable kernels need the same gpiod_set_value_cansleep() conversion at the corresponding open-coded call sites.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO\n\nrtl83xx_reset_assert() and rtl83xx_reset_deassert() are only called from\nthe probe path, which may sleep and is not timing-critical. When the\nreset GPIO is provided by a sleeping controller such as an I2C I/O\nexpander, gpiod_set_value() warns:\n\n WARNING: drivers/gpio/gpiolib.c:4030 at gpiod_set_value+0x44/0x80, CPU#1: kworker/u16:4/61\n Hardware name: B&O MAP CA33 Rev f (UNKNOWN) (DT)\n Workqueue: events_unbound deferred_probe_work_func\n pc : gpiod_set_value+0x44/0x80\n lr : rtl83xx_probe+0x1d8/0x3a0\n Call trace:\n gpiod_set_value+0x44/0x80 (P)\n rtl83xx_probe+0x1d8/0x3a0\n realtek_mdio_probe+0x24/0xa0\n mdio_probe+0x38/0x78\n really_probe+0xc4/0x3e0\n __driver_probe_device+0x15c/0x1b8\n driver_probe_device+0xb4/0x120\n __device_attach_driver+0xb8/0x1a0\n bus_for_each_drv+0x88/0xf0\n __device_attach+0xa0/0x1d8\n device_initial_probe+0x54/0x68\n bus_probe_device+0x38/0xa0\n deferred_probe_work_func+0xb8/0x120\n process_one_work+0x184/0x4e8\n worker_thread+0x188/0x308\n kthread+0x130/0x150\n ret_from_fork+0x10/0x20\n\nSwitch both helpers to gpiod_set_value_cansleep() so such a reset GPIO can\nbe used without triggering the warning.\n\nThe reset GPIO has been driven with the non-sleeping gpiod_set_value()\nsince the driver was added in v4.19. The call has since been refactored\nacross several files - from realtek-smi.c / realtek-mdio.c into the common\nrtl83xx.c module and then into the rtl83xx_reset_assert() and\nrtl83xx_reset_deassert() helpers (both in v6.9). This patch therefore\napplies as-is only to kernels that carry those helpers (v6.9+); older\nstable kernels need the same gpiod_set_value_cansleep() conversion at the\ncorresponding open-coded call sites.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10044 |
debian: CVE-2026-80999 was patched at 2026-09-16
2394.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-81013) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix heap OOB read on empty password write validate_password_input() computes length = strlen(buf) and then checks buf[length - 1] to strip a trailing newline, without checking that length is nonzero first. Writing an empty string (a bare '\\n') to current_password or new_password gives length == 0, and buf[length - 1] reads buf[-1], one byte before the heap allocation holding the copied input. KASAN confirms this directly: BUG: KASAN: slab-out-of-bounds in store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg] Read of size 1 at addr ffff88811bd8da9f by task sh/13740 ... store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg] current_password_store+0x14/0x20 [hp_bioscfg] ... The buggy address is located 23 bytes to the right of allocated 8-byte region [ffff88811bd8da80, ffff88811bd8da88) Reproduced identically via new_password_store. Execution continues past the bad read (the garbage byte only affects whether "length" is decremented by one), so the write completes and returns success; this is a pure information read past the buffer, not a crash, but it is still an out-of-bounds access KASAN correctly flags. Fix by only checking buf[length - 1] when length is nonzero.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: hp-bioscfg: fix heap OOB read on empty password write\n\nvalidate_password_input() computes length = strlen(buf) and then\nchecks buf[length - 1] to strip a trailing newline, without checking\nthat length is nonzero first. Writing an empty string (a bare '\\n')\nto current_password or new_password gives length == 0, and\nbuf[length - 1] reads buf[-1], one byte before the heap allocation\nholding the copied input.\n\nKASAN confirms this directly:\n\n BUG: KASAN: slab-out-of-bounds in store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg]\n Read of size 1 at addr ffff88811bd8da9f by task sh/13740\n ...\n store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg]\n current_password_store+0x14/0x20 [hp_bioscfg]\n ...\n The buggy address is located 23 bytes to the right of\n allocated 8-byte region [ffff88811bd8da80, ffff88811bd8da88)\n\nReproduced identically via new_password_store. Execution continues\npast the bad read (the garbage byte only affects whether "length" is\ndecremented by one), so the write completes and returns success; this\nis a pure information read past the buffer, not a crash, but it is\nstill an out-of-bounds access KASAN correctly flags.\n\nFix by only checking buf[length - 1] when length is nonzero.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07873 |
debian: CVE-2026-81013 was patched at 2026-09-16
2395.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-81014) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() sk_store() and kek_store() strip a trailing newline from the sysfs write before allocating the key buffer: \tlength = count; \tif (buf[length - 1] == '\\n') \t\tlength--; \tbioscfg_drv.spm_data.signing_key = kmemdup(buf, length, GFP_KERNEL); but then pass the original "count" (not "length") as the copy size to hp_wmi_perform_query(), which memcpy()s that many bytes out of the "length"-sized allocation, reading one byte past it whenever the write ends in a newline, the normal case for a shell "echo" into sysfs. KASAN confirms this directly: BUG: KASAN: slab-out-of-bounds in hp_wmi_perform_query+0x1e9/0x460 [hp_bioscfg] Read of size 28 at addr ffff88813c8e2b80 by task python3/16022 ... sk_store+0xa7/0x240 [hp_bioscfg] kernfs_fop_write_iter+0x3e1/0x5d0 ... The buggy address is located 0 bytes inside of allocated 27-byte region [ffff88813c8e2b80, ffff88813c8e2b9b) Reproduced identically for kek_store, and at multiple write sizes (28, 57, 201 bytes), each time reading exactly one byte past a kmemdup() allocation one byte smaller than the write. Fix by passing "length" instead of "count" to hp_wmi_perform_query() in both functions.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store()\n\nsk_store() and kek_store() strip a trailing newline from the sysfs\nwrite before allocating the key buffer:\n\n\tlength = count;\n\tif (buf[length - 1] == '\\n')\n\t\tlength--;\n\tbioscfg_drv.spm_data.signing_key = kmemdup(buf, length, GFP_KERNEL);\n\nbut then pass the original "count" (not "length") as the copy size to\nhp_wmi_perform_query(), which memcpy()s that many bytes out of the\n"length"-sized allocation, reading one byte past it whenever the write\nends in a newline, the normal case for a shell "echo" into sysfs.\n\nKASAN confirms this directly:\n\n BUG: KASAN: slab-out-of-bounds in hp_wmi_perform_query+0x1e9/0x460 [hp_bioscfg]\n Read of size 28 at addr ffff88813c8e2b80 by task python3/16022\n ...\n sk_store+0xa7/0x240 [hp_bioscfg]\n kernfs_fop_write_iter+0x3e1/0x5d0\n ...\n The buggy address is located 0 bytes inside of\n allocated 27-byte region [ffff88813c8e2b80, ffff88813c8e2b9b)\n\nReproduced identically for kek_store, and at multiple write sizes\n(28, 57, 201 bytes), each time reading exactly one byte past a\nkmemdup() allocation one byte smaller than the write.\n\nFix by passing "length" instead of "count" to hp_wmi_perform_query()\nin both functions.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06408 |
debian: CVE-2026-81014 was patched at 2026-09-16
2396.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89438) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate logical CPU id and clos id Validate max CLOS ID and logical CPU ID for core power feature. Reject any clos level or logical CPU number greater than the supported maximum. These are used to calculate MMIO offset.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: ISST: Validate logical CPU id and clos id\n\nValidate max CLOS ID and logical CPU ID for core power feature.\nReject any clos level or logical CPU number greater than the\nsupported maximum. These are used to calculate MMIO offset.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10045 |
debian: CVE-2026-89438 was patched at 2026-09-16
2397.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89439) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Add a NULL check for sst_inst[] To be consistent with other places, add a NULL check for failed socket loading by checking isst_common.sst_inst[].', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: ISST: Add a NULL check for sst_inst[]\n\nTo be consistent with other places, add a NULL check for failed socket\nloading by checking isst_common.sst_inst[].', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10044 |
debian: CVE-2026-89439 was patched at 2026-09-16
2398.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89444) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer set_attribute() populates the security area of the BIOS attribute request buffer with the current admin password via populate_security_buffer(), then dumps the whole request buffer with print_hex_dump_bytes(). This can expose the plaintext admin password in the kernel log. The same issue was fixed for the password attribute path by commit d1a196e0a6dc ("platform/x86: dell-wmi-sysman: Don't hex dump plaintext password data"). Remove the remaining dump from the BIOS attribute path.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer\n\nset_attribute() populates the security area of the BIOS attribute request\nbuffer with the current admin password via populate_security_buffer(), then\ndumps the whole request buffer with print_hex_dump_bytes(). This can expose\nthe plaintext admin password in the kernel log.\n\nThe same issue was fixed for the password attribute path by\ncommit d1a196e0a6dc ("platform/x86: dell-wmi-sysman: Don't hex dump\nplaintext password data"). Remove the remaining dump from the BIOS\nattribute path.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10805 |
debian: CVE-2026-89444 was patched at 2026-09-16
2399.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89451) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: iommu/sva: Set handle->dev before the SVA handle is visible iommu_attach_device_pasid() installs the new SVA attach handle in the group PASID lookup before iommu_sva_bind_device() returns. A concurrent bind can therefore find and reuse the same handle after iommu_sva_lock is dropped. handle->dev was initialized after dropping iommu_sva_lock. This leaves a window where a racing bind can return a handle whose dev pointer is still NULL. A subsequent iommu_sva_unbind_device() can then dereference it via handle->dev->iommu_group. Initialize handle->dev before releasing iommu_sva_lock so any visible SVA handle is fully initialized.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\niommu/sva: Set handle->dev before the SVA handle is visible\n\niommu_attach_device_pasid() installs the new SVA attach handle in the\ngroup PASID lookup before iommu_sva_bind_device() returns. A concurrent\nbind can therefore find and reuse the same handle after iommu_sva_lock is\ndropped.\n\nhandle->dev was initialized after dropping iommu_sva_lock. This leaves a\nwindow where a racing bind can return a handle whose dev pointer is still\nNULL. A subsequent iommu_sva_unbind_device() can then dereference it via\nhandle->dev->iommu_group.\n\nInitialize handle->dev before releasing iommu_sva_lock so any visible SVA\nhandle is fully initialized.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10044 |
debian: CVE-2026-89451 was patched at 2026-09-16
2400.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89453) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Put PCI device after handling PPR faults iommu_call_iopf_notifier() looks up the requester with pci_get_domain_bus_and_slot(), which returns a PCI device with its reference count incremented. Neither the successful iommu_report_device_fault() path nor the abort path drops that reference, so every handled PPR request leaks a PCI device reference. This is the same ownership rule that was fixed for the old iommu_v2 ppr_notifier() path by commit 6cf0981c2233 ("iommu/amd: Fix pci device refcount leak in ppr_notifier()"), but iommu_call_iopf_notifier() was added later as a separate PPR/IOPF notifier path. Drop the PCI device reference after handling the PPR entry.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Put PCI device after handling PPR faults\n\niommu_call_iopf_notifier() looks up the requester with\npci_get_domain_bus_and_slot(), which returns a PCI device with its\nreference count incremented.\n\nNeither the successful iommu_report_device_fault() path nor the abort\npath drops that reference, so every handled PPR request leaks a PCI\ndevice reference.\n\nThis is the same ownership rule that was fixed for the old iommu_v2\nppr_notifier() path by commit 6cf0981c2233 ("iommu/amd: Fix pci device\nrefcount leak in ppr_notifier()"), but iommu_call_iopf_notifier() was\nadded later as a separate PPR/IOPF notifier path.\n\nDrop the PCI device reference after handling the PPR entry.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10042 |
debian: CVE-2026-89453 was patched at 2026-09-16
2401.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89454) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts() plda_init_interrupts() initializes IRQ domains and creates IRQ mapping but does not unwind them when later step fails. If platform_get_irq() or either irq_create_mapping() fails in plda_init_interrupts(), the domains are never deinitialized. If irq_create_mapping() fails, port->intx_irq stays initialized. Hence, remove the IRQ domains in the error path by calling plda_pcie_irq_domain_deinit(). Since plda_pcie_irq_domain_deinit() now disposes of the intx_irq and msi_irq mappings itself before removing their domains, the msi_irq mapping failure path can go directly to err_irq_domain_deinit instead of disposing of port->intx_irq separately first. This issue was found by automated review of sashiko-bot [mani: commit log]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts()\n\nplda_init_interrupts() initializes IRQ domains and creates IRQ mapping but\ndoes not unwind them when later step fails.\n\nIf platform_get_irq() or either irq_create_mapping() fails\nin plda_init_interrupts(), the domains are never deinitialized. If\nirq_create_mapping() fails, port->intx_irq stays initialized.\n\nHence, remove the IRQ domains in the error path by calling\nplda_pcie_irq_domain_deinit().\n\nSince plda_pcie_irq_domain_deinit() now disposes of the intx_irq and\nmsi_irq mappings itself before removing their domains, the msi_irq\nmapping failure path can go directly to err_irq_domain_deinit instead of\ndisposing of port->intx_irq separately first.\n\nThis issue was found by automated review of sashiko-bot\n\n[mani: commit log]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10042 |
debian: CVE-2026-89454 was patched at 2026-09-16
2402.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89458) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Do not complete a failed ESE read as successful dasd_int_handler() completes an NRF read of an unallocated ESE track by calling ese_read() and unconditionally marking the request DASD_CQR_SUCCESS. dasd_eckd_ese_read() can return an error before it has zeroed the destination buffer: a failed sense-data parse or a current track outside the requested range both return early, leaving the destination pages untouched. The request is still completed successfully, so the block layer is handed stale / uninitialized memory instead of zeros. Check the ese_read() return value and fail the request through the normal error path instead of forcing DASD_CQR_SUCCESS.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ns390/dasd: Do not complete a failed ESE read as successful\n\ndasd_int_handler() completes an NRF read of an unallocated ESE track by\ncalling ese_read() and unconditionally marking the request\nDASD_CQR_SUCCESS. dasd_eckd_ese_read() can return an error before it has\nzeroed the destination buffer: a failed sense-data parse or a current\ntrack outside the requested range both return early, leaving the\ndestination pages untouched. The request is still completed successfully,\nso the block layer is handed stale / uninitialized memory instead of\nzeros.\n\nCheck the ese_read() return value and fail the request through the normal\nerror path instead of forcing DASD_CQR_SUCCESS.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07428 |
debian: CVE-2026-89458 was patched at 2026-09-16
2403.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89461) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: power: supply: max17040: synchronize work cancellation on suspend max17040_work() requeues itself after every poll. cancel_delayed_work() only cancels a pending instance and does not wait for a callback that is already running. If system suspend races with the polling callback, the callback can continue accessing the fuel gauge and requeue itself after the suspend callback returns. Use cancel_delayed_work_sync() to ensure polling is quiesced before suspend completes.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: max17040: synchronize work cancellation on suspend\n\nmax17040_work() requeues itself after every poll. cancel_delayed_work()\nonly cancels a pending instance and does not wait for a callback that is\nalready running.\n\nIf system suspend races with the polling callback, the callback can\ncontinue accessing the fuel gauge and requeue itself after the suspend\ncallback returns.\n\nUse cancel_delayed_work_sync() to ensure polling is quiesced before\nsuspend completes.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11451 |
debian: CVE-2026-89461 was patched at 2026-09-16
2404.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89462) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: power: supply: max17040: propagate register read errors max17040_get_vcell() and max17040_get_soc() ignore errors returned by regmap_read(). When an I2C transfer fails, the uninitialized register value is converted and reported to userspace as a valid voltage or state of charge. The polling worker can also replace the cached state of charge with the bogus value and emit a spurious change event. Propagate read errors through the power supply get_property callback and keep the last valid cached state of charge when polling fails.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: max17040: propagate register read errors\n\nmax17040_get_vcell() and max17040_get_soc() ignore errors returned by\nregmap_read(). When an I2C transfer fails, the uninitialized register\nvalue is converted and reported to userspace as a valid voltage or state\nof charge. The polling worker can also replace the cached state of charge\nwith the bogus value and emit a spurious change event.\n\nPropagate read errors through the power supply get_property callback and\nkeep the last valid cached state of charge when polling fails.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.0641 |
debian: CVE-2026-89462 was patched at 2026-09-16
2405.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89464) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: power: supply: twl4030_charger: cancel workers via devm bci is devm-allocated. Two workers (bci->work and bci->current_worker) dereference it. twl4030_bci_remove() disables charging and masks interrupts. It cancels neither worker. A worker pending at remove() can run after devm frees bci. The USB transceiver comes from devm_usb_get_phy_by_node(). devm unregisters its notifier only after remove() returns. A cancel_work_sync() in remove() can then race a notifier reschedule. devm_work_autocancel() and devm_delayed_work_autocancel() avoid that. They cancel the workers during devm release, before bci is freed. The current_worker is registered first, since devm will cancel in reverse order and bci->work can reschedule current_worker. [Move comment about order into the commit message]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: twl4030_charger: cancel workers via devm\n\nbci is devm-allocated. Two workers (bci->work and bci->current_worker)\ndereference it. twl4030_bci_remove() disables charging and masks\ninterrupts. It cancels neither worker. A worker pending at remove() can\nrun after devm frees bci.\n\nThe USB transceiver comes from devm_usb_get_phy_by_node(). devm\nunregisters its notifier only after remove() returns. A cancel_work_sync()\nin remove() can then race a notifier reschedule. devm_work_autocancel()\nand devm_delayed_work_autocancel() avoid that. They cancel the workers\nduring devm release, before bci is freed.\n\nThe current_worker is registered first, since devm will cancel in\nreverse order and bci->work can reschedule current_worker.\n\n[Move comment about order into the commit message]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06934 |
debian: CVE-2026-89464 was patched at 2026-09-16
2406.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89473) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: power: supply: bq25890: Fix power_supply reference leak bq25890_fw_probe() acquires a reference to a secondary charger using power_supply_get_by_name(), but the reference is not released on later probe failures or on driver detach. In particular, failures after bq25890_fw_probe() returns successfully, such as a failure in bq25890_hw_init(), also leak the reference. Register a device-managed cleanup action immediately after acquiring the secondary charger. This releases the reference on all subsequent probe failures and on driver detach. Found by code review.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: bq25890: Fix power_supply reference leak\n\nbq25890_fw_probe() acquires a reference to a secondary charger using\npower_supply_get_by_name(), but the reference is not released on later\nprobe failures or on driver detach.\n\nIn particular, failures after bq25890_fw_probe() returns successfully,\nsuch as a failure in bq25890_hw_init(), also leak the reference.\n\nRegister a device-managed cleanup action immediately after acquiring\nthe secondary charger. This releases the reference on all subsequent\nprobe failures and on driver detach.\n\nFound by code review.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10046 |
debian: CVE-2026-89473 was patched at 2026-09-16
2407.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89474) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: power: supply: bq256xx: drain usb_work before freeing the charger The USB-PHY notifier queues usb_work, whose handler calls power_supply_changed(bq->charger). The reset devm action only unregisters the notifier and was registered before the power supplies, so devm frees bq->charger on unwind before the action runs; a usb_work still queued can then dereference it. Register the reset action after the power supplies, so it unregisters the notifiers and drains usb_work before the supplies are released. Initialize usb_work and obtain the PHY references before registering the notifiers, so the worker cannot run before the supplies exist. Found by static analysis.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: bq256xx: drain usb_work before freeing the charger\n\nThe USB-PHY notifier queues usb_work, whose handler calls\npower_supply_changed(bq->charger). The reset devm action only unregisters\nthe notifier and was registered before the power supplies, so devm frees\nbq->charger on unwind before the action runs; a usb_work still queued can\nthen dereference it.\n\nRegister the reset action after the power supplies, so it unregisters\nthe notifiers and drains usb_work before the supplies are released.\nInitialize usb_work and obtain the PHY references before registering\nthe notifiers, so the worker cannot run before the supplies exist.\n\nFound by static analysis.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06934 |
debian: CVE-2026-89474 was patched at 2026-09-16
2408.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89484) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: lockd: fix NULL dereference on lockowner allocation failure nlmclnt_locks_init_private() installs NLM file lock operations even when nlmclnt_find_lockowner() fails to allocate a lockowner. nlmclnt_proc() then returns -ENOMEM, but the VFS still tears down the partially initialized file_lock and calls locks_release_private(). That invokes nlmclnt_locks_release_private(), which dereferences fl->fl_u.nfs_fl.owner and crashes because the owner was never installed. Clear fl_ops before attempting to initialize the NLM private state, and install the NLM lock operations only after a lockowner has been allocated successfully.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nlockd: fix NULL dereference on lockowner allocation failure\n\nnlmclnt_locks_init_private() installs NLM file lock operations even when\nnlmclnt_find_lockowner() fails to allocate a lockowner. nlmclnt_proc()\nthen returns -ENOMEM, but the VFS still tears down the partially\ninitialized file_lock and calls locks_release_private().\n\nThat invokes nlmclnt_locks_release_private(), which dereferences\nfl->fl_u.nfs_fl.owner and crashes because the owner was never installed.\n\nClear fl_ops before attempting to initialize the NLM private state, and\ninstall the NLM lock operations only after a lockowner has been allocated\nsuccessfully.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10041 |
debian: CVE-2026-89484 was patched at 2026-09-16
2409.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89490) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix readdir position truncation on 32-bit kernels In ocfs2_dir_foreach_blk_el(), the directory cookie position is rebuilt with \tctx->pos = (ctx->pos & ~(sb->s_blocksize - 1)) | offset; `ctx->pos` is loff_t (signed 64-bit), while `sb->s_blocksize` is unsigned long. On 32-bit kernels unsigned long is 32-bit, so the mask \t~(sb->s_blocksize - 1) is computed as a 32-bit unsigned value (e.g. 0xfffff000 for a 4 KiB block size). In the AND expression with the 64-bit `ctx->pos`, that unsigned operand is zero-extended to 64 bits per the usual arithmetic conversions, yielding 0x00000000fffff000. The high 32 bits of `ctx->pos` are silently cleared, even though directory size is allowed to exceed 4 GiB. When readdir() crosses the 4 GiB boundary on a 32-bit kernel the position is reset back into the first 4 GiB block, making the re-validation path re-enumerate already-returned dirents indefinitely. This is ocfs2_dir_foreach_blk_el(), the extent-list readdir path taken for all non-inline directories, so a directory large enough to cross 4 GiB reaches it. This is the same class of bug that commit 3dce5bb82c97 ("exfat: Fix bitwise operation having different size") fixed in exfat, and the fix mirrors the equivalent ext4 fix in this series. Cast the operand to loff_t so the mask is 64-bit before the AND: \tctx->pos = (ctx->pos & ~((loff_t)sb->s_blocksize - 1)) | offset; 64-bit kernels are unaffected.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix readdir position truncation on 32-bit kernels\n\nIn ocfs2_dir_foreach_blk_el(), the directory cookie position is\nrebuilt with\n\n\tctx->pos = (ctx->pos & ~(sb->s_blocksize - 1)) | offset;\n\n`ctx->pos` is loff_t (signed 64-bit), while `sb->s_blocksize` is\nunsigned long. On 32-bit kernels unsigned long is 32-bit, so the mask\n\n\t~(sb->s_blocksize - 1)\n\nis computed as a 32-bit unsigned value (e.g. 0xfffff000 for a 4 KiB\nblock size). In the AND expression with the 64-bit `ctx->pos`, that\nunsigned operand is zero-extended to 64 bits per the usual arithmetic\nconversions, yielding 0x00000000fffff000. The high 32 bits of\n`ctx->pos` are silently cleared, even though directory size is\nallowed to exceed 4 GiB.\n\nWhen readdir() crosses the 4 GiB boundary on a 32-bit kernel the\nposition is reset back into the first 4 GiB block, making the\nre-validation path re-enumerate already-returned dirents indefinitely.\n\nThis is ocfs2_dir_foreach_blk_el(), the extent-list readdir path taken\nfor all non-inline directories, so a directory large enough to cross\n4 GiB reaches it.\n\nThis is the same class of bug that commit 3dce5bb82c97 ("exfat: Fix\nbitwise operation having different size") fixed in exfat, and the\nfix mirrors the equivalent ext4 fix in this series. Cast the operand\nto loff_t so the mask is 64-bit before the AND:\n\n\tctx->pos = (ctx->pos & ~((loff_t)sb->s_blocksize - 1)) | offset;\n\n64-bit kernels are unaffected.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.0743 |
debian: CVE-2026-89490 was patched at 2026-09-16
2410.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89491) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin() Patch series "ocfs2: cluster: o2hb_region_pin() fixes", v2. This series fixes three related issues in o2hb_region_pin(), all are from the original implementation in commit: 58a3158a5d17 ("ocfs2/cluster: Pin/unpin o2hb regions"): 1) It is called with o2hb_live_lock (a spinlock) held, but the underlying configfs_depend_item() sleeps (takes inode rwsem and pins the filesystem). This triggers BUG under CONFIG_DEBUG_ATOMIC_SLEEP. 2) When called from the configfs drop_item callback, it creates a lock order inversion: parent inode_lock -> configfs root inode_lock, which can deadlock against subsystem unregistration paths taking root -> parent. 3) If pinning fails partway through o2hb_region_inc_user(), the o2hb_dependent_users counter is leaked and partially-pinned regions are never released, leaving heartbeat regions unprotected on subsequent mounts. Patch 1 reworks o2hb_region_pin() to drop o2hb_live_lock across each sleeping configfs_depend_item() call, using a config_item reference to keep the region alive while unlocked. Patch 2 adds a from_callback parameter to select configfs_depend_item_unlocked() when called from configfs context, avoiding the inode_lock nesting. Patch 3 fixes the error path in o2hb_region_inc_user() to unpin and decrement the counter on failure. This patch (of 3): o2hb_region_pin() is always called with the o2hb_live_lock spinlock held (from o2hb_region_inc_user() and o2hb_heartbeat_group_drop_item()), but it calls o2nm_depend_item() -> configfs_depend_item(), which sleeps: it pins the configfs filesystem and takes the configfs root inode rwsem. Under CONFIG_DEBUG_ATOMIC_SLEEP this triggers: BUG: sleeping function called from invalid context at kernel/locking/rwsem.c in_atomic(): 1, ... name: mount.ocfs2 down_write configfs_depend_item o2hb_region_pin o2hb_region_inc_user o2hb_register_callback dlm_register_domain_handlers ... ocfs2_dlm_init ocfs2_mount_volume ocfs2_fill_super Rework o2hb_region_pin() to pin one region at a time with the lock dropped across the sleeping call: under o2hb_live_lock find the next eligible region and take a config_item reference to keep it alive, drop the lock, call o2nm_depend_item(), then retake the lock and record the pin. The config_item_put() is done with the lock released as well, since o2hb_region_release() also acquires o2hb_live_lock and can sleep. The region list may change while unlocked, so the scan restarts from the top after each pin. Local heartbeat still pins only the matching region; global heartbeat pins all eligible regions. The unpin path is unaffected: configfs_undepend_item() only takes a spinlock and does not sleep.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin()\n\nPatch series "ocfs2: cluster: o2hb_region_pin() fixes", v2.\n\nThis series fixes three related issues in o2hb_region_pin(), all are from\nthe original implementation in commit: 58a3158a5d17 ("ocfs2/cluster:\nPin/unpin o2hb regions"):\n\n1) It is called with o2hb_live_lock (a spinlock) held, but the\n underlying configfs_depend_item() sleeps (takes inode rwsem and\n pins the filesystem). This triggers BUG under\n CONFIG_DEBUG_ATOMIC_SLEEP.\n\n2) When called from the configfs drop_item callback, it creates a\n lock order inversion: parent inode_lock -> configfs root\n inode_lock, which can deadlock against subsystem unregistration\n paths taking root -> parent.\n\n3) If pinning fails partway through o2hb_region_inc_user(), the\n o2hb_dependent_users counter is leaked and partially-pinned\n regions are never released, leaving heartbeat regions\n unprotected on subsequent mounts.\n\nPatch 1 reworks o2hb_region_pin() to drop o2hb_live_lock across each\nsleeping configfs_depend_item() call, using a config_item reference to\nkeep the region alive while unlocked.\n\nPatch 2 adds a from_callback parameter to select\nconfigfs_depend_item_unlocked() when called from configfs context,\navoiding the inode_lock nesting.\n\nPatch 3 fixes the error path in o2hb_region_inc_user() to unpin and\ndecrement the counter on failure.\n\n\nThis patch (of 3):\n\no2hb_region_pin() is always called with the o2hb_live_lock spinlock held\n(from o2hb_region_inc_user() and o2hb_heartbeat_group_drop_item()), but it\ncalls o2nm_depend_item() -> configfs_depend_item(), which sleeps: it pins\nthe configfs filesystem and takes the configfs root inode rwsem. Under\nCONFIG_DEBUG_ATOMIC_SLEEP this triggers:\n\n BUG: sleeping function called from invalid context at kernel/locking/rwsem.c\n in_atomic(): 1, ... name: mount.ocfs2\n down_write\n configfs_depend_item\n o2hb_region_pin\n o2hb_region_inc_user\n o2hb_register_callback\n dlm_register_domain_handlers\n ...\n ocfs2_dlm_init\n ocfs2_mount_volume\n ocfs2_fill_super\n\nRework o2hb_region_pin() to pin one region at a time with the lock dropped\nacross the sleeping call: under o2hb_live_lock find the next eligible\nregion and take a config_item reference to keep it alive, drop the lock,\ncall o2nm_depend_item(), then retake the lock and record the pin. The\nconfig_item_put() is done with the lock released as well, since\no2hb_region_release() also acquires o2hb_live_lock and can sleep. The\nregion list may change while unlocked, so the scan restarts from the top\nafter each pin. Local heartbeat still pins only the matching region;\nglobal heartbeat pins all eligible regions.\n\nThe unpin path is unaffected: configfs_undepend_item() only takes a\nspinlock and does not sleep.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11451 |
debian: CVE-2026-89491 was patched at 2026-09-16
2411.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89498) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: orangefs: fix double-free of trailer_buf on readdir copy failure On a readdir downcall, orangefs_devreq_write_iter() frees op->downcall.trailer_buf with vfree() when copy_from_iter_full() fails, but does not clear the pointer before goto Efault. The waiter in do_readdir() is then woken with a negative status and frees the same pointer again on its r < 0 path, causing a deterministic double-free. A client holding /dev/pvfs2-req triggers it by sending a readdir downcall whose declared trailer_size exceeds the bytes it supplies. Clear the pointer after freeing so the readdir-side vfree() becomes a no-op.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\norangefs: fix double-free of trailer_buf on readdir copy failure\n\nOn a readdir downcall, orangefs_devreq_write_iter() frees\nop->downcall.trailer_buf with vfree() when copy_from_iter_full() fails,\nbut does not clear the pointer before goto Efault. The waiter in\ndo_readdir() is then woken with a negative status and frees the same\npointer again on its r < 0 path, causing a deterministic double-free.\nA client holding /dev/pvfs2-req triggers it by sending a readdir\ndowncall whose declared trailer_size exceeds the bytes it supplies.\n\nClear the pointer after freeing so the readdir-side vfree() becomes a\nno-op.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07426 |
debian: CVE-2026-89498 was patched at 2026-09-16
2412.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89502) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Free cpu_buffer::free_page with subbuf_order When sub-buffers use an order greater than 0, cpu_buffer->free_page is allocated with subbuf_order. Use the correct order for cpu_buffer->free_page.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Free cpu_buffer::free_page with subbuf_order\n\nWhen sub-buffers use an order greater than 0, cpu_buffer->free_page is\nallocated with subbuf_order. Use the correct order for\ncpu_buffer->free_page.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10041 |
debian: CVE-2026-89502 was patched at 2026-09-16
2413.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89512) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: remoteproc: scp: Fix device reference leak on failed lookup Make sure to drop the reference taken to the SCP device when attempting to look up its driver data before the driver has been bound. Note that holding a reference to a device does not prevent its driver data from going away.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nremoteproc: scp: Fix device reference leak on failed lookup\n\nMake sure to drop the reference taken to the SCP device when attempting\nto look up its driver data before the driver has been bound.\n\nNote that holding a reference to a device does not prevent its driver\ndata from going away.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11451 |
debian: CVE-2026-89512 was patched at 2026-09-16
2414.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89515) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables() During fuzz testing, the following issue was discovered: BUG: KMSAN: uninit-value in __dma_map_sg_attrs+0x217/0x310 __dma_map_sg_attrs+0x217/0x310 dma_map_sg_attrs+0x4a/0x70 ata_qc_issue+0x9f8/0x1420 __ata_scsi_queuecmd+0x1657/0x1740 ata_scsi_queuecmd+0x79a/0x920 scsi_queue_rq+0x4472/0x4f40 blk_mq_dispatch_rq_list+0x1cca/0x3ee0 __blk_mq_sched_dispatch_requests+0x458/0x630 blk_mq_sched_dispatch_requests+0x15b/0x340 __blk_mq_run_hw_queue+0xe5/0x250 __blk_mq_delay_run_hw_queue+0x138/0x780 blk_mq_run_hw_queue+0x4bb/0x7e0 blk_mq_sched_insert_request+0x2a7/0x4c0 blk_execute_rq+0x497/0x8a0 sg_io+0xbe0/0xe20 scsi_ioctl+0x2b36/0x3c60 sr_block_ioctl+0x319/0x440 blkdev_ioctl+0x80f/0xd70 __se_sys_ioctl+0x219/0x420 __x64_sys_ioctl+0x93/0xe0 x64_sys_call+0x1d6c/0x3ad0 do_syscall_64+0x4c/0xa0 entry_SYSCALL_64_after_hwframe+0x6e/0xd8 Uninit was created at: __alloc_pages+0x5c0/0xc80 alloc_pages+0xe0e/0x1050 blk_rq_map_user_iov+0x2b77/0x6100 blk_rq_map_user_io+0x2fa/0x4d0 sg_io+0xad6/0xe20 scsi_ioctl+0x2b36/0x3c60 sr_block_ioctl+0x319/0x440 blkdev_ioctl+0x80f/0xd70 __se_sys_ioctl+0x219/0x420 __x64_sys_ioctl+0x93/0xe0 x64_sys_call+0x1d6c/0x3ad0 do_syscall_64+0x4c/0xa0 entry_SYSCALL_64_after_hwframe+0x6e/0xd8 Bytes 14-15 of 16 are uninitialized Memory access of size 16 starts at ffff88800cbdb000 When processing the last unaligned element of the scatterlist, it is supplemented with missing bytes in the amount of pad_len. These bytes remain uninitialized, which leads to a problem. Extend last_sg->length by pad_len first, then use sg_zero_buffer() to zero those pad_len bytes. sg_zero_buffer() uses sg_miter internally, which correctly handles sg entries spanning multiple pages and padding that crosses a page boundary. Found by Linux Verification Center (linuxtesting.org) with Syzkaller.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables()\n\nDuring fuzz testing, the following issue was discovered:\n\nBUG: KMSAN: uninit-value in __dma_map_sg_attrs+0x217/0x310\n __dma_map_sg_attrs+0x217/0x310\n dma_map_sg_attrs+0x4a/0x70\n ata_qc_issue+0x9f8/0x1420\n __ata_scsi_queuecmd+0x1657/0x1740\n ata_scsi_queuecmd+0x79a/0x920\n scsi_queue_rq+0x4472/0x4f40\n blk_mq_dispatch_rq_list+0x1cca/0x3ee0\n __blk_mq_sched_dispatch_requests+0x458/0x630\n blk_mq_sched_dispatch_requests+0x15b/0x340\n __blk_mq_run_hw_queue+0xe5/0x250\n __blk_mq_delay_run_hw_queue+0x138/0x780\n blk_mq_run_hw_queue+0x4bb/0x7e0\n blk_mq_sched_insert_request+0x2a7/0x4c0\n blk_execute_rq+0x497/0x8a0\n sg_io+0xbe0/0xe20\n scsi_ioctl+0x2b36/0x3c60\n sr_block_ioctl+0x319/0x440\n blkdev_ioctl+0x80f/0xd70\n __se_sys_ioctl+0x219/0x420\n __x64_sys_ioctl+0x93/0xe0\n x64_sys_call+0x1d6c/0x3ad0\n do_syscall_64+0x4c/0xa0\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\nUninit was created at:\n __alloc_pages+0x5c0/0xc80\n alloc_pages+0xe0e/0x1050\n blk_rq_map_user_iov+0x2b77/0x6100\n blk_rq_map_user_io+0x2fa/0x4d0\n sg_io+0xad6/0xe20\n scsi_ioctl+0x2b36/0x3c60\n sr_block_ioctl+0x319/0x440\n blkdev_ioctl+0x80f/0xd70\n __se_sys_ioctl+0x219/0x420\n __x64_sys_ioctl+0x93/0xe0\n x64_sys_call+0x1d6c/0x3ad0\n do_syscall_64+0x4c/0xa0\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\nBytes 14-15 of 16 are uninitialized\nMemory access of size 16 starts at ffff88800cbdb000\n\nWhen processing the last unaligned element of the scatterlist, it is\nsupplemented with missing bytes in the amount of pad_len. These bytes\nremain uninitialized, which leads to a problem.\n\nExtend last_sg->length by pad_len first, then use sg_zero_buffer() to\nzero those pad_len bytes. sg_zero_buffer() uses sg_miter internally,\nwhich correctly handles sg entries spanning multiple pages and padding\nthat crosses a page boundary.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07426 |
debian: CVE-2026-89515 was patched at 2026-09-16
2415.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89525) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: udf: reject VAT indexes equal to the entry count UDF 1.50 virtual partition mapping uses the VAT as an array of physical block mappings. s_num_entries stores the number of entries in that array, not the highest valid index. The valid VAT indexes are therefore below s_num_entries. udf_get_pblock_virt15() currently rejects only indexes greater than s_num_entries. A crafted image can request index s_num_entries, pass the bounds check, and make the kernel read one entry past the allocated VAT table. Change the check to reject block >= s_num_entries, so the count is handled as an exclusive upper bound. A crafted UDF image reproduced this on origin/master commit 0e35b9b6ec0ffcc5e23cbdec09f5c622ad532b53 with a KASAN slab-out-of-bounds report in udf_get_pblock_virt15(). Trail of Bits has a reproducer that triggers kernel panic demonstrating the bug, and can share it if needed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nudf: reject VAT indexes equal to the entry count\n\nUDF 1.50 virtual partition mapping uses the VAT as an array of physical\nblock mappings. s_num_entries stores the number of entries in that array,\nnot the highest valid index. The valid VAT indexes are therefore below\ns_num_entries.\n\nudf_get_pblock_virt15() currently rejects only indexes greater than\ns_num_entries. A crafted image can request index s_num_entries, pass the\nbounds check, and make the kernel read one entry past the allocated VAT table.\n\nChange the check to reject block >= s_num_entries, so the count is handled as\nan exclusive upper bound.\n\nA crafted UDF image reproduced this on origin/master commit\n0e35b9b6ec0ffcc5e23cbdec09f5c622ad532b53 with a KASAN slab-out-of-bounds\nreport in udf_get_pblock_virt15().\n\nTrail of Bits has a reproducer that triggers kernel panic demonstrating the bug, and can share it if needed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00184, EPSS Percentile is 0.08248 |
debian: CVE-2026-89525 was patched at 2026-09-16
2416.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89527) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: svcrdma: Use svc_xprt_put to free listener on create failure svc_rdma_create() calls kfree(cma_xprt) when svc_rdma_create_listen_id() fails. svc_xprt_init() has already acquired a net namespace reference via get_net_track(); kfree bypasses svc_xprt_free() which releases it. Replace the kfree() with svc_xprt_put() so the kref_init birth reference drops to zero and svc_xprt_free() dispatches svc_rdma_free() to clean up properly. sc_cm_id is still NULL at that point; the preceding patch added the necessary NULL guard in svc_rdma_free(). svc_xprt_free() also drops the module reference via module_put(), but the caller _svc_xprt_create() does the same on xpo_create failure, double-putting the single try_module_get() it acquired. Take a compensating __module_get() before the svc_xprt_put() to keep the count balanced, matching the convention in svc_rdma_accept()'s error path.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: Use svc_xprt_put to free listener on create failure\n\nsvc_rdma_create() calls kfree(cma_xprt) when\nsvc_rdma_create_listen_id() fails. svc_xprt_init() has already\nacquired a net namespace reference via get_net_track(); kfree\nbypasses svc_xprt_free() which releases it.\n\nReplace the kfree() with svc_xprt_put() so the kref_init birth\nreference drops to zero and svc_xprt_free() dispatches\nsvc_rdma_free() to clean up properly. sc_cm_id is still NULL\nat that point; the preceding patch added the necessary NULL\nguard in svc_rdma_free().\n\nsvc_xprt_free() also drops the module reference via\nmodule_put(), but the caller _svc_xprt_create() does the same\non xpo_create failure, double-putting the single\ntry_module_get() it acquired. Take a compensating\n__module_get() before the svc_xprt_put() to keep the count\nbalanced, matching the convention in svc_rdma_accept()'s error\npath.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00201, EPSS Percentile is 0.10171 |
debian: CVE-2026-89527 was patched at 2026-09-16
2417.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89531) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject connection when transport allocation fails handle_connect_req() returns without action when svc_rdma_create_xprt() fails to allocate the new transport. The CM core returns 0 for CONNECT_REQUEST events, so it does not destroy the new rdma_cm_id. Each allocation failure under memory pressure leaks one rdma_cm_id, and a remote peer driving connection attempts can amplify this. Reject the connection by returning a non-zero status from the CM event handler, which tells the CM core to destroy the orphaned cm_id.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: Reject connection when transport allocation fails\n\nhandle_connect_req() returns without action when\nsvc_rdma_create_xprt() fails to allocate the new transport.\nThe CM core returns 0 for CONNECT_REQUEST events, so it does\nnot destroy the new rdma_cm_id. Each allocation failure under\nmemory pressure leaks one rdma_cm_id, and a remote peer driving\nconnection attempts can amplify this.\n\nReject the connection by returning a non-zero status from the\nCM event handler, which tells the CM core to destroy the\norphaned cm_id.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06412 |
debian: CVE-2026-89531 was patched at 2026-09-16
2418.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89539) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: SUNRPC: reject duplicate CREDS_VALUE options gssx_dec_option_array() walks the wire-supplied option array and, for every entry whose name matches CREDS_VALUE, calls gssx_dec_linux_creds() on the same struct svc_cred. That helper unconditionally installs a fresh groups_alloc() result into creds->cr_group_info without releasing whatever pointer was already there: for (i = 0; i < count; i++) { ... decode name ... if (length == sizeof(CREDS_VALUE) && memcmp(p, CREDS_VALUE, sizeof(CREDS_VALUE)) == 0) { err = gssx_dec_linux_creds(xdr, creds); ... } } A reply that carries two CREDS_VALUE entries therefore overwrites cr_group_info on the second iteration and orphans the group_info allocated by the first call. The earlier free_creds path only releases the last cr_group_info via free_svc_cred(), so the first allocation's refcount stays at one and its kvmalloc-backed storage is leaked. No in-tree caller of gssp_accept_sec_context_upcall() expects more than one CREDS_VALUE per reply. Fix by tracking whether a CREDS_VALUE option has already been decoded and returning -EINVAL on any subsequent match, so the free_creds path releases the single group_info that was installed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: reject duplicate CREDS_VALUE options\n\ngssx_dec_option_array() walks the wire-supplied option array and, for\nevery entry whose name matches CREDS_VALUE, calls\ngssx_dec_linux_creds() on the same struct svc_cred. That helper\nunconditionally installs a fresh groups_alloc() result into\ncreds->cr_group_info without releasing whatever pointer was already\nthere:\n\n for (i = 0; i < count; i++) {\n ... decode name ...\n if (length == sizeof(CREDS_VALUE) &&\n memcmp(p, CREDS_VALUE, sizeof(CREDS_VALUE)) == 0) {\n err = gssx_dec_linux_creds(xdr, creds);\n ...\n }\n }\n\nA reply that carries two CREDS_VALUE entries therefore overwrites\ncr_group_info on the second iteration and orphans the group_info\nallocated by the first call. The earlier free_creds path only\nreleases the last cr_group_info via free_svc_cred(), so the first\nallocation's refcount stays at one and its kvmalloc-backed storage\nis leaked. No in-tree caller of gssp_accept_sec_context_upcall()\nexpects more than one CREDS_VALUE per reply.\n\nFix by tracking whether a CREDS_VALUE option has already been\ndecoded and returning -EINVAL on any subsequent match, so the\nfree_creds path releases the single group_info that was installed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06413 |
debian: CVE-2026-89539 was patched at 2026-09-16
2419.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89565) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipip: fix skb leak in collect_md mode when metadata_dst allocation fails In collect_md mode ipip_tunnel_rcv() returns 0 without freeing the skb when ip_tun_rx_dst() fails to allocate the metadata_dst. ipip_rcv() and mplsip_rcv() are registered as xfrm_tunnel handlers, so tunnel4_rcv() and tunnelmpls4_rcv() read the zero return as "the packet has been consumed" and do not free it either. The skb is leaked. The other tunnel drivers all dispose of the packet at this point: ip6_tunnel.c jumps to its drop label, ip_gre.c and ip6_gre.c return PACKET_REJECT, which makes gre_rcv() free the skb. Only ipip returns 0. Jump to the existing drop label instead. It frees the skb and still returns 0, so the packet keeps being reported as consumed, which is what we want here: the outer header has already been pulled, and neither the remaining handlers nor an ICMP unreachable have any use for it. Triggering this needs an ipip or mplsip tunnel in collect_md mode and an atomic allocation failure, which is why it has gone unnoticed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipip: fix skb leak in collect_md mode when metadata_dst allocation fails\n\nIn collect_md mode ipip_tunnel_rcv() returns 0 without freeing the skb\nwhen ip_tun_rx_dst() fails to allocate the metadata_dst. ipip_rcv() and\nmplsip_rcv() are registered as xfrm_tunnel handlers, so tunnel4_rcv()\nand tunnelmpls4_rcv() read the zero return as "the packet has been\nconsumed" and do not free it either. The skb is leaked.\n\nThe other tunnel drivers all dispose of the packet at this point:\nip6_tunnel.c jumps to its drop label, ip_gre.c and ip6_gre.c return\nPACKET_REJECT, which makes gre_rcv() free the skb. Only ipip returns 0.\n\nJump to the existing drop label instead. It frees the skb and still\nreturns 0, so the packet keeps being reported as consumed, which is what\nwe want here: the outer header has already been pulled, and neither the\nremaining handlers nor an ICMP unreachable have any use for it.\n\nTriggering this needs an ipip or mplsip tunnel in collect_md mode and an\natomic allocation failure, which is why it has gone unnoticed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06931 |
debian: CVE-2026-89565 was patched at 2026-09-16
2420.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89566) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: jbd2: check need_resched() when skipping busy checkpoint buffers journal_shrink_one_cp_list() skips busy checkpoint buffers when called with JBD2_SHRINK_BUSY_SKIP. The continue statement on this path also skips the need_resched() check at the end of the loop body. Consequently, when a checkpoint list contains mostly busy buffers, the shrinker can walk the entire list while holding journal->j_list_lock, even when a reschedule has been requested. Large checkpoint lists under memory pressure can therefore cause long lock hold times and leave other CPUs spinning on j_list_lock, resulting in soft lockups or RCU stalls. Route the busy-buffer path through the need_resched() check so that the shrinker can release j_list_lock and reschedule promptly, restoring parity with the clean-buffer path, which already checks need_resched(). This does not change which checkpoint buffers are eligible for removal.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\njbd2: check need_resched() when skipping busy checkpoint buffers\n\njournal_shrink_one_cp_list() skips busy checkpoint buffers when called\nwith JBD2_SHRINK_BUSY_SKIP. The continue statement on this path also\nskips the need_resched() check at the end of the loop body.\n\nConsequently, when a checkpoint list contains mostly busy buffers, the\nshrinker can walk the entire list while holding journal->j_list_lock,\neven when a reschedule has been requested. Large checkpoint lists under\nmemory pressure can therefore cause long lock hold times and leave other\nCPUs spinning on j_list_lock, resulting in soft lockups or RCU stalls.\n\nRoute the busy-buffer path through the need_resched() check so that the\nshrinker can release j_list_lock and reschedule promptly, restoring\nparity with the clean-buffer path, which already checks need_resched().\nThis does not change which checkpoint buffers are eligible for removal.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10045 |
debian: CVE-2026-89566 was patched at 2026-09-16
2421.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89567) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: jbd2: bound shrinker scans by examined checkpoint buffers The jbd2 shrinker currently accounts only checkpoint buffers that it successfully releases against nr_to_scan. Busy buffers therefore do not consume the scan budget. If a checkpoint transaction contains mostly busy buffers, the shrinker can scan its entire checkpoint list while holding journal->j_list_lock. Large checkpoint lists can result in excessive lock hold times and leave other CPUs spinning on j_list_lock, causing soft lockups or RCU stalls. Pass nr_to_scan into journal_shrink_one_cp_list() and decrement it for every buffer examined, including busy buffers. Pass NULL from checkpoint cleanup paths so their existing full-list behavior is preserved. This restores the scan-budget semantics that existed before journal_shrink_one_cp_list() was changed to always scan a complete checkpoint list.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\njbd2: bound shrinker scans by examined checkpoint buffers\n\nThe jbd2 shrinker currently accounts only checkpoint buffers that it\nsuccessfully releases against nr_to_scan. Busy buffers therefore do not\nconsume the scan budget.\n\nIf a checkpoint transaction contains mostly busy buffers, the shrinker\ncan scan its entire checkpoint list while holding journal->j_list_lock.\nLarge checkpoint lists can result in excessive lock hold times and leave\nother CPUs spinning on j_list_lock, causing soft lockups or RCU stalls.\n\nPass nr_to_scan into journal_shrink_one_cp_list() and decrement it for\nevery buffer examined, including busy buffers. Pass NULL from checkpoint\ncleanup paths so their existing full-list behavior is preserved.\n\nThis restores the scan-budget semantics that existed before\njournal_shrink_one_cp_list() was changed to always scan a complete\ncheckpoint list.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10045 |
debian: CVE-2026-89567 was patched at 2026-09-16
2422.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89572) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: cpufreq: apple-soc: Fix OPP table cleanup apple_soc_cpufreq_init() adds OPP tables from firmware, but some failure paths do not remove them. The driver also uses dev_pm_opp_remove_all_dynamic(), which is not the right cleanup helper for OPP tables loaded from firmware. Use the cpumask OPP helper after the policy CPU mask has been populated. Pair it with the matching cpumask remove helper on failure paths and in apple_soc_cpufreq_exit(). This also removes the separate dev_pm_opp_set_sharing_cpus() call, as the cpumask helper loads the DT OPP tables for all CPUs in the policy.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: apple-soc: Fix OPP table cleanup\n\napple_soc_cpufreq_init() adds OPP tables from firmware, but\nsome failure paths do not remove them. The driver also uses\ndev_pm_opp_remove_all_dynamic(), which is not the right cleanup\nhelper for OPP tables loaded from firmware.\n\nUse the cpumask OPP helper after the policy CPU mask has been\npopulated. Pair it with the matching cpumask remove helper on\nfailure paths and in apple_soc_cpufreq_exit(). This also removes\nthe separate dev_pm_opp_set_sharing_cpus() call, as the cpumask\nhelper loads the DT OPP tables for all CPUs in the policy.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06217 |
debian: CVE-2026-89572 was patched at 2026-09-16
2423.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89576) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: dm-era: fix shadowed superblock leak on take-snap failure metadata_take_snap() bumps the live superblock refcount and then dm_tm_shadow_block() allocates a new block for the metadata snapshot. If the subsequent dm_sm_inc_block() of writeset_tree_root or era_array_root fails, the function only unlocks the clone and returns. The newly allocated shadow block is never returned to the metadata space map, so each failed take-snap permanently leaks one metadata block. Free the clone with dm_sm_dec_block() on those error paths, matching the final step of metadata_drop_snap().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndm-era: fix shadowed superblock leak on take-snap failure\n\nmetadata_take_snap() bumps the live superblock refcount and then\ndm_tm_shadow_block() allocates a new block for the metadata snapshot.\nIf the subsequent dm_sm_inc_block() of writeset_tree_root or\nera_array_root fails, the function only unlocks the clone and\nreturns. The newly allocated shadow block is never returned to the\nmetadata space map, so each failed take-snap permanently leaks one\nmetadata block.\n\nFree the clone with dm_sm_dec_block() on those error paths, matching\nthe final step of metadata_drop_snap().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11445 |
debian: CVE-2026-89576 was patched at 2026-09-16
2424.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89582) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: bnx2x: fix double free in bnx2x_init_firmware() error path bnx2x_init_firmware() frees bp->init_ops, bp->init_data and bp->init_ops_offsets in its error path without setting them to NULL. The cleanup function bnx2x_release_firmware() frees the same three pointers unconditionally, so if init_firmware fails and release_firmware is later called (e.g. from __bnx2x_remove or through the function state machine), all three are freed a second time. Set each pointer to NULL after kfree() in the error path so that the subsequent kfree(NULL) in bnx2x_release_firmware() is a safe no-op.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbnx2x: fix double free in bnx2x_init_firmware() error path\n\nbnx2x_init_firmware() frees bp->init_ops, bp->init_data and\nbp->init_ops_offsets in its error path without setting them to NULL.\nThe cleanup function bnx2x_release_firmware() frees the same three\npointers unconditionally, so if init_firmware fails and\nrelease_firmware is later called (e.g. from __bnx2x_remove or through\nthe function state machine), all three are freed a second time.\n\nSet each pointer to NULL after kfree() in the error path so that the\nsubsequent kfree(NULL) in bnx2x_release_firmware() is a safe no-op.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07433 |
debian: CVE-2026-89582 was patched at 2026-09-16
2425.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89589) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks The CXL CPER work registration and unregistration helpers acquire cxl_cper_work_lock and cxl_cper_prot_err_work_lock with a spinlock guard(), which leaves local interrupts enabled. The corresponding post paths (cxl_cper_post_event(), cxl_cper_post_prot_err()) execute in hard IRQ context (they are called from the GHES error notification path) and acquire the same locks with an irqsave guard(). If a CPU is holding one of these locks via a spinlock guard() when a GHES interrupt arrives on the same CPU, the IRQ handler spins on the held lock waiting for it to release, while the lock holder is preempted by the IRQ. The result is a deadlock. Convert both locks from spinlock_t to raw_spinlock_t and use guard() at all call sites. On PREEMPT_RT kernels spinlock_t is backed by rt_mutex and sleeping from hard IRQ context is not permitted; raw_spinlock_t is safe in both contexts. Add WARN_ONCE to both register functions to surface double-registration bugs at runtime. Restructure both unregister functions to clear the global work pointer under the lock before calling cancel_work_sync(), closing the window where a CPER interrupt could schedule work on a pointer about to be freed. Add kfifo_reset() after cancel_work_sync() so stale entries are not replayed on next module load. Both kfifos are single-consumer: only one work_struct is registered at a time, enforced by the WARN_ONCE guard in the register functions. kfifo_reset() is safe outside the lock because cancel_work_sync() has already quiesced the consumer, and no new consumer can register until the current module exit completes and a fresh module init runs. Remove the redundant cancel_work_sync() call from cxl_ras_exit() and cxl_pci_driver_exit(). The CPER unregister functions now quiesce the work internally.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nacpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks\n\nThe CXL CPER work registration and unregistration helpers acquire\ncxl_cper_work_lock and cxl_cper_prot_err_work_lock with a spinlock\nguard(), which leaves local interrupts enabled. The corresponding post\npaths (cxl_cper_post_event(), cxl_cper_post_prot_err()) execute in hard\nIRQ context (they are called from the GHES error notification path) and\nacquire the same locks with an irqsave guard().\n\nIf a CPU is holding one of these locks via a spinlock guard() when a GHES\ninterrupt arrives on the same CPU, the IRQ handler spins on the held lock\nwaiting for it to release, while the lock holder is preempted by the IRQ.\nThe result is a deadlock.\n\nConvert both locks from spinlock_t to raw_spinlock_t and use guard() at\nall call sites. On PREEMPT_RT kernels spinlock_t is backed by rt_mutex and\nsleeping from hard IRQ context is not permitted; raw_spinlock_t is safe in\nboth contexts.\n\nAdd WARN_ONCE to both register functions to surface double-registration\nbugs at runtime.\n\nRestructure both unregister functions to clear the global work pointer\nunder the lock before calling cancel_work_sync(), closing the window\nwhere a CPER interrupt could schedule work on a pointer about to be\nfreed. Add kfifo_reset() after cancel_work_sync() so stale entries\nare not replayed on next module load.\n\nBoth kfifos are single-consumer: only one work_struct is registered at\na time, enforced by the WARN_ONCE guard in the register functions.\nkfifo_reset() is safe outside the lock because cancel_work_sync() has\nalready quiesced the consumer, and no new consumer can register until\nthe current module exit completes and a fresh module init runs.\n\nRemove the redundant cancel_work_sync() call from cxl_ras_exit() and\ncxl_pci_driver_exit(). The CPER unregister functions now quiesce\nthe work internally.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.07027 |
debian: CVE-2026-89589 was patched at 2026-09-16
2426.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89595) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fsnotify: Fix stale object mask after concurrent mark updates When a mark gets a new event bit, fanotify and inotify may avoid recalculating the object mask if the cached aggregate already contains that bit. This is racy with a recalculation triggered by a concurrent update to another mark on the same connector. The concurrent scan can read the mark before the new bit is added, while the updater reads the old aggregate before that scan publishes its result. The updater then skips recalculation and the scan publishes a mask without the bit, leaving the object mask stale after both updates complete. This can be reproduced with two fanotify groups watching the same inode: one thread removes FAN_MODIFY from one existing mark while another thread adds FAN_MODIFY to the other mark. After both fanotify_mark() calls return, writes can fail to produce FAN_MODIFY for the group whose mark now contains the bit. This was reproduced on an unmodified v6.12.95 kernel. The equivalent inotify interleaving loses IN_MODIFY events. For normal fanotify additions, recalculate whenever the raw mark mask changes. The normal mask is not cleared asynchronously, so an unchanged addition cannot introduce missing interest. Always recalculate ignore-mask updates because FS_MODIFY handling may clear the ignore mask without taking mark->lock, making snapshot comparisons unreliable. Always recalculate after updating an existing inotify watch. Its replace path temporarily sets mark->mask to zero, so a concurrent scan can observe zero even when the old and final masks are equal. Assigning the replacement mask directly would avoid the transient zero, but existing-watch updates are infrequent, so unconditional recalculation is simpler.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfsnotify: Fix stale object mask after concurrent mark updates\n\nWhen a mark gets a new event bit, fanotify and inotify may avoid\nrecalculating the object mask if the cached aggregate already contains that\nbit. This is racy with a recalculation triggered by a concurrent update to\nanother mark on the same connector.\n\nThe concurrent scan can read the mark before the new bit is added, while\nthe updater reads the old aggregate before that scan publishes its result.\nThe updater then skips recalculation and the scan publishes a mask without\nthe bit, leaving the object mask stale after both updates complete.\n\nThis can be reproduced with two fanotify groups watching the same inode:\none thread removes FAN_MODIFY from one existing mark while another thread\nadds FAN_MODIFY to the other mark. After both fanotify_mark() calls return,\nwrites can fail to produce FAN_MODIFY for the group whose mark now contains\nthe bit. This was reproduced on an unmodified v6.12.95 kernel. The\nequivalent inotify interleaving loses IN_MODIFY events.\n\nFor normal fanotify additions, recalculate whenever the raw mark mask\nchanges. The normal mask is not cleared asynchronously, so an unchanged\naddition cannot introduce missing interest. Always recalculate ignore-mask\nupdates because FS_MODIFY handling may clear the ignore mask without taking\nmark->lock, making snapshot comparisons unreliable.\n\nAlways recalculate after updating an existing inotify watch. Its replace\npath temporarily sets mark->mask to zero, so a concurrent scan can observe\nzero even when the old and final masks are equal. Assigning the replacement\nmask directly would avoid the transient zero, but existing-watch updates\nare infrequent, so unconditional recalculation is simpler.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11446 |
debian: CVE-2026-89595 was patched at 2026-09-16
2427.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89598) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fbdev: ssd1307fb: defer I2C transfers from damage callbacks The fbdev damage callbacks may run from fbcon while printk has disabled preemption. They currently update the display synchronously, which enters the sleeping I2C transfer path from atomic context. A complete report from an RK3566 system follows: [ 258.129004] watchdog: watchdog0: watchdog did not stop! [ 258.129067] BUG: scheduling while atomic: systemd/1/0x00000003 [ 258.129076] Modules linked in: algif_hash algif_skcipher af_alg bnep binfmt_misc lz4hc lz4 zram snd_soc_hdmi_codec brcmfmac_wcc hci_uart fb_ssd1306(C) fbtft(C) btqca btrtl btintel btsdio snd_soc_simple_card motorcomm pwm_fan snd_soc_simple_card_utils ssd130x_spi nls_iso8859_1 ssd130x btbcm drm_shmem_helper display_connector brcmfmac ssd1307fb brcmutil bluetooth cfg80211 rfkill snd_soc_rockchip_i2s_tdm snd_soc_rk817 hantro_vpu snd_soc_core snd_compress snd_pcm_dmaengine v4l2_vp9 snd_pcm v4l2_h264 rockchip_rga snd_timer rk_crypto2 spi_rockchip_sfc videobuf2_dma_contig snd sm3_generic v4l2_mem2mem videobuf2_dma_sg dwmac_rk sm3 soundcore videobuf2_memops videobuf2_v4l2 stmmac_platform dw_hdmi_cec videodev videobuf2_common dw_hdmi_i2s_audio stmmac rk817_charger pcs_xpcs mc cpufreq_dt sch_fq_codel ip_tables x_tables autofs4 [ 258.129215] Preemption disabled at: [ 258.129216] [<ffff80008012f96c>] vprintk_emit+0x11c/0x340 [ 258.129234] CPU: 0 PID: 1 Comm: systemd Tainted: G C 6.6.0-rc5-rockchip-rk356x #4 [ 258.129239] Hardware name: Rockchip RK3566 OPi 3B (DT) [ 258.129243] Call trace: [ 258.129245] dump_backtrace+0xa0/0x128 [ 258.129252] show_stack+0x20/0x38 [ 258.129256] dump_stack_lvl+0x60/0xb0 [ 258.129265] dump_stack+0x18/0x28 [ 258.129269] __schedule_bug+0xa0/0xc8 [ 258.129274] __schedule+0x9ac/0xd30 [ 258.129279] schedule+0x60/0x100 [ 258.129282] schedule_timeout+0x194/0x338 [ 258.129289] rk3x_i2c_xfer_common.isra.0+0x384/0x498 [ 258.129296] rk3x_i2c_xfer+0x20/0x60 [ 258.129300] __i2c_transfer+0x194/0x648 [ 258.129308] i2c_transfer+0x9c/0x130 [ 258.129313] i2c_transfer_buffer_flags+0x64/0x98 [ 258.129318] ssd1307fb_update_rect+0x42c/0x560 [ssd1307fb] [ 258.129334] ssd1307fb_defio_imageblit+0x34/0x50 [ssd1307fb] [ 258.129343] soft_cursor+0x13c/0x210 [ 258.129350] bit_cursor+0x2dc/0x550 [ 258.129354] fbcon_cursor+0xec/0x108 [ 258.129359] hide_cursor+0x44/0xc8 [ 258.129365] vt_console_print+0x398/0x3b0 [ 258.129370] console_flush_all.isra.0+0x17c/0x410 [ 258.129377] console_unlock+0x4c/0x100 [ 258.129382] vprintk_emit+0x1c8/0x340 [ 258.129386] vprintk_default+0x40/0x58 [ 258.129389] vprintk+0xb8/0xd0 [ 258.129392] _printk+0x68/0x98 [ 258.129398] watchdog_release+0x170/0x230 [ 258.129404] __fput+0xbc/0x288 [ 258.129409] __fput_sync+0x58/0x70 [ 258.129413] __arm64_sys_close+0x40/0x90 [ 258.129419] invoke_syscall+0x4c/0x118 [ 258.129426] el0_svc_common.constprop.0+0x48/0xf0 [ 258.129432] do_el0_svc+0x24/0x38 [ 258.129437] el0_svc+0x48/0x100 [ 258.129443] el0t_64_sync_handler+0xc0/0xc8 [ 258.129448] el0t_64_sync+0x190/0x198 [ 258.573087] ------------[ cut here ]------------ [ 258.573098] DEBUG_LOCKS_WARN_ON(val > preempt_count()) [ 258.573111] WARNING: CPU: 0 PID: 1 at kernel/sched/core.c:5871 preempt_count_sub+0x9c/0x148 [ 258.573130] Modules linked in: algif_hash algif_skcipher af_alg bnep binfmt_misc lz4hc lz4 zram snd_soc_hdmi_codec brcmfmac_wcc hci_uart fb_ssd1306(C) fbtft(C) btqca btrtl btintel btsdio snd_soc_simple_card motorcomm pwm_fan snd_soc_simple_card_utils ssd130x_spi nls_iso8859_1 ssd130x btbcm drm_shmem_helper display_connector brcmfmac ssd1307fb brcmutil bluetooth cfg80211 rfkill snd_soc_rockchip_i2s_tdm snd_soc_rk817 hantro_vpu snd_soc_core snd_compress snd_pcm_dmaengine v4l2_vp ---truncated---', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: ssd1307fb: defer I2C transfers from damage callbacks\n\nThe fbdev damage callbacks may run from fbcon while printk has disabled\npreemption. They currently update the display synchronously, which enters\nthe sleeping I2C transfer path from atomic context.\n\nA complete report from an RK3566 system follows:\n\n [ 258.129004] watchdog: watchdog0: watchdog did not stop!\n [ 258.129067] BUG: scheduling while atomic: systemd/1/0x00000003\n [ 258.129076] Modules linked in: algif_hash algif_skcipher af_alg bnep\n binfmt_misc lz4hc lz4 zram snd_soc_hdmi_codec brcmfmac_wcc hci_uart\n fb_ssd1306(C) fbtft(C) btqca btrtl btintel btsdio snd_soc_simple_card\n motorcomm pwm_fan snd_soc_simple_card_utils ssd130x_spi nls_iso8859_1\n ssd130x btbcm drm_shmem_helper display_connector brcmfmac ssd1307fb\n brcmutil bluetooth cfg80211 rfkill snd_soc_rockchip_i2s_tdm\n snd_soc_rk817 hantro_vpu snd_soc_core snd_compress snd_pcm_dmaengine\n v4l2_vp9 snd_pcm v4l2_h264 rockchip_rga snd_timer rk_crypto2\n spi_rockchip_sfc videobuf2_dma_contig snd sm3_generic v4l2_mem2mem\n videobuf2_dma_sg dwmac_rk sm3 soundcore videobuf2_memops videobuf2_v4l2\n stmmac_platform dw_hdmi_cec videodev videobuf2_common dw_hdmi_i2s_audio\n stmmac rk817_charger pcs_xpcs mc cpufreq_dt sch_fq_codel ip_tables\n x_tables autofs4\n [ 258.129215] Preemption disabled at:\n [ 258.129216] [<ffff80008012f96c>] vprintk_emit+0x11c/0x340\n [ 258.129234] CPU: 0 PID: 1 Comm: systemd Tainted: G C\n 6.6.0-rc5-rockchip-rk356x #4\n [ 258.129239] Hardware name: Rockchip RK3566 OPi 3B (DT)\n [ 258.129243] Call trace:\n [ 258.129245] dump_backtrace+0xa0/0x128\n [ 258.129252] show_stack+0x20/0x38\n [ 258.129256] dump_stack_lvl+0x60/0xb0\n [ 258.129265] dump_stack+0x18/0x28\n [ 258.129269] __schedule_bug+0xa0/0xc8\n [ 258.129274] __schedule+0x9ac/0xd30\n [ 258.129279] schedule+0x60/0x100\n [ 258.129282] schedule_timeout+0x194/0x338\n [ 258.129289] rk3x_i2c_xfer_common.isra.0+0x384/0x498\n [ 258.129296] rk3x_i2c_xfer+0x20/0x60\n [ 258.129300] __i2c_transfer+0x194/0x648\n [ 258.129308] i2c_transfer+0x9c/0x130\n [ 258.129313] i2c_transfer_buffer_flags+0x64/0x98\n [ 258.129318] ssd1307fb_update_rect+0x42c/0x560 [ssd1307fb]\n [ 258.129334] ssd1307fb_defio_imageblit+0x34/0x50 [ssd1307fb]\n [ 258.129343] soft_cursor+0x13c/0x210\n [ 258.129350] bit_cursor+0x2dc/0x550\n [ 258.129354] fbcon_cursor+0xec/0x108\n [ 258.129359] hide_cursor+0x44/0xc8\n [ 258.129365] vt_console_print+0x398/0x3b0\n [ 258.129370] console_flush_all.isra.0+0x17c/0x410\n [ 258.129377] console_unlock+0x4c/0x100\n [ 258.129382] vprintk_emit+0x1c8/0x340\n [ 258.129386] vprintk_default+0x40/0x58\n [ 258.129389] vprintk+0xb8/0xd0\n [ 258.129392] _printk+0x68/0x98\n [ 258.129398] watchdog_release+0x170/0x230\n [ 258.129404] __fput+0xbc/0x288\n [ 258.129409] __fput_sync+0x58/0x70\n [ 258.129413] __arm64_sys_close+0x40/0x90\n [ 258.129419] invoke_syscall+0x4c/0x118\n [ 258.129426] el0_svc_common.constprop.0+0x48/0xf0\n [ 258.129432] do_el0_svc+0x24/0x38\n [ 258.129437] el0_svc+0x48/0x100\n [ 258.129443] el0t_64_sync_handler+0xc0/0xc8\n [ 258.129448] el0t_64_sync+0x190/0x198\n [ 258.573087] ------------[ cut here ]------------\n [ 258.573098] DEBUG_LOCKS_WARN_ON(val > preempt_count())\n [ 258.573111] WARNING: CPU: 0 PID: 1 at kernel/sched/core.c:5871\n preempt_count_sub+0x9c/0x148\n [ 258.573130] Modules linked in: algif_hash algif_skcipher af_alg bnep\n binfmt_misc lz4hc lz4 zram snd_soc_hdmi_codec brcmfmac_wcc hci_uart\n fb_ssd1306(C) fbtft(C) btqca btrtl btintel btsdio snd_soc_simple_card\n motorcomm pwm_fan snd_soc_simple_card_utils ssd130x_spi nls_iso8859_1\n ssd130x btbcm drm_shmem_helper display_connector brcmfmac ssd1307fb\n brcmutil bluetooth cfg80211 rfkill snd_soc_rockchip_i2s_tdm\n snd_soc_rk817 hantro_vpu snd_soc_core snd_compress snd_pcm_dmaengine\n v4l2_vp\n---truncated---', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06416 |
debian: CVE-2026-89598 was patched at 2026-09-16
2428.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89604) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: efivarfs: Rate limit statfs() handler Ravi reports that statfs() may be called by unprivileged users on the efivarfs mount point, which may result in a flood of calls to the QueryVariableInfo() runtime service. These calls are disproportionately costly on x86 systems where the variable store is backed by SMM, as each SMM entry requires a rendez-vous of all the CPUs. So rate limit the calls to QueryVariableInfo() at twice per second, and return the most recently obtained value for calls that are elided.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nefivarfs: Rate limit statfs() handler\n\nRavi reports that statfs() may be called by unprivileged users on the\nefivarfs mount point, which may result in a flood of calls to the\nQueryVariableInfo() runtime service. These calls are disproportionately\ncostly on x86 systems where the variable store is backed by SMM, as each\nSMM entry requires a rendez-vous of all the CPUs.\n\nSo rate limit the calls to QueryVariableInfo() at twice per second, and\nreturn the most recently obtained value for calls that are elided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10807 |
debian: CVE-2026-89604 was patched at 2026-09-16
2429.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89618) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: eventfs: Initialize ei->children and ei->list in init_ei() eventfs_create_dir() allocates the eventfs_inode and initializes it with init_ei(). But this does not initialize the eventfs_inode list_heads. If the eventfs_create_dir() fails due to memory pressure, it will call free_ei() before it initialized the lists, and that checks to make sure the eventfs_inode has no children. But because the list wasn't initialized, it will give a false warning. Fix it by moving the list initialization into init_ei(). [ Rewrote change log ]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\neventfs: Initialize ei->children and ei->list in init_ei()\n\neventfs_create_dir() allocates the eventfs_inode and initializes it with\ninit_ei(). But this does not initialize the eventfs_inode list_heads. If\nthe eventfs_create_dir() fails due to memory pressure, it will call\nfree_ei() before it initialized the lists, and that checks to make sure\nthe eventfs_inode has no children. But because the list wasn't\ninitialized, it will give a false warning.\n\nFix it by moving the list initialization into init_ei().\n\n[ Rewrote change log ]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00175, EPSS Percentile is 0.0728 |
debian: CVE-2026-89618 was patched at 2026-09-16
2430.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89621) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: HID: mcp2221: validate report size in mcp2221_raw_event() mcp2221_raw_event() never validates the size of incoming HID reports. In the MCP2221_I2C_GET_DATA path it trusts the device-supplied data[3] as the copy length without checking that 4 + data[3] bytes actually exist in the received report. A malicious or misbehaving USB device can send a short report with a large data[3], causing the memcpy to read past the valid report data in the HID transfer buffer and leak uninitialized kernel memory back to userspace through the I2C/SMBus read path. Add a minimum size check at entry and validate that the source range fits within the received report before the copy.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nHID: mcp2221: validate report size in mcp2221_raw_event()\n\nmcp2221_raw_event() never validates the size of incoming HID reports.\nIn the MCP2221_I2C_GET_DATA path it trusts the device-supplied data[3]\nas the copy length without checking that 4 + data[3] bytes actually\nexist in the received report. A malicious or misbehaving USB device can\nsend a short report with a large data[3], causing the memcpy to read\npast the valid report data in the HID transfer buffer and leak\nuninitialized kernel memory back to userspace through the I2C/SMBus\nread path.\n\nAdd a minimum size check at entry and validate that the source range\nfits within the received report before the copy.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0022, EPSS Percentile is 0.12597 |
debian: CVE-2026-89621 was patched at 2026-09-16
2431.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89627) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: HID: roccat: free buffered reports when destroying device roccat_report_event() duplicates each report with kmemdup() and stores the allocation in a circular-buffer slot. The allocation is released only when that slot is reused. The device destruction paths free struct roccat_device without releasing reports still stored in cbuf[]. This makes those allocations unreachable and leaks up to ROCCAT_CBUF_SIZE report buffers per device. Add a small destructor that frees every buffered report before freeing the device, and use it in both paths that can destroy a registered device.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nHID: roccat: free buffered reports when destroying device\n\nroccat_report_event() duplicates each report with kmemdup() and stores\nthe allocation in a circular-buffer slot. The allocation is released only\nwhen that slot is reused.\n\nThe device destruction paths free struct roccat_device without releasing\nreports still stored in cbuf[]. This makes those allocations unreachable\nand leaks up to ROCCAT_CBUF_SIZE report buffers per device.\n\nAdd a small destructor that frees every buffered report before freeing the\ndevice, and use it in both paths that can destroy a registered device.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11449 |
debian: CVE-2026-89627 was patched at 2026-09-16
2432.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89628) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: HID: picolcd: clamp eeprom debugfs read to bytes actually received picolcd_debug_eeprom_read() trusts resp->raw_data[2] -- a length byte supplied by the device in its REPORT_EE_DATA reply -- clamped only to the caller's read() count: \tret = resp->raw_data[2]; \tif (ret > s) \t\tret = s; \tif (copy_to_user(u, resp->raw_data+3, ret)) It never checks resp->raw_size, the number of bytes picolcd_raw_event() actually copied into the 64-byte raw_data[] of the kmalloc'd struct picolcd_pending. A device (or a spoofed picoLCD) returning a length byte of 0xff, read with a count >= 255, makes copy_to_user() read past raw_data[] into adjacent slab memory and return it to userspace through the debugfs "eeprom" file: \tBUG: KASAN: slab-out-of-bounds in _copy_to_user \tRead of size 255 ... picolcd_debug_eeprom_read+0x214/0x2f0 [hid_picolcd] The debug-dump path in the same file already validates the device length byte against the received size before trusting it; this read does not. The file is created S_IRUSR (root-only) and a crafted device is needed, so it is neither unprivileged- nor remotely-triggerable. Clamp the copy length to resp->raw_size - 3 (the payload actually received, minus the 3-byte header), floored at 0 for short replies.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nHID: picolcd: clamp eeprom debugfs read to bytes actually received\n\npicolcd_debug_eeprom_read() trusts resp->raw_data[2] -- a length byte\nsupplied by the device in its REPORT_EE_DATA reply -- clamped only to\nthe caller's read() count:\n\n\tret = resp->raw_data[2];\n\tif (ret > s)\n\t\tret = s;\n\tif (copy_to_user(u, resp->raw_data+3, ret))\n\nIt never checks resp->raw_size, the number of bytes picolcd_raw_event()\nactually copied into the 64-byte raw_data[] of the kmalloc'd struct\npicolcd_pending. A device (or a spoofed picoLCD) returning a length byte\nof 0xff, read with a count >= 255, makes copy_to_user() read past\nraw_data[] into adjacent slab memory and return it to userspace through\nthe debugfs "eeprom" file:\n\n\tBUG: KASAN: slab-out-of-bounds in _copy_to_user\n\tRead of size 255 ... picolcd_debug_eeprom_read+0x214/0x2f0 [hid_picolcd]\n\nThe debug-dump path in the same file already validates the device length\nbyte against the received size before trusting it; this read does not.\nThe file is created S_IRUSR (root-only) and a crafted device is needed,\nso it is neither unprivileged- nor remotely-triggerable.\n\nClamp the copy length to resp->raw_size - 3 (the payload actually\nreceived, minus the 3-byte header), floored at 0 for short replies.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0022, EPSS Percentile is 0.12596 |
debian: CVE-2026-89628 was patched at 2026-09-16
2433.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89642) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: cifs: call pagecache_isize_extended() in cifs_setsize() when extending cifs_setsize() calls truncate_pagecache() but skips pagecache_isize_extended() on extension. truncate_setsize() shows the correct pattern: i_size_write(inode, newsize); if (newsize > oldsize) pagecache_isize_extended(inode, oldsize, newsize); truncate_pagecache(inode, newsize); pagecache_isize_extended() zeroes the tail of the page straddling old EOF. Without it, dirty bytes in that region can be written back to the server, exposing stale data in the newly extended range.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: call pagecache_isize_extended() in cifs_setsize() when extending\n\ncifs_setsize() calls truncate_pagecache() but skips\npagecache_isize_extended() on extension. truncate_setsize() shows\nthe correct pattern:\n\n i_size_write(inode, newsize);\n if (newsize > oldsize)\n pagecache_isize_extended(inode, oldsize, newsize);\n truncate_pagecache(inode, newsize);\n\npagecache_isize_extended() zeroes the tail of the page straddling old\nEOF. Without it, dirty bytes in that region can be written back to\nthe server, exposing stale data in the newly extended range.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.05055 |
debian: CVE-2026-89642 was patched at 2026-09-16
2434.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89644) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: btrfs: fix extent map leak in NOCOW direct I/O write btrfs_dio_iomap_begin() calls btrfs_get_extent(), which returns an extent map reference that must be dropped on all exit paths. For direct writes into a NOCOW range, btrfs_get_blocks_direct_write() keeps using that extent map and asks btrfs_create_dio_extent() to allocate the ordered extent. If that fails, for example because btrfs_alloc_ordered_extent() fails, the function returns the error without dropping the input extent map. The PREALLOC path avoided this by dropping the input extent map before replacing it with the newly created one. Check the error from btrfs_create_dio_extent() before replacing the map and drop the input extent map on failure.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix extent map leak in NOCOW direct I/O write\n\nbtrfs_dio_iomap_begin() calls btrfs_get_extent(), which returns an\nextent map reference that must be dropped on all exit paths.\n\nFor direct writes into a NOCOW range, btrfs_get_blocks_direct_write()\nkeeps using that extent map and asks btrfs_create_dio_extent() to\nallocate the ordered extent. If that fails, for example because\nbtrfs_alloc_ordered_extent() fails, the function returns the error\nwithout dropping the input extent map. The PREALLOC path avoided this by\ndropping the input extent map before replacing it with the newly created\none.\n\nCheck the error from btrfs_create_dio_extent() before replacing the\nmap and drop the input extent map on failure.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06217 |
debian: CVE-2026-89644 was patched at 2026-09-16
2435.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89645) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: btrfs: drop recovered reloc root refs on recovery failure During relocation recovery, each fs root gets a reference to its relocation root. If loading or adding a later root fails, or if the first transaction commit fails, btrfs_recover_relocation() jumps to out_unset before merge_reloc_roots() and clean_dirty_subvols(). put_reloc_control() drops the list-owned relocation root references, but it does not clear fs_root->reloc_root or drop the references owned by those pointers. Mount cleanup only drops them when BTRFS_FS_ERROR is set, so an error such as -ENOMEM while processing a later root can leave references behind. Keep temporary references to the fs roots associated during recovery. On failure, clear their reloc_root pointers and drop the corresponding references. Once the first transaction commit succeeds, drop only the temporary fs root references and let the normal merge and cleanup paths handle the relocation roots. Fault injection on a pending-relocation image confirmed the cleanup gap. With an injected first-commit failure, 25 fs roots had reloc_root set with fs_error=0. With this fix, the same failure path drops that count to 0 before mount fails.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: drop recovered reloc root refs on recovery failure\n\nDuring relocation recovery, each fs root gets a reference to its relocation\nroot. If loading or adding a later root fails, or if the first transaction\ncommit fails, btrfs_recover_relocation() jumps to out_unset before\nmerge_reloc_roots() and clean_dirty_subvols().\n\nput_reloc_control() drops the list-owned relocation root references, but it\ndoes not clear fs_root->reloc_root or drop the references owned by those\npointers. Mount cleanup only drops them when BTRFS_FS_ERROR is set, so an\nerror such as -ENOMEM while processing a later root can leave references\nbehind.\n\nKeep temporary references to the fs roots associated during recovery. On\nfailure, clear their reloc_root pointers and drop the corresponding\nreferences. Once the first transaction commit succeeds, drop only the\ntemporary fs root references and let the normal merge and cleanup paths\nhandle the relocation roots.\n\nFault injection on a pending-relocation image confirmed the cleanup gap.\nWith an injected first-commit failure, 25 fs roots had reloc_root set with\nfs_error=0. With this fix, the same failure path drops that count to 0\nbefore mount fails.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00225, EPSS Percentile is 0.1324 |
debian: CVE-2026-89645 was patched at 2026-09-16
2436.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89666) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops A client can send an NFSv3 SETATTR, CREATE, MKDIR, SYMLINK or MKNOD carrying an atime or mtime whose nseconds field is out of range. The value is well-formed on the wire and decodes cleanly into a valid uint32, but it is not a valid timespec64: tv_nsec must be less than NSEC_PER_SEC. Nothing in the setattr path clamps it. notify_change() runs the time through timestamp_truncate(), which does not reduce tv_nsec below NSEC_PER_SEC when the filesystem supports nanosecond granularity (s_time_gran == 1), and the inode atime/mtime setters store it verbatim (only ctime is normalized, via inode_set_ctime_to_ts()). The un-normalized value then corrupts on-disk metadata: ext4's ext4_encode_extra_time() shifts tv_nsec left by EXT4_EPOCH_BITS, which overflows the 32-bit extra field and clobbers the seconds-epoch bits, so the stored seconds (and thus the year) are wrong on read-back. XFS with bigtime mis-stores the timestamp for the same reason. Validate the client-supplied atime/mtime in the proc handlers and return NFS3ERR_INVAL before anything is changed. RFC 1813 lists NFS3ERR_INVAL for SETATTR and describes it as the error for a value the server 'can not store ... in its own representation'; the client maps it to EINVAL. Checking in the proc handlers, rather than in nfsd_setattr(), keeps the rejection in front of object creation. The create operations create the object before nfsd_create_setattr() runs, so a late failure would leave the new object behind and turn a non-idempotent request into a namespace change that reports failure. The check is therefore done up front, for the create operations before the object is created. tv_nsec is a long, so the comparison casts it to unsigned long (the same width) rather than to u32, matching timespec64_valid(). A u32 cast would truncate on 64-bit; the unsigned long cast also rejects a value that became negative when an out-of-range u32 wire nseconds was assigned to a 32-bit long. Only client-supplied times are checked: SET_TO_SERVER_TIME requests carry no client value. The sattrguard3 ctime is deliberately left alone: an out-of-range guard simply never matches the object's ctime and yields NFS3ERR_NOT_SYNC via the existing guardtime comparison, which is the protocol-correct outcome rather than rejecting the request.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops\n\nA client can send an NFSv3 SETATTR, CREATE, MKDIR, SYMLINK or MKNOD\ncarrying an atime or mtime whose nseconds field is out of range. The\nvalue is well-formed on the wire and decodes cleanly into a valid\nuint32, but it is not a valid timespec64: tv_nsec must be less than\nNSEC_PER_SEC.\n\nNothing in the setattr path clamps it. notify_change() runs the time\nthrough timestamp_truncate(), which does not reduce tv_nsec below\nNSEC_PER_SEC when the filesystem supports nanosecond granularity\n(s_time_gran == 1), and the inode atime/mtime setters store it verbatim\n(only ctime is normalized, via inode_set_ctime_to_ts()). The\nun-normalized value then corrupts on-disk metadata: ext4's\next4_encode_extra_time() shifts tv_nsec left by EXT4_EPOCH_BITS, which\noverflows the 32-bit extra field and clobbers the seconds-epoch bits, so\nthe stored seconds (and thus the year) are wrong on read-back. XFS with\nbigtime mis-stores the timestamp for the same reason.\n\nValidate the client-supplied atime/mtime in the proc handlers and return\nNFS3ERR_INVAL before anything is changed. RFC 1813 lists NFS3ERR_INVAL\nfor SETATTR and describes it as the error for a value the server 'can\nnot store ... in its own representation'; the client maps it to EINVAL.\n\nChecking in the proc handlers, rather than in nfsd_setattr(), keeps the\nrejection in front of object creation. The create operations create the\nobject before nfsd_create_setattr() runs, so a late failure would leave\nthe new object behind and turn a non-idempotent request into a namespace\nchange that reports failure. The check is therefore done up front, for\nthe create operations before the object is created.\n\ntv_nsec is a long, so the comparison casts it to unsigned long (the same\nwidth) rather than to u32, matching timespec64_valid(). A u32 cast would\ntruncate on 64-bit; the unsigned long cast also rejects a value that\nbecame negative when an out-of-range u32 wire nseconds was assigned to a\n32-bit long.\n\nOnly client-supplied times are checked: SET_TO_SERVER_TIME requests\ncarry no client value. The sattrguard3 ctime is deliberately left alone:\nan out-of-range guard simply never matches the object's ctime and yields\nNFS3ERR_NOT_SYNC via the existing guardtime comparison, which is the\nprotocol-correct outcome rather than rejecting the request.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06419 |
debian: CVE-2026-89666 was patched at 2026-09-16
2437.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89683) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: fix dentry ref leak on V4ROOT export filehandle lookup nfsd_set_fh_dentry() leaks the dentry reference from exportfs_decode_fh_raw() when the NFS3_FHSIZE or NFS_FHSIZE switch cases detect NFSEXP_V4ROOT and goto out. The out: label calls exp_put() but never dput(dentry), and fhp->fh_dentry was never assigned so fh_put() cannot compensate. A crafted NFSv3 filehandle targeting a V4ROOT export's fsid triggers the leak on every request.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix dentry ref leak on V4ROOT export filehandle lookup\n\nnfsd_set_fh_dentry() leaks the dentry reference from\nexportfs_decode_fh_raw() when the NFS3_FHSIZE or NFS_FHSIZE\nswitch cases detect NFSEXP_V4ROOT and goto out. The out: label\ncalls exp_put() but never dput(dentry), and fhp->fh_dentry was\nnever assigned so fh_put() cannot compensate.\n\nA crafted NFSv3 filehandle targeting a V4ROOT export's fsid\ntriggers the leak on every request.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00175, EPSS Percentile is 0.07281 |
debian: CVE-2026-89683 was patched at 2026-09-16
2438.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89693) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create() nfsd4_create() stores the return value of nfsd4_acl_to_attr() in status, but the switch(create->cr_type) block unconditionally overwrites it in every branch. ACL translation errors are silently discarded, and the CREATE proceeds without the requested ACL. Add an early exit check after nfsd4_acl_to_attr(), matching the pattern already used in nfsd4_setattr(). [ cel: prefer NFS4ERR_BADTYPE over NFS4ERR_ATTRNOTSUPP ]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: check nfsd4_acl_to_attr() return value in nfsd4_create()\n\nnfsd4_create() stores the return value of nfsd4_acl_to_attr() in\nstatus, but the switch(create->cr_type) block unconditionally\noverwrites it in every branch. ACL translation errors are silently\ndiscarded, and the CREATE proceeds without the requested ACL.\n\nAdd an early exit check after nfsd4_acl_to_attr(), matching the\npattern already used in nfsd4_setattr().\n\n[ cel: prefer NFS4ERR_BADTYPE over NFS4ERR_ATTRNOTSUPP ]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06218 |
debian: CVE-2026-89693 was patched at 2026-09-16
2439.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89694) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: check client ownership when cancelling a copy-notify stateid On the OFFLOAD_CANCEL path (clp != NULL), manage_cpntf_state() freed the target cpntf state without checking ownership. The lookup key st->si_opaque.so_id is allocated cyclically (guessable) and the embedded clientid is the fixed per-net nn->s2s_cp_cl_id, so any authenticated NFSv4.2 client could cancel and free another client's copy-notify stateid. Compare the creating clientid recorded in state->cp_p_clid against the requesting client's cl_clientid and return nfserr_bad_stateid on a mismatch instead of freeing the entry.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: check client ownership when cancelling a copy-notify stateid\n\nOn the OFFLOAD_CANCEL path (clp != NULL), manage_cpntf_state() freed the\ntarget cpntf state without checking ownership. The lookup key\nst->si_opaque.so_id is allocated cyclically (guessable) and the embedded\nclientid is the fixed per-net nn->s2s_cp_cl_id, so any authenticated\nNFSv4.2 client could cancel and free another client's copy-notify\nstateid.\n\nCompare the creating clientid recorded in state->cp_p_clid against the\nrequesting client's cl_clientid and return nfserr_bad_stateid on a\nmismatch instead of freeing the entry.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11446 |
debian: CVE-2026-89694 was patched at 2026-09-16
2440.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89698) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage struct nfsd_genl_rqstp declares rq_daddr and rq_saddr as plain "struct sockaddr" (16 bytes). When an IPv6 NFS client is connected, nfsd_genl_rpc_status_compose_msg() casts these fields to "struct sockaddr_in6 *" (28 bytes) and reads sin6_addr at offset 8..24, which extends 8 bytes past the end of the 16-byte sockaddr field into the adjacent rq_flags member. The 16-byte nla_put_in6_addr then ships 8 bytes of truncated IPv6 address followed by 8 bytes of rq_flags to userspace via the NFSD_A_RPC_STATUS_SADDR6/DADDR6 netlink attributes. This is reachable by any unprivileged process in the network namespace because NFSD_CMD_RPC_STATUS_GET uses GENL_CMD_CAP_DUMP without GENL_ADMIN_PERM. Fix by widening rq_daddr and rq_saddr to struct sockaddr_storage so the IPv6 casts operate within bounds, copying sizeof(struct sockaddr_storage) bytes in the memcpy calls so the full address is captured, and zero-initializing the genl_rqstp stack variable to prevent leaking uninitialized tail bytes through netlink.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage\n\nstruct nfsd_genl_rqstp declares rq_daddr and rq_saddr as plain\n"struct sockaddr" (16 bytes). When an IPv6 NFS client is connected,\nnfsd_genl_rpc_status_compose_msg() casts these fields to\n"struct sockaddr_in6 *" (28 bytes) and reads sin6_addr at offset 8..24,\nwhich extends 8 bytes past the end of the 16-byte sockaddr field into\nthe adjacent rq_flags member. The 16-byte nla_put_in6_addr then ships 8\nbytes of truncated IPv6 address followed by 8 bytes of rq_flags to\nuserspace via the NFSD_A_RPC_STATUS_SADDR6/DADDR6 netlink attributes.\n\nThis is reachable by any unprivileged process in the network namespace\nbecause NFSD_CMD_RPC_STATUS_GET uses GENL_CMD_CAP_DUMP without\nGENL_ADMIN_PERM.\n\nFix by widening rq_daddr and rq_saddr to struct sockaddr_storage so the\nIPv6 casts operate within bounds, copying sizeof(struct sockaddr_storage)\nbytes in the memcpy calls so the full address is captured, and\nzero-initializing the genl_rqstp stack variable to prevent leaking\nuninitialized tail bytes through netlink.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00198, EPSS Percentile is 0.09787 |
debian: CVE-2026-89698 was patched at 2026-09-16
2441.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89700) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: validate sockaddr length per family in listener_set nfsd_sock_nl_policy declares NFSD_A_SOCK_ADDR as a bare NLA_BINARY attribute with no minimum length. A CAP_NET_ADMIN caller can send a 16-byte NFSD_A_SOCK_ADDR with sa_family=AF_INET6, causing a 12-byte OOB read across three consumers (rpc_cmp_addr_port, svc_find_listener, kernel_bind). nfsd_nl_listener_set_doit() also parsed and validated each listener entry inline in two separate loops, interleaved with mutating the running listener configuration. The validation was duplicated, used an open-coded "nla_len < sizeof(struct sockaddr)" check that was too short for AF_INET6, and handled a malformed entry inconsistently depending on which loop noticed it. Add an nfsd_nl_validate_listeners() helper that walks the entire list once and confirms each entry parses, carries both an address and a transport name, and is long enough for its address family (sizeof(struct sockaddr_in) for AF_INET, sizeof(struct sockaddr_in6) for AF_INET6, -EAFNOSUPPORT otherwise). Call it before taking nfsd_mutex or creating the serv, so a malformed request fails cleanly with no side effects. Since every entry is known valid by the time the two existing loops run, drop the redundant presence and per-family length checks from both, leaving only the nla_parse_nested() call needed to extract the data.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: validate sockaddr length per family in listener_set\n\nnfsd_sock_nl_policy declares NFSD_A_SOCK_ADDR as a bare NLA_BINARY\nattribute with no minimum length. A CAP_NET_ADMIN caller can send a\n16-byte NFSD_A_SOCK_ADDR with sa_family=AF_INET6, causing a 12-byte\nOOB read across three consumers (rpc_cmp_addr_port, svc_find_listener,\nkernel_bind).\n\nnfsd_nl_listener_set_doit() also parsed and validated each listener\nentry inline in two separate loops, interleaved with mutating the\nrunning listener configuration. The validation was duplicated, used an\nopen-coded "nla_len < sizeof(struct sockaddr)" check that was too short\nfor AF_INET6, and handled a malformed entry inconsistently depending on\nwhich loop noticed it.\n\nAdd an nfsd_nl_validate_listeners() helper that walks the entire list\nonce and confirms each entry parses, carries both an address and a\ntransport name, and is long enough for its address family\n(sizeof(struct sockaddr_in) for AF_INET, sizeof(struct sockaddr_in6)\nfor AF_INET6, -EAFNOSUPPORT otherwise). Call it before taking\nnfsd_mutex or creating the serv, so a malformed request fails cleanly\nwith no side effects.\n\nSince every entry is known valid by the time the two existing loops\nrun, drop the redundant presence and per-family length checks from\nboth, leaving only the nla_parse_nested() call needed to extract the\ndata.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06213 |
debian: CVE-2026-89700 was patched at 2026-09-16
2442.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89710) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path When the server returns a new layout stateid while a valid one is still held, pnfs_layout_process() calls pnfs_mark_matching_lsegs_return() on the on-stack free_me list and jumps to out_forget. Segments whose reference count drops to zero are unlinked from lo->plh_segs and moved to free_me by mark_lseg_invalid(); for an idle cached segment the layout header holds the only reference, so this happens on the first decrement. out_forget never drains free_me -- only the success path calls pnfs_free_lseg_list(). Commit 814b84971388 ("pNFS/NFSv4: Fix a layout segment leak in pnfs_layout_process()") added the drain; commit 08bd8dbe8882 ("pNFS/NFSv4: Try to return invalid layout in pnfs_layout_process()") removed it while switching the destination to lo->plh_return_segs, which is drained elsewhere. Commit fb700ef02676 ("NFSv4.1: Simplify layout return in pnfs_layout_process()") switched the destination back to free_me without restoring the drain. Restore the pnfs_free_lseg_list() call.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path\n\nWhen the server returns a new layout stateid while a valid one is still\nheld, pnfs_layout_process() calls pnfs_mark_matching_lsegs_return() on\nthe on-stack free_me list and jumps to out_forget. Segments whose\nreference count drops to zero are unlinked from lo->plh_segs and moved\nto free_me by mark_lseg_invalid(); for an idle cached segment the layout\nheader holds the only reference, so this happens on the first decrement.\n\nout_forget never drains free_me -- only the success path calls\npnfs_free_lseg_list().\n\nCommit 814b84971388 ("pNFS/NFSv4: Fix a layout segment leak in\npnfs_layout_process()") added the drain; commit 08bd8dbe8882\n("pNFS/NFSv4: Try to return invalid layout in pnfs_layout_process()")\nremoved it while switching the destination to lo->plh_return_segs, which\nis drained elsewhere. Commit fb700ef02676 ("NFSv4.1: Simplify layout\nreturn in pnfs_layout_process()") switched the destination back to\nfree_me without restoring the drain.\n\nRestore the pnfs_free_lseg_list() call.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06929 |
debian: CVE-2026-89710 was patched at 2026-09-16
2443.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89717) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: zram: set default primary compressor in zram_destroy_comps() Patch series "zram: fix zram issues reported by sashiko". Sashiko drove by and reported [1] a couple of zram issues: a possible BUG_ON() in zlib code due to missing winbits range validation and one possible NULL-ptr dereference in zcomp. Both are low risk yet still worth fixing. This patch (of 2): zram_destroy_comps() resets all compressors and leaves them set to NULL, including the primary one, which is invalid device state, as now comp_algorithm_show()->strcmp() can be called on a NULL compressor. Set default primary compressor in zram_destroy_comps().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nzram: set default primary compressor in zram_destroy_comps()\n\nPatch series "zram: fix zram issues reported by sashiko".\n\nSashiko drove by and reported [1] a couple of zram issues:\na possible BUG_ON() in zlib code due to missing winbits range\nvalidation and one possible NULL-ptr dereference in zcomp.\nBoth are low risk yet still worth fixing.\n\n\nThis patch (of 2):\n\nzram_destroy_comps() resets all compressors and leaves them set to NULL,\nincluding the primary one, which is invalid device state, as now\ncomp_algorithm_show()->strcmp() can be called on a NULL compressor. Set\ndefault primary compressor in zram_destroy_comps().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06215 |
debian: CVE-2026-89717 was patched at 2026-09-16
2444.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89718) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: zram: fix out-of-bounds access in writeback_store() Patch series "zram: fix stale scan bounds after reinitialization". Both writeback_store() and read_block_state() derive their table scan bounds from zram->disksize before acquiring dev_lock. If the device is reset and reinitialized with a smaller disksize between that read and lock acquisition, the bound can describe the old table while the scan operates on the new one. This can lead to out-of-bounds slot accesses. Move both bound calculations under dev_lock so each bound remains consistent with the table throughout its scan. Keep the fixes separate because the affected interfaces originate from different commits and can be backported independently. This patch (of 2): writeback_store() calculates the table scan bounds before taking dev_lock. A reset followed by reconfiguration with a smaller disksize can therefore replace zram->table while writeback_store() is waiting for the lock. Once it acquires the lock, it sees an initialized device but scans the new table using the old upper bound, resulting in an out-of-bounds access. Calculate the number of pages while holding dev_lock so the scan bound matches the table protected by the lock.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nzram: fix out-of-bounds access in writeback_store()\n\nPatch series "zram: fix stale scan bounds after reinitialization".\n\nBoth writeback_store() and read_block_state() derive their table scan\nbounds from zram->disksize before acquiring dev_lock. If the device is\nreset and reinitialized with a smaller disksize between that read and lock\nacquisition, the bound can describe the old table while the scan operates\non the new one. This can lead to out-of-bounds slot accesses.\n\nMove both bound calculations under dev_lock so each bound remains\nconsistent with the table throughout its scan. Keep the fixes separate\nbecause the affected interfaces originate from different commits and can\nbe backported independently.\n\n\nThis patch (of 2):\n\nwriteback_store() calculates the table scan bounds before taking dev_lock.\nA reset followed by reconfiguration with a smaller disksize can therefore\nreplace zram->table while writeback_store() is waiting for the lock. Once\nit acquires the lock, it sees an initialized device but scans the new\ntable using the old upper bound, resulting in an out-of-bounds access.\n\nCalculate the number of pages while holding dev_lock so the scan bound\nmatches the table protected by the lock.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.05056 |
debian: CVE-2026-89718 was patched at 2026-09-16
2445.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89719) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: zram: fix out-of-bounds access in read_block_state() read_block_state() calculates nr_pages before taking dev_lock. If the device is reset and reinitialized with a smaller disksize before lock acquisition, nr_pages still describes the old table. The subsequent loop can then call slot_lock() past the end of the newly allocated table. Read disksize after acquiring dev_lock and checking that the device is initialized. The read lock then keeps the table and its bound stable for the duration of the scan.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nzram: fix out-of-bounds access in read_block_state()\n\nread_block_state() calculates nr_pages before taking dev_lock. If the\ndevice is reset and reinitialized with a smaller disksize before lock\nacquisition, nr_pages still describes the old table. The subsequent loop\ncan then call slot_lock() past the end of the newly allocated table.\n\nRead disksize after acquiring dev_lock and checking that the device is\ninitialized. The read lock then keeps the table and its bound stable for\nthe duration of the scan.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06216 |
debian: CVE-2026-89719 was patched at 2026-09-16
2446.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89732) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Prevent deadlock during ep0 read loop Currently, ffs_ep0_read() holds ffs->mutex when it prepares to go to sleep waiting for an event. When no setup events are pending, it calls wait_event_interruptible_exclusive_locked_irq() with the mutex still held. The wait macro deliberately drops the waitqueue spinlock before sleeping but does not drop the mutex. If a userspace daemon is polling ep0 via read() and the gadget is asynchronously torn down via configfs (e.g., echo "" > UDC), a deadlock can occur: 1. The configfs teardown calls functionfs_unbind(), which queues a FUNCTIONFS_UNBIND event. 2. The daemon wakes up, consumes the event, and drops the mutex. 3. However, if the daemon loops and immediately issues another read() before exiting, it reacquires ffs->mutex and again goes into an interruptible sleep. 4. Meanwhile, functionfs_unbind() continues execution and attempts to acquire ffs->mutex to tear down ep0req. 5. The kernel deadlocks because the configfs thread is stuck in an uninterruptible sleep waiting for the mutex, while the userspace daemon is in an interruptible sleep holding the mutex forever because no more events will arrive. To fix this, we drop both the waitqueue spinlock and ffs->mutex before going to sleep, and use wait_event_interruptible_exclusive() instead. Upon waking up, we jump back to the `retry` label to safely reacquire the mutex and re-evaluate the state machine. By not sleeping with ffs->mutex held, we natively decouple gadget teardowns (which require the mutex) from userspace polling.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_fs: Prevent deadlock during ep0 read loop\n\nCurrently, ffs_ep0_read() holds ffs->mutex when it prepares to go to\nsleep waiting for an event. When no setup events are pending, it calls\nwait_event_interruptible_exclusive_locked_irq() with the mutex still\nheld. The wait macro deliberately drops the waitqueue spinlock before\nsleeping but does not drop the mutex.\n\nIf a userspace daemon is polling ep0 via read() and the gadget is\nasynchronously torn down via configfs (e.g., echo "" > UDC), a\ndeadlock can occur:\n\n1. The configfs teardown calls functionfs_unbind(), which queues a\n FUNCTIONFS_UNBIND event.\n2. The daemon wakes up, consumes the event, and drops the mutex.\n3. However, if the daemon loops and immediately issues another read()\n before exiting, it reacquires ffs->mutex and again goes into an\n interruptible sleep.\n4. Meanwhile, functionfs_unbind() continues execution and attempts to\n acquire ffs->mutex to tear down ep0req.\n5. The kernel deadlocks because the configfs thread is stuck in an\n uninterruptible sleep waiting for the mutex, while the userspace\n daemon is in an interruptible sleep holding the mutex forever\n because no more events will arrive.\n\nTo fix this, we drop both the waitqueue spinlock and ffs->mutex before\ngoing to sleep, and use wait_event_interruptible_exclusive() instead.\nUpon waking up, we jump back to the `retry` label to safely reacquire\nthe mutex and re-evaluate the state machine. By not sleeping with\nffs->mutex held, we natively decouple gadget teardowns (which require\nthe mutex) from userspace polling.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00226, EPSS Percentile is 0.13486 |
debian: CVE-2026-89732 was patched at 2026-09-16
2447.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89735) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: usb: gadget: midi2: remove default configfs groups on teardown f_midi2_alloc_inst() creates default configfs child groups for the default endpoint and default block using configfs_add_default_group(), setting their internal refcount to 1. However, during function teardown in f_midi2_free_inst() or EP cleanup in f_midi2_ep_opts_release(), configfs_remove_default_groups() is never called, therefore never dropping the refcount and leaking struct f_midi2_ep_opts and f_midi2_block_opts. Add the missing configfs_remove_default_groups() in the afformentioned functions to free the structs properly.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: midi2: remove default configfs groups on teardown\n\nf_midi2_alloc_inst() creates default configfs child groups for the\ndefault endpoint and default block using configfs_add_default_group(),\nsetting their internal refcount to 1.\n\nHowever, during function teardown in f_midi2_free_inst() or EP cleanup\nin f_midi2_ep_opts_release(), configfs_remove_default_groups() is\nnever called, therefore never dropping the refcount and leaking struct\nf_midi2_ep_opts and f_midi2_block_opts.\n\nAdd the missing configfs_remove_default_groups() in the afformentioned\nfunctions to free the structs properly.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06415 |
debian: CVE-2026-89735 was patched at 2026-09-16
2448.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89740) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: serial: imx: serialize imx_uart_ports[] lifetime imx_uart_probe() publishes its devm-allocated port in imx_uart_ports[] before uart_add_one_port() because console setup uses the table. The entry is not cleared when adding the port fails or after removal, leaving a dangling pointer. A sibling probe can register the shared console through that stale entry. This was reproduced under KASAN on QEMU mcimx6ul-evk by unbinding a sibling UART, unbinding the console UART and rebinding the sibling. Keep the entry valid through uart_remove_one_port(), then clear it. Protect port addition and removal together with their table updates so sibling operations cannot interleave. Reject an occupied slot rather than clobbering an active port during a duplicate-line probe.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nserial: imx: serialize imx_uart_ports[] lifetime\n\nimx_uart_probe() publishes its devm-allocated port in imx_uart_ports[]\nbefore uart_add_one_port() because console setup uses the table. The entry\nis not cleared when adding the port fails or after removal, leaving a\ndangling pointer.\n\nA sibling probe can register the shared console through that stale entry.\nThis was reproduced under KASAN on QEMU mcimx6ul-evk by unbinding a\nsibling UART, unbinding the console UART and rebinding the sibling.\n\nKeep the entry valid through uart_remove_one_port(), then clear it. Protect\nport addition and removal together with their table updates so sibling\noperations cannot interleave. Reject an occupied slot rather than\nclobbering an active port during a duplicate-line probe.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10043 |
debian: CVE-2026-89740 was patched at 2026-09-16
2449.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89749) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: tracing: Fix crash passing ERR_PTR to kthread_stop() event_test_stuff() calls kthread_run() and unconditionally passes the returned task_struct pointer to kthread_stop(). kthread_run() returns an error pointer such as ERR_PTR(-ENOMEM) when kthread creation fails, for example under memory pressure during the boot-time event self-test. kthread_stop() then dereferences the invalid pointer, crashing the kernel. Check the result of kthread_run() before passing it to kthread_stop(). Use WARN_ON() so that a failure to create the self-test thread does not go unnoticed, matching the ring-buffer self-test fix in commit 91542863abad ("ring-buffer: Fix crash passing ERR_PTR to kthread_stop()").', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix crash passing ERR_PTR to kthread_stop()\n\nevent_test_stuff() calls kthread_run() and unconditionally passes the\nreturned task_struct pointer to kthread_stop(). kthread_run() returns an\nerror pointer such as ERR_PTR(-ENOMEM) when kthread creation fails, for\nexample under memory pressure during the boot-time event self-test.\nkthread_stop() then dereferences the invalid pointer, crashing the kernel.\n\nCheck the result of kthread_run() before passing it to kthread_stop(). Use\nWARN_ON() so that a failure to create the self-test thread does not go\nunnoticed, matching the ring-buffer self-test fix in commit\n91542863abad ("ring-buffer: Fix crash passing ERR_PTR to kthread_stop()").', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11547 |
debian: CVE-2026-89749 was patched at 2026-09-16
2450.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89751) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: x86/tdx: Fix off-by-one in port I/O handling handle_in() and handle_out() in arch/x86/coco/tdx/tdx.c use: u64 mask = GENMASK(BITS_PER_BYTE * size, 0); GENMASK(h, l) includes bit h. For size=1 (INB), this produces GENMASK(8, 0) = 0x1FF (9 bits) instead of GENMASK(7, 0) = 0xFF (8 bits). The mask is one bit too wide for all I/O sizes. Fix the mask calculation.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nx86/tdx: Fix off-by-one in port I/O handling\n\nhandle_in() and handle_out() in arch/x86/coco/tdx/tdx.c use:\n\n u64 mask = GENMASK(BITS_PER_BYTE * size, 0);\n\nGENMASK(h, l) includes bit h. For size=1 (INB), this produces\nGENMASK(8, 0) = 0x1FF (9 bits) instead of GENMASK(7, 0) = 0xFF (8\nbits). The mask is one bit too wide for all I/O sizes.\n\nFix the mask calculation.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06935 |
debian: CVE-2026-89751 was patched at 2026-09-16
2451.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89752) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm: memcg: stop reclaim when a limit update is superseded kernfs serializes file operations only per open file, so separate open files can update the same memory.high or memory.max file concurrently. Both handlers store the new limit before synchronous reclaim, but continue to use the writer's local target in the reclaim loop. If another writer raises or removes the limit, the first writer can continue reclaiming toward a stale target. For memory.max, this can leave the writer looping indefinitely once reclaim retries are exhausted. The OOM path sees sufficient margin under the current limit and returns true without killing, while the writer still compares usage against its stale target and records another OOM event. Check the current limit at the start of each reclaim iteration and stop if it no longer matches the writer's target. Reproducer: Populate a cgroup with anonymous memory and disable swapping. Lower memory.max from one open file, then restore it to "max" through another open file after the new limit becomes visible. Without the patch, the first writer remains blocked and repeatedly increments the OOM event counter. With the patch, it returns normally. This was not motivated by a reported production workload. We found it through automated randomized testing for our cgroup observability work and reduced it to the reproducer above.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm: memcg: stop reclaim when a limit update is superseded\n\nkernfs serializes file operations only per open file, so separate open\nfiles can update the same memory.high or memory.max file concurrently. \nBoth handlers store the new limit before synchronous reclaim, but continue\nto use the writer's local target in the reclaim loop. If another writer\nraises or removes the limit, the first writer can continue reclaiming\ntoward a stale target.\n\nFor memory.max, this can leave the writer looping indefinitely once\nreclaim retries are exhausted. The OOM path sees sufficient margin under\nthe current limit and returns true without killing, while the writer still\ncompares usage against its stale target and records another OOM event.\n\nCheck the current limit at the start of each reclaim iteration and stop if\nit no longer matches the writer's target.\n\nReproducer:\n\nPopulate a cgroup with anonymous memory and disable swapping. Lower\nmemory.max from one open file, then restore it to "max" through another\nopen file after the new limit becomes visible.\n\nWithout the patch, the first writer remains blocked and repeatedly\nincrements the OOM event counter. With the patch, it returns normally.\n\nThis was not motivated by a reported production workload. We found it\nthrough automated randomized testing for our cgroup observability work\nand reduced it to the reproducer above.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07425 |
debian: CVE-2026-89752 was patched at 2026-09-16
2452.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89753) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec() I am seeing some rcu_tasks stalls in the Meta fleet during reclaim. INFO: rcu_tasks detected stalls on tasks: \t0000000088620d09: .. nvcsw: 6735/6735 holdout: 1 idle_cpu: -1/8 \ttask:GlobalCPUThread state:R running task pid:2552016 tgid:2524552 Call Trace: shrink_lruvec mem_cgroup_iter shrink_node do_try_to_free_pages try_to_free_pages __alloc_frozen_pages_noprof alloc_pages_noprof pte_alloc_one __pte_alloc handle_mm_fault Nothing promises direct reclaim returns in bounded time, and the scan loop in shrink_lruvec() only calls cond_resched(), which is a no-op on PREEMPTION kernels. Involuntary preemption is not a Tasks-RCU quiescent state, so the reclaiming task never reports one and becomes a holdout. Upgrade it to cond_resched_tasks_rcu_qs(), which reports a quiescent state even when cond_resched() does nothing. PS: This has been discussed in [1]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/vmscan: report RCU-tasks quiescent states in shrink_lruvec()\n\nI am seeing some rcu_tasks stalls in the Meta fleet during reclaim.\n\n INFO: rcu_tasks detected stalls on tasks:\n\t0000000088620d09: .. nvcsw: 6735/6735 holdout: 1 idle_cpu: -1/8\n\ttask:GlobalCPUThread state:R running task pid:2552016 tgid:2524552\n Call Trace:\n shrink_lruvec\n mem_cgroup_iter\n shrink_node\n do_try_to_free_pages\n try_to_free_pages\n __alloc_frozen_pages_noprof\n alloc_pages_noprof\n pte_alloc_one\n __pte_alloc\n handle_mm_fault\n\nNothing promises direct reclaim returns in bounded time, and the scan loop\nin shrink_lruvec() only calls cond_resched(), which is a no-op on\nPREEMPTION kernels. Involuntary preemption is not a Tasks-RCU quiescent\nstate, so the reclaiming task never reports one and becomes a holdout.\n\nUpgrade it to cond_resched_tasks_rcu_qs(), which reports a quiescent state\neven when cond_resched() does nothing.\n\nPS: This has been discussed in [1]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07425 |
debian: CVE-2026-89753 was patched at 2026-09-16
2453.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89756) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch() migrate_pages_batch() unmaps each folio before moving it, and every unmap runs the mmu_notifier invalidate callbacks. On KVM hosts try_to_migrate() ends up in kvm_mmu_notifier_invalidate_range_start() -> tdp_mmu_zap_leafs(), which is expensive, so unmapping a large batch keeps the CPU busy for a long time. The loop already calls cond_resched(), but on PREEMPTION kernels that is a no-op, and involuntary preemption is not a Tasks-RCU quiescent state. A long batch therefore never reports a quiescent state, and the migrating task (e.g. kcompactd) becomes a Tasks-RCU holdout, stalling the Tasks-RCU grace period for minutes, which is common at Meta fleet: INFO: rcu_tasks detected stalls on tasks: 0000000055349ecc: .. nvcsw: 1157401/1157401 holdout: 1 idle_cpu: -1/56 task:kcompactd0 state:R running task Call Trace: tdp_mmu_zap_leafs tdp_mmu_next_root gfn_to_pfn_cache_invalidate_start kvm_mmu_notifier_invalidate_range_start __mmu_notifier_invalidate_range_start try_to_migrate_one try_to_migrate migrate_pages_batch migrate_pages compact_zone compact_node kcompactd kthread Use cond_resched_tasks_rcu_qs() so a quiescent state is reported even when cond_resched() does nothing. This has also been discussed at [1]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()\n\nmigrate_pages_batch() unmaps each folio before moving it, and every\nunmap runs the mmu_notifier invalidate callbacks. On KVM hosts\ntry_to_migrate() ends up in kvm_mmu_notifier_invalidate_range_start() ->\ntdp_mmu_zap_leafs(), which is expensive, so unmapping a large batch keeps\nthe CPU busy for a long time.\n\nThe loop already calls cond_resched(), but on PREEMPTION kernels that is\na no-op, and involuntary preemption is not a Tasks-RCU quiescent state.\n\nA long batch therefore never reports a quiescent state, and the\nmigrating task (e.g. kcompactd) becomes a Tasks-RCU holdout, stalling the\nTasks-RCU grace period for minutes, which is common at Meta fleet:\n\n INFO: rcu_tasks detected stalls on tasks:\n 0000000055349ecc: .. nvcsw: 1157401/1157401 holdout: 1 idle_cpu: -1/56 task:kcompactd0 state:R running task\n Call Trace:\n tdp_mmu_zap_leafs\n tdp_mmu_next_root\n gfn_to_pfn_cache_invalidate_start\n kvm_mmu_notifier_invalidate_range_start\n __mmu_notifier_invalidate_range_start\n try_to_migrate_one\n try_to_migrate\n migrate_pages_batch\n migrate_pages\n compact_zone\n compact_node\n kcompactd\n kthread\n\nUse cond_resched_tasks_rcu_qs() so a quiescent state is reported even\nwhen cond_resched() does nothing.\n\nThis has also been discussed at [1]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00191, EPSS Percentile is 0.09042 |
debian: CVE-2026-89756 was patched at 2026-09-16
2454.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89757) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm/mglru: fix and remove redundant unevictable folio handling sort_folio() has a shortcut for moving folios that are no longer evictable but are still sitting on a generation list. However, this shortcut is buggy. It does not follow the PG_lru usage convention, and it has a more serious issue. Unevictable folios are not threaded on lists[LRU_UNEVICTABLE], so that folio->lru can be reused to hold folio->mlock_count (see the comment in lruvec_init()). Hence lruvec_add_folio() skips the list_add() for them, and every other place that turns a folio unevictable initialises mlock_count explicitly: lru_add() sets it to 0, __mlock_folio() and __mlock_new_folio() set it to !!folio_test_mlocked(folio). sort_folio() sets nothing, and the lru_gen_del_folio() right above it may have already poisoned folio->lru via list_del(), so mlock_count ends up aliasing LIST_POISON2, which reads as 0x122, i.e. 290. The result is user visible. On munlock, __munlock_folio() decrements that bogus count, finds it still non-zero and bails out before clearing PG_mlocked, so the folio remains unevictable and the Mlocked accounting stays inflated until the folio is freed. The shortcut also touches the LRU flags in the wrong order. It calls lru_gen_del_folio() while PG_lru is still set, so a concurrent folio_test_clear_lru() (e.g. compaction, folio_isolate_lru()) can succeed on a folio that has already been taken off the generation list, which may lead to unexpected behavior. So fix it by isolating them as common folios and letting the generic shrink path cull them. This matches the classical LRU behavior, and there should be no visible effect on the generic eviction or isolation behavior. There is no performance concern either, such a folio goes through this once, and then it is off the generation lists for good.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/mglru: fix and remove redundant unevictable folio handling\n\nsort_folio() has a shortcut for moving folios that are no longer evictable\nbut are still sitting on a generation list. However, this shortcut is\nbuggy. It does not follow the PG_lru usage convention, and it has a more\nserious issue.\n\nUnevictable folios are not threaded on lists[LRU_UNEVICTABLE], so that\nfolio->lru can be reused to hold folio->mlock_count (see the comment in\nlruvec_init()). Hence lruvec_add_folio() skips the list_add() for them,\nand every other place that turns a folio unevictable initialises\nmlock_count explicitly: lru_add() sets it to 0, __mlock_folio() and\n__mlock_new_folio() set it to !!folio_test_mlocked(folio). sort_folio()\nsets nothing, and the lru_gen_del_folio() right above it may have already\npoisoned folio->lru via list_del(), so mlock_count ends up aliasing\nLIST_POISON2, which reads as 0x122, i.e. 290. The result is user\nvisible. On munlock, __munlock_folio() decrements that bogus count, finds\nit still non-zero and bails out before clearing PG_mlocked, so the folio\nremains unevictable and the Mlocked accounting stays inflated until the\nfolio is freed.\n\nThe shortcut also touches the LRU flags in the wrong order. It calls\nlru_gen_del_folio() while PG_lru is still set, so a concurrent\nfolio_test_clear_lru() (e.g. compaction, folio_isolate_lru()) can succeed\non a folio that has already been taken off the generation list, which may\nlead to unexpected behavior.\n\nSo fix it by isolating them as common folios and letting the generic\nshrink path cull them. This matches the classical LRU behavior, and there\nshould be no visible effect on the generic eviction or isolation behavior.\n\nThere is no performance concern either, such a folio goes through this\nonce, and then it is off the generation lists for good.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00184, EPSS Percentile is 0.08234 |
debian: CVE-2026-89757 was patched at 2026-09-16
2455.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89759) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm/kmemleak: avoid soft lockup when scanning task stacks Patch series "mm/kmemleak: avoid soft lockup when scanning task", v3. kmemleak_scan() scans every task stack under one rcu_read_lock() with no reschedule point, which can trip the soft lockup watchdog on hosts with very many threads. That prints the following message, depending on the workload+host configuration: watchdog: BUG: soft lockup - CPU#35 stuck for 22s! [kmemleak:537] scan_block kmemleak_scan kmemleak_scan_thread kthread Patch 1 walks the tasks with find_ge_pid() so the scan reschedules between tasks Patches 2-3 let the scan loops stop early once a scan is interrupted. This patch (of 3): kmemleak_scan() walks every thread and scans its kernel stack under a single rcu_read_lock() with no reschedule point. On a host with very many threads -- amplified by KASAN/lockdep in debug builds -- this loop can hog a CPU long enough to trip the soft lockup watchdog: watchdog: BUG: soft lockup - CPU#35 stuck for 22s! [kmemleak:537] scan_block kmemleak_scan kmemleak_scan_thread kthread A cond_resched() cannot be added directly: the loop runs inside an RCU read-side critical section. Walk the tasks one PID at a time with find_ge_pid(), taking the RCU read lock only to look up and pin each task. The stack is then scanned with no lock held, so cond_resched() runs between tasks and the scan stops early on scan_should_stop(). This follows the next_tgid()/task_seq_get_next() iteration pattern and keeps each RCU critical section short.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/kmemleak: avoid soft lockup when scanning task stacks\n\nPatch series "mm/kmemleak: avoid soft lockup when scanning task", v3.\n\nkmemleak_scan() scans every task stack under one rcu_read_lock() with no\nreschedule point, which can trip the soft lockup watchdog on hosts with\nvery many threads.\n\nThat prints the following message, depending on the workload+host\nconfiguration:\n\n watchdog: BUG: soft lockup - CPU#35 stuck for 22s! [kmemleak:537]\n scan_block\n kmemleak_scan\n kmemleak_scan_thread\n kthread\n\nPatch 1 walks the tasks with find_ge_pid() so the scan reschedules between\ntasks\n\nPatches 2-3 let the scan loops stop early once a scan is interrupted.\n\n\nThis patch (of 3):\n\nkmemleak_scan() walks every thread and scans its kernel stack under a\nsingle rcu_read_lock() with no reschedule point. On a host with very many\nthreads -- amplified by KASAN/lockdep in debug builds -- this loop can hog\na CPU long enough to trip the soft lockup watchdog:\n\n watchdog: BUG: soft lockup - CPU#35 stuck for 22s! [kmemleak:537]\n scan_block\n kmemleak_scan\n kmemleak_scan_thread\n kthread\n\nA cond_resched() cannot be added directly: the loop runs inside an RCU\nread-side critical section.\n\nWalk the tasks one PID at a time with find_ge_pid(), taking the RCU read\nlock only to look up and pin each task. The stack is then scanned with no\nlock held, so cond_resched() runs between tasks and the scan stops early\non scan_should_stop(). This follows the next_tgid()/task_seq_get_next()\niteration pattern and keeps each RCU critical section short.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00186, EPSS Percentile is 0.08459 |
debian: CVE-2026-89759 was patched at 2026-09-16
2456.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89765) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: timers/itimer: Zero-init old itimerval before copy to userspace On native sparc64, struct __kernel_old_timeval contains a four-byte hole after tv_usec because tv_sec is 64-bit while __kernel_suseconds_t is 32-bit. put_itimerval() fills only the named fields in a stack-allocated __kernel_old_itimerval and copies the entire object to userspace, so getitimer() can expose the two padding holes. Zero-initialize the aggregate before assigning the fields so implicit padding is deterministic before it crosses the user/kernel boundary.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntimers/itimer: Zero-init old itimerval before copy to userspace\n\nOn native sparc64, struct __kernel_old_timeval contains a four-byte hole\nafter tv_usec because tv_sec is 64-bit while __kernel_suseconds_t is 32-bit.\nput_itimerval() fills only the named fields in a stack-allocated\n__kernel_old_itimerval and copies the entire object to userspace, so\ngetitimer() can expose the two padding holes.\n\nZero-initialize the aggregate before assigning the fields so implicit\npadding is deterministic before it crosses the user/kernel boundary.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00196, EPSS Percentile is 0.09556 |
debian: CVE-2026-89765 was patched at 2026-09-16
2457.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89766) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: pidfd: hold exec_update_lock around namespace ioctl The PIDFD_GET_*_NAMESPACE ioctls in pidfd_ioctl() perform a filesystem credentials ptrace access check before handing out a namespace file descriptor. The accompanying comment states that the code "mirrors nsfs behavior", but, unlike the corresponding procfs paths, it does so without holding the target task's exec_update_lock. proc_ns_get_link() and proc_ns_readlink() both take exec_update_lock for reading around the ptrace check and the namespace lookup, so that the credentials used for the access decision match those of the task when its namespace is read. Without it, a caller can pass the check against the target's old credentials and then read the namespace after the target has execve()'d a setuid binary and committed new credentials -- accessing namespace information it should have been denied. Hold exec_update_lock for reading around the ptrace check and the namespace lookup so that pidfd truly mirrors nsfs behavior, as the comment already claims. open_namespace() itself runs outside the lock: once a namespace reference is obtained it carries its own refcount and is opened with the caller's own credentials, so a concurrent execve() on the target can no longer affect the outcome.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\npidfd: hold exec_update_lock around namespace ioctl\n\nThe PIDFD_GET_*_NAMESPACE ioctls in pidfd_ioctl() perform a filesystem\ncredentials ptrace access check before handing out a namespace file\ndescriptor. The accompanying comment states that the code "mirrors nsfs\nbehavior", but, unlike the corresponding procfs paths, it does so without\nholding the target task's exec_update_lock.\n\nproc_ns_get_link() and proc_ns_readlink() both take exec_update_lock for\nreading around the ptrace check and the namespace lookup, so that the\ncredentials used for the access decision match those of the task when its\nnamespace is read. Without it, a caller can pass the check against the\ntarget's old credentials and then read the namespace after the target has\nexecve()'d a setuid binary and committed new credentials -- accessing\nnamespace information it should have been denied.\n\nHold exec_update_lock for reading around the ptrace check and the\nnamespace lookup so that pidfd truly mirrors nsfs behavior, as the comment\nalready claims. open_namespace() itself runs outside the lock: once a\nnamespace reference is obtained it carries its own refcount and is opened\nwith the caller's own credentials, so a concurrent execve() on the target\ncan no longer affect the outcome.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00184, EPSS Percentile is 0.08234 |
debian: CVE-2026-89766 was patched at 2026-09-16
2458.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89768) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fs: fix user path of nested backing files backing_file_open() derives the path to be stored in the new backing file from user_file->f_path. This is incorrect when user_file itself is a backing file, which is the case for nested stacking filesystems, e.g. overlayfs mounts where the lowerdir of one overlayfs is the merged directory of another. Since commit def3ae83da02 ("fs: store real path instead of fake path in backing file f_path") the f_path of a backing file holds the real path of the intermediate layer, not the path that the user opened. Commit 924577e4f6ca ("ovl: Fix nested backing file paths") fixed this for such configurations by passing file_user_path() from ovl_open_realfile(). However, commit 6af36aeb147a ("lsm: add backing_file LSM hooks") changed the first argument of backing_file_open() from the user path back to the user file and derived the path from user_file->f_path again, silently re-introducing the problem. As a result, files mapped through a nested overlayfs show the wrong path in /proc/<pid>/maps and in perf/ftrace mmap records. For example, with two nested overlayfs mounts: mkdir -p /ovl/{lower,upper,work,merged} /ovl/nested echo hello > /ovl/lower/foo mount -t overlay overlay \\ \t-o lowerdir=/ovl/lower,upperdir=/ovl/upper,workdir=/ovl/work \\ \t/ovl/merged # at least two lowerdirs are needed when upperdir is nonexistent mount -t overlay overlay \\ \t-o lowerdir=/ovl/merged:/ovl/lower /ovl/nested mapping /ovl/nested/foo shows a disconnected path instead of the user path: # readlink /proc/self/fd/3 /ovl/nested/foo # grep foo /proc/self/maps 7f6e2c100000-7f6e2c101000 r--s 00000000 00:24 15813027 /foo The bogus path is derived from the f_path of the intermediate backing file, whose mount is a private clone that d_path() cannot resolve. Fix this by using file_user_path(), which returns the outermost user-visible path for backing files and falls back to &user_file->f_path for regular files. This restores the behavior of commit 924577e4f6ca ("ovl: Fix nested backing file paths") for overlayfs and also fixes the same problem for the other backing_file_open() callers, fuse passthrough and erofs ishare, when their user file is itself a backing file. backing_tmpfile_open() has the same pattern but is not affected: it is only called by ovl_create_tmpfile() for the upper layer, and another overlayfs is rejected as upperdir by the DCACHE_OP_REAL check in ovl_mount_dir_check(), so its user_file can never be a backing file.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfs: fix user path of nested backing files\n\nbacking_file_open() derives the path to be stored in the new backing\nfile from user_file->f_path. This is incorrect when user_file itself\nis a backing file, which is the case for nested stacking filesystems,\ne.g. overlayfs mounts where the lowerdir of one overlayfs is the merged\ndirectory of another. Since commit def3ae83da02 ("fs: store real path\ninstead of fake path in backing file f_path") the f_path of a backing\nfile holds the real path of the intermediate layer, not the path that\nthe user opened.\n\nCommit 924577e4f6ca ("ovl: Fix nested backing file paths") fixed this\nfor such configurations by passing file_user_path() from\novl_open_realfile(). However, commit 6af36aeb147a ("lsm: add\nbacking_file LSM hooks") changed the first argument of\nbacking_file_open() from the user path back to the user file and\nderived the path from user_file->f_path again, silently re-introducing\nthe problem.\n\nAs a result, files mapped through a nested overlayfs show the wrong\npath in /proc/<pid>/maps and in perf/ftrace mmap records. For example,\nwith two nested overlayfs mounts:\n\n mkdir -p /ovl/{lower,upper,work,merged} /ovl/nested\n echo hello > /ovl/lower/foo\n mount -t overlay overlay \\\n\t-o lowerdir=/ovl/lower,upperdir=/ovl/upper,workdir=/ovl/work \\\n\t/ovl/merged\n # at least two lowerdirs are needed when upperdir is nonexistent\n mount -t overlay overlay \\\n\t-o lowerdir=/ovl/merged:/ovl/lower /ovl/nested\n\nmapping /ovl/nested/foo shows a disconnected path instead of the user\npath:\n\n # readlink /proc/self/fd/3\n /ovl/nested/foo\n # grep foo /proc/self/maps\n 7f6e2c100000-7f6e2c101000 r--s 00000000 00:24 15813027 /foo\n\nThe bogus path is derived from the f_path of the intermediate backing\nfile, whose mount is a private clone that d_path() cannot resolve.\n\nFix this by using file_user_path(), which returns the outermost\nuser-visible path for backing files and falls back to\n&user_file->f_path for regular files. This restores the behavior of\ncommit 924577e4f6ca ("ovl: Fix nested backing file paths") for\noverlayfs and also fixes the same problem for the other\nbacking_file_open() callers, fuse passthrough and erofs ishare, when\ntheir user file is itself a backing file.\n\nbacking_tmpfile_open() has the same pattern but is not affected: it is\nonly called by ovl_create_tmpfile() for the upper layer, and another\noverlayfs is rejected as upperdir by the DCACHE_OP_REAL check in\novl_mount_dir_check(), so its user_file can never be a backing file.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00186, EPSS Percentile is 0.08459 |
debian: CVE-2026-89768 was patched at 2026-09-16
2459.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89776) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes The VXLAN VNI filter entry policy declares the GROUP/GROUP6 address attributes as NLA_BINARY with only a maximum length, so validate_nla() accepts a payload shorter than the address. The GROUP consumer reads it with nla_get_in_addr(), an unconditional 4-byte load, so a short attribute over-reads up to 3 bytes of uninitialised slab data, which are stored into remote_ip and echoed back via RTM_GETTUNNEL, disclosing kernel memory. Switch both entries to NLA_POLICY_EXACT_LEN() so the validator rejects any GROUP/GROUP6 that is not exactly 4 / 16 bytes; a valid address is always sent at full width.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes\n\nThe VXLAN VNI filter entry policy declares the GROUP/GROUP6 address\nattributes as NLA_BINARY with only a maximum length, so validate_nla()\naccepts a payload shorter than the address. The GROUP consumer reads it\nwith nla_get_in_addr(), an unconditional 4-byte load, so a short\nattribute over-reads up to 3 bytes of uninitialised slab data, which are\nstored into remote_ip and echoed back via RTM_GETTUNNEL, disclosing\nkernel memory.\n\nSwitch both entries to NLA_POLICY_EXACT_LEN() so the validator rejects\nany GROUP/GROUP6 that is not exactly 4 / 16 bytes; a valid address is\nalways sent at full width.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10808 |
debian: CVE-2026-89776 was patched at 2026-09-16
2460.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89780) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: restore skb->dev on deaggregated frames rmnet_map_deaggregate() allocates each sub-frame with alloc_skb() and leaves skb->dev NULL. __rmnet_map_ingress_handler() assigns skb->dev = ep->egress_dev only on the data path, but a MAP command frame is dispatched to rmnet_map_command() before that, so rmnet_map_send_ack() runs netif_tx_lock(skb->dev) on a NULL device. An unprivileged user reaches this by unsharing a user+net namespace, creating an rmnet link over a tap device with INGRESS_DEAGGREGATION and INGRESS_MAP_COMMANDS, and writing an aggregated frame carrying a flow-control command to the tap fd. Restore the assignment dropped by 378e25357ac7, so every skb leaving rmnet_map_deaggregate() has a valid device. BUG: KASAN: null-ptr-deref in _raw_spin_lock (kernel/locking/spinlock.c:158) Write of size 4 at addr 00000000000004b4 by task exploit/144 Call Trace: _raw_spin_lock (kernel/locking/spinlock.c:158) netif_tx_lock (net/sched/sch_generic.c:497) rmnet_map_command (drivers/net/ethernet/qualcomm/rmnet/rmnet_map_command.c:67) rmnet_rx_handler (drivers/net/ethernet/qualcomm/rmnet/rmnet_handlers.c:125) __netif_receive_skb_core.constprop.0 (net/core/dev.c:6103) ... __netif_receive_skb_one_core (net/core/dev.c:6214) netif_receive_skb (net/core/dev.c:6474) tun_get_user (drivers/net/tun.c:1966) tun_chr_write_iter (drivers/net/tun.c:2012) vfs_write (fs/read_write.c:687) ksys_write (fs/read_write.c:739) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) Kernel panic - not syncing: Fatal exception in interrupt', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: qualcomm: rmnet: restore skb->dev on deaggregated frames\n\nrmnet_map_deaggregate() allocates each sub-frame with alloc_skb() and\nleaves skb->dev NULL. __rmnet_map_ingress_handler() assigns\nskb->dev = ep->egress_dev only on the data path, but a MAP command frame\nis dispatched to rmnet_map_command() before that, so rmnet_map_send_ack()\nruns netif_tx_lock(skb->dev) on a NULL device. An unprivileged user\nreaches this by unsharing a user+net namespace, creating an rmnet link\nover a tap device with INGRESS_DEAGGREGATION and INGRESS_MAP_COMMANDS,\nand writing an aggregated frame carrying a flow-control command to the\ntap fd.\n\nRestore the assignment dropped by 378e25357ac7, so every skb leaving\nrmnet_map_deaggregate() has a valid device.\n\n BUG: KASAN: null-ptr-deref in _raw_spin_lock (kernel/locking/spinlock.c:158)\n Write of size 4 at addr 00000000000004b4 by task exploit/144\n Call Trace:\n _raw_spin_lock (kernel/locking/spinlock.c:158)\n netif_tx_lock (net/sched/sch_generic.c:497)\n rmnet_map_command (drivers/net/ethernet/qualcomm/rmnet/rmnet_map_command.c:67)\n rmnet_rx_handler (drivers/net/ethernet/qualcomm/rmnet/rmnet_handlers.c:125)\n __netif_receive_skb_core.constprop.0 (net/core/dev.c:6103)\n ...\n __netif_receive_skb_one_core (net/core/dev.c:6214)\n netif_receive_skb (net/core/dev.c:6474)\n tun_get_user (drivers/net/tun.c:1966)\n tun_chr_write_iter (drivers/net/tun.c:2012)\n vfs_write (fs/read_write.c:687)\n ksys_write (fs/read_write.c:739)\n do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n Kernel panic - not syncing: Fatal exception in interrupt', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11448 |
debian: CVE-2026-89780 was patched at 2026-09-16
2461.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-89784) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6 rpcb_register_inet4() and rpcb_register_inet6() store the result of rpc_sockaddr2uaddr() into map->r_addr without checking it for NULL. rpc_sockaddr2uaddr() returns NULL when its final kstrdup() fails, and the unchecked NULL is then carried into the synchronous RPCBPROC_SET encode path: rpcb_register_call() -> rpc_call_sync() -> rpcb_enc_getaddr() -> encode_rpcb_string(), whose first statement is strlen(string), dereferencing NULL and oopsing the kernel. The crash reproduces under failslab on v6.12; with KASAN the NULL dereference surfaces as a fault on the shadow of address zero: Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000 [#1] PREEMPT SMP KASAN RIP: 0010:strlen (lib/string.c:409) Call Trace: encode_rpcb_string (net/sunrpc/rpcb_clnt.c:890) rpcb_enc_getaddr (net/sunrpc/rpcb_clnt.c:910) rpcauth_wrap_req_encode (net/sunrpc/auth.c:745) call_encode (net/sunrpc/clnt.c:1966) __rpc_execute (net/sunrpc/sched.c:952) rpc_run_task (net/sunrpc/clnt.c:1243) rpc_call_sync (net/sunrpc/clnt.c:1272) rpcb_v4_register (net/sunrpc/rpcb_clnt.c:500) svc_generic_rpcbind_set nfsd_rpcbind_set svc_register svc_setup_socket svc_addsock write_ports nfsctl_transaction_write vfs_write The crash is reachable when an in-kernel RPC service (nfsd, lockd, nfs-callback) registers with the local rpcbind under enough memory pressure for the small GFP_KERNEL kstrdup() in rpc_sockaddr2uaddr() to fail. The asynchronous getport path already handles this exact failure mode by returning -ENOMEM; only the two register helpers omit the check. Mirror that handling: bail out with -ENOMEM when rpc_sockaddr2uaddr() returns NULL, before the address is fed into the encoder.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6\n\nrpcb_register_inet4() and rpcb_register_inet6() store the result of\nrpc_sockaddr2uaddr() into map->r_addr without checking it for NULL.\nrpc_sockaddr2uaddr() returns NULL when its final kstrdup() fails, and\nthe unchecked NULL is then carried into the synchronous RPCBPROC_SET\nencode path: rpcb_register_call() -> rpc_call_sync() ->\nrpcb_enc_getaddr() -> encode_rpcb_string(), whose first statement is\nstrlen(string), dereferencing NULL and oopsing the kernel.\n\nThe crash reproduces under failslab on v6.12; with KASAN the NULL\ndereference surfaces as a fault on the shadow of address zero:\n\n Oops: general protection fault, probably for non-canonical address\n 0xdffffc0000000000 [#1] PREEMPT SMP KASAN\n RIP: 0010:strlen (lib/string.c:409)\n Call Trace:\n encode_rpcb_string (net/sunrpc/rpcb_clnt.c:890)\n rpcb_enc_getaddr (net/sunrpc/rpcb_clnt.c:910)\n rpcauth_wrap_req_encode (net/sunrpc/auth.c:745)\n call_encode (net/sunrpc/clnt.c:1966)\n __rpc_execute (net/sunrpc/sched.c:952)\n rpc_run_task (net/sunrpc/clnt.c:1243)\n rpc_call_sync (net/sunrpc/clnt.c:1272)\n rpcb_v4_register (net/sunrpc/rpcb_clnt.c:500)\n svc_generic_rpcbind_set\n nfsd_rpcbind_set\n svc_register\n svc_setup_socket\n svc_addsock\n write_ports\n nfsctl_transaction_write\n vfs_write\n\nThe crash is reachable when an in-kernel RPC service (nfsd, lockd,\nnfs-callback) registers with the local rpcbind under enough memory\npressure for the small GFP_KERNEL kstrdup() in rpc_sockaddr2uaddr() to\nfail. The asynchronous getport path already handles this exact failure\nmode by returning -ENOMEM; only the two register helpers omit the check.\n\nMirror that handling: bail out with -ENOMEM when rpc_sockaddr2uaddr()\nreturns NULL, before the address is fed into the encoder.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11443 |
debian: CVE-2026-89784 was patched at 2026-09-16
2462.
Incorrect Calculation - Unknown Product (CVE-2026-6244) - Low [160]
Description: {'nvd_cve_data_all': 'libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00098, EPSS Percentile is 0.00885 |
debian: CVE-2026-6244 was patched at 2026-09-16
2463.
Incorrect Calculation - Unknown Product (CVE-2026-68767) - Low [160]
Description: {'nvd_cve_data_all': 'hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exactly HCBUFSIZ_LARGE bytes.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exactly HCBUFSIZ_LARGE bytes.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02792 |
debian: CVE-2026-68767 was patched at 2026-08-25
2464.
Memory Corruption - Unknown Product (CVE-2026-31912) - Low [160]
Description: {'nvd_cve_data_all': 'libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading the OS process memory in the 32GiB around the buffer on 64-bit architectures and in the entire address space on 32-bit architectures.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading the OS process memory in the 32GiB around the buffer on 64-bit architectures and in the entire address space on 32-bit architectures.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00098, EPSS Percentile is 0.00884 |
debian: CVE-2026-31912 was patched at 2026-09-16
2465.
Memory Corruption - Unknown Product (CVE-2026-40015) - Low [160]
Description: {'nvd_cve_data_all': 'An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read and crash the process. The crash interrupts hibernated IMAP sessions handled by the affected process, which can cause degradation of service for IMAP. Disable IMAP hibernation. Update to non-vulnerable version. No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read and crash the process. The crash interrupts hibernated IMAP sessions handled by the affected process, which can cause degradation of service for IMAP. Disable IMAP hibernation. Update to non-vulnerable version. No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0029, EPSS Percentile is 0.21622 |
altlinux: CVE-2026-40015 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-40015 was patched at 2026-09-16
2466.
Memory Corruption - Unknown Product (CVE-2026-68768) - Low [160]
Description: {'nvd_cve_data_all': 'hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. When assembling output into a fixed-size buffer (HCBUFSIZ_LARGE, ~16 MB), the function sequentially appends the username, separator, hash, and plaintext via memcpy without validating that the accumulated length stays within the buffer capacity. When run with --username --show against a crafted hash file containing an oversized username that nearly fills the buffer, the total assembled output exceeds the buffer, causing a heap buffer overflow that can corrupt memory and crash the process.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. When assembling output into a fixed-size buffer (HCBUFSIZ_LARGE, ~16 MB), the function sequentially appends the username, separator, hash, and plaintext via memcpy without validating that the accumulated length stays within the buffer capacity. When run with --username --show against a crafted hash file containing an oversized username that nearly fills the buffer, the total assembled output exceeds the buffer, causing a heap buffer overflow that can corrupt memory and crash the process.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00141, EPSS Percentile is 0.03827 |
debian: CVE-2026-68768 was patched at 2026-08-25
2467.
Memory Corruption - Unknown Product (CVE-2026-70654) - Low [160]
Description: {'nvd_cve_data_all': 'libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unusual custom libvips sources and use them to process untrusted uncompressed PPM images can trigger a max/min error in vips_source_read_to_memory in libvips/iofuncs/source.c. The function uses VIPS_MAX instead of VIPS_MIN when selecting the remaining read size, allowing up to 4032 bytes to be written beyond the allocated heap buffer and causing memory corruption or a process crash. This issue is fixed in version 8.18.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unusual custom libvips sources and use them to process untrusted uncompressed PPM images can trigger a max/min error in vips_source_read_to_memory in libvips/iofuncs/source.c. The function uses VIPS_MAX instead of VIPS_MIN when selecting the remaining read size, allowing up to 4032 bytes to be written beyond the allocated heap buffer and causing memory corruption or a process crash. This issue is fixed in version 8.18.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00114, EPSS Percentile is 0.0168 |
debian: CVE-2026-70654 was patched at 2026-08-25
2468.
Memory Corruption - Unknown Product (CVE-2026-75900) - Low [160]
Description: {'nvd_cve_data_all': 'An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the buffer length against sizeof(bh), where bh is a pointer, instead of sizeof(*bh), the actual struct size. This allows an undersized buffer to pass validation, causing a 2-byte heap overread on 64-bit systems (6 bytes on 32-bit) when accessing the totlen field. This may cause daemon termination on some platforms and leaks heap data to the log.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the buffer length against sizeof(bh), where bh is a pointer, instead of sizeof(*bh), the actual struct size. This allows an undersized buffer to pass validation, causing a 2-byte heap overread on 64-bit systems (6 bytes on 32-bit) when accessing the totlen field. This may cause daemon termination on some platforms and leaks heap data to the log.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00111, EPSS Percentile is 0.01518 |
debian: CVE-2026-75900 was patched at 2026-08-20
2469.
Memory Corruption - Unknown Product (CVE-2026-82522) - Low [160]
Description: {'nvd_cve_data_all': 'libjxl before 0.12 contains an integer underflow vulnerability in the container box parser that allows remote attackers to inject arbitrary metadata by exploiting 64-bit box size truncation to size_t on 32-bit platforms. Attackers can supply a crafted JPEG XL file causing the decoder to parse attacker-controlled codestream bytes as phantom box headers, enabling injection of arbitrary metadata (Exif, XMP, IPTC, JUMBF) and potential out-of-bounds reads.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'libjxl before 0.12 contains an integer underflow vulnerability in the container box parser that allows remote attackers to inject arbitrary metadata by exploiting 64-bit box size truncation to size_t on 32-bit platforms. Attackers can supply a crafted JPEG XL file causing the decoder to parse attacker-controlled codestream bytes as phantom box headers, enabling injection of arbitrary metadata (Exif, XMP, IPTC, JUMBF) and potential out-of-bounds reads.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00233, EPSS Percentile is 0.14388 |
debian: CVE-2026-82522 was patched at 2026-09-16
2470.
Memory Corruption - Unknown Product (CVE-2026-90557) - Low [160]
Description: {'nvd_cve_data_all': 'Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-range activity index that bypasses bounds checking and causes a crash or limited heap memory exposure when loaded.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-range activity index that bypasses bounds checking and causes a crash or limited heap memory exposure when loaded.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.02474 |
debian: CVE-2026-90557 was patched at 2026-09-16
2471.
Unknown Vulnerability Type - Rclone (CVE-2026-79777) - Low [159]
Description: {'nvd_cve_data_all': 'rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers, supporting over 40 cloud storage products including S3, Google Drive, Dropbox, OneDrive, and many more. | |
| 0.3 | 10 | CVSS Base Score is 2.7. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00239, EPSS Percentile is 0.15113 |
debian: CVE-2026-79777 was patched at 2026-09-16
2472.
Unknown Vulnerability Type - Rclone (CVE-2026-79779) - Low [159]
Description: {'nvd_cve_data_all': 'rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects. An on-path attacker observing the plaintext hop can capture and reuse credentials to perform WebDAV operations with the compromised account's permissions.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects. An on-path attacker observing the plaintext hop can capture and reuse credentials to perform WebDAV operations with the compromised account's permissions.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers, supporting over 40 cloud storage products including S3, Google Drive, Dropbox, OneDrive, and many more. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00108, EPSS Percentile is 0.01344 |
debian: CVE-2026-79779 was patched at 2026-09-16
2473.
Unknown Vulnerability Type - strongSwan (CVE-2026-78131) - Low [159]
Description: {'nvd_cve_data_all': 'strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | strongSwan is an open source IPsec-based VPN solution that provides secure network connectivity using IKEv1 and IKEv2 protocols, widely used on Linux systems for site-to-site and remote access VPN deployments. | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00231, EPSS Percentile is 0.14033 |
altlinux: CVE-2026-78131 was patched at 2026-09-11
debian: CVE-2026-78131 was patched at 2026-09-07, 2026-09-16
2474.
Unknown Vulnerability Type - IMAP (CVE-2026-61910) - Low [154]
Description: {'nvd_cve_data_all': 'An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annotation. This could allow the sharee to change the shared mailbox to perform the archived, snoozed, or other role, which might cause mail mail to be written to the shared mailbox, sharing more content than intended. (This is likely to be an unusual situation, made more unusual because if the target already has an non-shared mailbox with that role, role duplication suppression will prevent the update.)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annotation. This could allow the sharee to change the shared mailbox to perform the archived, snoozed, or other role, which might cause mail mail to be written to the shared mailbox, sharing more content than intended. (This is likely to be an unusual situation, made more unusual because if the target already has an non-shared mailbox with that role, role duplication suppression will prevent the update.)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:cyrus:imap (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00188, EPSS Percentile is 0.08654 |
debian: CVE-2026-61910 was patched at 2026-09-16
2475.
Unknown Vulnerability Type - Morgan (CVE-2026-15603) - Low [154]
Description: {'nvd_cve_data_all': 'morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line Separator), and U+2029 (Paragraph Separator). An unauthenticated remote client can place these characters in an attacker-controlled log token, for example a Basic auth username surfaced through the remote-user token, so that Unicode-aware downstream log processing splits a single request log into multiple logical records. This is a log forging issue (CWE-117) and an incomplete-fix follow-up to CVE-2026-5078, which only addressed ASCII control characters. The issue is fixed in morgan 1.12.0, which extends the escaping set to cover these Unicode line separators. Upgrade to morgan 1.12.0 to remediate.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line Separator), and U+2029 (Paragraph Separator). An unauthenticated remote client can place these characters in an attacker-controlled log token, for example a Basic auth username surfaced through the remote-user token, so that Unicode-aware downstream log processing splits a single request log into multiple logical records. This is a log forging issue (CWE-117) and an incomplete-fix follow-up to CVE-2026-5078, which only addressed ASCII control characters. The issue is fixed in morgan 1.12.0, which extends the escaping set to cover these Unicode line separators. Upgrade to morgan 1.12.0 to remediate.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:morgan_project:morgan (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.14601 |
debian: CVE-2026-15603 was patched at 2026-09-16
2476.
Unknown Vulnerability Type - Nodemailer (CVE-2026-82660) - Low [154]
Description: {'nvd_cve_data_all': 'Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Nodemailer is a Node.js module for sending email, supporting SMTP, message composition, attachments, and multiple transport mechanisms. | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00189, EPSS Percentile is 0.08753 |
debian: CVE-2026-82660 was patched at 2026-09-16
2477.
Unknown Vulnerability Type - Nodemailer (CVE-2026-82661) - Low [154]
Description: {'nvd_cve_data_all': 'Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail client behavior and message semantics.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail client behavior and message semantics.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Nodemailer is a Node.js module for sending email, supporting SMTP, message composition, attachments, and multiple transport mechanisms. | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0019, EPSS Percentile is 0.08867 |
debian: CVE-2026-82661 was patched at 2026-09-16
2478.
Unknown Vulnerability Type - Unknown Product (CVE-2026-89259) - Low [154]
Description: {'nvd_cve_data_all': 'Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --allow-child-process, --allow-worker). As a result, the restrictions intended by the fix for GHSA-x597-9fr4-5857 could still be bypassed, allowing a Node tool invoked during a build to read and write files outside the project's working directory. Affected versions are those after v0.43; the issue was fixed in v0.165.0 by removing tailwindcss from the default security.exec.allow list. Users who do not use TailwindCSS, or who only build trusted sites, are not affected. As a workaround, users can define a restrictive security.exec.allow list in hugo.toml.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --allow-child-process, --allow-worker). As a result, the restrictions intended by the fix for GHSA-x597-9fr4-5857 could still be bypassed, allowing a Node tool invoked during a build to read and write files outside the project's working directory. Affected versions are those after v0.43; the issue was fixed in v0.165.0 by removing tailwindcss from the default security.exec.allow list. Users who do not use TailwindCSS, or who only build trusted sites, are not affected. As a workaround, users can define a restrictive security.exec.allow list in hugo.toml.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00411, EPSS Percentile is 0.34864 |
debian: CVE-2026-89259 was patched at 2026-09-16
2479.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64596) - Low [150]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: libfs: set SB_I_NOEXEC and SB_I_NODEV by default in init_pseudo() Since commit 1e7ab6f67824 ("anon_inode: rework assertions"), path_noexec() warns when an anonymous-inode file is mmap'd from a superblock that has not set SB_I_NOEXEC. dma-buf backs its files this way and never set the flag, so mmap of any exported buffer trips the warning on a CONFIG_DEBUG_VFS=y kernel: WARNING: CPU: 11 PID: 121813 at fs/exec.c:118 path_noexec+0x47/0x50 do_mmap+0x2b5/0x680 vm_mmap_pgoff+0x129/0x210 ksys_mmap_pgoff+0x177/0x240 __x64_sys_mmap+0x33/0x70 init_pseudo() sets up internal SB_NOUSER mounts that are never path-reachable. Set both flags here so every pseudo filesystem gets them by default instead of each caller setting them. SB_I_NODEV is inert for unreachable mounts. SB_I_NOEXEC has one visible effect: an executable mapping of a pseudo-fs fd, such as a dma-buf, now fails with -EPERM, which is the invariant the assertion enforces. No in-tree caller maps these executable. Reproduce on CONFIG_DEBUG_VFS=y: make -C tools/testing/selftests/dmabuf-heaps sudo ./tools/testing/selftests/dmabuf-heaps/dmabuf-heap -t system', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nlibfs: set SB_I_NOEXEC and SB_I_NODEV by default in init_pseudo()\n\nSince commit 1e7ab6f67824 ("anon_inode: rework assertions"),\npath_noexec() warns when an anonymous-inode file is mmap'd from a\nsuperblock that has not set SB_I_NOEXEC. dma-buf backs its files this\nway and never set the flag, so mmap of any exported buffer trips the\nwarning on a CONFIG_DEBUG_VFS=y kernel:\n\n WARNING: CPU: 11 PID: 121813 at fs/exec.c:118 path_noexec+0x47/0x50\n do_mmap+0x2b5/0x680\n vm_mmap_pgoff+0x129/0x210\n ksys_mmap_pgoff+0x177/0x240\n __x64_sys_mmap+0x33/0x70\n\ninit_pseudo() sets up internal SB_NOUSER mounts that are never\npath-reachable. Set both flags here so every pseudo filesystem gets\nthem by default instead of each caller setting them.\n\nSB_I_NODEV is inert for unreachable mounts. SB_I_NOEXEC has one\nvisible effect: an executable mapping of a pseudo-fs fd, such as a\ndma-buf, now fails with -EPERM, which is the invariant the assertion\nenforces. No in-tree caller maps these executable.\n\nReproduce on CONFIG_DEBUG_VFS=y:\n\n make -C tools/testing/selftests/dmabuf-heaps\n sudo ./tools/testing/selftests/dmabuf-heaps/dmabuf-heap -t system', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.0 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.0499 |
ubuntu: CVE-2026-64596 was patched at 2026-09-07, 2026-09-16
2480.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80705) - Low [150]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: check if dml21_add_phantom_plane() is successful Verify that the phantom plane was allocated to avoid a later segfault. (cherry picked from commit 5adb54abe5a8e82cbff7f8806db30a5f4924329f)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: check if dml21_add_phantom_plane() is successful\n\nVerify that the phantom plane was allocated to avoid a later\nsegfault.\n\n(cherry picked from commit 5adb54abe5a8e82cbff7f8806db30a5f4924329f)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.0 | 10 | EPSS Probability is 0.00145, EPSS Percentile is 0.04113 |
debian: CVE-2026-80705 was patched at 2026-09-16
2481.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80860) - Low [150]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fuse: fix race between interrupt and resend After commit f8fce75fedf7 ("fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req") the WARN_ON(!list_empty(&req->intr_entry)) in fuse_request_free() still triggers due to the following race: In request_wait_answer() if (test_bit(FR_SENT, &req->flags)) -> returns true In fuse_chan_resend() clear_bit(FR_SENT, &req->flags) In request_wait_answer() queue_interrupt(req) Fix by: - move clearing FR_SENT inside fpq->lock - move setting FR_PENDING inside fiq->lock - recheck FR_SENT after acquiring fiq->lock in fuse_dev_queue_interrupt()', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: fix race between interrupt and resend\n\nAfter commit f8fce75fedf7 ("fuse: clear intr_entry in fuse_resend and\nfuse_remove_pending_req") the WARN_ON(!list_empty(&req->intr_entry)) in\nfuse_request_free() still triggers due to the following race:\n\nIn request_wait_answer()\n if (test_bit(FR_SENT, &req->flags)) -> returns true\n\nIn fuse_chan_resend()\n clear_bit(FR_SENT, &req->flags)\n\nIn request_wait_answer()\n queue_interrupt(req)\n\nFix by:\n\n - move clearing FR_SENT inside fpq->lock\n\n - move setting FR_PENDING inside fiq->lock\n\n - recheck FR_SENT after acquiring fiq->lock in fuse_dev_queue_interrupt()', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.0 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.04991 |
debian: CVE-2026-80860 was patched at 2026-09-16
2482.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80866) - Low [150]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: tipc: avoid busy looping in tipc_exit_net() Blamed commit introduced a busy-wait loop in tipc_exit_net() to wait for pending UDP bearer cleanup works to complete: while (atomic_read(&tn->wq_count)) cond_resched(); This loop can busy-wait for a long time if cond_resched() is a NOP. This typically happens if the netns exit is executed by a high priority task, or under kernels configured without preemption (CONFIG_PREEMPT_NONE). In such cases, it wastes CPU cycles and can lead to soft lockups. Fix this by replacing the busy loop with wait_var_event(), allowing the thread to sleep properly until the work queue count reaches zero. Accordingly, update cleanup_bearer() to use atomic_dec_and_test() and wake_up_var() to wake up the waiter when the count drops to zero. This uses the global wait queue hash table, avoiding the need to bloat struct tipc_net with a wait_queue_head_t. The atomic_dec_and_test() provides the necessary memory barrier to ensure the wakeup is not missed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: avoid busy looping in tipc_exit_net()\n\nBlamed commit introduced a busy-wait loop in tipc_exit_net()\nto wait for pending UDP bearer cleanup works to complete:\n\n while (atomic_read(&tn->wq_count))\n cond_resched();\n\nThis loop can busy-wait for a long time if cond_resched() is a NOP. This\ntypically happens if the netns exit is executed by a high priority task,\nor under kernels configured without preemption (CONFIG_PREEMPT_NONE). In\nsuch cases, it wastes CPU cycles and can lead to soft lockups.\n\nFix this by replacing the busy loop with wait_var_event(), allowing the\nthread to sleep properly until the work queue count reaches zero.\n\nAccordingly, update cleanup_bearer() to use atomic_dec_and_test() and\nwake_up_var() to wake up the waiter when the count drops to zero.\n\nThis uses the global wait queue hash table, avoiding the need to bloat\nstruct tipc_net with a wait_queue_head_t. The atomic_dec_and_test()\nprovides the necessary memory barrier to ensure the wakeup is not missed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.0 | 10 | EPSS Probability is 0.00145, EPSS Percentile is 0.04141 |
debian: CVE-2026-80866 was patched at 2026-09-16
2483.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80872) - Low [150]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/tas2781: Cancel async firmware request at unbind TAS2781 HDA I2C and SPI queue RCA firmware loading from component bind with request_firmware_nowait(). The firmware loader keeps the callback module pinned and holds a device reference, but the callback still uses driver-private HDA state. Component unbind removes controls and DSP state immediately. Later device removal tears down the TAS2781 private data, including codec_lock. If the async firmware callback runs after unbind has started, it can operate on state that is being torn down. Cancel or synchronize the async firmware request before removing controls and DSP state. A queued callback is cancelled, and an already-running callback is allowed to finish before unbind continues.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda/tas2781: Cancel async firmware request at unbind\n\nTAS2781 HDA I2C and SPI queue RCA firmware loading from component\nbind with request_firmware_nowait(). The firmware loader keeps the\ncallback module pinned and holds a device reference, but the callback\nstill uses driver-private HDA state.\n\nComponent unbind removes controls and DSP state immediately. Later\ndevice removal tears down the TAS2781 private data, including\ncodec_lock. If the async firmware callback runs after unbind has\nstarted, it can operate on state that is being torn down.\n\nCancel or synchronize the async firmware request before removing\ncontrols and DSP state. A queued callback is cancelled, and an\nalready-running callback is allowed to finish before unbind continues.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.0 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.04991 |
debian: CVE-2026-80872 was patched at 2026-09-16
2484.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80899) - Low [150]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: erofs: remove fscache backend entirely EROFS over fscache was introduced to provide image lazy pulling functionality. After the feature landed, the fscache subsystem made netfs a new hard dependency, which is unexpected for a local filesystem and has an kernel-defined caching hierarchy which could be inflexible compared to the fanotify pre-content hooks. Therefore, this feature has been deprecated for almost two years. As EROFS file-backed mounts and fanotify pre-content hooks both upstream for a while and already providing equivalent functionality (erofs-utils has supported fanotify pre-content hooks), let's remove the fscache backend now. The main application of this feature is Nydus [1], and they plan to move to use fanotify pre-content hooks in the near future too. I hope this patch can be merged into Linux 7.2, which is also motivated by newly found implementation issues [2][3] that are not worth investigating given the deprecation and limited development resources. The associated fscache/cachefiles cleanup patch will follow separately through the vfs tree (netfs) later: it seems fine since the codebase is isolated by CONFIG_CACHEFILES_ONDEMAND. [1] https://github.com/dragonflyoss/nydus/blob/v2.1.0/docs/nydus-fscache.md [2] https://github.com/dragonflyoss/nydus/pull/1824 [3] https://lore.kernel.org/r/20260619135800.1594811-1-michael.bommarito@gmail.com', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: remove fscache backend entirely\n\nEROFS over fscache was introduced to provide image lazy pulling\nfunctionality. After the feature landed, the fscache subsystem made\nnetfs a new hard dependency, which is unexpected for a local filesystem\nand has an kernel-defined caching hierarchy which could be inflexible\ncompared to the fanotify pre-content hooks. Therefore, this feature has\nbeen deprecated for almost two years.\n\nAs EROFS file-backed mounts and fanotify pre-content hooks both upstream\nfor a while and already providing equivalent functionality (erofs-utils\nhas supported fanotify pre-content hooks), let's remove the fscache\nbackend now.\n\nThe main application of this feature is Nydus [1], and they plan to move\nto use fanotify pre-content hooks in the near future too.\n\nI hope this patch can be merged into Linux 7.2, which is also motivated\nby newly found implementation issues [2][3] that are not worth\ninvestigating given the deprecation and limited development resources.\nThe associated fscache/cachefiles cleanup patch will follow separately\nthrough the vfs tree (netfs) later: it seems fine since the codebase is\nisolated by CONFIG_CACHEFILES_ONDEMAND.\n\n[1] https://github.com/dragonflyoss/nydus/blob/v2.1.0/docs/nydus-fscache.md\n[2] https://github.com/dragonflyoss/nydus/pull/1824\n[3] https://lore.kernel.org/r/20260619135800.1594811-1-michael.bommarito@gmail.com', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.0 | 10 | EPSS Probability is 0.00145, EPSS Percentile is 0.04177 |
debian: CVE-2026-80899 was patched at 2026-09-16
2485.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80905) - Low [150]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: tap: fix wrong transport_header when sending VLAN-tagged frame In tap_get_user_xdp(), when processing a VLAN-tagged frame (e.g. ETH_P_8021Q), skb_set_network_header() is called first to advance network_header past the VLAN tag to the inner protocol header. skb_probe_transport_header() is then called with skb->protocol still set to ETH_P_8021Q, while nhoff (derived from skb_network_offset()) already points past the VLAN tag to the inner protocol header. In __skb_flow_dissect(), proto is initialized to ETH_P_8021Q and nhoff points past the VLAN tag. When the dissector hits case ETH_P_8021Q, it reads a struct vlan_hdr at the current nhoff via __skb_header_pointer(), but that offset contains the inner protocol header (e.g. an IP header). The bytes are misinterpreted as a VLAN header, yielding a garbage encapsulated EtherType that matches no known protocol. The dissector returns false, so skb_probe_transport_header() never calls skb_set_transport_header(), leaving transport_header at its uninitialized sentinel value (~0U). Move skb_set_network_header() to after skb_probe_transport_header(). At the time skb_probe_transport_header() is called, network_header still points to the VLAN header (offset ETH_HLEN), so nhoff is correct and the flow dissector can parse the VLAN header, extract the inner EtherType, and advance nhoff to the inner protocol header, allowing transport_header to be set correctly.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tap: fix wrong transport_header when sending VLAN-tagged frame\n\nIn tap_get_user_xdp(), when processing a VLAN-tagged frame (e.g.\nETH_P_8021Q), skb_set_network_header() is called first to advance\nnetwork_header past the VLAN tag to the inner protocol header.\nskb_probe_transport_header() is then called with skb->protocol still\nset to ETH_P_8021Q, while nhoff (derived from skb_network_offset())\nalready points past the VLAN tag to the inner protocol header.\n\nIn __skb_flow_dissect(), proto is initialized to ETH_P_8021Q and nhoff\npoints past the VLAN tag. When the dissector hits case ETH_P_8021Q, it\nreads a struct vlan_hdr at the current nhoff via __skb_header_pointer(),\nbut that offset contains the inner protocol header (e.g. an IP header).\nThe bytes are misinterpreted as a VLAN header, yielding a garbage\nencapsulated EtherType that matches no known protocol. The dissector\nreturns false, so skb_probe_transport_header() never calls\nskb_set_transport_header(), leaving transport_header at its uninitialized\nsentinel value (~0U).\n\nMove skb_set_network_header() to after skb_probe_transport_header(). At\nthe time skb_probe_transport_header() is called, network_header still\npoints to the VLAN header (offset ETH_HLEN), so nhoff is correct and the\nflow dissector can parse the VLAN header, extract the inner EtherType,\nand advance nhoff to the inner protocol header, allowing transport_header\nto be set correctly.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.0 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.04991 |
debian: CVE-2026-80905 was patched at 2026-09-16
2486.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-80925) - Low [150]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: vlan: fix skb_under_panic and races when toggling HW VLAN offload Toggling hardware VLAN TX offload (NETIF_F_HW_VLAN_CTAG_TX or NETIF_F_HW_VLAN_STAG_TX) on a lower device invokes vlan_transfer_features(), which dynamically changed vlandev->hard_header_len. This causes two issues: 1. Lockless TX paths (e.g. packet_snd in af_packet.c, ip6_finish_output2) read dev->hard_header_len without holding RTNL lock. Mutating hard_header_len dynamically under RTNL creates a data race where upper layers reserve insufficient headroom based on a stale hard_header_len, resulting in skb_under_panic when vlan_dev_hard_header() is called. 2. In addition, vlan_transfer_features() updated hard_header_len without updating header_ops, causing a mismatch between allocated headroom and header creation. Always setting dev->hard_header_len = real_dev->hard_header_len and dev->needed_headroom = real_dev->needed_headroom + VLAN_HLEN unconditionally ensures: - dev->hard_header_len remains 100% static and immutable at real_dev->hard_header_len, eliminating all dynamic runtime updates and data races on hard_header_len. - Upper layers allocating skbs via LL_RESERVED_SPACE() will always reserve sufficient headroom for software VLAN tag insertion (real_dev->hard_header_len + real_dev->needed_headroom + VLAN_HLEN). - vlandev inherits real_dev->needed_tailroom so underlying trailer/padding/ICV requirements are honored. - AF_PACKET SOCK_RAW network header offsets remain correctly aligned at real_dev->hard_header_len. - vlan_header_ops is used unconditionally. Note to stable teams: Make sure to backport these commits: e16e960d55a4 ("ipvlan: inherit needed_headroom and needed_tailroom from phy_dev") cef51860becd ("macvlan: inherit needed_headroom and needed_tailroom from lowerdev")', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvlan: fix skb_under_panic and races when toggling HW VLAN offload\n\nToggling hardware VLAN TX offload (NETIF_F_HW_VLAN_CTAG_TX or\nNETIF_F_HW_VLAN_STAG_TX) on a lower device invokes vlan_transfer_features(),\nwhich dynamically changed vlandev->hard_header_len.\n\nThis causes two issues:\n1. Lockless TX paths (e.g. packet_snd in af_packet.c, ip6_finish_output2)\n read dev->hard_header_len without holding RTNL lock. Mutating\n hard_header_len dynamically under RTNL creates a data race where upper\n layers reserve insufficient headroom based on a stale hard_header_len,\n resulting in skb_under_panic when vlan_dev_hard_header() is called.\n2. In addition, vlan_transfer_features() updated hard_header_len without\n updating header_ops, causing a mismatch between allocated headroom\n and header creation.\n\nAlways setting dev->hard_header_len = real_dev->hard_header_len and\ndev->needed_headroom = real_dev->needed_headroom + VLAN_HLEN unconditionally\nensures:\n- dev->hard_header_len remains 100% static and immutable at real_dev->hard_header_len,\n eliminating all dynamic runtime updates and data races on hard_header_len.\n- Upper layers allocating skbs via LL_RESERVED_SPACE() will always reserve\n sufficient headroom for software VLAN tag insertion (real_dev->hard_header_len +\n real_dev->needed_headroom + VLAN_HLEN).\n- vlandev inherits real_dev->needed_tailroom so underlying trailer/padding/ICV\n requirements are honored.\n- AF_PACKET SOCK_RAW network header offsets remain correctly aligned at\n real_dev->hard_header_len.\n- vlan_header_ops is used unconditionally.\n\nNote to stable teams: Make sure to backport these commits:\n\ne16e960d55a4 ("ipvlan: inherit needed_headroom and needed_tailroom from phy_dev")\ncef51860becd ("macvlan: inherit needed_headroom and needed_tailroom from lowerdev")', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.0 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.04993 |
debian: CVE-2026-80925 was patched at 2026-09-16
2487.
Denial of Service - Unknown Product (CVE-2026-18743) - Low [148]
Description: {'nvd_cve_data_all': 'A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.2 | 10 | CVSS Base Score is 2.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00141, EPSS Percentile is 0.03814 |
debian: CVE-2026-18743 was patched at 2026-09-16
2488.
Incorrect Calculation - Unknown Product (CVE-2026-72854) - Low [148]
Description: {'nvd_cve_data_all': 'msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_buffer API, computes its new buffer size using an unchecked size_t addition of the requested size and the amount already used. The doubling loop guards its own multiplication against overflow, but the addition in the loop condition is unguarded, so a request near SIZE_MAX wraps: the loop condition is already satisfied, the allocation is performed at the small pre-wrap size, and the function returns true. The caller is told the requested capacity was reserved when it was not, so a subsequent write of the requested length overflows the heap buffer. The library's own example/lib_buffer_unpack.c demonstrates the reserve-then-write pattern, and its defensive assert comparing capacity against the request is compiled out under NDEBUG. msgpack-c's own decode entry points do not derive the reservation size from untrusted input, so reaching this requires an integration that passes an attacker-influenced length to the reservation API, such as a length-prefixed streaming transport.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_buffer API, computes its new buffer size using an unchecked size_t addition of the requested size and the amount already used. The doubling loop guards its own multiplication against overflow, but the addition in the loop condition is unguarded, so a request near SIZE_MAX wraps: the loop condition is already satisfied, the allocation is performed at the small pre-wrap size, and the function returns true. The caller is told the requested capacity was reserved when it was not, so a subsequent write of the requested length overflows the heap buffer. The library's own example/lib_buffer_unpack.c demonstrates the reserve-then-write pattern, and its defensive assert comparing capacity against the request is compiled out under NDEBUG. msgpack-c's own decode entry points do not derive the reservation size from untrusted input, so reaching this requires an integration that passes an attacker-influenced length to the reservation API, such as a length-prefixed streaming transport.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00113, EPSS Percentile is 0.01592 |
debian: CVE-2026-72854 was patched at 2026-08-25
2489.
Memory Corruption - Unknown Product (CVE-2026-18313) - Low [148]
Description: {'nvd_cve_data_all': 'rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use. A malicious client can cause the server to leak memory substantially faster.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use. A malicious client can cause the server to leak memory substantially faster.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00212, EPSS Percentile is 0.11717 |
debian: CVE-2026-18313 was patched at 2026-09-16
2490.
Memory Corruption - Unknown Product (CVE-2026-73324) - Low [148]
Description: {'nvd_cve_data_all': 'Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build configuration.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build configuration.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00213, EPSS Percentile is 0.11736 |
debian: CVE-2026-73324 was patched at 2026-09-16
2491.
Memory Corruption - Unknown Product (CVE-2026-82631) - Low [148]
Description: {'nvd_cve_data_all': 'A security flaw has been discovered in valkey-io valkey 9.1.0. The affected element is the function handleClientsBlockedOnKey of the file src/blocked.c of the component Blocked-on-keys Subsystem. The manipulation results in use after free. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit has been released to the public and may be used for attacks. The patch is identified as b2fb0e13f5b4c8c2fb63dcfc2c37a067a0d6d20b. Applying a patch is advised to resolve this issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A security flaw has been discovered in valkey-io valkey 9.1.0. The affected element is the function handleClientsBlockedOnKey of the file src/blocked.c of the component Blocked-on-keys Subsystem. The manipulation results in use after free. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit has been released to the public and may be used for attacks. The patch is identified as b2fb0e13f5b4c8c2fb63dcfc2c37a067a0d6d20b. Applying a patch is advised to resolve this issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.2 | 10 | CVSS Base Score is 2.2. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00358, EPSS Percentile is 0.29426 |
debian: CVE-2026-82631 was patched at 2026-09-16
2492.
Memory Corruption - Unknown Product (CVE-2026-87736) - Low [148]
Description: {'nvd_cve_data_all': 'An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00212, EPSS Percentile is 0.11683 |
debian: CVE-2026-87736 was patched at 2026-09-16
2493.
Memory Corruption - Unknown Product (CVE-2026-90682) - Low [148]
Description: {'nvd_cve_data_all': 'A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS_LONG leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS_LONG leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.02464 |
debian: CVE-2026-90682 was patched at 2026-09-16
2494.
Unknown Vulnerability Type - MongoDB (CVE-2026-81523) - Low [147]
Description: {'nvd_cve_data_all': 'A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied database identifier to be accepted without sanitization. The resulting impact is limited to incorrect schema selection, which may lead to limited disclosure or modification of information handled by the application.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied database identifier to be accepted without sanitization. The resulting impact is limited to incorrect schema selection, which may lead to limited disclosure or modification of information handled by the application.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | MongoDB is a source-available, cross-platform, document-oriented database program | |
| 0.4 | 10 | CVSS Base Score is 4.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00074, EPSS Percentile is 0.00088 |
debian: CVE-2026-81523 was patched at 2026-09-16
2495.
Unknown Vulnerability Type - Rclone (CVE-2026-79783) - Low [147]
Description: {'nvd_cve_data_all': 'rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservation from an untrusted remote, attackers can plant a setuid binary that escalates privileges to root if rclone runs as root, or to the service account user otherwise.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservation from an untrusted remote, attackers can plant a setuid binary that escalates privileges to root if rclone runs as root, or to the service account user otherwise.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers, supporting over 40 cloud storage products including S3, Google Drive, Dropbox, OneDrive, and many more. | |
| 0.4 | 10 | CVSS Base Score is 3.6. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0014, EPSS Percentile is 0.03758 |
debian: CVE-2026-79783 was patched at 2026-09-16
2496.
Unknown Vulnerability Type - Vault (CVE-2026-84962) - Low [147]
Description: {'nvd_cve_data_all': 'An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's identity, escalating database-level access into cloud key control and defeating client-side encryption.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's identity, escalating database-level access into cloud key control and defeating client-side encryption.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Vault secures, stores, and tightly controls access to tokens, passwords, certificates, API keys, and other secrets critical in modern computing | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.01898 |
debian: CVE-2026-84962 was patched at 2026-09-16
2497.
Unknown Vulnerability Type - libheif (CVE-2026-84450) - Low [147]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, a crafted image item containing a clap property and an ispe width or height greater than INT32_MAX + 1 can reach crop calculations through heif_image_handle_get_image_tiling(). Box_clap::left_rounded() or Box_clap::top_rounded() passes the image dimension minus one to Fraction::Fraction(), whose uint32_t constructor uses an assertion as input validation, causing assert-enabled builds to abort. Release builds can instead compute invalid crop geometry, and the tiling API returns dimensions that the normal decode security limits reject. This issue is fixed in version 1.23.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | libheif is an open source HEIF and AVIF image file format decoder and encoder library, supporting modern image codecs and container features. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-84450 was patched at 2026-09-16
2498.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-92031) - Low [145]
Description: {'nvd_cve_data_all': 'Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05182 |
altlinux: CVE-2026-92031 was patched at 2026-09-16
debian: CVE-2026-92031 was patched at 2026-09-16, 2026-09-17
2499.
Unknown Vulnerability Type - IMAP (CVE-2026-61909) - Low [142]
Description: {'nvd_cve_data_all': 'An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a calendar-multiget or addressbook-multiget REPORT.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a calendar-multiget or addressbook-multiget REPORT.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:cyrus:imap (exists in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00204, EPSS Percentile is 0.10625 |
debian: CVE-2026-61909 was patched at 2026-09-16
2500.
Unknown Vulnerability Type - IMAP (CVE-2026-61911) - Low [142]
Description: {'nvd_cve_data_all': 'An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which fileinto branch fired during LMTP delivery.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which fileinto branch fired during LMTP delivery.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:cyrus:imap (exists in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00217, EPSS Percentile is 0.1233 |
debian: CVE-2026-61911 was patched at 2026-09-16
2501.
Unknown Vulnerability Type - Suricata (CVE-2026-57222) - Low [142]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, crafted IPv4 and IPv6 address pairs can collide in the IPPair hash because src/ippair.c did not compare the IP address family before reusing IPPair-backed state. This can apply state from one IP family to another for xbits track ip_pair, FTP data expectations, and, on the 7.0 release line, thresholding, detection_filter, and rate_filter rules using track by_both, causing incorrect detection state. This issue is fixed in versions 8.0.6 and 7.0.17.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Suricata is an open-source intrusion detection and prevention system (IDS/IPS) and network security monitoring engine that supports deep packet inspection and threat detection. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-57222 was patched at 2026-09-16
2502.
Unknown Vulnerability Type - Suricata (CVE-2026-57229) - Low [142]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SMTP MIME parser in rust/src/mime/smtp.rs does not fully reset state when processing Content-Type: message/rfc822 encapsulation. An outer MIME part's encoding or filename state can leak into the inner message, allowing crafted mail to evade detections based on file.data, file.name, or extracted URLs when SMTP MIME decoding is enabled. This issue is fixed in version 8.0.6.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Suricata is an open-source intrusion detection and prevention system (IDS/IPS) and network security monitoring engine that supports deep packet inspection and threat detection. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-57229 was patched at 2026-09-16
2503.
Unknown Vulnerability Type - Unknown Product (CVE-2026-72818) - Low [142]
Description: {'nvd_cve_data_all': 'The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\\-][a-z0-9]+)* is unbounded. Input consisting of many alternating label separators can be partitioned in exponentially many ways, and because the branch also requires a trailing top-level domain that such input never supplies, the engine explores those partitions before failing at each offset. A few kilobytes of input therefore consumes seconds to minutes of single-threaded CPU, and the HANG_RE substitution performed before matching does not collapse the pattern. TweetTokenizer is intended for tokenizing untrusted social-media text, so any service that applies it, or the module-level casual_tokenize, to submitted text can be stalled per request without authentication. Version 3.10.1 bounds the label repetition.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\\-][a-z0-9]+)* is unbounded. Input consisting of many alternating label separators can be partitioned in exponentially many ways, and because the branch also requires a trailing top-level domain that such input never supplies, the engine explores those partitions before failing at each offset. A few kilobytes of input therefore consumes seconds to minutes of single-threaded CPU, and the HANG_RE substitution performed before matching does not collapse the pattern. TweetTokenizer is intended for tokenizing untrusted social-media text, so any service that applies it, or the module-level casual_tokenize, to submitted text can be stalled per request without authentication. Version 3.10.1 bounds the label repetition.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00505, EPSS Percentile is 0.41904 |
debian: CVE-2026-72818 was patched at 2026-08-25
2504.
Unknown Vulnerability Type - Unknown Product (CVE-2026-76878) - Low [142]
Description: {'nvd_cve_data_all': 'In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked policy enforcement since its introduction in the Ussuri release (Watcher 4.0.0).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false value removes the key and skips the branch that normally restricts results to the caller's project. A non-admin user with the reader role can list alarms from all projects, exposing alarm actions containing trust webhook URLs, Heat signal endpoints, project IDs, and user IDs. The parameter can also be combined with a foreign project_id to target a specific project's alarms. A related concern is that OpenStack Watcher does not apply authorization to its webhook trigger endpoint. Any authenticated user who learns an audit's webhook URL, for example from this leaked Aodh alarm metadata, can start an EVENT audit and its associated action plan regardless of their own project or role. The webhook endpoint has lacked policy enforcement since its introduction in the Ussuri release (Watcher 4.0.0).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00476, EPSS Percentile is 0.40013 |
debian: CVE-2026-76878 was patched at 2026-08-25
2505.
Unknown Vulnerability Type - Unknown Product (CVE-2026-80182) - Low [142]
Description: {'nvd_cve_data_all': 'In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain them. The delegation restrictions that block these operations did not consistently apply to all delegated token types, allowing an OAuth1-scoped token, for example, to create application credentials or authorize OAuth1 request tokens despite those operations being restricted for other delegated token types. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain them. The delegation restrictions that block these operations did not consistently apply to all delegated token types, allowing an OAuth1-scoped token, for example, to create application credentials or authorize OAuth1 request tokens despite those operations being restricted for other delegated token types. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.6. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00505, EPSS Percentile is 0.41939 |
debian: CVE-2026-80182 was patched at 2026-09-01, 2026-09-16
2506.
Unknown Vulnerability Type - Unknown Product (CVE-2026-80184) - Low [142]
Description: {'nvd_cve_data_all': 'In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) could be submitted to the token-method authentication path for reauthentication to escape their intended project scope. When an application credential token was presented with no explicit scope, Keystone would issue a new token scoped to the credential owner's default project rather than the project for which the credential was issued, bypassing the intended project boundary. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) could be submitted to the token-method authentication path for reauthentication to escape their intended project scope. When an application credential token was presented with no explicit scope, Keystone would issue a new token scoped to the credential owner's default project rather than the project for which the credential was issued, bypassing the intended project boundary. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.6. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00513, EPSS Percentile is 0.42421 |
debian: CVE-2026-80184 was patched at 2026-09-01, 2026-09-16
2507.
Memory Corruption - Unknown Product (CVE-2026-63632) - Low [136]
Description: {'nvd_cve_data_all': 'Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a Gemm node has input tensors with fewer than two dimensions because B_shape[1], A_shape[0], or A_shape[1] is accessed without a rank check, potentially causing a process crash during an opset 7 to 6 downgrade. This issue is fixed in version 1.22.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a Gemm node has input tensors with fewer than two dimensions because B_shape[1], A_shape[0], or A_shape[1] is accessed without a rank check, potentially causing a process crash during an opset 7 to 6 downgrade. This issue is fixed in version 1.22.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00163, EPSS Percentile is 0.05913 |
debian: CVE-2026-63632 was patched at 2026-08-25
2508.
Memory Corruption - Unknown Product (CVE-2026-82677) - Low [136]
Description: {'nvd_cve_data_all': 'A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: b349fe2821e3998534b1454c1b64a478daf8c6b7. To fix this issue, it is recommended to deploy a patch.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: b349fe2821e3998534b1454c1b64a478daf8c6b7. To fix this issue, it is recommended to deploy a patch.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.2 | 10 | CVSS Base Score is 2.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00288, EPSS Percentile is 0.21414 |
debian: CVE-2026-82677 was patched at 2026-09-16
2509.
Memory Corruption - Unknown Product (CVE-2026-91826) - Low [136]
Description: {'nvd_cve_data_all': 'Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b8213279e9e8b71e39.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations.\n\n\nThis issue affects rLottie: 480a2ad0c5d2e45458c545b8213279e9e8b71e39.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0011, EPSS Percentile is 0.01463 |
debian: CVE-2026-91826 was patched at 2026-09-16
2510.
Unknown Vulnerability Type - ImageMagick (CVE-2026-86422) - Low [135]
Description: {'nvd_cve_data_all': 'ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap symlinks between policy validation and file access to read or write policy-denied files.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap symlinks between policy validation and file access to read or write policy-denied files.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00103, EPSS Percentile is 0.0108 |
altlinux: CVE-2026-86422 was patched at 2026-08-31
2511.
Unknown Vulnerability Type - Python (CVE-2026-68939) - Low [135]
Description: {'nvd_cve_data_all': 'Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read accepts shell glob metacharacters in .python-version values, and unquoted PYENV_VERSION expansion in libexec/pyenv-version-name, libexec/pyenv-which, libexec/pyenv-prefix, libexec/pyenv-local, libexec/pyenv-global, libexec/pyenv-version, and libexec/pyenv-versions pathname-expands the value against the current directory, allowing a matching attacker-controlled file to silently select a different installed interpreter or version. This issue is fixed in version 2.8.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read accepts shell glob metacharacters in .python-version values, and unquoted PYENV_VERSION expansion in libexec/pyenv-version-name, libexec/pyenv-which, libexec/pyenv-prefix, libexec/pyenv-local, libexec/pyenv-global, libexec/pyenv-version, and libexec/pyenv-versions pathname-expands the value against the current directory, allowing a matching attacker-controlled file to silently select a different installed interpreter or version. This issue is fixed in version 2.8.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.2 | 10 | CVSS Base Score is 2.0. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00171, EPSS Percentile is 0.06756 |
debian: CVE-2026-68939 was patched at 2026-08-20
2512.
Unknown Vulnerability Type - Rclone (CVE-2026-79782) - Low [135]
Description: {'nvd_cve_data_all': 'rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request headers.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request headers.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers, supporting over 40 cloud storage products including S3, Google Drive, Dropbox, OneDrive, and many more. | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00132, EPSS Percentile is 0.03128 |
debian: CVE-2026-79782 was patched at 2026-09-16
2513.
Unknown Vulnerability Type - Unknown Product (CVE-2026-56854) - Low [130]
Description: {'nvd_cve_data_all': 'The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.256 |
debian: CVE-2026-56854 was patched at 2026-09-16
2514.
Unknown Vulnerability Type - Unknown Product (CVE-2026-90460) - Low [130]
Description: {'nvd_cve_data_all': 'An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or deleting credentials via the /v3/credentials API. EC2-derived tokens can additionally read credential blobs, exposing TOTP MFA seeds and other secrets. Also, PATCH /v3/credentials does not validate the requested post-update project_id, allowing any delegated token to move a credential to an unauthorized project. All Keystone deployments using delegated authentication are affected.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or deleting credentials via the /v3/credentials API. EC2-derived tokens can additionally read credential blobs, exposing TOTP MFA seeds and other secrets. Also, PATCH /v3/credentials does not validate the requested post-update project_id, allowing any delegated token to move a credential to an unauthorized project. All Keystone deployments using delegated authentication are affected.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.6. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00337, EPSS Percentile is 0.26967 |
debian: CVE-2026-90460 was patched at 2026-09-16
2515.
Unknown Vulnerability Type - Unknown Product (CVE-2026-92238) - Low [130]
Description: {'nvd_cve_data_all': 'A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00179, EPSS Percentile is 0.07667 |
debian: CVE-2026-92238 was patched at 2026-09-16, 2026-09-17
2516.
Unknown Vulnerability Type - GitHub (CVE-2026-89258) - Low [128]
Description: {'nvd_cve_data_all': 'Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not dropped during direct resource lookups, allowing path confinement to be bypassed. An attacker who can place — or who convinces a site author to place — a symlink inside a mounted directory (for example, in a locally vendored theme under themes/) can cause functions that perform direct lookups, such as resources.Get and os.ReadFile, to follow that symlink and read files outside the intended project boundaries, disclosing their contents in the built site. Themes mounted as Go modules fetched from GitHub have symlinks stripped on download and are not affected, and multi-directory walks (e.g. content/asset walking) are not affected. This issue is an incomplete-fix follow-up to GHSA-c3wq-j5vh-68rc and GHSA-fw87-fv5r-9fpw; it is fixed in v0.165.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not dropped during direct resource lookups, allowing path confinement to be bypassed. An attacker who can place — or who convinces a site author to place — a symlink inside a mounted directory (for example, in a locally vendored theme under themes/) can cause functions that perform direct lookups, such as resources.Get and os.ReadFile, to follow that symlink and read files outside the intended project boundaries, disclosing their contents in the built site. Themes mounted as Go modules fetched from GitHub have symlinks stripped on download and are not affected, and multi-directory walks (e.g. content/asset walking) are not affected. This issue is an incomplete-fix follow-up to GHSA-c3wq-j5vh-68rc and GHSA-fw87-fv5r-9fpw; it is fixed in v0.165.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.2 | 14 | GitHub, Inc. is an Internet hosting service for software development and version control using Git | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00315, EPSS Percentile is 0.24451 |
debian: CVE-2026-89258 was patched at 2026-09-16
2517.
Unknown Vulnerability Type - GVfs (CVE-2026-84267) - Low [126]
Description: {'nvd_cve_data_all': 'A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer with a certain length but the function does not verify that the buffer is completely filled, leaving the remainder of the buffer containing uninitialized heap contents. If the server sends a short FXP_HANDLE reply, these uninitialized bytes are taken as the file handle. The client will then echo these uninitialized bytes back to the server on all subsequent requests using that handle. With a length of 128 bytes, this issue allows the malicious server to deterministically read uninitialized heap memory from the gvfsd-sftp process, leaking its heap base and the load address of the libgio library, resulting in a deterministic defeat of Address Space Layout Randomization (ASLR).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer with a certain length but the function does not verify that the buffer is completely filled, leaving the remainder of the buffer containing uninitialized heap contents. If the server sends a short FXP_HANDLE reply, these uninitialized bytes are taken as the file handle. The client will then echo these uninitialized bytes back to the server on all subsequent requests using that handle. With a length of 128 bytes, this issue allows the malicious server to deterministically read uninitialized heap memory from the gvfsd-sftp process, leaking its heap base and the load address of the libgio library, resulting in a deterministic defeat of Address Space Layout Randomization (ASLR).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.4 | 14 | GVfs (GNOME Virtual File System) is userspace virtual filesystem software for GNOME that provides backends (including FTP) to access different remote and local file systems transparently. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00212, EPSS Percentile is 0.11702 |
debian: CVE-2026-84267 was patched at 2026-09-16
2518.
Unknown Vulnerability Type - Spring Framework (CVE-2026-59314) - Low [126]
Description: {'nvd_cve_data_all': 'Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response splitting when the input is a malicious file name. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response splitting when the input is a malicious file name.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpring Framework 6.1.0 - 6.1.28\nSpring Framework 6.0.0 - 6.0.30\nSpring Framework 5.3.0 - 5.3.49\nSpring Framework 5.2.25.RELEASE and earlier', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.4 | 14 | The Spring Framework is an application framework and inversion of control container for the Java platform | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00198, EPSS Percentile is 0.09762 |
debian: CVE-2026-59314 was patched at 2026-09-16
2519.
Memory Corruption - Unknown Product (CVE-2025-15614) - Low [125]
Description: {'nvd_cve_data_all': 'ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files that cause the decompressor to read one byte past the allocated heap buffer, potentially crashing the process.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files that cause the decompressor to read one byte past the allocated heap buffer, potentially crashing the process.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00118, EPSS Percentile is 0.01929 |
debian: CVE-2025-15614 was patched at 2026-09-16
2520.
Memory Corruption - Unknown Product (CVE-2026-75904) - Low [125]
Description: {'nvd_cve_data_all': 'libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and then subtracts one before indexing the 191-byte static array pat_loops, so an index of zero reads pat_loops[-1], one byte before the array. The index is the smpno field of a parsed MIDI event, which is initialised to zero and only later overwritten from a program-change parameter, so an event reaching the note test before an instrument is assigned carries zero. A 32-byte MIDI file supplied to the library's public ModPlug_Load entry point drives the path through CSoundFile::Create, CSoundFile::ReadMID, and MID_ReadPatterns to the read. The byte read out of bounds determines whether a note event is treated as looping, so adjacent static storage influences playback state.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and then subtracts one before indexing the 191-byte static array pat_loops, so an index of zero reads pat_loops[-1], one byte before the array. The index is the smpno field of a parsed MIDI event, which is initialised to zero and only later overwritten from a program-change parameter, so an event reaching the note test before an instrument is assigned carries zero. A 32-byte MIDI file supplied to the library's public ModPlug_Load entry point drives the path through CSoundFile::Create, CSoundFile::ReadMID, and MID_ReadPatterns to the read. The byte read out of bounds determines whether a note event is treated as looping, so adjacent static storage influences playback state.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00119, EPSS Percentile is 0.02023 |
debian: CVE-2026-75904 was patched at 2026-08-20
2521.
Memory Corruption - Unknown Product (CVE-2026-86564) - Low [125]
Description: {'nvd_cve_data_all': 'A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00103, EPSS Percentile is 0.01101 |
debian: CVE-2026-86564 was patched at 2026-09-16
2522.
Memory Corruption - Unknown Product (CVE-2026-90681) - Low [125]
Description: {'nvd_cve_data_all': 'A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.01564 |
debian: CVE-2026-90681 was patched at 2026-09-16
2523.
Unknown Vulnerability Type - ImageMagick (CVE-2026-86424) - Low [123]
Description: {'nvd_cve_data_all': 'ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) and the file write operation (use-time) to write to policy-denied locations.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) and the file write operation (use-time) to write to policy-denied locations.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.2 | 10 | CVSS Base Score is 2.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00109, EPSS Percentile is 0.01398 |
altlinux: CVE-2026-86424 was patched at 2026-08-31
debian: CVE-2026-86424 was patched at 2026-09-16
2524.
Unknown Vulnerability Type - gitoxide (CVE-2026-91986) - Low [121]
Description: {'nvd_cve_data_all': 'gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.3 | 14 | gitoxide is an idiomatic, lean, fast & safe pure Rust implementation of Git, designed for correctness and performance, available both as a Rust library (gix crate) and command-line interface tools. | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00203, EPSS Percentile is 0.10529 |
debian: CVE-2026-91986 was patched at 2026-09-16
2525.
Unknown Vulnerability Type - Unknown Product (CVE-2026-50152) - Low [119]
Description: {'nvd_cve_data_all': 'Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only `mon allow r` capabilities to read the entire store by sending a single crafted MMonSubscribe message. The config-key store holds sensitive secrets including OSD LUKS disk-encryption passphrases and, on cephadm-managed clusters, the SSH private key that cephadm uses to reach every host in the cluster. Because that key grants root on every node under the default cephadm configuration, a low-privileged read-only account can escalate to full cluster and host compromise. This issue is fixed in versions 20.2.4 and 19.2.6', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only \xa0`mon allow r` capabilities to read the entire store by sending a single crafted MMonSubscribe message. The config-key store holds sensitive secrets including OSD LUKS disk-encryption passphrases and, on cephadm-managed clusters, the SSH private key that cephadm uses to reach every host in the cluster. Because that key grants root on every node under the default cephadm configuration, a low-privileged read-only account can escalate to full cluster and host compromise. This issue is fixed in versions 20.2.4 and 19.2.6', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00162, EPSS Percentile is 0.05826 |
debian: CVE-2026-50152 was patched at 2026-08-25
2526.
Unknown Vulnerability Type - Unknown Product (CVE-2026-58438) - Low [119]
Description: {'nvd_cve_data_all': 'Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00268, EPSS Percentile is 0.19034 |
altlinux: CVE-2026-58438 was patched at 2026-08-27, 2026-08-29, 2026-09-04
redos: CVE-2026-58438 was patched at 2026-09-02
2527.
Unknown Vulnerability Type - Unknown Product (CVE-2026-63337) - Low [119]
Description: {'nvd_cve_data_all': 'The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.tools.jsonrpc.ProcedureDescription receives a javaReturnType value in an untrusted system.describe response and passes it through JSONUtil.tryFill, setJavaReturnType, and computeReturnTypeAsJavaClass to Class.forName(javaReturnType) with initialization enabled. An attacker able to answer the JsonRpcClient request through a shared broker or network interception can select a class already present in the victim JVM and trigger its static initializer, while JsonRpcClient.java later passes getReturnType output to mapper.parse and may also create type confusion. Successful exploitation can affect confidentiality, integrity, and availability in the client process. This issue is fixed in version 5.33.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.tools.jsonrpc.ProcedureDescription receives a javaReturnType value in an untrusted system.describe response and passes it through JSONUtil.tryFill, setJavaReturnType, and computeReturnTypeAsJavaClass to Class.forName(javaReturnType) with initialization enabled. An attacker able to answer the JsonRpcClient request through a shared broker or network interception can select a class already present in the victim JVM and trigger its static initializer, while JsonRpcClient.java later passes getReturnType output to mapper.parse and may also create type confusion. Successful exploitation can affect confidentiality, integrity, and availability in the client process. This issue is fixed in version 5.33.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00317, EPSS Percentile is 0.24607 |
debian: CVE-2026-63337 was patched at 2026-08-20
2528.
Unknown Vulnerability Type - Unknown Product (CVE-2026-87853) - Low [119]
Description: {'nvd_cve_data_all': 'A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an exact match. An attacker whose IdP identifier is a strict prefix of a target user's identifier can authenticate as the target user.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an exact match. An attacker whose IdP identifier is a strict prefix of a target user's identifier can authenticate as the target user.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00281, EPSS Percentile is 0.20617 |
debian: CVE-2026-87853 was patched at 2026-09-16
2529.
Memory Corruption - Unknown Product (CVE-2026-65609) - Low [113]
Description: {'nvd_cve_data_all': 'nnn is vulnerable to Out-of-Bound write vulnerability. Due to lack of validation of attacker-controlled length fields deserialized from a session file, a crafted session file can cause nnn to write data beyond the bounds of fixed-size global buffers when loaded with the -s option. An attacker who can place a malicious session file in the victim's nnn session directory can exploit this to corrupt adjacent global state. Maintainer of this project was notified about this vulnerability. It might has been addressed, but the maintainer did not provide a vulnerable version range. Only version 5.2 was tested and confirmed as vulnerable.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'nnn is vulnerable to Out-of-Bound write vulnerability.\xa0Due to lack of validation of attacker-controlled length fields deserialized from a session file, a crafted session file can cause nnn to write data beyond the bounds of fixed-size global buffers when loaded with the -s option. An attacker who can place a malicious session file in the victim's nnn session directory can exploit this to corrupt adjacent global state.\n\n\n\n\nMaintainer of this project was notified about this vulnerability. It might has been addressed, but the maintainer did not provide a vulnerable version range. Only version 5.2 was tested and confirmed as vulnerable.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.2 | 10 | CVSS Base Score is 2.4. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00115, EPSS Percentile is 0.01752 |
debian: CVE-2026-65609 was patched at 2026-08-25
2530.
Memory Corruption - Unknown Product (CVE-2026-65610) - Low [113]
Description: {'nvd_cve_data_all': 'nnn stores homelen variable as uchar_t, which can only represent values in the range 0-255. An attacker who can influence the victim's execution environment can provide an arbitrary HOME path with length that is truncated to 0. The expression (homelen - 1) is promoted to signed int and becomes -1 and producing an out-of-bounds read and an out-of-bounds write one byte before the path buffer. Maintainer of this project was notified about this vulnerability. It might has been addressed, but the maintainer did not provide a vulnerable version range. Only version 5.2 was tested and confirmed as vulnerable.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'nnn stores homelen variable as uchar_t, which can only represent values in the range 0-255. An attacker who can influence the victim's execution environment can provide\xa0an arbitrary HOME path with length\xa0that is truncated\xa0to 0. The expression (homelen - 1) is promoted to signed int and\xa0becomes -1 and producing an\xa0out-of-bounds read and an out-of-bounds write one byte before the path buffer.\xa0\n\n\n\n\nMaintainer of this project was notified about this vulnerability. It might has been addressed, but the maintainer did not provide a vulnerable version range. Only version 5.2 was tested and confirmed as vulnerable.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.2 | 10 | CVSS Base Score is 2.4. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02424 |
debian: CVE-2026-65610 was patched at 2026-08-25
2531.
Unknown Vulnerability Type - Unknown Product (CVE-2026-15806) - Low [107]
Description: {'nvd_cve_data_all': 'The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://. Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication. Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00407, EPSS Percentile is 0.34496 |
debian: CVE-2026-15806 was patched at 2026-08-20
2532.
Unknown Vulnerability Type - Unknown Product (CVE-2026-15809) - Low [107]
Description: {'nvd_cve_data_all': 'A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06849 |
altlinux: CVE-2026-15809 was patched at 2026-09-11, 2026-09-14, 2026-09-16
redhat: CVE-2026-15809 was patched at 2026-08-25, 2026-09-01, 2026-09-02, 2026-09-10
2533.
Unknown Vulnerability Type - Unknown Product (CVE-2026-17495) - Low [107]
Description: {'nvd_cve_data_all': 'moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to moment.locale() can bypass the locale-name path-traversal guard. The guard assumes the input is a string, so an object whose match() method satisfies the check while its toString() returns a traversal path reaches an internal require() call with attacker-controlled path segments. This is an incomplete fix for CVE-2022-24785 and primarily affects npm (server-side) users that pass user-provided input directly to moment.locale(). The issue is fixed in moment 2.31.0, and users should upgrade to 2.31.0 or later. As a workaround, validate that any user-supplied input is a string before passing it to moment.locale().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to moment.locale() can bypass the locale-name path-traversal guard. The guard assumes the input is a string, so an object whose match() method satisfies the check while its toString() returns a traversal path reaches an internal require() call with attacker-controlled path segments. This is an incomplete fix for CVE-2022-24785 and primarily affects npm (server-side) users that pass user-provided input directly to moment.locale(). The issue is fixed in moment 2.31.0, and users should upgrade to 2.31.0 or later. As a workaround, validate that any user-supplied input is a string before passing it to moment.locale().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00356, EPSS Percentile is 0.29192 |
debian: CVE-2026-17495 was patched at 2026-09-16
2534.
Unknown Vulnerability Type - Unknown Product (CVE-2026-18654) - Low [107]
Description: {'nvd_cve_data_all': 'Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow man-in-the-middle attackers to intercept SSHsessions and file transfers via network positioning between the client and the EMR cluster endpoint. To remediate this issue, users should upgrade to AWS CLI v1 1.45.28 or later, or AWS CLI v2 2.35.3 or later.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow man-in-the-middle attackers to intercept SSHsessions and file transfers via network positioning between the client and the EMR cluster endpoint.\n\n\n\nTo remediate this issue, users should upgrade to AWS CLI v1 1.45.28 or later, or AWS CLI v2 2.35.3 or later.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00291, EPSS Percentile is 0.21702 |
redos: CVE-2026-18654 was patched at 2026-09-07
2535.
Unknown Vulnerability Type - Unknown Product (CVE-2026-74994) - Low [107]
Description: {'nvd_cve_data_all': 'The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user added to one protected directory is accepted as valid for all other protected directories on the same server instance. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user added to one protected directory is accepted as valid for all other protected directories on the same server instance.\n\nThis issue affects OTP from OTP\xa017.0 before OTP\xa027.3.4.17, from OTP\xa028.0 before OTP\xa028.5.0.6, and from OTP\xa029.0 before OTP\xa029.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP\xa017.0, corresponding to inets before 5.10, is affected is unknown.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00364, EPSS Percentile is 0.29987 |
debian: CVE-2026-74994 was patched at 2026-09-16
2536.
Unknown Vulnerability Type - Unknown Product (CVE-2026-82049) - Low [107]
Description: {'nvd_cve_data_all': 'In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In CPython 3.13 and earlier, the tarfile\xa0module's data\xa0and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00182, EPSS Percentile is 0.07991 |
debian: CVE-2026-82049 was patched at 2026-09-16
2537.
Unknown Vulnerability Type - Unknown Product (CVE-2026-87766) - Low [107]
Description: {'nvd_cve_data_all': 'A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0014, EPSS Percentile is 0.03692 |
debian: CVE-2026-87766 was patched at 2026-08-27, 2026-09-16
2538.
Unknown Vulnerability Type - Unknown Product (CVE-2026-92239) - Low [107]
Description: {'nvd_cve_data_all': 'A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00179, EPSS Percentile is 0.07667 |
debian: CVE-2026-92239 was patched at 2026-09-16, 2026-09-17
2539.
Unknown Vulnerability Type - gitoxide (CVE-2026-82249) - Low [97]
Description: {'nvd_cve_data_all': 'gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns to inject additional helper protocol fields and cause credential helpers to return credentials for attacker-specified hosts instead of the requested URL.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns to inject additional helper protocol fields and cause credential helpers to return credentials for attacker-specified hosts instead of the requested URL.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.3 | 14 | gitoxide is an idiomatic, lean, fast & safe pure Rust implementation of Git, designed for correctness and performance, available both as a Rust library (gix crate) and command-line interface tools. | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00167, EPSS Percentile is 0.06313 |
debian: CVE-2026-82249 was patched at 2026-09-16
2540.
Unknown Vulnerability Type - Unknown Product (CVE-2026-54258) - Low [95]
Description: {'nvd_cve_data_all': 'ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to directly fetch media for events belonging to monitors they are not allowed to access. The normal UI correctly hides the restricted monitor and its events, but direct event media views accept an arbitrary `eid` and stream media from the event path without enforcing the event/monitor-level ACL. This exposes private surveillance footage across monitor boundaries. Versions 1.36.39, 1.38.4, and 1.39.11 fix the issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to directly fetch media for events belonging to monitors they are not allowed to access. The normal UI correctly hides the restricted monitor and its events, but direct event media views accept an arbitrary `eid` and stream media from the event path without enforcing the event/monitor-level ACL. This exposes private surveillance footage across monitor boundaries. Versions 1.36.39, 1.38.4, and 1.39.11 fix the issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00201, EPSS Percentile is 0.10156 |
debian: CVE-2026-54258 was patched at 2026-09-16
2541.
Unknown Vulnerability Type - Unknown Product (CVE-2026-59678) - Low [95]
Description: {'nvd_cve_data_all': 'An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager.\n\n\n\n\n\n\nThis issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00158, EPSS Percentile is 0.05397 |
altlinux: CVE-2026-59678 was patched at 2026-08-25, 2026-09-02
2542.
Unknown Vulnerability Type - Unknown Product (CVE-2026-62146) - Low [95]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expose a host-side runtime-management resource inside the container, enabling container escape.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-62146 was patched at 2026-09-11, 2026-09-14, 2026-09-16
2543.
Unknown Vulnerability Type - Unknown Product (CVE-2026-65611) - Low [95]
Description: {'nvd_cve_data_all': 'nnn does not sanitize the path variable. An attacker can create a directory on a shared filesystem, removable media, or inside an extracted archive whose name contains a single quote followed by shell syntax. If the victim enters that directory in nnn and uses the batch copy or move workflow, the crafted directory name is embedded into the generated shell command and the injected payload executes with the privileges of the nnn process. Maintainer of this project was notified about this vulnerability. It might has been addressed, but the maintainer did not provide a vulnerable version range. Only version 5.2 was tested and confirmed as vulnerable.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'nnn does not sanitize the path variable. An attacker can create\xa0a directory on a shared filesystem, removable media,\xa0or inside an extracted archive whose name contains a single quote followed\xa0by shell syntax. If the victim enters that directory in nnn and uses the\xa0batch copy or move workflow, the crafted directory name is embedded into the\xa0generated shell command and the injected payload executes with the privileges of the nnn process.\n\n\nMaintainer of this project was notified about this vulnerability. It might has been addressed, but the maintainer did not provide a vulnerable version range. Only version 5.2 was tested and confirmed as vulnerable.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.25404 |
debian: CVE-2026-65611 was patched at 2026-08-25
2544.
Unknown Vulnerability Type - Unknown Product (CVE-2026-65612) - Low [95]
Description: {'nvd_cve_data_all': 'nnn does not sanitize the filename variable. An attacker can place a file with a crafted name on a shared filesystem, removable media, or inside an extracted archive whose name contains a single quote followed by shell syntax. If the victim navigates to that file and opens it with preview-tabbed, the filename is embedded into the generated shell command and the injected payload executes with the privileges of the nnn process. Maintainer of this project was notified about this vulnerability. It might has been addressed, but the maintainer did not provide a vulnerable version range. Only version 5.2 was tested and confirmed as vulnerable.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'nnn does not sanitize the filename variable. An attacker can place a file with a crafted name on a shared filesystem, removable media, or inside an extracted archive\xa0whose name contains a single quote followed\xa0by shell syntax. If the victim navigates\nto that file and opens it with preview-tabbed, the filename is embedded into the\xa0generated shell command and the injected payload executes with the privileges of the nnn process.\n\n\n\nMaintainer of this project was notified about this vulnerability. It might has been addressed, but the maintainer did not provide a vulnerable version range. Only version 5.2 was tested and confirmed as vulnerable.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.0033, EPSS Percentile is 0.26158 |
debian: CVE-2026-65612 was patched at 2026-08-25
2545.
Unknown Vulnerability Type - Unknown Product (CVE-2026-78408) - Low [95]
Description: {'nvd_cve_data_all': 'The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00113, EPSS Percentile is 0.01613 |
debian: CVE-2026-78408 was patched at 2026-09-16
2546.
Unknown Vulnerability Type - Unknown Product (CVE-2026-80183) - Low [95]
Description: {'nvd_cve_data_all': 'In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. With include_names, the response discloses the names and home-domain IDs of every user, group, project, and role involved. The literal "default" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of "None" in list_role_assignments_for_tree.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. With include_names, the response discloses the names and home-domain IDs of every user, group, project, and role involved. The literal "default" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of "None" in\xa0\n\nlist_role_assignments_for_tree.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00226, EPSS Percentile is 0.13403 |
debian: CVE-2026-80183 was patched at 2026-09-01, 2026-09-16
2547.
Unknown Vulnerability Type - Unknown Product (CVE-2026-85013) - Low [95]
Description: {'nvd_cve_data_all': 'A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name, containing shell metacharacters, is evaluated as a command. This can lead to arbitrary command execution in the completing user's shell, impacting their confidentiality, integrity, and availability.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name, containing shell metacharacters, is evaluated as a command. This can lead to arbitrary command execution in the completing user's shell, impacting their confidentiality, integrity, and availability.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00213, EPSS Percentile is 0.11767 |
debian: CVE-2026-85013 was patched at 2026-09-16
2548.
Unknown Vulnerability Type - Unknown Product (CVE-2026-88859) - Low [95]
Description: {'nvd_cve_data_all': 'A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler incorrectly assigns an attacker-controlled JavaScript URL to an iframe's source. This action leads to arbitrary JavaScript execution within the mail-viewing context, effectively bypassing the security measures designed to prevent script execution in email content.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler incorrectly assigns an attacker-controlled JavaScript URL to an iframe's source. This action leads to arbitrary JavaScript execution within the mail-viewing context, effectively bypassing the security measures designed to prevent script execution in email content.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00318, EPSS Percentile is 0.24751 |
debian: CVE-2026-88859 was patched at 2026-09-16
2549.
Unknown Vulnerability Type - Unknown Product (CVE-2026-89087) - Low [95]
Description: {'nvd_cve_data_all': 'The cstruct package before 6.3.0 for OCaml mishandles indexes.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The cstruct package before 6.3.0 for OCaml mishandles indexes.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00188, EPSS Percentile is 0.08593 |
debian: CVE-2026-89087 was patched at 2026-09-16
2550.
Unknown Vulnerability Type - Unknown Product (CVE-2026-90472) - Low [95]
Description: {'nvd_cve_data_all': 'msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing per-request deserialization failures.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing per-request deserialization failures.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00333, EPSS Percentile is 0.26481 |
debian: CVE-2026-90472 was patched at 2026-09-16
2551.
Unknown Vulnerability Type - Unknown Product (CVE-2024-58384) - Low [83]
Description: {'nvd_cve_data_all': 'Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00242, EPSS Percentile is 0.15567 |
debian: CVE-2024-58384 was patched at 2026-09-16
2552.
Unknown Vulnerability Type - Unknown Product (CVE-2026-61907) - Low [83]
Description: {'nvd_cve_data_all': 'An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to the user, despite having no insert permissions to the target mailbox.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0035, EPSS Percentile is 0.28484 |
debian: CVE-2026-61907 was patched at 2026-09-16
2553.
Unknown Vulnerability Type - Unknown Product (CVE-2026-77159) - Low [83]
Description: {'nvd_cve_data_all': 'A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can replace the logfile with a symlink, causing libvirtd (running as root) to transfer ownership of an arbitrary file to the swtpm user.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can replace the logfile with a symlink, causing libvirtd (running as root) to transfer ownership of an arbitrary file to the swtpm user.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00162, EPSS Percentile is 0.05826 |
debian: CVE-2026-77159 was patched at 2026-09-16
2554.
Unknown Vulnerability Type - Unknown Product (CVE-2026-78409) - Low [83]
Description: {'nvd_cve_data_all': 'The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.02447 |
debian: CVE-2026-78409 was patched at 2026-09-16
2555.
Unknown Vulnerability Type - Unknown Product (CVE-2026-79619) - Low [83]
Description: {'nvd_cve_data_all': 'On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an unprivileged local user to perform operations that should require root. Affected operations include pool-administrative operations (eg create, import, destroy), pool event log access (zpool events) and fault injection (zinject). Exploiting the problem requires only that the local user is permitted to open /dev/zfs (governed by local device permissions) and that the kernel permits unprivileged user namespace creation. No prior access to the target pool or its underlying devices is needed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00139, EPSS Percentile is 0.03628 |
debian: CVE-2026-79619 was patched at 2026-08-24, 2026-09-16
ubuntu: CVE-2026-79619 was patched at 2026-08-31, 2026-09-16
2556.
Unknown Vulnerability Type - Unknown Product (CVE-2026-84828) - Low [83]
Description: {'nvd_cve_data_all': 'A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the files are shorter than 256 bytes. The file contents are read with root privileges by the pcsd daemon and can be exfiltrated by the attacker through subsequent cluster node communication. This allows disclosure of sensitive data such as API keys, tokens, or configuration secrets that would otherwise be inaccessible to the attacker.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the files are shorter than 256 bytes. The file contents are read with root privileges by the pcsd daemon and can be exfiltrated by the attacker through subsequent cluster node communication. This allows disclosure of sensitive data such as API keys, tokens, or configuration secrets that would otherwise be inaccessible to the attacker.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00103, EPSS Percentile is 0.01077 |
debian: CVE-2026-84828 was patched at 2026-09-16
2557.
Unknown Vulnerability Type - Unknown Product (CVE-2026-87737) - Low [83]
Description: {'nvd_cve_data_all': 'An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST elliptic-curve scalar multiplication: the time required for a lookup can depend on a secret.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST elliptic-curve scalar multiplication: the time required for a lookup can depend on a secret.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00212, EPSS Percentile is 0.11687 |
debian: CVE-2026-87737 was patched at 2026-09-16
2558.
Unknown Vulnerability Type - Unknown Product (CVE-2026-90461) - Low [83]
Description: {'nvd_cve_data_all': 'OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00207, EPSS Percentile is 0.11006 |
debian: CVE-2026-90461 was patched at 2026-09-16
2559.
Unknown Vulnerability Type - Unknown Product (CVE-2026-17113) - Low [71]
Description: {'nvd_cve_data_all': 'A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in `server/container_create.go`). When a `CreateContainer` request supplies a `nil` CRI `Envs` field, CRI-O falls back to using the target OCI image's `config.Env` entries unfiltered, in contrast to the normal merge path, which validates each entry for a `key=value` form before use. An OCI image whose `config.Env` contains an entry with no `=` character (e.g. a bare `NOEQUALS` string) causes CRI-O to split that entry into a single-element slice and then index its second element, which is out of range. This triggers an unrecovered Go runtime panic in the `crio` daemon process, crashing it and terminating the container-runtime service for all workloads on the node until it is restarted.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in CRI-O's container-creation environment-variable handling\n(`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in\n`server/container_create.go`). When a `CreateContainer` request supplies a `nil` CRI\n`Envs` field, CRI-O falls back to using the target OCI image's `config.Env` entries\nunfiltered, in contrast to the normal merge path, which validates each entry for a\n`key=value` form before use. An OCI image whose `config.Env` contains an entry with no\n`=` character (e.g. a bare `NOEQUALS` string) causes CRI-O to split that entry into a\nsingle-element slice and then index its second element, which is out of range. This\ntriggers an unrecovered Go runtime panic in the `crio` daemon process, crashing it and\nterminating the container-runtime service for all workloads on the node until it is\nrestarted.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00107, EPSS Percentile is 0.01284 |
altlinux: CVE-2026-17113 was patched at 2026-09-11, 2026-09-14
2560.
Unknown Vulnerability Type - Unknown Product (CVE-2026-18238) - Low [71]
Description: {'nvd_cve_data_all': 'The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07437 |
debian: CVE-2026-18238 was patched at 2026-09-16
2561.
Unknown Vulnerability Type - Unknown Product (CVE-2026-33606) - Low [71]
Description: {'nvd_cve_data_all': 'Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync with the stream protocol, for example during a migration. Injected commands can modify mailbox state on the destination during migration or replication, including internal mailbox attributes that a user should not be able to set directly. It can also cause dsync errors. Avoid running dsync with the stream protocol on mailboxes with untrusted content. Update to non-vulnerable version. No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync with the stream protocol, for example during a migration. Injected commands can modify mailbox state on the destination during migration or replication, including internal mailbox attributes that a user should not be able to set directly. It can also cause dsync errors. Avoid running dsync with the stream protocol on mailboxes with untrusted content. Update to non-vulnerable version. No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00204, EPSS Percentile is 0.10615 |
altlinux: CVE-2026-33606 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-33606 was patched at 2026-09-16
2562.
Unknown Vulnerability Type - Unknown Product (CVE-2026-38819) - Low [71]
Description: {'nvd_cve_data_all': 'Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07547 |
debian: CVE-2026-38819 was patched at 2026-09-16
2563.
Unknown Vulnerability Type - Unknown Product (CVE-2026-75758) - Low [71]
Description: {'nvd_cve_data_all': 'Uncontrolled Recursion vulnerability in the Elixir standard library allows an attacker who controls a list passed to inspect/1, List.to_string/1, or List.to_charlist/1 to exhaust a BEAM node's memory. Inspect.List's charlist branch in lib/elixir/lib/inspect.ex classifies a list as a charlist using List.ascii_printable?/2, which examines only the first :printable_limit (4096 by default) elements, and then calls IO.chardata_to_string/1 on the whole term. A list whose printable prefix exceeds that limit but which contains a later element that is not a code point (an atom, an out-of-range integer, or an improper tail) is therefore mis-classified, and the conversion raises ArgumentError. That conversion runs inside List.to_string/1, whose rescue clause builds its message by interpolating inspect(list), which re-enters the same branch and raises again. The nested inspection is an argument to raise, so the recursion is not in tail position and every level is retained: the process stack grows monotonically while each cycle re-walks the list, until the process is killed by max_heap_size or, by default, the node runs out of memory. List.to_charlist/1 has the same rescue shape. Below the printable limit the inner inspect/1 sees the invalid element within its counter and renders the list in ordinary bracket form, so a single ArgumentError is raised and no recursion occurs. This issue affects elixir: from 1.15.0-rc.0 before 1.18.5, from 1.19.0-rc.0 before 1.19.6, and from 1.20.0-rc.0 before 1.20.4.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uncontrolled Recursion vulnerability in the Elixir standard library allows an attacker who controls a list passed to inspect/1, List.to_string/1, or List.to_charlist/1 to exhaust a BEAM node's memory.\n\nInspect.List's charlist branch in lib/elixir/lib/inspect.ex classifies a list as a charlist using List.ascii_printable?/2, which examines only the first :printable_limit (4096 by default) elements, and then calls IO.chardata_to_string/1 on the whole term. A list whose printable prefix exceeds that limit but which contains a later element that is not a code point (an atom, an out-of-range integer, or an improper tail) is therefore mis-classified, and the conversion raises ArgumentError. That conversion runs inside List.to_string/1, whose rescue clause builds its message by interpolating inspect(list), which re-enters the same branch and raises again. The nested inspection is an argument to raise, so the recursion is not in tail position and every level is retained: the process stack grows monotonically while each cycle re-walks the list, until the process is killed by max_heap_size or, by default, the node runs out of memory. List.to_charlist/1 has the same rescue shape.\n\nBelow the printable limit the inner inspect/1 sees the invalid element within its counter and renders the list in ordinary bracket form, so a single ArgumentError is raised and no recursion occurs.\n\nThis issue affects elixir: from 1.15.0-rc.0 before 1.18.5, from 1.19.0-rc.0 before 1.19.6, and from 1.20.0-rc.0 before 1.20.4.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02668 |
debian: CVE-2026-75758 was patched at 2026-09-16
2564.
Unknown Vulnerability Type - Unknown Product (CVE-2026-82797) - Low [71]
Description: {'nvd_cve_data_all': 'Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads. This issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Serialized Data with Nested Payloads.\n\nThis issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00103, EPSS Percentile is 0.01108 |
debian: CVE-2026-82797 was patched at 2026-09-16
2565.
Unknown Vulnerability Type - Unknown Product (CVE-2026-86231) - Low [71]
Description: {'nvd_cve_data_all': 'A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of the argument known_hosts results in improper check for certificate revocation. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.28.6 is able to address this issue. The patch is named 194a2f76a5c0f1c3f778565be3fd66bcafc42d23. You should upgrade the affected component.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of the argument known_hosts results in improper check for certificate revocation. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.28.6 is able to address this issue. The patch is named 194a2f76a5c0f1c3f778565be3fd66bcafc42d23. You should upgrade the affected component.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00273, EPSS Percentile is 0.1971 |
debian: CVE-2026-86231 was patched at 2026-09-16
2566.
Unknown Vulnerability Type - Unknown Product (CVE-2026-88265) - Low [71]
Description: {'nvd_cve_data_all': 'A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.6. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00119, EPSS Percentile is 0.02035 |
debian: CVE-2026-88265 was patched at 2026-09-16
2567.
Unknown Vulnerability Type - Unknown Product (CVE-2026-91991) - Low [71]
Description: {'nvd_cve_data_all': 'Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-delimited data in capitalized parameters like Domain, Path, or SameSite to bypass validation and modify cookie security attributes.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-delimited data in capitalized parameters like Domain, Path, or SameSite to bypass validation and modify cookie security attributes.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00219, EPSS Percentile is 0.12471 |
debian: CVE-2026-91991 was patched at 2026-09-16
2568.
Unknown Vulnerability Type - Unknown Product (CVE-2026-52681) - Low [59]
Description: {'nvd_cve_data_all': 'Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the active script. Compiled script files are also not removed when a script is deleted or renamed. The configured Sieve CPU limit can be bypassed, allowing sustained CPU consumption, and the leftover files increase disk consumption. Both can cause degradation of service for mail delivery. Monitor system for abnormal CPU usage and disk consumption. Update to non-vulnerable version. No publicly available exploits are known.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the active script. Compiled script files are also not removed when a script is deleted or renamed. The configured Sieve CPU limit can be bypassed, allowing sustained CPU consumption, and the leftover files increase disk consumption. Both can cause degradation of service for mail delivery. Monitor system for abnormal CPU usage and disk consumption. Update to non-vulnerable version. No publicly available exploits are known.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00254, EPSS Percentile is 0.17168 |
altlinux: CVE-2026-52681 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-52681 was patched at 2026-09-16
2569.
Unknown Vulnerability Type - Unknown Product (CVE-2026-70653) - Low [59]
Description: {'nvd_cve_data_all': 'libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-style Radiance RLE decoder in libvips/foreign/radiance.c can process a repeat marker at the beginning of a scanline in scanline_read_old and read q[-1] before any prior pixel exists. A crafted Radiance image loaded through VipsForeignLoadRad can therefore disclose four bytes of adjacent heap data, most likely other image data. This issue is fixed in version 8.18.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-style Radiance RLE decoder in libvips/foreign/radiance.c can process a repeat marker at the beginning of a scanline in scanline_read_old and read q[-1] before any prior pixel exists. A crafted Radiance image loaded through VipsForeignLoadRad can therefore disclose four bytes of adjacent heap data, most likely other image data. This issue is fixed in version 8.18.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02426 |
debian: CVE-2026-70653 was patched at 2026-08-25
2570.
Unknown Vulnerability Type - Unknown Product (CVE-2026-72847) - Low [59]
Description: {'nvd_cve_data_all': 'broot renders each file and directory name in its interactive tree view exactly as read from the filesystem. Names are converted with a plain to_string_lossy() call in src/tree_build/builder.rs and in TreeLine::unprune in src/tree/tree_line.rs, and no control-character filtering exists anywhere in the code, even though the doc comment on the TreeLine name field states that some characters may have been stripped. Any local user who can create a file can therefore place an escape sequence in its name and have it written unmodified to the terminal of anyone who browses that directory, between broot's own styling codes. A reported proof of concept used an OSC 52 clipboard-write sequence and captured the raw bytes broot wrote to its pty, confirming the sequence reaches the terminal unstripped. What an injected OSC or CSI sequence can then do depends on the terminal emulator in use. Browsing a directory is broot's primary function and carries no expectation that the content is trusted.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'broot renders each file and directory name in its interactive tree view exactly as read from the filesystem. Names are converted with a plain to_string_lossy() call in src/tree_build/builder.rs and in TreeLine::unprune in src/tree/tree_line.rs, and no control-character filtering exists anywhere in the code, even though the doc comment on the TreeLine name field states that some characters may have been stripped. Any local user who can create a file can therefore place an escape sequence in its name and have it written unmodified to the terminal of anyone who browses that directory, between broot's own styling codes. A reported proof of concept used an OSC 52 clipboard-write sequence and captured the raw bytes broot wrote to its pty, confirming the sequence reaches the terminal unstripped. What an injected OSC or CSI sequence can then do depends on the terminal emulator in use. Browsing a directory is broot's primary function and carries no expectation that the content is trusted.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00103, EPSS Percentile is 0.01082 |
debian: CVE-2026-72847 was patched at 2026-08-25
2571.
Unknown Vulnerability Type - Unknown Product (CVE-2026-79603) - Low [59]
Description: {'nvd_cve_data_all': 'x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-used. Since it's possible for the page to be scrubbed ahead of the TLB flush, there's a window where a PV guest can modify an already scrubbed page.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'x86 PV guests can free memory pages while still keeping a stale TLB entry\npointing to them. A TLB flush is only issued by Xen (if needed) when the\npage is re-used. Since it's possible for the page to be scrubbed ahead of\nthe TLB flush, there's a window where a PV guest can modify an already\nscrubbed page.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00231, EPSS Percentile is 0.14093 |
debian: CVE-2026-79603 was patched at 2026-09-16
2572.
Unknown Vulnerability Type - Unknown Product (CVE-2026-90467) - Low [59]
Description: {'nvd_cve_data_all': 'aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like AUTH, NOTIFY, or ORCPT to envelope commands, forging authenticated identities or forcing delivery notifications to third parties.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like AUTH, NOTIFY, or ORCPT to envelope commands, forging authenticated identities or forcing delivery notifications to third parties.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.0. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00229, EPSS Percentile is 0.1382 |
debian: CVE-2026-90467 was patched at 2026-09-16
2573.
Unknown Vulnerability Type - Unknown Product (CVE-2026-75421) - Low [47]
Description: {'nvd_cve_data_all': 'aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in the IOFile::getLine() function.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in the IOFile::getLine() function.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00118, EPSS Percentile is 0.01942 |
debian: CVE-2026-75421 was patched at 2026-09-16
2574.
Unknown Vulnerability Type - Unknown Product (CVE-2026-79699) - Low [47]
Description: {'nvd_cve_data_all': 'A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory to be replaced with an arbitrary file when processed by storage/pkg/archive.UnpackLayer, ApplyLayer, or ApplyUncompressedLayer.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory to be replaced with an arbitrary file when processed by storage/pkg/archive.UnpackLayer, ApplyLayer, or ApplyUncompressedLayer.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0013, EPSS Percentile is 0.02973 |
debian: CVE-2026-79699 was patched at 2026-09-16
2575.
Unknown Vulnerability Type - Unknown Product (CVE-2026-87735) - Low [47]
Description: {'nvd_cve_data_all': 'An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an undocumented exception for a small message during RSA decryption or encryption.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an undocumented exception for a small message during RSA decryption or encryption.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00141, EPSS Percentile is 0.03827 |
debian: CVE-2026-87735 was patched at 2026-09-16
2576.
Unknown Vulnerability Type - Unknown Product (CVE-2026-64846) - Low [35]
Description: {'nvd_cve_data_all': 'Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the recursive-nix experimental feature can exploit a time-of-check/time-of-use race involving final symlink handling in the LocalStore restore path. The race can cause writeFile to follow a substituted final symlink when opening a path with O_TRUNC instead of enforcing FinalSymlink::DontFollow, allowing the Nix process or nix-daemon to create or truncate an empty file outside the build sandbox with the daemon user's permissions. The primitive does not provide arbitrary-content writes and requires winning the race. This issue is fixed in version 2.35.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the recursive-nix experimental feature can exploit a time-of-check/time-of-use race involving final symlink handling in the LocalStore restore path. The race can cause writeFile to follow a substituted final symlink when opening a path with O_TRUNC instead of enforcing FinalSymlink::DontFollow, allowing the Nix process or nix-daemon to create or truncate an empty file outside the build sandbox with the daemon user's permissions. The primitive does not provide arbitrary-content writes and requires winning the race. This issue is fixed in version 2.35.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 2.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00088, EPSS Percentile is 0.00429 |
debian: CVE-2026-64846 was patched at 2026-08-25
2577.
Unknown Vulnerability Type - Unknown Product (CVE-2026-90773) - Low [35]
Description: {'nvd_cve_data_all': 'procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command column. Local attackers can execute processes with malicious ANSI or OSC escape sequences in their command line arguments, which are written unmodified to other users' terminals for interpretation by terminal emulators.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command column. Local attackers can execute processes with malicious ANSI or OSC escape sequences in their command line arguments, which are written unmodified to other users' terminals for interpretation by terminal emulators.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00105, EPSS Percentile is 0.01212 |
debian: CVE-2026-90773 was patched at 2026-09-16
2578.
Unknown Vulnerability Type - Unknown Product (CVE-2026-70652) - Low [23]
Description: {'nvd_cve_data_all': 'libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enlarges an incoming JPEG to a very large output before encoding a gain map through VipsForeignSaveUhdr. The undersized allocation can cause a heap buffer over-read that may disclose adjacent data or crash the process. This issue is fixed in version 8.18.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enlarges an incoming JPEG to a very large output before encoding a gain map through VipsForeignSaveUhdr. The undersized allocation can cause a heap buffer over-read that may disclose adjacent data or crash the process. This issue is fixed in version 8.18.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.2 | 10 | CVSS Base Score is 2.0. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00114, EPSS Percentile is 0.0168 |
debian: CVE-2026-70652 was patched at 2026-08-25
2579.
Unknown Vulnerability Type - Unknown Product (CVE-2026-74259) - Low [11]
Description: {'nvd_cve_data_all': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07827 |
oraclelinux: CVE-2026-74259 was patched at 2026-09-04
2580.
Unknown Vulnerability Type - Unknown Product (CVE-2025-70291) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2025-70291 was patched at 2026-09-16
2581.
Unknown Vulnerability Type - Unknown Product (CVE-2025-70292) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2025-70292 was patched at 2026-09-16
2582.
Unknown Vulnerability Type - Unknown Product (CVE-2026-15264) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-15264 was patched at 2026-09-16
2583.
Unknown Vulnerability Type - Unknown Product (CVE-2026-16288) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-16288 was patched at 2026-09-16
2584.
Unknown Vulnerability Type - Unknown Product (CVE-2026-16658) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-16658 was patched at 2026-09-16
2585.
Unknown Vulnerability Type - Unknown Product (CVE-2026-17516) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-17516 was patched at 2026-09-16
2586.
Unknown Vulnerability Type - Unknown Product (CVE-2026-18054) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-18054 was patched at 2026-09-16
2587.
Unknown Vulnerability Type - Unknown Product (CVE-2026-25946) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': '', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-25946 was patched at 2026-08-27, 2026-08-29, 2026-09-04
2588.
Unknown Vulnerability Type - Unknown Product (CVE-2026-49275) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-49275 was patched at 2026-09-02
debian: CVE-2026-49275 was patched at 2026-09-16
2589.
Unknown Vulnerability Type - Unknown Product (CVE-2026-50624) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-50624 was patched at 2026-09-16
2590.
Unknown Vulnerability Type - Unknown Product (CVE-2026-58581) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-58581 was patched at 2026-09-16
2591.
Unknown Vulnerability Type - Unknown Product (CVE-2026-58582) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-58582 was patched at 2026-09-16
2592.
Unknown Vulnerability Type - Unknown Product (CVE-2026-60008) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': '', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-60008 was patched at 2026-08-27, 2026-08-29, 2026-09-04
2593.
Unknown Vulnerability Type - Unknown Product (CVE-2026-60010) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-60010 was patched at 2026-09-04, 2026-09-07
2594.
Unknown Vulnerability Type - Unknown Product (CVE-2026-60018) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-60018 was patched at 2026-09-04, 2026-09-07
2595.
Unknown Vulnerability Type - Unknown Product (CVE-2026-60021) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-60021 was patched at 2026-09-04, 2026-09-07
2596.
Unknown Vulnerability Type - Unknown Product (CVE-2026-61402) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-61402 was patched at 2026-09-16
oraclelinux: CVE-2026-61402 was patched at 2026-09-03
2597.
Unknown Vulnerability Type - Unknown Product (CVE-2026-61404) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-61404 was patched at 2026-09-16
2598.
Unknown Vulnerability Type - Unknown Product (CVE-2026-61405) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-61405 was patched at 2026-09-16
2599.
Unknown Vulnerability Type - Unknown Product (CVE-2026-61406) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-61406 was patched at 2026-09-16
2600.
Unknown Vulnerability Type - Unknown Product (CVE-2026-61476) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-61476 was patched at 2026-09-16
2601.
Unknown Vulnerability Type - Unknown Product (CVE-2026-62925) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-62925 was patched at 2026-09-04, 2026-09-07
2602.
Unknown Vulnerability Type - Unknown Product (CVE-2026-63021) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-63021 was patched at 2026-09-04, 2026-09-07
2603.
Unknown Vulnerability Type - Unknown Product (CVE-2026-63109) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-63109 was patched at 2026-09-16
2604.
Unknown Vulnerability Type - Unknown Product (CVE-2026-63110) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-63110 was patched at 2026-09-16
oraclelinux: CVE-2026-63110 was patched at 2026-09-03
2605.
Unknown Vulnerability Type - Unknown Product (CVE-2026-63320) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-63320 was patched at 2026-09-16
oraclelinux: CVE-2026-63320 was patched at 2026-09-03
2606.
Unknown Vulnerability Type - Unknown Product (CVE-2026-63321) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-63321 was patched at 2026-09-16
2607.
Unknown Vulnerability Type - Unknown Product (CVE-2026-63322) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-63322 was patched at 2026-09-16
2608.
Unknown Vulnerability Type - Unknown Product (CVE-2026-63323) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-63323 was patched at 2026-09-16
2609.
Unknown Vulnerability Type - Unknown Product (CVE-2026-63676) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-63676 was patched at 2026-09-16
2610.
Unknown Vulnerability Type - Unknown Product (CVE-2026-63792) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-63792 was patched at 2026-09-04, 2026-09-07
2611.
Unknown Vulnerability Type - Unknown Product (CVE-2026-65107) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-65107 was patched at 2026-09-09, 2026-09-16
2612.
Unknown Vulnerability Type - Unknown Product (CVE-2026-65108) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-65108 was patched at 2026-09-09, 2026-09-16
2613.
Unknown Vulnerability Type - Unknown Product (CVE-2026-65109) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-65109 was patched at 2026-09-09, 2026-09-16
2614.
Unknown Vulnerability Type - Unknown Product (CVE-2026-65138) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-65138 was patched at 2026-09-09, 2026-09-16
2615.
Unknown Vulnerability Type - Unknown Product (CVE-2026-65139) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-65139 was patched at 2026-09-09, 2026-09-16
2616.
Unknown Vulnerability Type - Unknown Product (CVE-2026-65140) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-65140 was patched at 2026-09-09, 2026-09-16
2617.
Unknown Vulnerability Type - Unknown Product (CVE-2026-65165) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-65165 was patched at 2026-09-09, 2026-09-16
2618.
Unknown Vulnerability Type - Unknown Product (CVE-2026-65928) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-65928 was patched at 2026-09-16
oraclelinux: CVE-2026-65928 was patched at 2026-09-03
2619.
Unknown Vulnerability Type - Unknown Product (CVE-2026-65929) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-65929 was patched at 2026-09-16
oraclelinux: CVE-2026-65929 was patched at 2026-09-03
2620.
Unknown Vulnerability Type - Unknown Product (CVE-2026-66022) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-66022 was patched at 2026-09-16
oraclelinux: CVE-2026-66022 was patched at 2026-09-03
2621.
Unknown Vulnerability Type - Unknown Product (CVE-2026-66849) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-66849 was patched at 2026-09-04, 2026-09-07
2622.
Unknown Vulnerability Type - Unknown Product (CVE-2026-66853) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-66853 was patched at 2026-09-04, 2026-09-07
2623.
Unknown Vulnerability Type - Unknown Product (CVE-2026-66874) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-66874 was patched at 2026-09-04, 2026-09-07
2624.
Unknown Vulnerability Type - Unknown Product (CVE-2026-66877) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-66877 was patched at 2026-09-04, 2026-09-07
2625.
Unknown Vulnerability Type - Unknown Product (CVE-2026-67577) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-67577 was patched at 2026-09-04, 2026-09-07
2626.
Unknown Vulnerability Type - Unknown Product (CVE-2026-68546) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-68546 was patched at 2026-09-02
debian: CVE-2026-68546 was patched at 2026-09-16
2627.
Unknown Vulnerability Type - Unknown Product (CVE-2026-68547) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-68547 was patched at 2026-09-02
debian: CVE-2026-68547 was patched at 2026-09-16
2628.
Unknown Vulnerability Type - Unknown Product (CVE-2026-68957) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-68957 was patched at 2026-09-04, 2026-09-07
2629.
Unknown Vulnerability Type - Unknown Product (CVE-2026-68964) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-68964 was patched at 2026-09-04, 2026-09-07
2630.
Unknown Vulnerability Type - Unknown Product (CVE-2026-69159) - Low [0]
Description: {'nvd_cve_data_all': 'Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67306. Reason: This candidate is a duplicate of CVE-2026-67306. Notes: All CVE users should reference CVE-2026-67306 instead of this candidate.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67306. Reason: This candidate is a duplicate of CVE-2026-67306. Notes: All CVE users should reference CVE-2026-67306 instead of this candidate.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
almalinux: CVE-2026-69159 was patched at 2026-08-31
oraclelinux: CVE-2026-69159 was patched at 2026-09-01
2631.
Unknown Vulnerability Type - Unknown Product (CVE-2026-71196) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-71196 was patched at 2026-09-16
2632.
Unknown Vulnerability Type - Unknown Product (CVE-2026-71197) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-71197 was patched at 2026-09-16
2633.
Unknown Vulnerability Type - Unknown Product (CVE-2026-71223) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-71223 was patched at 2026-09-16
2634.
Unknown Vulnerability Type - Unknown Product (CVE-2026-73278) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': '', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-73278 was patched at 2026-08-27, 2026-08-29, 2026-09-04
2635.
Unknown Vulnerability Type - Unknown Product (CVE-2026-73535) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': '', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-73535 was patched at 2026-08-27, 2026-08-29, 2026-09-04
2636.
Unknown Vulnerability Type - Unknown Product (CVE-2026-73539) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': '', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-73539 was patched at 2026-08-27, 2026-08-29, 2026-09-04
2637.
Unknown Vulnerability Type - Unknown Product (CVE-2026-73800) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': '', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-73800 was patched at 2026-08-27, 2026-08-29, 2026-09-04
2638.
Unknown Vulnerability Type - Unknown Product (CVE-2026-73804) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': '', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-73804 was patched at 2026-08-27, 2026-08-29, 2026-09-04
2639.
Unknown Vulnerability Type - Unknown Product (CVE-2026-73814) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': '', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-73814 was patched at 2026-08-27, 2026-08-29, 2026-09-04
2640.
Unknown Vulnerability Type - Unknown Product (CVE-2026-77679) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-77679 was patched at 2026-09-12
2641.
Unknown Vulnerability Type - Unknown Product (CVE-2026-77682) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-77682 was patched at 2026-09-12
debian: CVE-2026-77682 was patched at 2026-08-25
2642.
Unknown Vulnerability Type - Unknown Product (CVE-2026-78433) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-78433 was patched at 2026-09-04, 2026-09-07
2643.
Unknown Vulnerability Type - Unknown Product (CVE-2026-79604) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-79604 was patched at 2026-09-16
2644.
Unknown Vulnerability Type - Unknown Product (CVE-2026-80220) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-80220 was patched at 2026-09-16
2645.
Unknown Vulnerability Type - Unknown Product (CVE-2026-81500) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-81500 was patched at 2026-09-16
2646.
Unknown Vulnerability Type - Unknown Product (CVE-2026-81501) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-81501 was patched at 2026-09-16
2647.
Unknown Vulnerability Type - Unknown Product (CVE-2026-82373) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-82373 was patched at 2026-09-16
2648.
Unknown Vulnerability Type - Unknown Product (CVE-2026-82374) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-82374 was patched at 2026-09-16
2649.
Unknown Vulnerability Type - Unknown Product (CVE-2026-84471) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-84471 was patched at 2026-09-16
2650.
Unknown Vulnerability Type - Unknown Product (CVE-2026-85218) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-85218 was patched at 2026-09-16
2651.
Unknown Vulnerability Type - Unknown Product (CVE-2026-85498) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
ubuntu: CVE-2026-85498 was patched at 2026-09-15, 2026-09-16
2652.
Unknown Vulnerability Type - Unknown Product (CVE-2026-89085) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-89085 was patched at 2026-09-16
2653.
Unknown Vulnerability Type - Unknown Product (CVE-2026-89088) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-89088 was patched at 2026-09-16
altlinux: CVE-2026-60004 was patched at 2026-08-27, 2026-08-29, 2026-09-04
altlinux: CVE-2026-85046 was patched at 2026-09-05
altlinux: CVE-2026-87491 was patched at 2026-09-17
debian: CVE-2026-85046 was patched at 2026-09-05, 2026-09-16
debian: CVE-2026-87491 was patched at 2026-09-16
debian: CVE-2026-77806 was patched at 2026-08-21, 2026-08-25
altlinux: CVE-2026-20896 was patched at 2026-08-27, 2026-08-29, 2026-09-04
altlinux: CVE-2026-18963 was patched at 2026-08-20, 2026-08-26, 2026-08-28
debian: CVE-2026-55584 was patched at 2026-09-16
altlinux: CVE-2026-76578 was patched at 2026-09-07
debian: CVE-2026-76578 was patched at 2026-09-16
altlinux: CVE-2026-13608 was patched at 2026-09-02, 2026-09-07
altlinux: CVE-2026-19931 was patched at 2026-09-02, 2026-09-07
debian: CVE-2026-13608 was patched at 2026-09-16
debian: CVE-2026-19931 was patched at 2026-09-16
altlinux: CVE-2026-53622 was patched at 2026-09-15, 2026-09-16
almalinux: CVE-2026-76560 was patched at 2026-09-08
altlinux: CVE-2026-76560 was patched at 2026-09-08, 2026-09-11
debian: CVE-2026-76560 was patched at 2026-09-16
oraclelinux: CVE-2026-76560 was patched at 2026-09-08, 2026-09-10
redhat: CVE-2026-76560 was patched at 2026-09-08
altlinux: CVE-2026-55986 was patched at 2026-08-27, 2026-08-29, 2026-09-04
redos: CVE-2026-55986 was patched at 2026-08-20
debian: CVE-2026-65915 was patched at 2026-08-25
altlinux: CVE-2026-78904 was patched at 2026-08-28
altlinux: CVE-2026-78905 was patched at 2026-08-28
altlinux: CVE-2026-78938 was patched at 2026-08-28
altlinux: CVE-2026-79266 was patched at 2026-08-28
altlinux: CVE-2026-85045 was patched at 2026-09-05
altlinux: CVE-2026-87528 was patched at 2026-09-17
altlinux: CVE-2026-87533 was patched at 2026-09-17
debian: CVE-2026-78904 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78905 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78938 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79266 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-85045 was patched at 2026-09-05, 2026-09-16
debian: CVE-2026-87528 was patched at 2026-09-16
debian: CVE-2026-87533 was patched at 2026-09-16
debian: CVE-2026-56702 was patched at 2026-09-16
debian: CVE-2026-56705 was patched at 2026-09-16
debian: CVE-2026-79657 was patched at 2026-09-16
debian: CVE-2026-56703 was patched at 2026-09-16
almalinux: CVE-2026-63633 was patched at 2026-08-31
debian: CVE-2026-63633 was patched at 2026-08-25
oraclelinux: CVE-2026-63633 was patched at 2026-09-01
debian: CVE-2026-66897 was patched at 2026-09-16
debian: CVE-2025-25977 was patched at 2026-08-25
altlinux: CVE-2026-76218 was patched at 2026-09-01
altlinux: CVE-2026-76220 was patched at 2026-09-01
altlinux: CVE-2026-76221 was patched at 2026-09-01
altlinux: CVE-2026-78676 was patched at 2026-09-01
debian: CVE-2026-76218 was patched at 2026-08-20
debian: CVE-2026-76220 was patched at 2026-08-20
debian: CVE-2026-76221 was patched at 2026-08-20
debian: CVE-2026-78676 was patched at 2026-08-25
debian: CVE-2026-87817 was patched at 2026-09-16
redos: CVE-2026-76218 was patched at 2026-09-02
redos: CVE-2026-76220 was patched at 2026-09-01
redos: CVE-2026-76221 was patched at 2026-09-01
redos: CVE-2026-78676 was patched at 2026-09-08
debian: CVE-2026-79675 was patched at 2026-09-16
debian: CVE-2026-78680 was patched at 2026-08-25
altlinux: CVE-2026-59087 was patched at 2026-09-14
altlinux: CVE-2026-78465 was patched at 2026-09-14
debian: CVE-2026-78465 was patched at 2026-08-25
debian: CVE-2026-78367 was patched at 2026-08-25
debian: CVE-2026-52490 was patched at 2026-09-16
altlinux: CVE-2026-56158 was patched at 2026-08-31, 2026-09-02
altlinux: CVE-2026-22874 was patched at 2026-08-27, 2026-08-29, 2026-09-04
debian: CVE-2026-63311 was patched at 2026-08-25
debian: CVE-2026-78682 was patched at 2026-08-25
debian: CVE-2026-82659 was patched at 2026-09-16
debian: CVE-2026-83609 was patched at 2026-09-16
debian: CVE-2026-83616 was patched at 2026-09-16
debian: CVE-2026-83618 was patched at 2026-09-16
debian: CVE-2026-84361 was patched at 2026-09-16
debian: CVE-2026-89044 was patched at 2026-09-16
altlinux: CVE-2026-19843 was patched at 2026-09-08, 2026-09-11
debian: CVE-2026-19843 was patched at 2026-09-16
altlinux: CVE-2026-58424 was patched at 2026-08-27, 2026-08-29, 2026-09-04
altlinux: CVE-2026-58433 was patched at 2026-08-27, 2026-08-29, 2026-09-04
redos: CVE-2026-58433 was patched at 2026-08-20
altlinux: CVE-2026-78903 was patched at 2026-08-28
altlinux: CVE-2026-87441 was patched at 2026-09-17
altlinux: CVE-2026-87447 was patched at 2026-09-17
altlinux: CVE-2026-87468 was patched at 2026-09-17
altlinux: CVE-2026-87475 was patched at 2026-09-17
altlinux: CVE-2026-87483 was patched at 2026-09-17
altlinux: CVE-2026-87493 was patched at 2026-09-17
altlinux: CVE-2026-87503 was patched at 2026-09-17
altlinux: CVE-2026-87505 was patched at 2026-09-17
altlinux: CVE-2026-87513 was patched at 2026-09-17
altlinux: CVE-2026-87515 was patched at 2026-09-17
altlinux: CVE-2026-87532 was patched at 2026-09-17
altlinux: CVE-2026-87535 was patched at 2026-09-17
altlinux: CVE-2026-87575 was patched at 2026-09-17
altlinux: CVE-2026-87577 was patched at 2026-09-17
altlinux: CVE-2026-87580 was patched at 2026-09-17
altlinux: CVE-2026-87584 was patched at 2026-09-17
altlinux: CVE-2026-87589 was patched at 2026-09-17
altlinux: CVE-2026-87599 was patched at 2026-09-17
altlinux: CVE-2026-87606 was patched at 2026-09-17
debian: CVE-2026-78903 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-87441 was patched at 2026-09-16
debian: CVE-2026-87447 was patched at 2026-09-16
debian: CVE-2026-87468 was patched at 2026-09-16
debian: CVE-2026-87475 was patched at 2026-09-16
debian: CVE-2026-87483 was patched at 2026-09-16
debian: CVE-2026-87493 was patched at 2026-09-16
debian: CVE-2026-87503 was patched at 2026-09-16
debian: CVE-2026-87505 was patched at 2026-09-16
debian: CVE-2026-87513 was patched at 2026-09-16
debian: CVE-2026-87515 was patched at 2026-09-16
debian: CVE-2026-87532 was patched at 2026-09-16
debian: CVE-2026-87535 was patched at 2026-09-16
debian: CVE-2026-87575 was patched at 2026-09-16
debian: CVE-2026-87577 was patched at 2026-09-16
debian: CVE-2026-87580 was patched at 2026-09-16
debian: CVE-2026-87584 was patched at 2026-09-16
debian: CVE-2026-87589 was patched at 2026-09-16
debian: CVE-2026-87599 was patched at 2026-09-16
debian: CVE-2026-87606 was patched at 2026-09-16
altlinux: CVE-2026-80230 was patched at 2026-09-02, 2026-09-07
altlinux: CVE-2026-80231 was patched at 2026-09-02, 2026-09-07
altlinux: CVE-2026-80255 was patched at 2026-09-02, 2026-09-07
altlinux: CVE-2026-82209 was patched at 2026-09-02, 2026-09-07
debian: CVE-2026-80230 was patched at 2026-09-16
debian: CVE-2026-80255 was patched at 2026-09-16
debian: CVE-2026-82209 was patched at 2026-09-16
debian: CVE-2026-63382 was patched at 2026-08-25, 2026-09-11
debian: CVE-2026-63385 was patched at 2026-08-25, 2026-09-11
ubuntu: CVE-2026-63382 was patched at 2026-09-01, 2026-09-16
ubuntu: CVE-2026-63385 was patched at 2026-09-01, 2026-09-16
debian: CVE-2026-19032 was patched at 2026-09-16
altlinux: CVE-2026-88008 was patched at 2026-09-15, 2026-09-16
debian: CVE-2026-78683 was patched at 2026-08-25
altlinux: CVE-2026-82208 was patched at 2026-09-02, 2026-09-07
debian: CVE-2026-82208 was patched at 2026-09-16
oraclelinux: CVE-2026-72568 was patched at 2026-09-09
redhat: CVE-2026-72568 was patched at 2026-09-08
debian: CVE-2026-66046 was patched at 2026-08-20
debian: CVE-2026-84304 was patched at 2026-09-16
debian: CVE-2026-83606 was patched at 2026-09-16
debian: CVE-2026-83612 was patched at 2026-09-16
debian: CVE-2026-83613 was patched at 2026-09-16
debian: CVE-2026-83614 was patched at 2026-09-16
debian: CVE-2026-83615 was patched at 2026-09-16
debian: CVE-2026-83619 was patched at 2026-09-16
debian: CVE-2026-90776 was patched at 2026-09-16
redos: CVE-2026-41642 was patched at 2026-09-07
debian: CVE-2026-63383 was patched at 2026-08-25, 2026-09-11
debian: CVE-2026-63384 was patched at 2026-08-25, 2026-09-11
debian: CVE-2026-63388 was patched at 2026-08-25, 2026-09-11
ubuntu: CVE-2026-63383 was patched at 2026-09-01, 2026-09-16
ubuntu: CVE-2026-63384 was patched at 2026-09-01, 2026-09-16
debian: CVE-2026-66393 was patched at 2026-08-25
debian: CVE-2026-78681 was patched at 2026-08-25
debian: CVE-2026-80205 was patched at 2026-09-16
debian: CVE-2026-80206 was patched at 2026-09-16
debian: CVE-2026-81722 was patched at 2026-09-16
debian: CVE-2026-81724 was patched at 2026-09-16
debian: CVE-2026-81725 was patched at 2026-09-16
debian: CVE-2026-68553 was patched at 2026-08-25
debian: CVE-2026-52022 was patched at 2026-09-11, 2026-09-16
debian: CVE-2026-52023 was patched at 2026-09-11, 2026-09-16
debian: CVE-2026-87819 was patched at 2026-09-16
altlinux: CVE-2026-63308 was patched at 2026-09-11
redos: CVE-2026-63308 was patched at 2026-09-08
debian: CVE-2026-89147 was patched at 2026-09-16
altlinux: CVE-2026-87486 was patched at 2026-09-17
debian: CVE-2026-87486 was patched at 2026-09-16
debian: CVE-2026-82254 was patched at 2026-09-16
ubuntu: CVE-2026-22791 was patched at 2026-08-31, 2026-09-16
debian: CVE-2026-88047 was patched at 2026-09-16
debian: CVE-2026-88054 was patched at 2026-09-16
debian: CVE-2026-87824 was patched at 2026-09-16
debian: CVE-2026-59983 was patched at 2026-09-16
debian: CVE-2026-59984 was patched at 2026-09-16
debian: CVE-2026-59985 was patched at 2026-09-16
debian: CVE-2026-84309 was patched at 2026-09-16
debian: CVE-2026-84310 was patched at 2026-09-16
debian: CVE-2026-84305 was patched at 2026-09-16
debian: CVE-2026-77354 was patched at 2026-08-25
redos: CVE-2026-50810 was patched at 2026-08-24
debian: CVE-2026-22591 was patched at 2026-09-16
debian: CVE-2026-86776 was patched at 2026-09-16
redos: CVE-2026-47753 was patched at 2026-09-01
redos: CVE-2026-48754 was patched at 2026-08-24
debian: CVE-2026-83605 was patched at 2026-09-16
debian: CVE-2026-83607 was patched at 2026-09-16
debian: CVE-2026-83617 was patched at 2026-09-16
debian: CVE-2026-86431 was patched at 2026-09-16
altlinux: CVE-2026-33525 was patched at 2026-08-30
debian: CVE-2026-65053 was patched at 2026-09-16
debian: CVE-2026-76642 was patched at 2026-09-16
debian: CVE-2026-19816 was patched at 2026-09-16
almalinux: CVE-2026-74581 was patched at 2026-08-26, 2026-09-03
debian: CVE-2026-74581 was patched at 2026-08-25
debian: CVE-2026-74586 was patched at 2026-08-25
debian: CVE-2026-80521 was patched at 2026-09-16
debian: CVE-2026-80714 was patched at 2026-09-16
debian: CVE-2026-80844 was patched at 2026-09-16
debian: CVE-2026-81000 was patched at 2026-09-16
oraclelinux: CVE-2026-74581 was patched at 2026-08-26, 2026-09-04, 2026-09-07
oraclelinux: CVE-2026-74586 was patched at 2026-09-04
oraclelinux: CVE-2026-80714 was patched at 2026-09-04
redhat: CVE-2026-74581 was patched at 2026-08-26, 2026-08-27, 2026-09-01, 2026-09-03
altlinux: CVE-2026-80229 was patched at 2026-09-02, 2026-09-07
debian: CVE-2026-80229 was patched at 2026-09-16
debian: CVE-2026-75143 was patched at 2026-08-20
ubuntu: CVE-2026-75143 was patched at 2026-09-03, 2026-09-16
altlinux: CVE-2026-18924 was patched at 2026-09-02, 2026-09-07
debian: CVE-2026-18924 was patched at 2026-09-16
altlinux: CVE-2026-20911 was patched at 2026-08-21, 2026-08-26
almalinux: CVE-2026-63652 was patched at 2026-08-31
altlinux: CVE-2026-85090 was patched at 2026-09-10, 2026-09-11
debian: CVE-2026-63652 was patched at 2026-08-25
debian: CVE-2026-85090 was patched at 2026-09-16
oraclelinux: CVE-2026-63652 was patched at 2026-09-01
redos: CVE-2026-63652 was patched at 2026-09-07
debian: CVE-2026-63381 was patched at 2026-08-25, 2026-09-11
debian: CVE-2026-63387 was patched at 2026-08-25, 2026-09-11
ubuntu: CVE-2026-63381 was patched at 2026-09-01, 2026-09-16
altlinux: CVE-2026-84118 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
debian: CVE-2026-90829 was patched at 2026-09-16
debian: CVE-2026-91781 was patched at 2026-09-16
debian: CVE-2026-91782 was patched at 2026-09-16
altlinux: CVE-2026-87586 was patched at 2026-09-17
altlinux: CVE-2026-87596 was patched at 2026-09-17
debian: CVE-2026-87586 was patched at 2026-09-16
debian: CVE-2026-87596 was patched at 2026-09-16
debian: CVE-2026-89156 was patched at 2026-09-16
debian: CVE-2026-89160 was patched at 2026-09-16
debian: CVE-2026-88049 was patched at 2026-09-16
debian: CVE-2026-88051 was patched at 2026-09-16
debian: CVE-2026-88052 was patched at 2026-09-16
debian: CVE-2026-88053 was patched at 2026-09-16
debian: CVE-2026-87795 was patched at 2026-09-16
debian: CVE-2026-87825 was patched at 2026-09-16
debian: CVE-2026-87877 was patched at 2026-09-16
debian: CVE-2026-86137 was patched at 2026-09-16
debian: CVE-2026-22590 was patched at 2026-09-16
debian: CVE-2026-61555 was patched at 2026-09-16
debian: CVE-2026-76905 was patched at 2026-08-25
debian: CVE-2026-76014 was patched at 2026-08-20
debian: CVE-2026-84311 was patched at 2026-09-16
altlinux: CVE-2026-87482 was patched at 2026-09-17
altlinux: CVE-2026-87497 was patched at 2026-09-17
altlinux: CVE-2026-87629 was patched at 2026-09-17
debian: CVE-2026-87482 was patched at 2026-09-16
debian: CVE-2026-87497 was patched at 2026-09-16
debian: CVE-2026-87629 was patched at 2026-09-16
altlinux: CVE-2026-85089 was patched at 2026-09-10, 2026-09-11
debian: CVE-2026-85089 was patched at 2026-09-16
altlinux: CVE-2026-84127 was patched at 2026-09-01, 2026-09-05
debian: CVE-2026-59982 was patched at 2026-09-16
debian: CVE-2026-88048 was patched at 2026-09-16
debian: CVE-2026-80101 was patched at 2026-09-16
debian: CVE-2026-85769 was patched at 2026-09-16
debian: CVE-2026-89162 was patched at 2026-09-16
debian: CVE-2026-34968 was patched at 2026-09-16
debian: CVE-2026-62384 was patched at 2026-08-25
debian: CVE-2026-62385 was patched at 2026-08-25
debian: CVE-2026-62388 was patched at 2026-08-25
debian: CVE-2026-63312 was patched at 2026-08-25
debian: CVE-2026-79676 was patched at 2026-09-16
debian: CVE-2026-81726 was patched at 2026-09-16
altlinux: CVE-2026-76222 was patched at 2026-09-01
altlinux: CVE-2026-78677 was patched at 2026-09-01
debian: CVE-2026-76222 was patched at 2026-08-20
debian: CVE-2026-78677 was patched at 2026-08-25
redos: CVE-2026-76222 was patched at 2026-09-01
redos: CVE-2026-78677 was patched at 2026-09-08
redos: CVE-2026-48753 was patched at 2026-08-24
debian: CVE-2026-49114 was patched at 2026-08-25
altlinux: CVE-2026-76219 was patched at 2026-09-01
debian: CVE-2026-76219 was patched at 2026-08-20
redos: CVE-2026-76219 was patched at 2026-09-01
debian: CVE-2026-81727 was patched at 2026-09-16
altlinux: CVE-2026-76217 was patched at 2026-09-01
altlinux: CVE-2026-78675 was patched at 2026-09-01
altlinux: CVE-2026-78678 was patched at 2026-09-01
debian: CVE-2026-76217 was patched at 2026-08-20
debian: CVE-2026-78675 was patched at 2026-08-25
debian: CVE-2026-78678 was patched at 2026-08-25
debian: CVE-2026-87818 was patched at 2026-09-16
redos: CVE-2026-76217 was patched at 2026-09-01
redos: CVE-2026-78675 was patched at 2026-09-08
redos: CVE-2026-78678 was patched at 2026-09-08
debian: CVE-2026-62383 was patched at 2026-08-25
debian: CVE-2026-70626 was patched at 2026-08-25
debian: CVE-2026-79674 was patched at 2026-09-16
altlinux: CVE-2026-59774 was patched at 2026-08-27, 2026-08-29, 2026-09-04
altlinux: CVE-2026-87445 was patched at 2026-09-17
altlinux: CVE-2026-87484 was patched at 2026-09-17
altlinux: CVE-2026-87496 was patched at 2026-09-17
altlinux: CVE-2026-87501 was patched at 2026-09-17
altlinux: CVE-2026-87540 was patched at 2026-09-17
altlinux: CVE-2026-87615 was patched at 2026-09-17
debian: CVE-2026-87445 was patched at 2026-09-16
debian: CVE-2026-87484 was patched at 2026-09-16
debian: CVE-2026-87496 was patched at 2026-09-16
debian: CVE-2026-87501 was patched at 2026-09-16
debian: CVE-2026-87540 was patched at 2026-09-16
debian: CVE-2026-87615 was patched at 2026-09-16
debian: CVE-2026-86143 was patched at 2026-09-16
debian: CVE-2026-90781 was patched at 2026-09-16
debian: CVE-2026-89157 was patched at 2026-09-16
debian: CVE-2026-54770 was patched at 2026-08-25
debian: CVE-2026-65640 was patched at 2026-08-20
almalinux: CVE-2026-14457 was patched at 2026-09-14
almalinux: CVE-2026-18798 was patched at 2026-09-14
almalinux: CVE-2026-63073 was patched at 2026-09-14
almalinux: CVE-2026-63076 was patched at 2026-09-14
altlinux: CVE-2026-14457 was patched at 2026-08-26
altlinux: CVE-2026-63073 was patched at 2026-08-26
altlinux: CVE-2026-63076 was patched at 2026-08-26
debian: CVE-2026-14457 was patched at 2026-08-25, 2026-09-16
debian: CVE-2026-18798 was patched at 2026-08-25, 2026-09-16
debian: CVE-2026-63073 was patched at 2026-08-25, 2026-09-16
debian: CVE-2026-63076 was patched at 2026-08-25, 2026-09-16
oraclelinux: CVE-2026-14457 was patched at 2026-09-14
oraclelinux: CVE-2026-18798 was patched at 2026-09-14
oraclelinux: CVE-2026-63073 was patched at 2026-09-14
oraclelinux: CVE-2026-63076 was patched at 2026-09-14
redhat: CVE-2026-14457 was patched at 2026-09-14
redhat: CVE-2026-18798 was patched at 2026-09-14
redhat: CVE-2026-63073 was patched at 2026-09-14
redhat: CVE-2026-63076 was patched at 2026-09-14
ubuntu: CVE-2026-14457 was patched at 2026-08-25, 2026-09-16
ubuntu: CVE-2026-18798 was patched at 2026-08-25, 2026-09-16
ubuntu: CVE-2026-63073 was patched at 2026-08-25, 2026-09-16
ubuntu: CVE-2026-63076 was patched at 2026-08-25, 2026-09-16
altlinux: CVE-2026-76017 was patched at 2026-08-21
altlinux: CVE-2026-76018 was patched at 2026-08-21
altlinux: CVE-2026-76020 was patched at 2026-08-21
altlinux: CVE-2026-76021 was patched at 2026-08-21
altlinux: CVE-2026-76022 was patched at 2026-08-21
altlinux: CVE-2026-76023 was patched at 2026-08-21
altlinux: CVE-2026-78891 was patched at 2026-08-28
altlinux: CVE-2026-78899 was patched at 2026-08-28
altlinux: CVE-2026-78900 was patched at 2026-08-28
altlinux: CVE-2026-78901 was patched at 2026-08-28
altlinux: CVE-2026-78906 was patched at 2026-08-28
altlinux: CVE-2026-78909 was patched at 2026-08-28
altlinux: CVE-2026-78910 was patched at 2026-08-28
altlinux: CVE-2026-78911 was patched at 2026-08-28
altlinux: CVE-2026-78913 was patched at 2026-08-28
altlinux: CVE-2026-78915 was patched at 2026-08-28
altlinux: CVE-2026-78934 was patched at 2026-08-28
altlinux: CVE-2026-78935 was patched at 2026-08-28
altlinux: CVE-2026-78937 was patched at 2026-08-28
altlinux: CVE-2026-78939 was patched at 2026-08-28
altlinux: CVE-2026-78944 was patched at 2026-08-28
altlinux: CVE-2026-78945 was patched at 2026-08-28
altlinux: CVE-2026-78948 was patched at 2026-08-28
altlinux: CVE-2026-78950 was patched at 2026-08-28
altlinux: CVE-2026-78951 was patched at 2026-08-28
altlinux: CVE-2026-78952 was patched at 2026-08-28
altlinux: CVE-2026-78956 was patched at 2026-08-28
altlinux: CVE-2026-78963 was patched at 2026-08-28
altlinux: CVE-2026-78964 was patched at 2026-08-28
altlinux: CVE-2026-78978 was patched at 2026-08-28
altlinux: CVE-2026-78983 was patched at 2026-08-28
altlinux: CVE-2026-78985 was patched at 2026-08-28
altlinux: CVE-2026-78989 was patched at 2026-08-28
altlinux: CVE-2026-78990 was patched at 2026-08-28
altlinux: CVE-2026-78999 was patched at 2026-08-28
altlinux: CVE-2026-79008 was patched at 2026-08-28
altlinux: CVE-2026-79012 was patched at 2026-08-28
altlinux: CVE-2026-79019 was patched at 2026-08-28
altlinux: CVE-2026-79026 was patched at 2026-08-28
altlinux: CVE-2026-79027 was patched at 2026-08-28
altlinux: CVE-2026-79033 was patched at 2026-08-28
altlinux: CVE-2026-79039 was patched at 2026-08-28
altlinux: CVE-2026-79043 was patched at 2026-08-28
altlinux: CVE-2026-79047 was patched at 2026-08-28
altlinux: CVE-2026-79048 was patched at 2026-08-28
altlinux: CVE-2026-79052 was patched at 2026-08-28
altlinux: CVE-2026-79054 was patched at 2026-08-28
altlinux: CVE-2026-79056 was patched at 2026-08-28
altlinux: CVE-2026-79057 was patched at 2026-08-28
altlinux: CVE-2026-79064 was patched at 2026-08-28
altlinux: CVE-2026-79069 was patched at 2026-08-28
altlinux: CVE-2026-79071 was patched at 2026-08-28
altlinux: CVE-2026-79073 was patched at 2026-08-28
altlinux: CVE-2026-79078 was patched at 2026-08-28
altlinux: CVE-2026-79083 was patched at 2026-08-28
altlinux: CVE-2026-79091 was patched at 2026-08-28
altlinux: CVE-2026-79097 was patched at 2026-08-28
altlinux: CVE-2026-79109 was patched at 2026-08-28
altlinux: CVE-2026-79111 was patched at 2026-08-28
altlinux: CVE-2026-79119 was patched at 2026-08-28
altlinux: CVE-2026-79121 was patched at 2026-08-28
altlinux: CVE-2026-79127 was patched at 2026-08-28
altlinux: CVE-2026-79128 was patched at 2026-08-28
altlinux: CVE-2026-79129 was patched at 2026-08-28
altlinux: CVE-2026-79130 was patched at 2026-08-28
altlinux: CVE-2026-79131 was patched at 2026-08-28
altlinux: CVE-2026-79132 was patched at 2026-08-28
altlinux: CVE-2026-79138 was patched at 2026-08-28
altlinux: CVE-2026-79139 was patched at 2026-08-28
altlinux: CVE-2026-79140 was patched at 2026-08-28
altlinux: CVE-2026-79142 was patched at 2026-08-28
altlinux: CVE-2026-79149 was patched at 2026-08-28
altlinux: CVE-2026-79150 was patched at 2026-08-28
altlinux: CVE-2026-79155 was patched at 2026-08-28
altlinux: CVE-2026-79175 was patched at 2026-08-28
altlinux: CVE-2026-79182 was patched at 2026-08-28
altlinux: CVE-2026-79183 was patched at 2026-08-28
altlinux: CVE-2026-79187 was patched at 2026-08-28
altlinux: CVE-2026-79188 was patched at 2026-08-28
altlinux: CVE-2026-79189 was patched at 2026-08-28
altlinux: CVE-2026-79194 was patched at 2026-08-28
altlinux: CVE-2026-79195 was patched at 2026-08-28
altlinux: CVE-2026-79197 was patched at 2026-08-28
altlinux: CVE-2026-79198 was patched at 2026-08-28
altlinux: CVE-2026-79200 was patched at 2026-08-28
altlinux: CVE-2026-79202 was patched at 2026-08-28
altlinux: CVE-2026-79209 was patched at 2026-08-28
altlinux: CVE-2026-79210 was patched at 2026-08-28
altlinux: CVE-2026-79215 was patched at 2026-08-28
altlinux: CVE-2026-79216 was patched at 2026-08-28
altlinux: CVE-2026-79218 was patched at 2026-08-28
altlinux: CVE-2026-79219 was patched at 2026-08-28
altlinux: CVE-2026-79224 was patched at 2026-08-28
altlinux: CVE-2026-79227 was patched at 2026-08-28
altlinux: CVE-2026-79230 was patched at 2026-08-28
altlinux: CVE-2026-79231 was patched at 2026-08-28
altlinux: CVE-2026-79232 was patched at 2026-08-28
altlinux: CVE-2026-79235 was patched at 2026-08-28
altlinux: CVE-2026-79236 was patched at 2026-08-28
altlinux: CVE-2026-79240 was patched at 2026-08-28
altlinux: CVE-2026-79244 was patched at 2026-08-28
altlinux: CVE-2026-79245 was patched at 2026-08-28
altlinux: CVE-2026-79247 was patched at 2026-08-28
altlinux: CVE-2026-79256 was patched at 2026-08-28
altlinux: CVE-2026-79257 was patched at 2026-08-28
altlinux: CVE-2026-79263 was patched at 2026-08-28
altlinux: CVE-2026-79275 was patched at 2026-08-28
altlinux: CVE-2026-79282 was patched at 2026-08-28
altlinux: CVE-2026-79286 was patched at 2026-08-28
altlinux: CVE-2026-79290 was patched at 2026-08-28
altlinux: CVE-2026-79292 was patched at 2026-08-28
altlinux: CVE-2026-84324 was patched at 2026-09-03
altlinux: CVE-2026-84326 was patched at 2026-09-03
altlinux: CVE-2026-84333 was patched at 2026-09-03
altlinux: CVE-2026-84334 was patched at 2026-09-03
altlinux: CVE-2026-84335 was patched at 2026-09-03
altlinux: CVE-2026-84347 was patched at 2026-09-03
altlinux: CVE-2026-84349 was patched at 2026-09-03
altlinux: CVE-2026-84350 was patched at 2026-09-03
altlinux: CVE-2026-84351 was patched at 2026-09-03
altlinux: CVE-2026-84352 was patched at 2026-09-03
altlinux: CVE-2026-84353 was patched at 2026-09-03
altlinux: CVE-2026-84354 was patched at 2026-09-03
altlinux: CVE-2026-85042 was patched at 2026-09-05
altlinux: CVE-2026-85047 was patched at 2026-09-05
altlinux: CVE-2026-85048 was patched at 2026-09-05
altlinux: CVE-2026-85049 was patched at 2026-09-05
altlinux: CVE-2026-85050 was patched at 2026-09-05
altlinux: CVE-2026-85051 was patched at 2026-09-05
altlinux: CVE-2026-85053 was patched at 2026-09-05
altlinux: CVE-2026-87430 was patched at 2026-09-17
altlinux: CVE-2026-87438 was patched at 2026-09-17
altlinux: CVE-2026-87440 was patched at 2026-09-17
altlinux: CVE-2026-87444 was patched at 2026-09-17
altlinux: CVE-2026-87448 was patched at 2026-09-17
altlinux: CVE-2026-87455 was patched at 2026-09-17
altlinux: CVE-2026-87457 was patched at 2026-09-17
altlinux: CVE-2026-87460 was patched at 2026-09-17
altlinux: CVE-2026-87464 was patched at 2026-09-17
altlinux: CVE-2026-87467 was patched at 2026-09-17
altlinux: CVE-2026-87470 was patched at 2026-09-17
altlinux: CVE-2026-87474 was patched at 2026-09-17
altlinux: CVE-2026-87479 was patched at 2026-09-17
altlinux: CVE-2026-87480 was patched at 2026-09-17
altlinux: CVE-2026-87481 was patched at 2026-09-17
altlinux: CVE-2026-87487 was patched at 2026-09-17
altlinux: CVE-2026-87488 was patched at 2026-09-17
altlinux: CVE-2026-87489 was patched at 2026-09-17
altlinux: CVE-2026-87492 was patched at 2026-09-17
altlinux: CVE-2026-87494 was patched at 2026-09-17
altlinux: CVE-2026-87500 was patched at 2026-09-17
altlinux: CVE-2026-87504 was patched at 2026-09-17
altlinux: CVE-2026-87506 was patched at 2026-09-17
altlinux: CVE-2026-87509 was patched at 2026-09-17
altlinux: CVE-2026-87510 was patched at 2026-09-17
altlinux: CVE-2026-87512 was patched at 2026-09-17
altlinux: CVE-2026-87514 was patched at 2026-09-17
altlinux: CVE-2026-87520 was patched at 2026-09-17
altlinux: CVE-2026-87524 was patched at 2026-09-17
altlinux: CVE-2026-87526 was patched at 2026-09-17
altlinux: CVE-2026-87527 was patched at 2026-09-17
altlinux: CVE-2026-87529 was patched at 2026-09-17
altlinux: CVE-2026-87530 was patched at 2026-09-17
altlinux: CVE-2026-87536 was patched at 2026-09-17
altlinux: CVE-2026-87537 was patched at 2026-09-17
altlinux: CVE-2026-87542 was patched at 2026-09-17
altlinux: CVE-2026-87547 was patched at 2026-09-17
altlinux: CVE-2026-87553 was patched at 2026-09-17
altlinux: CVE-2026-87554 was patched at 2026-09-17
altlinux: CVE-2026-87558 was patched at 2026-09-17
altlinux: CVE-2026-87572 was patched at 2026-09-17
altlinux: CVE-2026-87578 was patched at 2026-09-17
altlinux: CVE-2026-87579 was patched at 2026-09-17
altlinux: CVE-2026-87581 was patched at 2026-09-17
altlinux: CVE-2026-87582 was patched at 2026-09-17
altlinux: CVE-2026-87585 was patched at 2026-09-17
altlinux: CVE-2026-87587 was patched at 2026-09-17
altlinux: CVE-2026-87588 was patched at 2026-09-17
altlinux: CVE-2026-87601 was patched at 2026-09-17
altlinux: CVE-2026-87604 was patched at 2026-09-17
altlinux: CVE-2026-87607 was patched at 2026-09-17
altlinux: CVE-2026-87609 was patched at 2026-09-17
altlinux: CVE-2026-87612 was patched at 2026-09-17
altlinux: CVE-2026-87613 was patched at 2026-09-17
altlinux: CVE-2026-87616 was patched at 2026-09-17
altlinux: CVE-2026-87617 was patched at 2026-09-17
altlinux: CVE-2026-87618 was patched at 2026-09-17
altlinux: CVE-2026-87621 was patched at 2026-09-17
altlinux: CVE-2026-87625 was patched at 2026-09-17
altlinux: CVE-2026-87628 was patched at 2026-09-17
altlinux: CVE-2026-87633 was patched at 2026-09-17
altlinux: CVE-2026-87634 was patched at 2026-09-17
altlinux: CVE-2026-87636 was patched at 2026-09-17
altlinux: CVE-2026-87637 was patched at 2026-09-17
altlinux: CVE-2026-87638 was patched at 2026-09-17
altlinux: CVE-2026-87639 was patched at 2026-09-17
altlinux: CVE-2026-87643 was patched at 2026-09-17
altlinux: CVE-2026-87644 was patched at 2026-09-17
altlinux: CVE-2026-87646 was patched at 2026-09-17
altlinux: CVE-2026-87648 was patched at 2026-09-17
altlinux: CVE-2026-87650 was patched at 2026-09-17
altlinux: CVE-2026-87654 was patched at 2026-09-17
altlinux: CVE-2026-91709 was patched at 2026-09-17
altlinux: CVE-2026-91710 was patched at 2026-09-17
altlinux: CVE-2026-91711 was patched at 2026-09-17
altlinux: CVE-2026-91712 was patched at 2026-09-17
altlinux: CVE-2026-91715 was patched at 2026-09-17
altlinux: CVE-2026-91716 was patched at 2026-09-17
altlinux: CVE-2026-91718 was patched at 2026-09-17
altlinux: CVE-2026-91721 was patched at 2026-09-17
altlinux: CVE-2026-91722 was patched at 2026-09-17
altlinux: CVE-2026-91724 was patched at 2026-09-17
altlinux: CVE-2026-91727 was patched at 2026-09-17
altlinux: CVE-2026-91728 was patched at 2026-09-17
altlinux: CVE-2026-91729 was patched at 2026-09-17
altlinux: CVE-2026-91731 was patched at 2026-09-17
altlinux: CVE-2026-91734 was patched at 2026-09-17
altlinux: CVE-2026-91735 was patched at 2026-09-17
altlinux: CVE-2026-91736 was patched at 2026-09-17
altlinux: CVE-2026-91737 was patched at 2026-09-17
altlinux: CVE-2026-91738 was patched at 2026-09-17
altlinux: CVE-2026-91741 was patched at 2026-09-17
altlinux: CVE-2026-91743 was patched at 2026-09-17
altlinux: CVE-2026-91745 was patched at 2026-09-17
altlinux: CVE-2026-91748 was patched at 2026-09-17
altlinux: CVE-2026-91749 was patched at 2026-09-17
debian: CVE-2026-76017 was patched at 2026-08-25, 2026-08-27
debian: CVE-2026-76018 was patched at 2026-08-25, 2026-08-27
debian: CVE-2026-76020 was patched at 2026-08-25, 2026-08-27
debian: CVE-2026-76021 was patched at 2026-08-25, 2026-08-27
debian: CVE-2026-76022 was patched at 2026-08-25, 2026-08-27
debian: CVE-2026-76023 was patched at 2026-08-25, 2026-08-27
debian: CVE-2026-78891 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78899 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78900 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78901 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78906 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78909 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78910 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78911 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78913 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78915 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78934 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78935 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78937 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78939 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78944 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78945 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78948 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78950 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78951 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78952 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78956 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78963 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78964 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78978 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78983 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78985 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78989 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78990 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78999 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79008 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79012 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79019 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79026 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79027 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79033 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79039 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79043 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79047 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79048 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79052 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79054 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79056 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79057 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79064 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79069 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79071 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79073 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79078 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79083 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79091 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79097 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79109 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79111 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79119 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79121 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79127 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79128 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79129 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79130 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79131 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79132 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79138 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79139 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79140 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79142 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79149 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79150 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79155 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79175 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79182 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79183 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79187 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79188 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79189 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79194 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79195 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79197 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79198 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79200 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79202 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79209 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79210 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79215 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79216 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79218 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79219 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79224 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79227 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79230 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79231 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79232 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79235 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79236 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79240 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79244 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79245 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79247 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79256 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79257 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79263 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79275 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79282 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79286 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79290 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79292 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84324 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84326 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84333 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84334 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84335 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84347 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84349 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84350 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84351 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84352 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84353 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84354 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-85042 was patched at 2026-09-05, 2026-09-16
debian: CVE-2026-85047 was patched at 2026-09-05, 2026-09-16
debian: CVE-2026-85048 was patched at 2026-09-05, 2026-09-16
debian: CVE-2026-85049 was patched at 2026-09-05, 2026-09-16
debian: CVE-2026-85050 was patched at 2026-09-05, 2026-09-16
debian: CVE-2026-85051 was patched at 2026-09-05, 2026-09-16
debian: CVE-2026-85053 was patched at 2026-09-05, 2026-09-16
debian: CVE-2026-87430 was patched at 2026-09-16
debian: CVE-2026-87438 was patched at 2026-09-16
debian: CVE-2026-87440 was patched at 2026-09-16
debian: CVE-2026-87444 was patched at 2026-09-16
debian: CVE-2026-87448 was patched at 2026-09-16
debian: CVE-2026-87455 was patched at 2026-09-16
debian: CVE-2026-87457 was patched at 2026-09-16
debian: CVE-2026-87460 was patched at 2026-09-16
debian: CVE-2026-87464 was patched at 2026-09-16
debian: CVE-2026-87467 was patched at 2026-09-16
debian: CVE-2026-87470 was patched at 2026-09-16
debian: CVE-2026-87474 was patched at 2026-09-16
debian: CVE-2026-87479 was patched at 2026-09-16
debian: CVE-2026-87480 was patched at 2026-09-16
debian: CVE-2026-87481 was patched at 2026-09-16
debian: CVE-2026-87487 was patched at 2026-09-16
debian: CVE-2026-87488 was patched at 2026-09-16
debian: CVE-2026-87489 was patched at 2026-09-16
debian: CVE-2026-87492 was patched at 2026-09-16
debian: CVE-2026-87494 was patched at 2026-09-16
debian: CVE-2026-87500 was patched at 2026-09-16
debian: CVE-2026-87504 was patched at 2026-09-16
debian: CVE-2026-87506 was patched at 2026-09-16
debian: CVE-2026-87509 was patched at 2026-09-16
debian: CVE-2026-87510 was patched at 2026-09-16
debian: CVE-2026-87512 was patched at 2026-09-16
debian: CVE-2026-87514 was patched at 2026-09-16
debian: CVE-2026-87520 was patched at 2026-09-16
debian: CVE-2026-87524 was patched at 2026-09-16
debian: CVE-2026-87526 was patched at 2026-09-16
debian: CVE-2026-87527 was patched at 2026-09-16
debian: CVE-2026-87529 was patched at 2026-09-16
debian: CVE-2026-87530 was patched at 2026-09-16
debian: CVE-2026-87536 was patched at 2026-09-16
debian: CVE-2026-87537 was patched at 2026-09-16
debian: CVE-2026-87542 was patched at 2026-09-16
debian: CVE-2026-87547 was patched at 2026-09-16
debian: CVE-2026-87553 was patched at 2026-09-16
debian: CVE-2026-87554 was patched at 2026-09-16
debian: CVE-2026-87558 was patched at 2026-09-16
debian: CVE-2026-87572 was patched at 2026-09-16
debian: CVE-2026-87578 was patched at 2026-09-16
debian: CVE-2026-87579 was patched at 2026-09-16
debian: CVE-2026-87581 was patched at 2026-09-16
debian: CVE-2026-87582 was patched at 2026-09-16
debian: CVE-2026-87585 was patched at 2026-09-16
debian: CVE-2026-87587 was patched at 2026-09-16
debian: CVE-2026-87588 was patched at 2026-09-16
debian: CVE-2026-87601 was patched at 2026-09-16
debian: CVE-2026-87604 was patched at 2026-09-16
debian: CVE-2026-87607 was patched at 2026-09-16
debian: CVE-2026-87609 was patched at 2026-09-16
debian: CVE-2026-87612 was patched at 2026-09-16
debian: CVE-2026-87613 was patched at 2026-09-16
debian: CVE-2026-87616 was patched at 2026-09-16
debian: CVE-2026-87617 was patched at 2026-09-16
debian: CVE-2026-87618 was patched at 2026-09-16
debian: CVE-2026-87621 was patched at 2026-09-16
debian: CVE-2026-87625 was patched at 2026-09-16
debian: CVE-2026-87628 was patched at 2026-09-16
debian: CVE-2026-87633 was patched at 2026-09-16
debian: CVE-2026-87634 was patched at 2026-09-16
debian: CVE-2026-87636 was patched at 2026-09-16
debian: CVE-2026-87637 was patched at 2026-09-16
debian: CVE-2026-87638 was patched at 2026-09-16
debian: CVE-2026-87639 was patched at 2026-09-16
debian: CVE-2026-87643 was patched at 2026-09-16
debian: CVE-2026-87644 was patched at 2026-09-16
debian: CVE-2026-87646 was patched at 2026-09-16
debian: CVE-2026-87648 was patched at 2026-09-16
debian: CVE-2026-87650 was patched at 2026-09-16
debian: CVE-2026-87654 was patched at 2026-09-16
debian: CVE-2026-91709 was patched at 2026-09-16
debian: CVE-2026-91710 was patched at 2026-09-16
debian: CVE-2026-91711 was patched at 2026-09-16
debian: CVE-2026-91712 was patched at 2026-09-16
debian: CVE-2026-91715 was patched at 2026-09-16
debian: CVE-2026-91716 was patched at 2026-09-16
debian: CVE-2026-91718 was patched at 2026-09-16
debian: CVE-2026-91721 was patched at 2026-09-16
debian: CVE-2026-91722 was patched at 2026-09-16
debian: CVE-2026-91724 was patched at 2026-09-16
debian: CVE-2026-91727 was patched at 2026-09-16
debian: CVE-2026-91728 was patched at 2026-09-16
debian: CVE-2026-91729 was patched at 2026-09-16
debian: CVE-2026-91731 was patched at 2026-09-16
debian: CVE-2026-91734 was patched at 2026-09-16
debian: CVE-2026-91735 was patched at 2026-09-16
debian: CVE-2026-91736 was patched at 2026-09-16
debian: CVE-2026-91737 was patched at 2026-09-16
debian: CVE-2026-91738 was patched at 2026-09-16
debian: CVE-2026-91741 was patched at 2026-09-16
debian: CVE-2026-91743 was patched at 2026-09-16
debian: CVE-2026-91745 was patched at 2026-09-16
debian: CVE-2026-91748 was patched at 2026-09-16
debian: CVE-2026-91749 was patched at 2026-09-16
debian: CVE-2026-59944 was patched at 2026-09-16
debian: CVE-2026-76174 was patched at 2026-09-16
redos: CVE-2026-12046 was patched at 2026-09-07
debian: CVE-2026-83557 was patched at 2026-09-16
debian: CVE-2026-72710 was patched at 2026-09-16
debian: CVE-2026-91957 was patched at 2026-09-16
debian: CVE-2026-91963 was patched at 2026-09-16
debian: CVE-2026-91964 was patched at 2026-09-16
altlinux: CVE-2026-62897 was patched at 2026-08-31, 2026-09-02
redos: CVE-2026-62897 was patched at 2026-09-07
debian: CVE-2026-18147 was patched at 2026-09-16
debian: CVE-2026-11573 was patched at 2026-09-16
almalinux: CVE-2026-18355 was patched at 2026-09-08
altlinux: CVE-2026-18355 was patched at 2026-09-08, 2026-09-11
debian: CVE-2026-18355 was patched at 2026-09-16
oraclelinux: CVE-2026-18355 was patched at 2026-09-08, 2026-09-10
redhat: CVE-2026-18355 was patched at 2026-09-08
debian: CVE-2026-71513 was patched at 2026-08-25
debian: CVE-2026-89489 was patched at 2026-09-16
debian: CVE-2026-68006 was patched at 2026-09-16
debian: CVE-2026-34398 was patched at 2026-08-25, 2026-08-26
debian: CVE-2026-87874 was patched at 2026-09-16
debian: CVE-2026-85197 was patched at 2026-09-16
debian: CVE-2026-47884 was patched at 2026-09-16
debian: CVE-2025-70290 was patched at 2026-09-16
debian: CVE-2025-70293 was patched at 2026-09-16
almalinux: CVE-2026-81934 was patched at 2026-09-08
altlinux: CVE-2026-81934 was patched at 2026-09-14
debian: CVE-2026-81934 was patched at 2026-09-16
oraclelinux: CVE-2026-81934 was patched at 2026-09-09, 2026-09-14
redhat: CVE-2026-81934 was patched at 2026-09-08
debian: CVE-2026-78689 was patched at 2026-09-16
almalinux: CVE-2026-56684 was patched at 2026-09-08
altlinux: CVE-2026-56684 was patched at 2026-08-20, 2026-08-23
debian: CVE-2026-56684 was patched at 2026-08-25
oraclelinux: CVE-2026-56684 was patched at 2026-09-08
redhat: CVE-2026-56684 was patched at 2026-09-08
debian: CVE-2026-90648 was patched at 2026-09-16
altlinux: CVE-2026-62871 was patched at 2026-08-31, 2026-09-02
redos: CVE-2026-62871 was patched at 2026-09-07
debian: CVE-2026-84268 was patched at 2026-09-16
redos: CVE-2026-24187 was patched at 2026-09-08
redos: CVE-2026-24190 was patched at 2026-09-08
redos: CVE-2026-24192 was patched at 2026-09-08
redos: CVE-2026-24193 was patched at 2026-09-08
redos: CVE-2026-24194 was patched at 2026-09-08
altlinux: CVE-2026-70354 was patched at 2026-08-31, 2026-09-02
redos: CVE-2026-70354 was patched at 2026-09-07
debian: CVE-2026-18393 was patched at 2026-09-16
debian: CVE-2026-82327 was patched at 2026-09-16
debian: CVE-2026-84233 was patched at 2026-09-16
debian: CVE-2026-90947 was patched at 2026-09-16
debian: CVE-2026-90948 was patched at 2026-09-16
debian: CVE-2026-92248 was patched at 2026-09-16
almalinux: CVE-2026-63639 was patched at 2026-09-08
altlinux: CVE-2026-63639 was patched at 2026-08-20, 2026-08-23
debian: CVE-2026-15686 was patched at 2026-08-25
debian: CVE-2026-19774 was patched at 2026-09-16
debian: CVE-2026-38821 was patched at 2026-09-16
debian: CVE-2026-40013 was patched at 2026-09-16
debian: CVE-2026-42007 was patched at 2026-09-16
debian: CVE-2026-55588 was patched at 2026-09-16
debian: CVE-2026-55893 was patched at 2026-08-25
debian: CVE-2026-55894 was patched at 2026-08-25
debian: CVE-2026-56704 was patched at 2026-09-16
debian: CVE-2026-56711 was patched at 2026-09-16
debian: CVE-2026-63639 was patched at 2026-08-25
debian: CVE-2026-68766 was patched at 2026-08-25
debian: CVE-2026-69242 was patched at 2026-08-25
debian: CVE-2026-71220 was patched at 2026-09-16
debian: CVE-2026-71221 was patched at 2026-09-16
debian: CVE-2026-75131 was patched at 2026-09-14, 2026-09-16
debian: CVE-2026-75538 was patched at 2026-09-16
debian: CVE-2026-79992 was patched at 2026-09-16
debian: CVE-2026-80186 was patched at 2026-09-16
debian: CVE-2026-84838 was patched at 2026-09-16
debian: CVE-2026-89329 was patched at 2026-09-16
debian: CVE-2026-90558 was patched at 2026-09-16
oraclelinux: CVE-2026-63639 was patched at 2026-09-08
redhat: CVE-2026-63639 was patched at 2026-09-08
altlinux: CVE-2026-86320 was patched at 2026-09-12
debian: CVE-2026-86320 was patched at 2026-09-16
debian: CVE-2026-77652 was patched at 2026-09-16
debian: CVE-2026-52491 was patched at 2026-09-16
debian: CVE-2026-76060 was patched at 2026-09-16
debian: CVE-2026-84837 was patched at 2026-09-16
debian: CVE-2026-82853 was patched at 2026-09-16
debian: CVE-2026-82854 was patched at 2026-09-16
debian: CVE-2026-19203 was patched at 2026-09-16
debian: CVE-2023-54397 was patched at 2026-09-16
debian: CVE-2024-14029 was patched at 2026-09-16
debian: CVE-2026-38820 was patched at 2026-09-16
debian: CVE-2026-38822 was patched at 2026-09-16
debian: CVE-2026-66357 was patched at 2026-09-16
debian: CVE-2018-1000644 was patched at 2026-08-25
debian: CVE-2026-17615 was patched at 2026-09-16
debian: CVE-2026-19614 was patched at 2026-09-16
debian: CVE-2026-74752 was patched at 2026-09-16
debian: CVE-2026-80560 was patched at 2026-09-16
debian: CVE-2026-89579 was patched at 2026-09-16
debian: CVE-2026-89610 was patched at 2026-09-16
debian: CVE-2026-89638 was patched at 2026-09-16
debian: CVE-2026-18917 was patched at 2026-08-25
redos: CVE-2026-58641 was patched at 2026-09-07
altlinux: CVE-2026-62886 was patched at 2026-08-31, 2026-09-02
redos: CVE-2026-62886 was patched at 2026-09-07
debian: CVE-2026-57223 was patched at 2026-09-16
altlinux: CVE-2026-88924 was patched at 2026-09-12
debian: CVE-2026-88924 was patched at 2026-09-16
debian: CVE-2026-19624 was patched at 2026-09-14, 2026-09-16
debian: CVE-2026-70665 was patched at 2026-09-16
debian: CVE-2026-90463 was patched at 2026-09-16
debian: CVE-2026-88056 was patched at 2026-09-16
altlinux: CVE-2026-87595 was patched at 2026-09-17
debian: CVE-2026-87595 was patched at 2026-09-16
debian: CVE-2026-62993 was patched at 2026-09-16
debian: CVE-2026-19953 was patched at 2026-09-16
debian: CVE-2026-86144 was patched at 2026-09-16
debian: CVE-2026-75899 was patched at 2026-08-25
debian: CVE-2026-76172 was patched at 2026-08-25
debian: CVE-2026-84394 was patched at 2026-09-16
altlinux: CVE-2026-4200 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-42007 was patched at 2026-09-16
debian: CVE-2026-42008 was patched at 2026-09-16
altlinux: CVE-2026-55073 was patched at 2026-09-09
debian: CVE-2026-55073 was patched at 2026-09-16
debian: CVE-2026-10582 was patched at 2026-09-16
debian: CVE-2026-34964 was patched at 2026-09-16
debian: CVE-2026-71198 was patched at 2026-09-16
debian: CVE-2026-76177 was patched at 2026-09-16
debian: CVE-2026-77648 was patched at 2026-08-25
almalinux: CVE-2026-69806 was patched at 2026-09-15
oraclelinux: CVE-2026-69806 was patched at 2026-09-15, 2026-09-16
ubuntu: CVE-2026-69806 was patched at 2026-09-10, 2026-09-16
debian: CVE-2026-76176 was patched at 2026-09-16
altlinux: CVE-2026-79249 was patched at 2026-08-28
altlinux: CVE-2026-91719 was patched at 2026-09-17
debian: CVE-2026-79249 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-91719 was patched at 2026-09-16
altlinux: CVE-2026-54310 was patched at 2026-08-26, 2026-08-28, 2026-08-29, 2026-09-01
debian: CVE-2026-73073 was patched at 2026-08-20
redos: CVE-2026-73073 was patched at 2026-09-08
ubuntu: CVE-2026-73073 was patched at 2026-08-25, 2026-09-16
debian: CVE-2026-72708 was patched at 2026-09-16
altlinux: CVE-2026-18708 was patched at 2026-08-26
debian: CVE-2026-34789 was patched at 2026-08-25, 2026-08-26
debian: CVE-2026-59281 was patched at 2026-09-16
almalinux: CVE-2026-19546 was patched at 2026-09-09
debian: CVE-2026-40018 was patched at 2026-09-16
debian: CVE-2026-76175 was patched at 2026-09-16
oraclelinux: CVE-2026-19546 was patched at 2026-09-10
redhat: CVE-2026-19546 was patched at 2026-09-09
debian: CVE-2026-88057 was patched at 2026-09-16
debian: CVE-2026-88058 was patched at 2026-09-16
debian: CVE-2026-88060 was patched at 2026-09-16
redos: CVE-2026-17033 was patched at 2026-09-08
almalinux: CVE-2026-49825 was patched at 2026-09-09
debian: CVE-2026-49825 was patched at 2026-08-25
oraclelinux: CVE-2026-49825 was patched at 2026-09-10
redhat: CVE-2026-49825 was patched at 2026-09-09
debian: CVE-2026-19872 was patched at 2026-09-16
debian: CVE-2026-85484 was patched at 2026-09-16
debian: CVE-2026-85485 was patched at 2026-09-16
debian: CVE-2026-85630 was patched at 2026-09-16
debian: CVE-2026-75838 was patched at 2026-08-20
debian: CVE-2026-77506 was patched at 2026-08-25
debian: CVE-2026-10618 was patched at 2026-09-16
debian: CVE-2026-76178 was patched at 2026-09-16
debian: CVE-2026-77643 was patched at 2026-08-25
debian: CVE-2026-90848 was patched at 2026-09-16
altlinux: CVE-2026-74938 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-74968 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-74970 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-74981 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-75874 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03, 2026-09-10
altlinux: CVE-2026-84129 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
altlinux: CVE-2026-84133 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
altlinux: CVE-2026-84135 was patched at 2026-09-01, 2026-09-05
altlinux: CVE-2026-84137 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
altlinux: CVE-2026-84140 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
debian: CVE-2026-75874 was patched at 2026-09-02, 2026-09-04, 2026-09-16
oraclelinux: CVE-2026-75874 was patched at 2026-09-14
debian: CVE-2026-37236 was patched at 2026-09-16
altlinux: CVE-2026-65637 was patched at 2026-08-26, 2026-08-27, 2026-09-11, 2026-09-16
debian: CVE-2026-65637 was patched at 2026-09-16
altlinux: CVE-2026-78894 was patched at 2026-08-28
altlinux: CVE-2026-78895 was patched at 2026-08-28
altlinux: CVE-2026-78908 was patched at 2026-08-28
altlinux: CVE-2026-78940 was patched at 2026-08-28
altlinux: CVE-2026-78941 was patched at 2026-08-28
altlinux: CVE-2026-78942 was patched at 2026-08-28
altlinux: CVE-2026-78943 was patched at 2026-08-28
altlinux: CVE-2026-78946 was patched at 2026-08-28
altlinux: CVE-2026-78953 was patched at 2026-08-28
altlinux: CVE-2026-78966 was patched at 2026-08-28
altlinux: CVE-2026-78976 was patched at 2026-08-28
altlinux: CVE-2026-78980 was patched at 2026-08-28
altlinux: CVE-2026-78987 was patched at 2026-08-28
altlinux: CVE-2026-79000 was patched at 2026-08-28
altlinux: CVE-2026-79002 was patched at 2026-08-28
altlinux: CVE-2026-79006 was patched at 2026-08-28
altlinux: CVE-2026-79013 was patched at 2026-08-28
altlinux: CVE-2026-79015 was patched at 2026-08-28
altlinux: CVE-2026-79017 was patched at 2026-08-28
altlinux: CVE-2026-79025 was patched at 2026-08-28
altlinux: CVE-2026-79031 was patched at 2026-08-28
altlinux: CVE-2026-79032 was patched at 2026-08-28
altlinux: CVE-2026-79034 was patched at 2026-08-28
altlinux: CVE-2026-79049 was patched at 2026-08-28
altlinux: CVE-2026-79050 was patched at 2026-08-28
altlinux: CVE-2026-79051 was patched at 2026-08-28
altlinux: CVE-2026-79053 was patched at 2026-08-28
altlinux: CVE-2026-79065 was patched at 2026-08-28
altlinux: CVE-2026-79066 was patched at 2026-08-28
altlinux: CVE-2026-79070 was patched at 2026-08-28
altlinux: CVE-2026-79076 was patched at 2026-08-28
altlinux: CVE-2026-79077 was patched at 2026-08-28
altlinux: CVE-2026-79084 was patched at 2026-08-28
altlinux: CVE-2026-79094 was patched at 2026-08-28
altlinux: CVE-2026-79099 was patched at 2026-08-28
altlinux: CVE-2026-79103 was patched at 2026-08-28
altlinux: CVE-2026-79105 was patched at 2026-08-28
altlinux: CVE-2026-79106 was patched at 2026-08-28
altlinux: CVE-2026-79110 was patched at 2026-08-28
altlinux: CVE-2026-79123 was patched at 2026-08-28
altlinux: CVE-2026-79136 was patched at 2026-08-28
altlinux: CVE-2026-79141 was patched at 2026-08-28
altlinux: CVE-2026-79151 was patched at 2026-08-28
altlinux: CVE-2026-79178 was patched at 2026-08-28
altlinux: CVE-2026-79185 was patched at 2026-08-28
altlinux: CVE-2026-79186 was patched at 2026-08-28
altlinux: CVE-2026-79191 was patched at 2026-08-28
altlinux: CVE-2026-79192 was patched at 2026-08-28
altlinux: CVE-2026-79193 was patched at 2026-08-28
altlinux: CVE-2026-79199 was patched at 2026-08-28
altlinux: CVE-2026-79203 was patched at 2026-08-28
altlinux: CVE-2026-79205 was patched at 2026-08-28
altlinux: CVE-2026-79213 was patched at 2026-08-28
altlinux: CVE-2026-79214 was patched at 2026-08-28
altlinux: CVE-2026-79217 was patched at 2026-08-28
altlinux: CVE-2026-79228 was patched at 2026-08-28
altlinux: CVE-2026-79237 was patched at 2026-08-28
altlinux: CVE-2026-79243 was patched at 2026-08-28
altlinux: CVE-2026-79251 was patched at 2026-08-28
altlinux: CVE-2026-79253 was patched at 2026-08-28
altlinux: CVE-2026-79254 was patched at 2026-08-28
altlinux: CVE-2026-79255 was patched at 2026-08-28
altlinux: CVE-2026-79259 was patched at 2026-08-28
altlinux: CVE-2026-79260 was patched at 2026-08-28
altlinux: CVE-2026-79261 was patched at 2026-08-28
altlinux: CVE-2026-79262 was patched at 2026-08-28
altlinux: CVE-2026-79264 was patched at 2026-08-28
altlinux: CVE-2026-79272 was patched at 2026-08-28
altlinux: CVE-2026-79288 was patched at 2026-08-28
altlinux: CVE-2026-79289 was patched at 2026-08-28
altlinux: CVE-2026-84325 was patched at 2026-09-03
altlinux: CVE-2026-84332 was patched at 2026-09-03
altlinux: CVE-2026-84357 was patched at 2026-09-03
altlinux: CVE-2026-84359 was patched at 2026-09-03
altlinux: CVE-2026-85043 was patched at 2026-09-05
altlinux: CVE-2026-87433 was patched at 2026-09-17
altlinux: CVE-2026-87449 was patched at 2026-09-17
altlinux: CVE-2026-87461 was patched at 2026-09-17
altlinux: CVE-2026-87466 was patched at 2026-09-17
altlinux: CVE-2026-87469 was patched at 2026-09-17
altlinux: CVE-2026-87471 was patched at 2026-09-17
altlinux: CVE-2026-87472 was patched at 2026-09-17
altlinux: CVE-2026-87495 was patched at 2026-09-17
altlinux: CVE-2026-87499 was patched at 2026-09-17
altlinux: CVE-2026-87508 was patched at 2026-09-17
altlinux: CVE-2026-87516 was patched at 2026-09-17
altlinux: CVE-2026-87541 was patched at 2026-09-17
altlinux: CVE-2026-87543 was patched at 2026-09-17
altlinux: CVE-2026-87544 was patched at 2026-09-17
altlinux: CVE-2026-87546 was patched at 2026-09-17
altlinux: CVE-2026-87548 was patched at 2026-09-17
altlinux: CVE-2026-87551 was patched at 2026-09-17
altlinux: CVE-2026-87556 was patched at 2026-09-17
altlinux: CVE-2026-87560 was patched at 2026-09-17
altlinux: CVE-2026-87561 was patched at 2026-09-17
altlinux: CVE-2026-87563 was patched at 2026-09-17
altlinux: CVE-2026-87568 was patched at 2026-09-17
altlinux: CVE-2026-87570 was patched at 2026-09-17
altlinux: CVE-2026-87571 was patched at 2026-09-17
altlinux: CVE-2026-87573 was patched at 2026-09-17
altlinux: CVE-2026-87590 was patched at 2026-09-17
altlinux: CVE-2026-87591 was patched at 2026-09-17
altlinux: CVE-2026-87598 was patched at 2026-09-17
altlinux: CVE-2026-87600 was patched at 2026-09-17
altlinux: CVE-2026-87603 was patched at 2026-09-17
altlinux: CVE-2026-87608 was patched at 2026-09-17
altlinux: CVE-2026-87610 was patched at 2026-09-17
altlinux: CVE-2026-87619 was patched at 2026-09-17
altlinux: CVE-2026-87622 was patched at 2026-09-17
altlinux: CVE-2026-87626 was patched at 2026-09-17
altlinux: CVE-2026-87632 was patched at 2026-09-17
altlinux: CVE-2026-87641 was patched at 2026-09-17
altlinux: CVE-2026-87642 was patched at 2026-09-17
altlinux: CVE-2026-87645 was patched at 2026-09-17
altlinux: CVE-2026-87656 was patched at 2026-09-17
debian: CVE-2026-78894 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78895 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78908 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78940 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78941 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78942 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78943 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78946 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78953 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78966 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78976 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78980 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78987 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79000 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79002 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79006 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79013 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79015 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79017 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79025 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79031 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79032 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79034 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79049 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79050 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79051 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79053 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79065 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79066 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79070 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79076 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79077 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79084 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79094 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79099 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79103 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79105 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79106 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79110 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79123 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79136 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79141 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79151 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79178 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79185 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79186 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79191 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79192 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79193 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79199 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79203 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79205 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79213 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79214 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79217 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79228 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79237 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79243 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79251 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79253 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79254 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79255 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79259 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79260 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79261 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79262 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79264 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79272 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79288 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79289 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84325 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84332 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84357 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84359 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-85043 was patched at 2026-09-05, 2026-09-16
debian: CVE-2026-87433 was patched at 2026-09-16
debian: CVE-2026-87449 was patched at 2026-09-16
debian: CVE-2026-87461 was patched at 2026-09-16
debian: CVE-2026-87466 was patched at 2026-09-16
debian: CVE-2026-87469 was patched at 2026-09-16
debian: CVE-2026-87471 was patched at 2026-09-16
debian: CVE-2026-87472 was patched at 2026-09-16
debian: CVE-2026-87495 was patched at 2026-09-16
debian: CVE-2026-87499 was patched at 2026-09-16
debian: CVE-2026-87508 was patched at 2026-09-16
debian: CVE-2026-87516 was patched at 2026-09-16
debian: CVE-2026-87541 was patched at 2026-09-16
debian: CVE-2026-87543 was patched at 2026-09-16
debian: CVE-2026-87544 was patched at 2026-09-16
debian: CVE-2026-87546 was patched at 2026-09-16
debian: CVE-2026-87548 was patched at 2026-09-16
debian: CVE-2026-87551 was patched at 2026-09-16
debian: CVE-2026-87556 was patched at 2026-09-16
debian: CVE-2026-87560 was patched at 2026-09-16
debian: CVE-2026-87561 was patched at 2026-09-16
debian: CVE-2026-87563 was patched at 2026-09-16
debian: CVE-2026-87568 was patched at 2026-09-16
debian: CVE-2026-87570 was patched at 2026-09-16
debian: CVE-2026-87571 was patched at 2026-09-16
debian: CVE-2026-87573 was patched at 2026-09-16
debian: CVE-2026-87590 was patched at 2026-09-16
debian: CVE-2026-87591 was patched at 2026-09-16
debian: CVE-2026-87598 was patched at 2026-09-16
debian: CVE-2026-87600 was patched at 2026-09-16
debian: CVE-2026-87603 was patched at 2026-09-16
debian: CVE-2026-87608 was patched at 2026-09-16
debian: CVE-2026-87610 was patched at 2026-09-16
debian: CVE-2026-87619 was patched at 2026-09-16
debian: CVE-2026-87622 was patched at 2026-09-16
debian: CVE-2026-87626 was patched at 2026-09-16
debian: CVE-2026-87632 was patched at 2026-09-16
debian: CVE-2026-87641 was patched at 2026-09-16
debian: CVE-2026-87642 was patched at 2026-09-16
debian: CVE-2026-87645 was patched at 2026-09-16
debian: CVE-2026-87656 was patched at 2026-09-16
debian: CVE-2026-16434 was patched at 2026-09-16
debian: CVE-2026-49283 was patched at 2026-08-25
debian: CVE-2026-56706 was patched at 2026-09-16
debian: CVE-2026-53600 was patched at 2026-09-16
debian: CVE-2026-91949 was patched at 2026-09-16
debian: CVE-2026-72889 was patched at 2026-08-20
altlinux: CVE-2026-64728 was patched at 2026-08-24
debian: CVE-2026-64728 was patched at 2026-08-24, 2026-08-25
ubuntu: CVE-2026-64728 was patched at 2026-08-31, 2026-09-16
debian: CVE-2026-82474 was patched at 2026-09-16
altlinux: CVE-2026-84637 was patched at 2026-09-03, 2026-09-09
altlinux: CVE-2026-33604 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-33604 was patched at 2026-09-16
altlinux: CVE-2026-18691 was patched at 2026-08-26
altlinux: CVE-2026-18705 was patched at 2026-08-26
altlinux: CVE-2026-82065 was patched at 2026-09-09, 2026-09-10
altlinux: CVE-2026-62902 was patched at 2026-08-31, 2026-09-02
redos: CVE-2026-62902 was patched at 2026-09-07
almalinux: CVE-2026-58649 was patched at 2026-09-15
oraclelinux: CVE-2026-58649 was patched at 2026-09-15, 2026-09-16
ubuntu: CVE-2026-58649 was patched at 2026-09-10, 2026-09-16
altlinux: CVE-2026-16093 was patched at 2026-09-01, 2026-09-04, 2026-09-07
altlinux: CVE-2026-78134 was patched at 2026-09-11
debian: CVE-2026-78134 was patched at 2026-09-07, 2026-09-16
debian: CVE-2026-76816 was patched at 2026-09-16
redos: CVE-2026-41207 was patched at 2026-09-04
altlinux: CVE-2026-75803 was patched at 2026-08-26
debian: CVE-2026-75803 was patched at 2026-08-25
ubuntu: CVE-2026-75803 was patched at 2026-08-25, 2026-09-16
debian: CVE-2026-48932 was patched at 2026-09-16
debian: CVE-2026-75975 was patched at 2026-08-25
debian: CVE-2026-18540 was patched at 2026-09-16
debian: CVE-2026-84947 was patched at 2026-09-16
debian: CVE-2026-84961 was patched at 2026-09-16
debian: CVE-2026-85008 was patched at 2026-09-16
debian: CVE-2026-78807 was patched at 2026-09-16
redos: CVE-2025-33221 was patched at 2026-09-08
redos: CVE-2026-24195 was patched at 2026-09-08
debian: CVE-2026-82662 was patched at 2026-09-16
debian: CVE-2026-55371 was patched at 2026-09-16
debian: CVE-2026-63336 was patched at 2026-08-20
debian: CVE-2026-68554 was patched at 2026-08-25
debian: CVE-2026-78323 was patched at 2026-08-25
debian: CVE-2026-87872 was patched at 2026-09-16
debian: CVE-2025-30156 was patched at 2026-08-25
debian: CVE-2026-34959 was patched at 2026-09-16
debian: CVE-2026-39944 was patched at 2026-08-25
debian: CVE-2026-48548 was patched at 2026-09-16
debian: CVE-2026-48549 was patched at 2026-09-16
debian: CVE-2026-53499 was patched at 2026-08-25, 2026-09-08
debian: CVE-2026-54330 was patched at 2026-08-25
debian: CVE-2026-61634 was patched at 2026-08-20
debian: CVE-2026-63335 was patched at 2026-08-20
debian: CVE-2026-73276 was patched at 2026-09-16
debian: CVE-2026-73812 was patched at 2026-09-16
debian: CVE-2026-75032 was patched at 2026-08-20
debian: CVE-2026-86145 was patched at 2026-09-04, 2026-09-16
debian: CVE-2026-87732 was patched at 2026-09-16
debian: CVE-2026-87733 was patched at 2026-09-16
debian: CVE-2026-89169 was patched at 2026-09-16
oraclelinux: CVE-2025-31356 was patched at 2026-09-02, 2026-09-16
oraclelinux: CVE-2026-20715 was patched at 2026-09-02, 2026-09-16
redos: CVE-2026-61711 was patched at 2026-09-07
altlinux: CVE-2026-84185 was patched at 2026-09-02, 2026-09-07
debian: CVE-2026-84185 was patched at 2026-09-16
altlinux: CVE-2026-74979 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-84117 was patched at 2026-09-01, 2026-09-05
altlinux: CVE-2026-84128 was patched at 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
altlinux: CVE-2026-66422 was patched at 2026-08-26, 2026-08-27, 2026-09-11, 2026-09-16
debian: CVE-2026-66422 was patched at 2026-09-16
debian: CVE-2026-86219 was patched at 2026-09-16
altlinux: CVE-2026-88018 was patched at 2026-09-09
debian: CVE-2026-88018 was patched at 2026-09-16
almalinux: CVE-2026-18922 was patched at 2026-09-08
altlinux: CVE-2026-18922 was patched at 2026-09-08, 2026-09-11
debian: CVE-2026-18922 was patched at 2026-09-16
oraclelinux: CVE-2026-18922 was patched at 2026-09-08, 2026-09-10
redhat: CVE-2026-18922 was patched at 2026-09-08
redos: CVE-2026-40344 was patched at 2026-09-02
redos: CVE-2026-41145 was patched at 2026-09-02
altlinux: CVE-2026-71113 was patched at 2026-08-21
altlinux: CVE-2026-71114 was patched at 2026-08-21
altlinux: CVE-2026-71115 was patched at 2026-08-21
altlinux: CVE-2026-71116 was patched at 2026-08-21
altlinux: CVE-2026-71126 was patched at 2026-08-21
altlinux: CVE-2026-71127 was patched at 2026-08-21
altlinux: CVE-2026-71129 was patched at 2026-08-21
altlinux: CVE-2026-71130 was patched at 2026-08-21
altlinux: CVE-2026-71131 was patched at 2026-08-21
altlinux: CVE-2026-71132 was patched at 2026-08-21
altlinux: CVE-2026-71134 was patched at 2026-08-21
altlinux: CVE-2026-71135 was patched at 2026-08-21
altlinux: CVE-2026-71136 was patched at 2026-08-21
altlinux: CVE-2026-71137 was patched at 2026-08-21
altlinux: CVE-2026-71138 was patched at 2026-08-21
altlinux: CVE-2026-71139 was patched at 2026-08-21
altlinux: CVE-2026-71140 was patched at 2026-08-21
altlinux: CVE-2026-71141 was patched at 2026-08-21
altlinux: CVE-2026-71151 was patched at 2026-08-21
altlinux: CVE-2026-11861 was patched at 2026-08-20
debian: CVE-2026-11861 was patched at 2026-08-25
altlinux: CVE-2026-20779 was patched at 2026-08-27, 2026-08-29, 2026-09-04
altlinux: CVE-2026-58508 was patched at 2026-08-27, 2026-08-29, 2026-09-04
redos: CVE-2026-58508 was patched at 2026-08-20
debian: CVE-2026-90711 was patched at 2026-09-16
altlinux: CVE-2026-73208 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-42008 was patched at 2026-09-16
debian: CVE-2026-73208 was patched at 2026-09-16
debian: CVE-2026-44476 was patched at 2026-09-16
altlinux: CVE-2026-14613 was patched at 2026-08-20, 2026-08-26, 2026-08-28
altlinux: CVE-2026-16072 was patched at 2026-09-01, 2026-09-04, 2026-09-07
altlinux: CVE-2026-16104 was patched at 2026-09-01, 2026-09-04, 2026-09-07
altlinux: CVE-2026-18215 was patched at 2026-09-01, 2026-09-04, 2026-09-07
altlinux: CVE-2016-2102 was patched at 2026-08-24
altlinux: CVE-2026-88007 was patched at 2026-09-15, 2026-09-16
altlinux: CVE-2026-88009 was patched at 2026-09-15, 2026-09-16
altlinux: CVE-2026-18664 was patched at 2026-08-27, 2026-08-28, 2026-09-01
altlinux: CVE-2026-19538 was patched at 2026-08-27, 2026-08-28, 2026-09-01
debian: CVE-2026-18664 was patched at 2026-09-16
debian: CVE-2026-19538 was patched at 2026-09-16
altlinux: CVE-2026-60725 was patched at 2026-08-24
altlinux: CVE-2026-78135 was patched at 2026-09-11
debian: CVE-2026-78135 was patched at 2026-09-07, 2026-09-16
altlinux: CVE-2026-82070 was patched at 2026-09-09, 2026-09-10
altlinux: CVE-2026-79201 was patched at 2026-08-28
debian: CVE-2026-79201 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-63379 was patched at 2026-08-25, 2026-09-11
altlinux: CVE-2026-88011 was patched at 2026-09-15, 2026-09-16
altlinux: CVE-2026-88879 was patched at 2026-09-15, 2026-09-16
altlinux: CVE-2026-40205 was patched at 2026-08-29, 2026-09-01
altlinux: CVE-2026-58421 was patched at 2026-08-27, 2026-08-29, 2026-09-04
altlinux: CVE-2026-58422 was patched at 2026-08-27, 2026-08-29, 2026-09-04
altlinux: CVE-2026-58423 was patched at 2026-08-27, 2026-08-29, 2026-09-04
debian: CVE-2026-40204 was patched at 2026-09-16
debian: CVE-2026-40205 was patched at 2026-09-16
debian: CVE-2026-85152 was patched at 2026-09-16
debian: CVE-2026-82247 was patched at 2026-09-16
debian: CVE-2026-82255 was patched at 2026-09-16
oraclelinux: CVE-2026-20885 was patched at 2026-09-02, 2026-09-16
oraclelinux: CVE-2026-20898 was patched at 2026-09-02, 2026-09-16
debian: CVE-2026-75509 was patched at 2026-09-16
debian: CVE-2026-74734 was patched at 2026-09-16
debian: CVE-2026-80636 was patched at 2026-09-16
debian: CVE-2026-80655 was patched at 2026-09-16
debian: CVE-2026-80765 was patched at 2026-09-16
debian: CVE-2026-80823 was patched at 2026-09-16
debian: CVE-2026-80864 was patched at 2026-09-16
debian: CVE-2026-80870 was patched at 2026-09-16
debian: CVE-2026-81003 was patched at 2026-09-16
debian: CVE-2026-89657 was patched at 2026-09-16
redos: CVE-2026-80870 was patched at 2026-09-16
altlinux: CVE-2026-79090 was patched at 2026-08-28
altlinux: CVE-2026-79226 was patched at 2026-08-28
altlinux: CVE-2026-79276 was patched at 2026-08-28
altlinux: CVE-2026-84358 was patched at 2026-09-03
altlinux: CVE-2026-87538 was patched at 2026-09-17
altlinux: CVE-2026-87655 was patched at 2026-09-17
debian: CVE-2026-79090 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79226 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79276 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84358 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-87538 was patched at 2026-09-16
debian: CVE-2026-87655 was patched at 2026-09-16
almalinux: CVE-2026-54874 was patched at 2026-09-14
almalinux: CVE-2026-63072 was patched at 2026-09-14
almalinux: CVE-2026-63074 was patched at 2026-09-14
almalinux: CVE-2026-63075 was patched at 2026-09-14
altlinux: CVE-2026-54874 was patched at 2026-08-26
altlinux: CVE-2026-63072 was patched at 2026-08-26
altlinux: CVE-2026-63074 was patched at 2026-08-26
altlinux: CVE-2026-63075 was patched at 2026-08-26
debian: CVE-2026-54874 was patched at 2026-08-25, 2026-09-16
debian: CVE-2026-63072 was patched at 2026-08-25, 2026-09-16
debian: CVE-2026-63074 was patched at 2026-08-25, 2026-09-16
debian: CVE-2026-63075 was patched at 2026-08-25, 2026-09-16
oraclelinux: CVE-2026-54874 was patched at 2026-09-14
oraclelinux: CVE-2026-63072 was patched at 2026-09-14
oraclelinux: CVE-2026-63074 was patched at 2026-09-14
oraclelinux: CVE-2026-63075 was patched at 2026-09-14
redhat: CVE-2026-54874 was patched at 2026-09-14
redhat: CVE-2026-63072 was patched at 2026-09-14
redhat: CVE-2026-63074 was patched at 2026-09-14
redhat: CVE-2026-63075 was patched at 2026-09-14
ubuntu: CVE-2026-54874 was patched at 2026-08-25, 2026-09-16
ubuntu: CVE-2026-63072 was patched at 2026-08-25, 2026-09-16
ubuntu: CVE-2026-63074 was patched at 2026-08-25, 2026-09-16
ubuntu: CVE-2026-63075 was patched at 2026-08-25, 2026-09-16
debian: CVE-2024-58382 was patched at 2026-09-16
debian: CVE-2026-49289 was patched at 2026-08-25
debian: CVE-2026-68497 was patched at 2026-09-16
altlinux: CVE-2026-68763 was patched at 2026-08-26, 2026-08-27, 2026-09-11, 2026-09-16
debian: CVE-2026-68763 was patched at 2026-09-16
redos: CVE-2026-18047 was patched at 2026-09-08
altlinux: CVE-2026-73196 was patched at 2026-08-20
altlinux: CVE-2026-73197 was patched at 2026-08-20
altlinux: CVE-2026-73198 was patched at 2026-08-20
altlinux: CVE-2026-79678 was patched at 2026-09-07
debian: CVE-2026-73196 was patched at 2026-08-25
debian: CVE-2026-73197 was patched at 2026-08-25
debian: CVE-2026-73198 was patched at 2026-08-25
debian: CVE-2026-79678 was patched at 2026-09-16
altlinux: CVE-2026-74950 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-74951 was patched at 2026-08-20, 2026-08-28
altlinux: CVE-2026-74952 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-74955 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-74958 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-74978 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-74980 was patched at 2026-08-20, 2026-08-28
altlinux: CVE-2026-74982 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-74985 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-84138 was patched at 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
altlinux: CVE-2026-84139 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
altlinux: CVE-2026-92015 was patched at 2026-09-16
altlinux: CVE-2026-92017 was patched at 2026-09-16
altlinux: CVE-2026-92033 was patched at 2026-09-16
altlinux: CVE-2026-92047 was patched at 2026-09-16
altlinux: CVE-2026-92053 was patched at 2026-09-16
altlinux: CVE-2026-92055 was patched at 2026-09-16
altlinux: CVE-2026-92062 was patched at 2026-09-16
altlinux: CVE-2026-92073 was patched at 2026-09-16
debian: CVE-2026-92015 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92017 was patched at 2026-09-16, 2026-09-17
altlinux: CVE-2026-43804 was patched at 2026-08-24
debian: CVE-2026-43804 was patched at 2026-08-24, 2026-08-25
ubuntu: CVE-2026-43804 was patched at 2026-08-31, 2026-09-16
debian: CVE-2026-87908 was patched at 2026-09-16
almalinux: CVE-2026-18453 was patched at 2026-09-08
almalinux: CVE-2026-78701 was patched at 2026-09-08
altlinux: CVE-2026-18453 was patched at 2026-09-08, 2026-09-11
debian: CVE-2026-18453 was patched at 2026-09-16
oraclelinux: CVE-2026-18453 was patched at 2026-09-08, 2026-09-10
oraclelinux: CVE-2026-78701 was patched at 2026-09-08
redhat: CVE-2026-18453 was patched at 2026-09-08
redhat: CVE-2026-78701 was patched at 2026-09-08
altlinux: CVE-2026-45292 was patched at 2026-08-20, 2026-08-26, 2026-08-28
debian: CVE-2026-45404 was patched at 2026-09-16
debian: CVE-2026-38350 was patched at 2026-09-16
debian: CVE-2026-90816 was patched at 2026-09-16
redos: CVE-2026-39414 was patched at 2026-09-01
altlinux: CVE-2026-60314 was patched at 2026-08-24
debian: CVE-2026-82397 was patched at 2026-09-16
debian: CVE-2026-82562 was patched at 2026-09-16
debian: CVE-2026-91951 was patched at 2026-09-16
debian: CVE-2026-91952 was patched at 2026-09-16
debian: CVE-2026-91953 was patched at 2026-09-16
debian: CVE-2026-91954 was patched at 2026-09-16
debian: CVE-2026-91955 was patched at 2026-09-16
debian: CVE-2026-91961 was patched at 2026-09-16
altlinux: CVE-2026-86420 was patched at 2026-08-31
altlinux: CVE-2026-86421 was patched at 2026-08-31
altlinux: CVE-2026-86423 was patched at 2026-08-31
altlinux: CVE-2026-86425 was patched at 2026-08-31
debian: CVE-2026-86420 was patched at 2026-09-16
debian: CVE-2026-86421 was patched at 2026-09-16
debian: CVE-2026-86423 was patched at 2026-09-16
debian: CVE-2026-86425 was patched at 2026-09-16
altlinux: CVE-2026-73639 was patched at 2026-08-26, 2026-08-27
debian: CVE-2026-19873 was patched at 2026-09-16
debian: CVE-2026-73639 was patched at 2026-08-20
debian: CVE-2026-77117 was patched at 2026-09-16
debian: CVE-2026-80489 was patched at 2026-09-16
debian: CVE-2026-89092 was patched at 2026-09-16
ubuntu: CVE-2026-77117 was patched at 2026-09-08, 2026-09-16
ubuntu: CVE-2026-80489 was patched at 2026-09-08, 2026-09-16
debian: CVE-2026-76098 was patched at 2026-09-16
debian: CVE-2026-55951 was patched at 2026-09-16
debian: CVE-2026-69664 was patched at 2026-09-16
debian: CVE-2026-70399 was patched at 2026-09-16
debian: CVE-2026-71380 was patched at 2026-09-16
debian: CVE-2026-12611 was patched at 2026-09-16
debian: CVE-2026-19204 was patched at 2026-09-16
altlinux: CVE-2026-18688 was patched at 2026-08-26
altlinux: CVE-2026-18693 was patched at 2026-08-26
altlinux: CVE-2026-18694 was patched at 2026-08-26
altlinux: CVE-2026-18695 was patched at 2026-08-26
altlinux: CVE-2026-18697 was patched at 2026-08-26
altlinux: CVE-2026-18699 was patched at 2026-08-26
altlinux: CVE-2026-18700 was patched at 2026-08-26
altlinux: CVE-2026-18701 was patched at 2026-08-26
altlinux: CVE-2026-18702 was patched at 2026-08-26
altlinux: CVE-2026-82052 was patched at 2026-09-09, 2026-09-10
altlinux: CVE-2026-82054 was patched at 2026-09-09, 2026-09-10
altlinux: CVE-2026-82056 was patched at 2026-09-09, 2026-09-10
altlinux: CVE-2026-82058 was patched at 2026-09-09, 2026-09-10
altlinux: CVE-2026-82059 was patched at 2026-09-09, 2026-09-10
altlinux: CVE-2026-82063 was patched at 2026-09-09, 2026-09-10
altlinux: CVE-2026-82064 was patched at 2026-09-09, 2026-09-10
altlinux: CVE-2026-82068 was patched at 2026-09-09, 2026-09-10
altlinux: CVE-2026-82075 was patched at 2026-09-09, 2026-09-10
altlinux: CVE-2026-82076 was patched at 2026-09-09, 2026-09-10
altlinux: CVE-2026-19401 was patched at 2026-08-27, 2026-08-28, 2026-09-01
debian: CVE-2026-19401 was patched at 2026-09-16
debian: CVE-2026-74860 was patched at 2026-09-16
altlinux: CVE-2026-78129 was patched at 2026-09-11
altlinux: CVE-2026-78132 was patched at 2026-09-11
debian: CVE-2026-78129 was patched at 2026-09-07, 2026-09-16
debian: CVE-2026-78132 was patched at 2026-09-07, 2026-09-16
altlinux: CVE-2026-23938 was patched at 2026-08-26, 2026-08-27, 2026-08-28
debian: CVE-2026-23938 was patched at 2026-08-20
debian: CVE-2026-76235 was patched at 2026-08-20, 2026-08-27
debian: CVE-2026-56855 was patched at 2026-09-16
debian: CVE-2026-78662 was patched at 2026-09-16
redos: CVE-2026-56148 was patched at 2026-09-02
redos: CVE-2026-56149 was patched at 2026-09-02
debian: CVE-2026-78222 was patched at 2026-09-16
altlinux: CVE-2026-70633 was patched at 2026-08-26, 2026-08-28, 2026-08-29, 2026-09-01
altlinux: CVE-2026-18916 was patched at 2026-08-27, 2026-08-28, 2026-09-01
debian: CVE-2026-18916 was patched at 2026-09-16
redos: CVE-2026-54448 was patched at 2026-09-02
altlinux: CVE-2026-48521 was patched at 2026-08-28, 2026-08-31
altlinux: CVE-2026-73547 was patched at 2026-08-28, 2026-08-31
debian: CVE-2026-47886 was patched at 2026-09-16
debian: CVE-2026-47891 was patched at 2026-09-16
debian: CVE-2026-59282 was patched at 2026-09-16
debian: CVE-2026-79775 was patched at 2026-09-16
debian: CVE-2026-79778 was patched at 2026-09-16
debian: CVE-2026-88015 was patched at 2026-09-16
debian: CVE-2026-86428 was patched at 2026-09-16
debian: CVE-2026-86429 was patched at 2026-09-16
debian: CVE-2026-86430 was patched at 2026-09-16
debian: CVE-2026-76956 was patched at 2026-08-25
debian: CVE-2026-79770 was patched at 2026-09-16
debian: CVE-2026-79771 was patched at 2026-09-16
altlinux: CVE-2026-71125 was patched at 2026-08-21
altlinux: CVE-2026-71128 was patched at 2026-08-21
debian: CVE-2026-85534 was patched at 2026-09-16
altlinux: CVE-2026-58374 was patched at 2026-08-31
debian: CVE-2026-53532 was patched at 2026-09-16
debian: CVE-2026-54920 was patched at 2026-09-16
debian: CVE-2026-59981 was patched at 2026-09-16
debian: CVE-2026-68516 was patched at 2026-09-16
redos: CVE-2026-24182 was patched at 2026-09-08
redos: CVE-2026-24197 was patched at 2026-09-08
redos: CVE-2026-24199 was patched at 2026-09-08
debian: CVE-2026-57224 was patched at 2026-09-16
debian: CVE-2026-57227 was patched at 2026-09-16
debian: CVE-2026-84971 was patched at 2026-09-16
debian: CVE-2026-84890 was patched at 2026-09-16
debian: CVE-2026-84269 was patched at 2026-09-16
debian: CVE-2026-84270 was patched at 2026-09-16
debian: CVE-2024-58379 was patched at 2026-09-16
altlinux: CVE-2026-88012 was patched at 2026-09-15, 2026-09-16
altlinux: CVE-2026-88878 was patched at 2026-09-15, 2026-09-16
debian: CVE-2026-15310 was patched at 2026-09-16
debian: CVE-2026-53938 was patched at 2026-09-15, 2026-09-16
altlinux: CVE-2026-33263 was patched at 2026-08-29, 2026-09-01
debian: CVE-2026-33263 was patched at 2026-09-16
almalinux: CVE-2026-85150 was patched at 2026-09-10, 2026-09-14
altlinux: CVE-2026-27852 was patched at 2026-08-29, 2026-09-01
altlinux: CVE-2026-33607 was patched at 2026-08-29, 2026-09-01
altlinux: CVE-2026-40014 was patched at 2026-08-29, 2026-09-01
altlinux: CVE-2026-40017 was patched at 2026-08-29, 2026-09-01
altlinux: CVE-2026-42391 was patched at 2026-08-29, 2026-09-01
altlinux: CVE-2026-42395 was patched at 2026-08-29, 2026-09-01
altlinux: CVE-2026-52687 was patched at 2026-08-29, 2026-09-01
altlinux: CVE-2026-73209 was patched at 2026-08-29, 2026-09-01
altlinux: CVE-2026-80179 was patched at 2026-08-28, 2026-08-31
altlinux: CVE-2026-85150 was patched at 2026-09-08
debian: CVE-2026-16599 was patched at 2026-09-16
debian: CVE-2026-18743 was patched at 2026-09-16
debian: CVE-2026-27852 was patched at 2026-09-16
debian: CVE-2026-31911 was patched at 2026-09-16
debian: CVE-2026-33605 was patched at 2026-09-16
debian: CVE-2026-33607 was patched at 2026-09-16
debian: CVE-2026-40014 was patched at 2026-09-16
debian: CVE-2026-40017 was patched at 2026-09-16
debian: CVE-2026-40019 was patched at 2026-09-16
debian: CVE-2026-42391 was patched at 2026-09-16
debian: CVE-2026-42395 was patched at 2026-09-16
debian: CVE-2026-50161 was patched at 2026-08-25
debian: CVE-2026-52687 was patched at 2026-09-16
debian: CVE-2026-53495 was patched at 2026-09-16
debian: CVE-2026-61666 was patched at 2026-08-25
debian: CVE-2026-6554 was patched at 2026-09-16
debian: CVE-2026-65976 was patched at 2026-08-20
debian: CVE-2026-68005 was patched at 2026-08-20
debian: CVE-2026-68555 was patched at 2026-08-25
debian: CVE-2026-69219 was patched at 2026-08-20
debian: CVE-2026-69220 was patched at 2026-08-20
debian: CVE-2026-71219 was patched at 2026-09-16
debian: CVE-2026-71222 was patched at 2026-09-16
debian: CVE-2026-71224 was patched at 2026-09-16
debian: CVE-2026-71832 was patched at 2026-08-25
debian: CVE-2026-73199 was patched at 2026-08-25
debian: CVE-2026-73209 was patched at 2026-09-16
debian: CVE-2026-74835 was patched at 2026-09-16
debian: CVE-2026-75140 was patched at 2026-08-25
debian: CVE-2026-78002 was patched at 2026-09-16
debian: CVE-2026-78322 was patched at 2026-09-16
debian: CVE-2026-79515 was patched at 2026-09-16
debian: CVE-2026-79516 was patched at 2026-09-16
debian: CVE-2026-79590 was patched at 2026-09-16
debian: CVE-2026-79921 was patched at 2026-09-16
debian: CVE-2026-80179 was patched at 2026-09-16
debian: CVE-2026-80185 was patched at 2026-09-16
debian: CVE-2026-81665 was patched at 2026-09-16
debian: CVE-2026-81666 was patched at 2026-09-16
debian: CVE-2026-81723 was patched at 2026-09-16
debian: CVE-2026-83530 was patched at 2026-09-16
debian: CVE-2026-84375 was patched at 2026-09-16
debian: CVE-2026-84732 was patched at 2026-09-16
debian: CVE-2026-84965 was patched at 2026-09-16
debian: CVE-2026-85150 was patched at 2026-09-16
debian: CVE-2026-85234 was patched at 2026-09-16
debian: CVE-2026-86432 was patched at 2026-09-16
debian: CVE-2026-86433 was patched at 2026-09-16
debian: CVE-2026-86434 was patched at 2026-09-16
debian: CVE-2026-86435 was patched at 2026-09-16
debian: CVE-2026-87724 was patched at 2026-09-16
debian: CVE-2026-88914 was patched at 2026-09-16
debian: CVE-2026-90994 was patched at 2026-09-16
debian: CVE-2026-90995 was patched at 2026-09-16
debian: CVE-2026-90996 was patched at 2026-09-16
debian: CVE-2026-91752 was patched at 2026-09-16
debian: CVE-2026-91926 was patched at 2026-09-16
debian: CVE-2026-91990 was patched at 2026-09-16
oraclelinux: CVE-2026-81665 was patched at 2026-09-16
oraclelinux: CVE-2026-85150 was patched at 2026-09-11, 2026-09-14
redos: CVE-2026-61712 was patched at 2026-09-07
oraclelinux: CVE-2026-20775 was patched at 2026-09-02, 2026-09-16
debian: CVE-2026-73502 was patched at 2026-08-20
debian: CVE-2026-89045 was patched at 2026-09-16
altlinux: CVE-2026-74954 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-74961 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-74986 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-84130 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
altlinux: CVE-2026-84132 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
altlinux: CVE-2026-84134 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
altlinux: CVE-2026-84136 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
altlinux: CVE-2026-84142 was patched at 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
altlinux: CVE-2026-64713 was patched at 2026-08-24
debian: CVE-2026-64713 was patched at 2026-08-24, 2026-08-25
ubuntu: CVE-2026-64713 was patched at 2026-08-31, 2026-09-16
altlinux: CVE-2026-25038 was patched at 2026-08-27, 2026-08-29, 2026-09-04
altlinux: CVE-2026-78893 was patched at 2026-08-28
altlinux: CVE-2026-78896 was patched at 2026-08-28
altlinux: CVE-2026-78897 was patched at 2026-08-28
altlinux: CVE-2026-78936 was patched at 2026-08-28
altlinux: CVE-2026-78949 was patched at 2026-08-28
altlinux: CVE-2026-78955 was patched at 2026-08-28
altlinux: CVE-2026-78957 was patched at 2026-08-28
altlinux: CVE-2026-78960 was patched at 2026-08-28
altlinux: CVE-2026-78975 was patched at 2026-08-28
altlinux: CVE-2026-78981 was patched at 2026-08-28
altlinux: CVE-2026-78991 was patched at 2026-08-28
altlinux: CVE-2026-79001 was patched at 2026-08-28
altlinux: CVE-2026-79016 was patched at 2026-08-28
altlinux: CVE-2026-79018 was patched at 2026-08-28
altlinux: CVE-2026-79023 was patched at 2026-08-28
altlinux: CVE-2026-79024 was patched at 2026-08-28
altlinux: CVE-2026-79028 was patched at 2026-08-28
altlinux: CVE-2026-79030 was patched at 2026-08-28
altlinux: CVE-2026-79038 was patched at 2026-08-28
altlinux: CVE-2026-79044 was patched at 2026-08-28
altlinux: CVE-2026-79055 was patched at 2026-08-28
altlinux: CVE-2026-79059 was patched at 2026-08-28
altlinux: CVE-2026-79068 was patched at 2026-08-28
altlinux: CVE-2026-79074 was patched at 2026-08-28
altlinux: CVE-2026-79075 was patched at 2026-08-28
altlinux: CVE-2026-79086 was patched at 2026-08-28
altlinux: CVE-2026-79095 was patched at 2026-08-28
altlinux: CVE-2026-79104 was patched at 2026-08-28
altlinux: CVE-2026-79122 was patched at 2026-08-28
altlinux: CVE-2026-79124 was patched at 2026-08-28
altlinux: CVE-2026-79125 was patched at 2026-08-28
altlinux: CVE-2026-79126 was patched at 2026-08-28
altlinux: CVE-2026-79133 was patched at 2026-08-28
altlinux: CVE-2026-79134 was patched at 2026-08-28
altlinux: CVE-2026-79144 was patched at 2026-08-28
altlinux: CVE-2026-79146 was patched at 2026-08-28
altlinux: CVE-2026-79147 was patched at 2026-08-28
altlinux: CVE-2026-79154 was patched at 2026-08-28
altlinux: CVE-2026-79176 was patched at 2026-08-28
altlinux: CVE-2026-79181 was patched at 2026-08-28
altlinux: CVE-2026-79196 was patched at 2026-08-28
altlinux: CVE-2026-79207 was patched at 2026-08-28
altlinux: CVE-2026-79220 was patched at 2026-08-28
altlinux: CVE-2026-79234 was patched at 2026-08-28
altlinux: CVE-2026-79242 was patched at 2026-08-28
altlinux: CVE-2026-79246 was patched at 2026-08-28
altlinux: CVE-2026-79252 was patched at 2026-08-28
altlinux: CVE-2026-79265 was patched at 2026-08-28
altlinux: CVE-2026-79271 was patched at 2026-08-28
altlinux: CVE-2026-79274 was patched at 2026-08-28
altlinux: CVE-2026-79287 was patched at 2026-08-28
altlinux: CVE-2026-79291 was patched at 2026-08-28
altlinux: CVE-2026-79293 was patched at 2026-08-28
altlinux: CVE-2026-84323 was patched at 2026-09-03
altlinux: CVE-2026-84327 was patched at 2026-09-03
altlinux: CVE-2026-84348 was patched at 2026-09-03
altlinux: CVE-2026-87431 was patched at 2026-09-17
altlinux: CVE-2026-87435 was patched at 2026-09-17
altlinux: CVE-2026-87437 was patched at 2026-09-17
altlinux: CVE-2026-87439 was patched at 2026-09-17
altlinux: CVE-2026-87443 was patched at 2026-09-17
altlinux: CVE-2026-87450 was patched at 2026-09-17
altlinux: CVE-2026-87451 was patched at 2026-09-17
altlinux: CVE-2026-87454 was patched at 2026-09-17
altlinux: CVE-2026-87459 was patched at 2026-09-17
altlinux: CVE-2026-87476 was patched at 2026-09-17
altlinux: CVE-2026-87477 was patched at 2026-09-17
altlinux: CVE-2026-87478 was patched at 2026-09-17
altlinux: CVE-2026-87490 was patched at 2026-09-17
altlinux: CVE-2026-87518 was patched at 2026-09-17
altlinux: CVE-2026-87521 was patched at 2026-09-17
altlinux: CVE-2026-87523 was patched at 2026-09-17
altlinux: CVE-2026-87531 was patched at 2026-09-17
altlinux: CVE-2026-87539 was patched at 2026-09-17
altlinux: CVE-2026-87545 was patched at 2026-09-17
altlinux: CVE-2026-87552 was patched at 2026-09-17
altlinux: CVE-2026-87565 was patched at 2026-09-17
altlinux: CVE-2026-87566 was patched at 2026-09-17
altlinux: CVE-2026-87574 was patched at 2026-09-17
altlinux: CVE-2026-87593 was patched at 2026-09-17
altlinux: CVE-2026-87594 was patched at 2026-09-17
altlinux: CVE-2026-87605 was patched at 2026-09-17
altlinux: CVE-2026-87620 was patched at 2026-09-17
altlinux: CVE-2026-87623 was patched at 2026-09-17
altlinux: CVE-2026-87658 was patched at 2026-09-17
altlinux: CVE-2026-91714 was patched at 2026-09-17
altlinux: CVE-2026-91717 was patched at 2026-09-17
altlinux: CVE-2026-91725 was patched at 2026-09-17
altlinux: CVE-2026-91744 was patched at 2026-09-17
debian: CVE-2026-78893 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78896 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78897 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78936 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78949 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78955 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78957 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78960 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78975 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78981 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78991 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79001 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79016 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79018 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79023 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79024 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79028 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79030 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79038 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79044 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79055 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79059 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79068 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79074 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79075 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79086 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79095 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79104 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79122 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79124 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79125 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79126 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79133 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79134 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79144 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79146 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79147 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79154 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79176 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79181 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79196 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79207 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79220 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79234 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79242 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79246 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79252 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79265 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79271 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79274 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79287 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79291 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79293 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84323 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84327 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84348 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-87431 was patched at 2026-09-16
debian: CVE-2026-87435 was patched at 2026-09-16
debian: CVE-2026-87437 was patched at 2026-09-16
debian: CVE-2026-87439 was patched at 2026-09-16
debian: CVE-2026-87443 was patched at 2026-09-16
debian: CVE-2026-87450 was patched at 2026-09-16
debian: CVE-2026-87451 was patched at 2026-09-16
debian: CVE-2026-87454 was patched at 2026-09-16
debian: CVE-2026-87459 was patched at 2026-09-16
debian: CVE-2026-87476 was patched at 2026-09-16
debian: CVE-2026-87477 was patched at 2026-09-16
debian: CVE-2026-87478 was patched at 2026-09-16
debian: CVE-2026-87490 was patched at 2026-09-16
debian: CVE-2026-87518 was patched at 2026-09-16
debian: CVE-2026-87521 was patched at 2026-09-16
debian: CVE-2026-87523 was patched at 2026-09-16
debian: CVE-2026-87531 was patched at 2026-09-16
debian: CVE-2026-87539 was patched at 2026-09-16
debian: CVE-2026-87545 was patched at 2026-09-16
debian: CVE-2026-87552 was patched at 2026-09-16
debian: CVE-2026-87565 was patched at 2026-09-16
debian: CVE-2026-87566 was patched at 2026-09-16
debian: CVE-2026-87574 was patched at 2026-09-16
debian: CVE-2026-87593 was patched at 2026-09-16
debian: CVE-2026-87594 was patched at 2026-09-16
debian: CVE-2026-87605 was patched at 2026-09-16
debian: CVE-2026-87620 was patched at 2026-09-16
debian: CVE-2026-87623 was patched at 2026-09-16
debian: CVE-2026-87658 was patched at 2026-09-16
debian: CVE-2026-91714 was patched at 2026-09-16
debian: CVE-2026-91717 was patched at 2026-09-16
debian: CVE-2026-91725 was patched at 2026-09-16
debian: CVE-2026-91744 was patched at 2026-09-16
redos: CVE-2026-48040 was patched at 2026-09-04
altlinux: CVE-2026-62898 was patched at 2026-08-31, 2026-09-02
redos: CVE-2026-62898 was patched at 2026-09-07
altlinux: CVE-2026-23937 was patched at 2026-08-26, 2026-08-27, 2026-08-28
debian: CVE-2026-23937 was patched at 2026-08-20
debian: CVE-2026-91946 was patched at 2026-09-16
debian: CVE-2026-88059 was patched at 2026-09-16
debian: CVE-2026-77680 was patched at 2026-09-16
debian: CVE-2026-91786 was patched at 2026-09-16
altlinux: CVE-2026-16108 was patched at 2026-09-01, 2026-09-04, 2026-09-07
altlinux: CVE-2026-17048 was patched at 2026-08-20, 2026-08-26, 2026-08-28
debian: CVE-2026-84933 was patched at 2026-09-16
debian: CVE-2026-89046 was patched at 2026-09-16
debian: CVE-2026-59189 was patched at 2026-09-16
debian: CVE-2026-79776 was patched at 2026-09-16
debian: CVE-2026-79780 was patched at 2026-09-16
debian: CVE-2026-88013 was patched at 2026-09-16
debian: CVE-2026-18090 was patched at 2026-09-16
redos: CVE-2026-24196 was patched at 2026-09-08
debian: CVE-2026-78475 was patched at 2026-08-25
debian: CVE-2026-82324 was patched at 2026-09-16
debian: CVE-2026-82328 was patched at 2026-09-16
debian: CVE-2026-82343 was patched at 2026-09-16
redos: CVE-2026-24198 was patched at 2026-09-08
debian: CVE-2026-91992 was patched at 2026-09-16
debian: CVE-2026-72924 was patched at 2026-09-16
altlinux: CVE-2026-40203 was patched at 2026-08-29, 2026-09-01
altlinux: CVE-2026-42392 was patched at 2026-08-29, 2026-09-01
altlinux: CVE-2026-42393 was patched at 2026-08-29, 2026-09-01
altlinux: CVE-2026-58419 was patched at 2026-08-27, 2026-08-29, 2026-09-04
debian: CVE-2026-40203 was patched at 2026-09-16
debian: CVE-2026-42392 was patched at 2026-09-16
debian: CVE-2026-42393 was patched at 2026-09-16
oraclelinux: CVE-2026-20708 was patched at 2026-09-02, 2026-09-16
oraclelinux: CVE-2026-20712 was patched at 2026-09-02, 2026-09-16
oraclelinux: CVE-2026-20734 was patched at 2026-09-02, 2026-09-16
oraclelinux: CVE-2026-20705 was patched at 2026-09-02, 2026-09-16
redos: CVE-2026-42600 was patched at 2026-08-31
debian: CVE-2026-82253 was patched at 2026-09-16
debian: CVE-2026-19672 was patched at 2026-09-16
altlinux: CVE-2026-19729 was patched at 2026-09-01, 2026-09-04, 2026-09-07
debian: CVE-2026-74859 was patched at 2026-09-16
altlinux: CVE-2026-27704 was patched at 2026-08-28
debian: CVE-2026-79781 was patched at 2026-09-16
debian: CVE-2026-88046 was patched at 2026-09-16
debian: CVE-2026-34967 was patched at 2026-09-16
debian: CVE-2026-47256 was patched at 2026-09-16
debian: CVE-2026-82251 was patched at 2026-09-16
debian: CVE-2026-79655 was patched at 2026-09-16
debian: CVE-2026-79705 was patched at 2026-09-16
debian: CVE-2026-82035 was patched at 2026-09-16
debian: CVE-2026-82481 was patched at 2026-09-16
debian: CVE-2026-85396 was patched at 2026-09-16
debian: CVE-2026-87910 was patched at 2026-09-16
debian: CVE-2026-71514 was patched at 2026-08-25
debian: CVE-2026-59280 was patched at 2026-09-16
debian: CVE-2026-74582 was patched at 2026-08-25
debian: CVE-2026-74583 was patched at 2026-08-25
debian: CVE-2026-74587 was patched at 2026-08-25
debian: CVE-2026-74588 was patched at 2026-08-25
debian: CVE-2026-74589 was patched at 2026-08-25
debian: CVE-2026-74599 was patched at 2026-08-25
debian: CVE-2026-74604 was patched at 2026-08-25
debian: CVE-2026-74606 was patched at 2026-08-25
debian: CVE-2026-74608 was patched at 2026-08-25
debian: CVE-2026-74609 was patched at 2026-08-25
debian: CVE-2026-74610 was patched at 2026-08-25
debian: CVE-2026-74613 was patched at 2026-08-25
debian: CVE-2026-74615 was patched at 2026-08-25
debian: CVE-2026-74623 was patched at 2026-08-25
debian: CVE-2026-74628 was patched at 2026-08-25
debian: CVE-2026-74630 was patched at 2026-08-25
debian: CVE-2026-74631 was patched at 2026-08-25
debian: CVE-2026-74634 was patched at 2026-08-25
debian: CVE-2026-74635 was patched at 2026-08-25
debian: CVE-2026-74637 was patched at 2026-08-25
debian: CVE-2026-74650 was patched at 2026-08-25
debian: CVE-2026-74651 was patched at 2026-08-25
debian: CVE-2026-74656 was patched at 2026-08-25
debian: CVE-2026-74660 was patched at 2026-08-25
debian: CVE-2026-74661 was patched at 2026-08-25
debian: CVE-2026-74669 was patched at 2026-08-25
debian: CVE-2026-74671 was patched at 2026-08-25
debian: CVE-2026-74672 was patched at 2026-08-25
debian: CVE-2026-74677 was patched at 2026-08-25
debian: CVE-2026-74678 was patched at 2026-08-25
debian: CVE-2026-74679 was patched at 2026-08-25
debian: CVE-2026-74688 was patched at 2026-08-25
debian: CVE-2026-74689 was patched at 2026-08-25
debian: CVE-2026-74700 was patched at 2026-08-25
debian: CVE-2026-74705 was patched at 2026-08-25
debian: CVE-2026-74711 was patched at 2026-08-25
debian: CVE-2026-74714 was patched at 2026-08-25
debian: CVE-2026-74722 was patched at 2026-08-25
debian: CVE-2026-74724 was patched at 2026-08-25
debian: CVE-2026-74725 was patched at 2026-08-25
debian: CVE-2026-74730 was patched at 2026-08-25
debian: CVE-2026-74732 was patched at 2026-08-25
debian: CVE-2026-74739 was patched at 2026-09-16
debian: CVE-2026-74743 was patched at 2026-09-16
debian: CVE-2026-74744 was patched at 2026-09-16
debian: CVE-2026-74746 was patched at 2026-09-16
debian: CVE-2026-80536 was patched at 2026-08-29, 2026-09-16
debian: CVE-2026-80556 was patched at 2026-09-16
debian: CVE-2026-80563 was patched at 2026-09-16
debian: CVE-2026-80568 was patched at 2026-09-16
debian: CVE-2026-80570 was patched at 2026-09-16
debian: CVE-2026-80577 was patched at 2026-09-16
debian: CVE-2026-80589 was patched at 2026-09-16
debian: CVE-2026-80593 was patched at 2026-09-16
debian: CVE-2026-80597 was patched at 2026-09-16
debian: CVE-2026-80598 was patched at 2026-09-16
debian: CVE-2026-80600 was patched at 2026-09-16
debian: CVE-2026-80601 was patched at 2026-09-16
debian: CVE-2026-80603 was patched at 2026-09-16
debian: CVE-2026-80604 was patched at 2026-09-16
debian: CVE-2026-80614 was patched at 2026-09-16
debian: CVE-2026-80620 was patched at 2026-09-16
debian: CVE-2026-80622 was patched at 2026-09-16
debian: CVE-2026-80624 was patched at 2026-09-16
debian: CVE-2026-80627 was patched at 2026-09-16
debian: CVE-2026-80635 was patched at 2026-09-16
debian: CVE-2026-80650 was patched at 2026-09-16
debian: CVE-2026-80664 was patched at 2026-09-16
debian: CVE-2026-80678 was patched at 2026-09-16
debian: CVE-2026-80679 was patched at 2026-09-16
debian: CVE-2026-80681 was patched at 2026-09-16
debian: CVE-2026-80689 was patched at 2026-09-16
debian: CVE-2026-80693 was patched at 2026-09-16
debian: CVE-2026-80704 was patched at 2026-09-16
debian: CVE-2026-80725 was patched at 2026-08-29, 2026-09-16
debian: CVE-2026-80726 was patched at 2026-09-16
debian: CVE-2026-80730 was patched at 2026-09-16
debian: CVE-2026-80731 was patched at 2026-09-16
debian: CVE-2026-80732 was patched at 2026-09-16
debian: CVE-2026-80743 was patched at 2026-09-16
debian: CVE-2026-80752 was patched at 2026-09-16
debian: CVE-2026-80762 was patched at 2026-09-16
debian: CVE-2026-80764 was patched at 2026-09-16
debian: CVE-2026-80766 was patched at 2026-09-16
debian: CVE-2026-80767 was patched at 2026-09-16
debian: CVE-2026-80770 was patched at 2026-09-16
debian: CVE-2026-80772 was patched at 2026-09-16
debian: CVE-2026-80780 was patched at 2026-09-16
debian: CVE-2026-80781 was patched at 2026-09-16
debian: CVE-2026-80783 was patched at 2026-09-16
debian: CVE-2026-80784 was patched at 2026-09-16
debian: CVE-2026-80792 was patched at 2026-09-16
debian: CVE-2026-80795 was patched at 2026-09-16
debian: CVE-2026-80796 was patched at 2026-09-16
debian: CVE-2026-80798 was patched at 2026-09-16
debian: CVE-2026-80802 was patched at 2026-09-16
debian: CVE-2026-80824 was patched at 2026-09-16
debian: CVE-2026-80826 was patched at 2026-09-16
debian: CVE-2026-80827 was patched at 2026-09-16
debian: CVE-2026-80830 was patched at 2026-09-16
debian: CVE-2026-80833 was patched at 2026-09-16
debian: CVE-2026-80834 was patched at 2026-09-16
debian: CVE-2026-80836 was patched at 2026-09-16
debian: CVE-2026-80837 was patched at 2026-09-16
debian: CVE-2026-80841 was patched at 2026-09-16
debian: CVE-2026-80842 was patched at 2026-09-16
debian: CVE-2026-80848 was patched at 2026-09-16
debian: CVE-2026-80849 was patched at 2026-09-16
debian: CVE-2026-80850 was patched at 2026-09-16
debian: CVE-2026-80852 was patched at 2026-09-16
debian: CVE-2026-80863 was patched at 2026-09-16
debian: CVE-2026-80886 was patched at 2026-09-16
debian: CVE-2026-80914 was patched at 2026-09-16
debian: CVE-2026-80917 was patched at 2026-09-16
debian: CVE-2026-80923 was patched at 2026-09-16
debian: CVE-2026-80926 was patched at 2026-09-16
debian: CVE-2026-80932 was patched at 2026-09-16
debian: CVE-2026-80935 was patched at 2026-09-16
debian: CVE-2026-80937 was patched at 2026-09-16
debian: CVE-2026-80941 was patched at 2026-09-16
debian: CVE-2026-80942 was patched at 2026-09-16
debian: CVE-2026-80947 was patched at 2026-09-16
debian: CVE-2026-80948 was patched at 2026-09-16
debian: CVE-2026-80949 was patched at 2026-09-16
debian: CVE-2026-80951 was patched at 2026-09-16
debian: CVE-2026-80952 was patched at 2026-09-16
debian: CVE-2026-80963 was patched at 2026-09-16
debian: CVE-2026-80971 was patched at 2026-09-16
debian: CVE-2026-80982 was patched at 2026-09-16
debian: CVE-2026-80991 was patched at 2026-09-16
debian: CVE-2026-80992 was patched at 2026-09-16
debian: CVE-2026-80994 was patched at 2026-09-16
debian: CVE-2026-81001 was patched at 2026-09-16
debian: CVE-2026-81005 was patched at 2026-09-16
debian: CVE-2026-81008 was patched at 2026-09-16
debian: CVE-2026-81017 was patched at 2026-09-16
debian: CVE-2026-89437 was patched at 2026-09-16
debian: CVE-2026-89442 was patched at 2026-09-16
debian: CVE-2026-89455 was patched at 2026-09-16
debian: CVE-2026-89457 was patched at 2026-09-16
debian: CVE-2026-89460 was patched at 2026-09-16
debian: CVE-2026-89463 was patched at 2026-09-16
debian: CVE-2026-89467 was patched at 2026-09-16
debian: CVE-2026-89468 was patched at 2026-09-16
debian: CVE-2026-89469 was patched at 2026-09-16
debian: CVE-2026-89470 was patched at 2026-09-16
debian: CVE-2026-89471 was patched at 2026-09-16
debian: CVE-2026-89472 was patched at 2026-09-16
debian: CVE-2026-89475 was patched at 2026-09-16
debian: CVE-2026-89479 was patched at 2026-09-16
debian: CVE-2026-89488 was patched at 2026-09-16
debian: CVE-2026-89492 was patched at 2026-09-16
debian: CVE-2026-89493 was patched at 2026-09-16
debian: CVE-2026-89494 was patched at 2026-09-16
debian: CVE-2026-89495 was patched at 2026-09-16
debian: CVE-2026-89496 was patched at 2026-09-16
debian: CVE-2026-89508 was patched at 2026-09-16
debian: CVE-2026-89511 was patched at 2026-09-16
debian: CVE-2026-89528 was patched at 2026-09-16
debian: CVE-2026-89532 was patched at 2026-09-16
debian: CVE-2026-89534 was patched at 2026-09-16
debian: CVE-2026-89543 was patched at 2026-09-16
debian: CVE-2026-89544 was patched at 2026-09-16
debian: CVE-2026-89545 was patched at 2026-09-16
debian: CVE-2026-89548 was patched at 2026-09-16
debian: CVE-2026-89552 was patched at 2026-09-16
debian: CVE-2026-89553 was patched at 2026-09-16
debian: CVE-2026-89555 was patched at 2026-09-16
debian: CVE-2026-89569 was patched at 2026-09-16
debian: CVE-2026-89575 was patched at 2026-09-16
debian: CVE-2026-89580 was patched at 2026-09-16
debian: CVE-2026-89587 was patched at 2026-09-16
debian: CVE-2026-89596 was patched at 2026-09-16
debian: CVE-2026-89603 was patched at 2026-09-16
debian: CVE-2026-89622 was patched at 2026-09-16
debian: CVE-2026-89624 was patched at 2026-09-16
debian: CVE-2026-89625 was patched at 2026-09-16
debian: CVE-2026-89636 was patched at 2026-09-16
debian: CVE-2026-89637 was patched at 2026-09-16
debian: CVE-2026-89650 was patched at 2026-09-16
debian: CVE-2026-89651 was patched at 2026-09-16
debian: CVE-2026-89652 was patched at 2026-09-16
debian: CVE-2026-89658 was patched at 2026-09-16
debian: CVE-2026-89659 was patched at 2026-09-16
debian: CVE-2026-89660 was patched at 2026-09-16
debian: CVE-2026-89662 was patched at 2026-09-16
debian: CVE-2026-89663 was patched at 2026-09-16
debian: CVE-2026-89669 was patched at 2026-09-16
debian: CVE-2026-89671 was patched at 2026-09-16
debian: CVE-2026-89674 was patched at 2026-09-16
debian: CVE-2026-89682 was patched at 2026-09-16
debian: CVE-2026-89688 was patched at 2026-09-16
debian: CVE-2026-89690 was patched at 2026-09-16
debian: CVE-2026-89696 was patched at 2026-09-16
debian: CVE-2026-89703 was patched at 2026-09-16
debian: CVE-2026-89708 was patched at 2026-09-16
debian: CVE-2026-89709 was patched at 2026-09-16
debian: CVE-2026-89720 was patched at 2026-09-16
debian: CVE-2026-89722 was patched at 2026-09-16
debian: CVE-2026-89724 was patched at 2026-09-16
debian: CVE-2026-89725 was patched at 2026-09-16
debian: CVE-2026-89726 was patched at 2026-09-16
debian: CVE-2026-89729 was patched at 2026-09-16
debian: CVE-2026-89730 was patched at 2026-09-16
debian: CVE-2026-89731 was patched at 2026-09-16
debian: CVE-2026-89736 was patched at 2026-09-16
debian: CVE-2026-89741 was patched at 2026-09-16
debian: CVE-2026-89742 was patched at 2026-09-16
debian: CVE-2026-89743 was patched at 2026-09-16
debian: CVE-2026-89746 was patched at 2026-09-16
debian: CVE-2026-89747 was patched at 2026-09-16
debian: CVE-2026-89750 was patched at 2026-09-16
debian: CVE-2026-89761 was patched at 2026-09-16
debian: CVE-2026-89763 was patched at 2026-09-16
debian: CVE-2026-89777 was patched at 2026-09-16
debian: CVE-2026-89781 was patched at 2026-09-16
debian: CVE-2026-89782 was patched at 2026-09-16
debian: CVE-2026-89783 was patched at 2026-09-16
debian: CVE-2026-89785 was patched at 2026-09-16
debian: CVE-2026-89786 was patched at 2026-09-16
debian: CVE-2026-89787 was patched at 2026-09-16
debian: CVE-2026-89788 was patched at 2026-09-16
debian: CVE-2026-89789 was patched at 2026-09-16
oraclelinux: CVE-2025-39729 was patched at 2026-09-04
oraclelinux: CVE-2026-68378 was patched at 2026-09-04
oraclelinux: CVE-2026-74352 was patched at 2026-09-04
oraclelinux: CVE-2026-74582 was patched at 2026-09-04
oraclelinux: CVE-2026-74583 was patched at 2026-09-04
oraclelinux: CVE-2026-74587 was patched at 2026-09-04
oraclelinux: CVE-2026-74588 was patched at 2026-09-04
oraclelinux: CVE-2026-74589 was patched at 2026-09-04
oraclelinux: CVE-2026-74599 was patched at 2026-09-04
oraclelinux: CVE-2026-74604 was patched at 2026-09-04
oraclelinux: CVE-2026-74606 was patched at 2026-09-04
oraclelinux: CVE-2026-74608 was patched at 2026-09-04
oraclelinux: CVE-2026-74609 was patched at 2026-09-04
oraclelinux: CVE-2026-74610 was patched at 2026-09-04
oraclelinux: CVE-2026-74613 was patched at 2026-09-04
oraclelinux: CVE-2026-74615 was patched at 2026-09-04
oraclelinux: CVE-2026-74623 was patched at 2026-09-04
oraclelinux: CVE-2026-74630 was patched at 2026-09-04
oraclelinux: CVE-2026-74634 was patched at 2026-09-04
oraclelinux: CVE-2026-74635 was patched at 2026-09-04
oraclelinux: CVE-2026-74650 was patched at 2026-09-04
oraclelinux: CVE-2026-74651 was patched at 2026-09-04
oraclelinux: CVE-2026-74656 was patched at 2026-09-04
oraclelinux: CVE-2026-74660 was patched at 2026-09-04
oraclelinux: CVE-2026-74661 was patched at 2026-09-04
oraclelinux: CVE-2026-74669 was patched at 2026-09-04
oraclelinux: CVE-2026-74671 was patched at 2026-09-04
oraclelinux: CVE-2026-74677 was patched at 2026-09-04
oraclelinux: CVE-2026-74678 was patched at 2026-09-04
oraclelinux: CVE-2026-74679 was patched at 2026-09-04
oraclelinux: CVE-2026-74688 was patched at 2026-09-04
oraclelinux: CVE-2026-74689 was patched at 2026-09-04
oraclelinux: CVE-2026-74700 was patched at 2026-09-04
oraclelinux: CVE-2026-74705 was patched at 2026-09-04
oraclelinux: CVE-2026-74714 was patched at 2026-09-04
oraclelinux: CVE-2026-74722 was patched at 2026-09-04
oraclelinux: CVE-2026-74724 was patched at 2026-09-04
oraclelinux: CVE-2026-74725 was patched at 2026-09-04
oraclelinux: CVE-2026-74730 was patched at 2026-09-04
oraclelinux: CVE-2026-74732 was patched at 2026-09-04
oraclelinux: CVE-2026-74746 was patched at 2026-09-04
oraclelinux: CVE-2026-80593 was patched at 2026-09-04
oraclelinux: CVE-2026-80601 was patched at 2026-09-04
oraclelinux: CVE-2026-80603 was patched at 2026-09-04
oraclelinux: CVE-2026-80604 was patched at 2026-09-04
oraclelinux: CVE-2026-80622 was patched at 2026-09-04
oraclelinux: CVE-2026-80664 was patched at 2026-09-04
oraclelinux: CVE-2026-80678 was patched at 2026-09-04
oraclelinux: CVE-2026-80681 was patched at 2026-09-04
oraclelinux: CVE-2026-80731 was patched at 2026-09-04
redhat: CVE-2026-74582 was patched at 2026-09-04
redos: CVE-2026-80593 was patched at 2026-09-16
redos: CVE-2026-80597 was patched at 2026-09-16
redos: CVE-2026-80598 was patched at 2026-09-16
redos: CVE-2026-80600 was patched at 2026-09-16
redos: CVE-2026-80601 was patched at 2026-09-16
redos: CVE-2026-80603 was patched at 2026-09-16
redos: CVE-2026-80620 was patched at 2026-09-16
redos: CVE-2026-80622 was patched at 2026-09-16
redos: CVE-2026-80627 was patched at 2026-09-16
redos: CVE-2026-80635 was patched at 2026-09-16
redos: CVE-2026-80664 was patched at 2026-09-16
redos: CVE-2026-80886 was patched at 2026-09-16
ubuntu: CVE-2026-64466 was patched at 2026-09-07, 2026-09-16
ubuntu: CVE-2026-64502 was patched at 2026-09-07, 2026-09-16
ubuntu: CVE-2026-64601 was patched at 2026-09-07, 2026-09-16
altlinux: CVE-2026-74937 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-74947 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-74988 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-74989 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-84123 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
altlinux: CVE-2026-84125 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
altlinux: CVE-2026-84126 was patched at 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
altlinux: CVE-2026-84144 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
altlinux: CVE-2026-92006 was patched at 2026-09-16
altlinux: CVE-2026-92007 was patched at 2026-09-16
altlinux: CVE-2026-92008 was patched at 2026-09-16
altlinux: CVE-2026-92009 was patched at 2026-09-16
altlinux: CVE-2026-92010 was patched at 2026-09-16
altlinux: CVE-2026-92011 was patched at 2026-09-16
altlinux: CVE-2026-92012 was patched at 2026-09-16
altlinux: CVE-2026-92013 was patched at 2026-09-16
altlinux: CVE-2026-92020 was patched at 2026-09-16
altlinux: CVE-2026-92043 was patched at 2026-09-16
altlinux: CVE-2026-92050 was patched at 2026-09-16
altlinux: CVE-2026-92054 was patched at 2026-09-16
debian: CVE-2026-92006 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92007 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92008 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92009 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92010 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92011 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92012 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92013 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92014 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92020 was patched at 2026-09-16, 2026-09-17
altlinux: CVE-2026-64719 was patched at 2026-08-24
altlinux: CVE-2026-64757 was patched at 2026-08-24
altlinux: CVE-2026-64783 was patched at 2026-08-24
debian: CVE-2026-64719 was patched at 2026-08-24, 2026-08-25
debian: CVE-2026-64757 was patched at 2026-08-24, 2026-08-25
debian: CVE-2026-64783 was patched at 2026-08-24, 2026-08-25
ubuntu: CVE-2026-64719 was patched at 2026-08-31, 2026-09-16
ubuntu: CVE-2026-64757 was patched at 2026-08-31, 2026-09-16
ubuntu: CVE-2026-64783 was patched at 2026-08-31, 2026-09-16
altlinux: CVE-2026-78183 was patched at 2026-08-25, 2026-08-26, 2026-08-27, 2026-08-28
altlinux: CVE-2026-79004 was patched at 2026-08-28
altlinux: CVE-2026-79020 was patched at 2026-08-28
altlinux: CVE-2026-79112 was patched at 2026-08-28
altlinux: CVE-2026-79206 was patched at 2026-08-28
altlinux: CVE-2026-79239 was patched at 2026-08-28
altlinux: CVE-2026-79241 was patched at 2026-08-28
altlinux: CVE-2026-85052 was patched at 2026-09-05
altlinux: CVE-2026-87525 was patched at 2026-09-17
altlinux: CVE-2026-87592 was patched at 2026-09-17
altlinux: CVE-2026-87602 was patched at 2026-09-17
altlinux: CVE-2026-87640 was patched at 2026-09-17
altlinux: CVE-2026-87657 was patched at 2026-09-17
altlinux: CVE-2026-91726 was patched at 2026-09-17
altlinux: CVE-2026-91747 was patched at 2026-09-17
debian: CVE-2026-79004 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79020 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79112 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79206 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79239 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79241 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-85052 was patched at 2026-09-05, 2026-09-16
debian: CVE-2026-87525 was patched at 2026-09-16
debian: CVE-2026-87592 was patched at 2026-09-16
debian: CVE-2026-87602 was patched at 2026-09-16
debian: CVE-2026-87640 was patched at 2026-09-16
debian: CVE-2026-87657 was patched at 2026-09-16
debian: CVE-2026-91726 was patched at 2026-09-16
debian: CVE-2026-91747 was patched at 2026-09-16
altlinux: CVE-2026-78126 was patched at 2026-09-11
altlinux: CVE-2026-78130 was patched at 2026-09-11
altlinux: CVE-2026-78133 was patched at 2026-09-11
debian: CVE-2026-78126 was patched at 2026-09-07, 2026-09-16
debian: CVE-2026-78130 was patched at 2026-09-07, 2026-09-16
debian: CVE-2026-78133 was patched at 2026-09-07, 2026-09-16
altlinux: CVE-2026-78123 was patched at 2026-09-11
debian: CVE-2026-78123 was patched at 2026-09-07, 2026-09-16
debian: CVE-2026-84964 was patched at 2026-09-16
debian: CVE-2026-75141 was patched at 2026-08-20
debian: CVE-2026-75142 was patched at 2026-08-20
debian: CVE-2026-75144 was patched at 2026-08-20
debian: CVE-2026-75146 was patched at 2026-08-20
ubuntu: CVE-2026-75141 was patched at 2026-09-03, 2026-09-16
ubuntu: CVE-2026-75142 was patched at 2026-09-03, 2026-09-16
ubuntu: CVE-2026-75144 was patched at 2026-09-03, 2026-09-16
ubuntu: CVE-2026-75146 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-77358 was patched at 2026-09-16
debian: CVE-2026-91947 was patched at 2026-09-16
debian: CVE-2026-91950 was patched at 2026-09-16
debian: CVE-2026-91956 was patched at 2026-09-16
debian: CVE-2026-91958 was patched at 2026-09-16
debian: CVE-2026-91959 was patched at 2026-09-16
debian: CVE-2026-77658 was patched at 2026-09-16
altlinux: CVE-2026-23935 was patched at 2026-08-26, 2026-08-27, 2026-08-28
debian: CVE-2026-23935 was patched at 2026-08-20
debian: CVE-2026-87875 was patched at 2026-09-16
altlinux: CVE-2026-70634 was patched at 2026-08-26, 2026-08-28, 2026-08-29, 2026-09-01
altlinux: CVE-2026-70635 was patched at 2026-08-26, 2026-08-28, 2026-08-29, 2026-09-01
altlinux: CVE-2026-82066 was patched at 2026-09-09, 2026-09-10
altlinux: CVE-2026-89099 was patched at 2026-09-12, 2026-09-14
debian: CVE-2026-84968 was patched at 2026-09-16
debian: CVE-2026-84969 was patched at 2026-09-16
debian: CVE-2026-88032 was patched at 2026-09-16
debian: CVE-2026-86098 was patched at 2026-09-16
altlinux: CVE-2026-84641 was patched at 2026-09-03, 2026-09-09
debian: CVE-2026-84641 was patched at 2026-09-04, 2026-09-16
debian: CVE-2026-47888 was patched at 2026-09-16
debian: CVE-2026-86140 was patched at 2026-09-16
debian: CVE-2026-86141 was patched at 2026-09-16
debian: CVE-2026-86142 was patched at 2026-09-16
ubuntu: CVE-2026-73071 was patched at 2026-08-20, 2026-08-25
debian: CVE-2026-90801 was patched at 2026-09-16
debian: CVE-2026-90802 was patched at 2026-09-16
debian: CVE-2026-90803 was patched at 2026-09-16
debian: CVE-2026-90804 was patched at 2026-09-16
debian: CVE-2026-90828 was patched at 2026-09-16
debian: CVE-2026-90830 was patched at 2026-09-16
debian: CVE-2026-90831 was patched at 2026-09-16
debian: CVE-2026-91779 was patched at 2026-09-16
debian: CVE-2026-91780 was patched at 2026-09-16
debian: CVE-2026-18374 was patched at 2026-09-16
debian: CVE-2026-57225 was patched at 2026-09-16
debian: CVE-2026-57226 was patched at 2026-09-16
debian: CVE-2026-57228 was patched at 2026-09-16
altlinux: CVE-2026-50572 was patched at 2026-08-28, 2026-08-31
debian: CVE-2026-77219 was patched at 2026-08-25
debian: CVE-2026-61908 was patched at 2026-09-16
debian: CVE-2026-61915 was patched at 2026-09-16
debian: CVE-2026-82608 was patched at 2026-09-11, 2026-09-16
debian: CVE-2026-55059 was patched at 2026-09-16
debian: CVE-2026-59184 was patched at 2026-09-16
debian: CVE-2026-59186 was patched at 2026-09-16
debian: CVE-2026-59187 was patched at 2026-09-16
debian: CVE-2026-68515 was patched at 2026-09-16
debian: CVE-2026-76957 was patched at 2026-08-25
debian: CVE-2026-82591 was patched at 2026-09-16
debian: CVE-2026-90560 was patched at 2026-09-16
debian: CVE-2026-90852 was patched at 2026-09-16
debian: CVE-2026-81893 was patched at 2026-09-16
ubuntu: CVE-2026-62291 was patched at 2026-08-26, 2026-09-16
altlinux: CVE-2026-40015 was patched at 2026-08-29, 2026-09-01
debian: CVE-2025-15614 was patched at 2026-09-16
debian: CVE-2026-0799 was patched at 2026-09-16
debian: CVE-2026-13732 was patched at 2026-09-16
debian: CVE-2026-18313 was patched at 2026-09-16
debian: CVE-2026-31912 was patched at 2026-09-16
debian: CVE-2026-40015 was patched at 2026-09-16
debian: CVE-2026-54789 was patched at 2026-08-25, 2026-09-02
debian: CVE-2026-59949 was patched at 2026-08-25
debian: CVE-2026-63409 was patched at 2026-08-25
debian: CVE-2026-63632 was patched at 2026-08-25
debian: CVE-2026-65609 was patched at 2026-08-25
debian: CVE-2026-65610 was patched at 2026-08-25
debian: CVE-2026-65832 was patched at 2026-08-20
debian: CVE-2026-68768 was patched at 2026-08-25
debian: CVE-2026-70654 was patched at 2026-08-25
debian: CVE-2026-73324 was patched at 2026-09-16
debian: CVE-2026-75900 was patched at 2026-08-20
debian: CVE-2026-75904 was patched at 2026-08-20
debian: CVE-2026-77118 was patched at 2026-08-25
debian: CVE-2026-77220 was patched at 2026-08-25
debian: CVE-2026-78161 was patched at 2026-08-25
debian: CVE-2026-78376 was patched at 2026-09-16
debian: CVE-2026-79591 was patched at 2026-09-16
debian: CVE-2026-79592 was patched at 2026-09-16
debian: CVE-2026-79602 was patched at 2026-09-16
debian: CVE-2026-82522 was patched at 2026-09-16
debian: CVE-2026-82623 was patched at 2026-09-16
debian: CVE-2026-82631 was patched at 2026-09-16
debian: CVE-2026-82677 was patched at 2026-09-16
debian: CVE-2026-82820 was patched at 2026-09-16
debian: CVE-2026-82821 was patched at 2026-09-16
debian: CVE-2026-83596 was patched at 2026-09-16
debian: CVE-2026-85091 was patched at 2026-09-16
debian: CVE-2026-85504 was patched at 2026-09-16
debian: CVE-2026-85505 was patched at 2026-09-16
debian: CVE-2026-85506 was patched at 2026-09-16
debian: CVE-2026-85507 was patched at 2026-09-16
debian: CVE-2026-85508 was patched at 2026-09-16
debian: CVE-2026-85509 was patched at 2026-09-16
debian: CVE-2026-86095 was patched at 2026-09-16
debian: CVE-2026-86564 was patched at 2026-09-16
debian: CVE-2026-87736 was patched at 2026-09-16
debian: CVE-2026-87933 was patched at 2026-09-16
debian: CVE-2026-89266 was patched at 2026-09-16
debian: CVE-2026-90556 was patched at 2026-09-16
debian: CVE-2026-90557 was patched at 2026-09-16
debian: CVE-2026-90681 was patched at 2026-09-16
debian: CVE-2026-90682 was patched at 2026-09-16
debian: CVE-2026-90698 was patched at 2026-09-16
debian: CVE-2026-90783 was patched at 2026-09-16
debian: CVE-2026-91826 was patched at 2026-09-16
debian: CVE-2026-92240 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-88050 was patched at 2026-09-16
redos: CVE-2025-15667 was patched at 2026-08-24
redos: CVE-2025-15668 was patched at 2026-08-24
redos: CVE-2026-14790 was patched at 2026-08-24
debian: CVE-2026-18495 was patched at 2026-09-16
debian: CVE-2026-78254 was patched at 2026-09-16
altlinux: CVE-2026-74977 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-84141 was patched at 2026-08-20, 2026-08-28, 2026-09-01, 2026-09-03, 2026-09-05, 2026-09-09
altlinux: CVE-2026-65927 was patched at 2026-08-26, 2026-08-27, 2026-09-11, 2026-09-16
debian: CVE-2026-65927 was patched at 2026-09-16
debian: CVE-2026-80605 was patched at 2026-09-16
debian: CVE-2026-80671 was patched at 2026-09-16
debian: CVE-2026-89559 was patched at 2026-09-16
oraclelinux: CVE-2026-80605 was patched at 2026-09-04
redos: CVE-2026-80605 was patched at 2026-09-16
altlinux: CVE-2026-79148 was patched at 2026-08-28
altlinux: CVE-2026-79223 was patched at 2026-08-28
altlinux: CVE-2026-87630 was patched at 2026-09-17
altlinux: CVE-2026-91746 was patched at 2026-09-17
debian: CVE-2026-79148 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79223 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-87630 was patched at 2026-09-16
debian: CVE-2026-91746 was patched at 2026-09-16
debian: CVE-2026-63117 was patched at 2026-08-25
debian: CVE-2026-91962 was patched at 2026-09-16
redos: CVE-2026-63117 was patched at 2026-09-07
altlinux: CVE-2026-86138 was patched at 2026-09-09
debian: CVE-2026-86138 was patched at 2026-09-16
debian: CVE-2026-86139 was patched at 2026-09-16
debian: CVE-2026-87823 was patched at 2026-09-16
debian: CVE-2026-89158 was patched at 2026-09-16
debian: CVE-2026-88035 was patched at 2026-09-16
debian: CVE-2026-55373 was patched at 2026-09-16
debian: CVE-2026-59183 was patched at 2026-09-16
debian: CVE-2026-68552 was patched at 2026-08-25
debian: CVE-2026-6244 was patched at 2026-09-16
debian: CVE-2026-68767 was patched at 2026-08-25
debian: CVE-2026-72854 was patched at 2026-08-25
debian: CVE-2026-87020 was patched at 2026-09-16
debian: CVE-2026-90473 was patched at 2026-09-16
debian: CVE-2026-82250 was patched at 2026-09-16
debian: CVE-2026-52492 was patched at 2026-09-16
redos: CVE-2026-14801 was patched at 2026-08-24
ubuntu: CVE-2026-66755 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78679 was patched at 2026-08-25
altlinux: CVE-2026-64730 was patched at 2026-08-24
debian: CVE-2026-64730 was patched at 2026-08-24, 2026-08-25
ubuntu: CVE-2026-64730 was patched at 2026-08-31, 2026-09-16
debian: CVE-2026-62380 was patched at 2026-08-25
altlinux: CVE-2026-74975 was patched at 2026-08-20, 2026-08-28
altlinux: CVE-2026-92051 was patched at 2026-09-16
altlinux: CVE-2026-92069 was patched at 2026-09-16
altlinux: CVE-2026-78912 was patched at 2026-08-28
altlinux: CVE-2026-79173 was patched at 2026-08-28
altlinux: CVE-2026-79204 was patched at 2026-08-28
altlinux: CVE-2026-79233 was patched at 2026-08-28
altlinux: CVE-2026-79250 was patched at 2026-08-28
altlinux: CVE-2026-79283 was patched at 2026-08-28
altlinux: CVE-2026-84330 was patched at 2026-09-03
altlinux: CVE-2026-84356 was patched at 2026-09-03
altlinux: CVE-2026-87463 was patched at 2026-09-17
altlinux: CVE-2026-87562 was patched at 2026-09-17
altlinux: CVE-2026-87583 was patched at 2026-09-17
altlinux: CVE-2026-87597 was patched at 2026-09-17
altlinux: CVE-2026-87635 was patched at 2026-09-17
altlinux: CVE-2026-87653 was patched at 2026-09-17
altlinux: CVE-2026-91723 was patched at 2026-09-17
debian: CVE-2026-78912 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79173 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79204 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79233 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79250 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79283 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84330 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84356 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-87463 was patched at 2026-09-16
debian: CVE-2026-87562 was patched at 2026-09-16
debian: CVE-2026-87583 was patched at 2026-09-16
debian: CVE-2026-87597 was patched at 2026-09-16
debian: CVE-2026-87635 was patched at 2026-09-16
debian: CVE-2026-87653 was patched at 2026-09-16
debian: CVE-2026-91723 was patched at 2026-09-16
altlinux: CVE-2026-88004 was patched at 2026-09-15, 2026-09-16
debian: CVE-2026-63435 was patched at 2026-09-16
debian: CVE-2026-74580 was patched at 2026-08-25
debian: CVE-2026-74584 was patched at 2026-08-25
debian: CVE-2026-74585 was patched at 2026-08-25
debian: CVE-2026-74590 was patched at 2026-08-25
debian: CVE-2026-74592 was patched at 2026-08-25
debian: CVE-2026-74594 was patched at 2026-08-25
debian: CVE-2026-74595 was patched at 2026-08-25
debian: CVE-2026-74597 was patched at 2026-08-25
debian: CVE-2026-74598 was patched at 2026-08-25
debian: CVE-2026-74600 was patched at 2026-08-25
debian: CVE-2026-74601 was patched at 2026-08-25
debian: CVE-2026-74602 was patched at 2026-08-25
debian: CVE-2026-74603 was patched at 2026-08-25
debian: CVE-2026-74605 was patched at 2026-08-25
debian: CVE-2026-74607 was patched at 2026-08-25
debian: CVE-2026-74611 was patched at 2026-08-25
debian: CVE-2026-74612 was patched at 2026-08-25
debian: CVE-2026-74614 was patched at 2026-08-25
debian: CVE-2026-74616 was patched at 2026-08-25
debian: CVE-2026-74618 was patched at 2026-08-25
debian: CVE-2026-74619 was patched at 2026-08-25
debian: CVE-2026-74620 was patched at 2026-08-25
debian: CVE-2026-74621 was patched at 2026-08-25
debian: CVE-2026-74622 was patched at 2026-08-25
debian: CVE-2026-74624 was patched at 2026-08-25
debian: CVE-2026-74625 was patched at 2026-08-25
debian: CVE-2026-74626 was patched at 2026-08-25, 2026-08-29
debian: CVE-2026-74632 was patched at 2026-08-25
debian: CVE-2026-74636 was patched at 2026-08-25
debian: CVE-2026-74638 was patched at 2026-08-25
debian: CVE-2026-74641 was patched at 2026-08-25
debian: CVE-2026-74644 was patched at 2026-08-25
debian: CVE-2026-74646 was patched at 2026-08-25
debian: CVE-2026-74647 was patched at 2026-08-25
debian: CVE-2026-74648 was patched at 2026-08-25
debian: CVE-2026-74649 was patched at 2026-08-25
debian: CVE-2026-74653 was patched at 2026-08-25, 2026-08-29
debian: CVE-2026-74654 was patched at 2026-08-25
debian: CVE-2026-74655 was patched at 2026-08-25
debian: CVE-2026-74657 was patched at 2026-08-25
debian: CVE-2026-74658 was patched at 2026-08-25
debian: CVE-2026-74659 was patched at 2026-08-25
debian: CVE-2026-74662 was patched at 2026-08-25, 2026-08-29
debian: CVE-2026-74663 was patched at 2026-08-25
debian: CVE-2026-74664 was patched at 2026-08-25
debian: CVE-2026-74665 was patched at 2026-08-25
debian: CVE-2026-74666 was patched at 2026-08-25
debian: CVE-2026-74667 was patched at 2026-08-25
debian: CVE-2026-74668 was patched at 2026-08-25
debian: CVE-2026-74670 was patched at 2026-08-25
debian: CVE-2026-74673 was patched at 2026-08-25
debian: CVE-2026-74675 was patched at 2026-08-25
debian: CVE-2026-74676 was patched at 2026-08-25
debian: CVE-2026-74680 was patched at 2026-08-25
debian: CVE-2026-74682 was patched at 2026-08-25
debian: CVE-2026-74683 was patched at 2026-08-25
debian: CVE-2026-74685 was patched at 2026-08-25
debian: CVE-2026-74687 was patched at 2026-08-25
debian: CVE-2026-74690 was patched at 2026-08-25
debian: CVE-2026-74691 was patched at 2026-08-25
debian: CVE-2026-74692 was patched at 2026-08-25
debian: CVE-2026-74693 was patched at 2026-08-25
debian: CVE-2026-74694 was patched at 2026-08-25
debian: CVE-2026-74695 was patched at 2026-08-25
debian: CVE-2026-74696 was patched at 2026-08-25
debian: CVE-2026-74697 was patched at 2026-08-25
debian: CVE-2026-74701 was patched at 2026-08-25
debian: CVE-2026-74704 was patched at 2026-08-25
debian: CVE-2026-74710 was patched at 2026-08-25
debian: CVE-2026-74712 was patched at 2026-08-25
debian: CVE-2026-74713 was patched at 2026-08-25
debian: CVE-2026-74715 was patched at 2026-08-25
debian: CVE-2026-74717 was patched at 2026-08-25
debian: CVE-2026-74718 was patched at 2026-08-25
debian: CVE-2026-74719 was patched at 2026-08-25
debian: CVE-2026-74720 was patched at 2026-08-25
debian: CVE-2026-74723 was patched at 2026-08-25
debian: CVE-2026-74726 was patched at 2026-08-25
debian: CVE-2026-74728 was patched at 2026-08-25
debian: CVE-2026-74729 was patched at 2026-08-25
debian: CVE-2026-74733 was patched at 2026-08-25
debian: CVE-2026-74735 was patched at 2026-09-16
debian: CVE-2026-74736 was patched at 2026-09-16
debian: CVE-2026-74737 was patched at 2026-09-16
debian: CVE-2026-74740 was patched at 2026-09-16
debian: CVE-2026-74742 was patched at 2026-09-16
debian: CVE-2026-74747 was patched at 2026-09-16
debian: CVE-2026-74748 was patched at 2026-09-16
debian: CVE-2026-74753 was patched at 2026-09-16
debian: CVE-2026-74754 was patched at 2026-09-16
debian: CVE-2026-80522 was patched at 2026-09-16
debian: CVE-2026-80525 was patched at 2026-09-16
debian: CVE-2026-80526 was patched at 2026-09-16
debian: CVE-2026-80527 was patched at 2026-09-16
debian: CVE-2026-80528 was patched at 2026-09-16
debian: CVE-2026-80529 was patched at 2026-09-16
debian: CVE-2026-80530 was patched at 2026-09-16
debian: CVE-2026-80531 was patched at 2026-09-16
debian: CVE-2026-80532 was patched at 2026-09-16
debian: CVE-2026-80533 was patched at 2026-09-16
debian: CVE-2026-80534 was patched at 2026-09-16
debian: CVE-2026-80535 was patched at 2026-09-16
debian: CVE-2026-80539 was patched at 2026-09-16
debian: CVE-2026-80540 was patched at 2026-09-16
debian: CVE-2026-80541 was patched at 2026-09-16
debian: CVE-2026-80547 was patched at 2026-09-16
debian: CVE-2026-80548 was patched at 2026-09-16
debian: CVE-2026-80549 was patched at 2026-09-16
debian: CVE-2026-80550 was patched at 2026-09-16
debian: CVE-2026-80551 was patched at 2026-09-16
debian: CVE-2026-80552 was patched at 2026-09-16
debian: CVE-2026-80553 was patched at 2026-09-16
debian: CVE-2026-80554 was patched at 2026-09-16
debian: CVE-2026-80555 was patched at 2026-09-16
debian: CVE-2026-80557 was patched at 2026-08-29, 2026-09-16
debian: CVE-2026-80558 was patched at 2026-09-16
debian: CVE-2026-80559 was patched at 2026-09-16
debian: CVE-2026-80561 was patched at 2026-09-16
debian: CVE-2026-80562 was patched at 2026-08-29, 2026-09-16
debian: CVE-2026-80565 was patched at 2026-09-16
debian: CVE-2026-80566 was patched at 2026-09-16
debian: CVE-2026-80567 was patched at 2026-09-16
debian: CVE-2026-80569 was patched at 2026-09-16
debian: CVE-2026-80572 was patched at 2026-08-29, 2026-09-16
debian: CVE-2026-80573 was patched at 2026-09-16
debian: CVE-2026-80574 was patched at 2026-09-16
debian: CVE-2026-80575 was patched at 2026-09-16
debian: CVE-2026-80576 was patched at 2026-09-16
debian: CVE-2026-80578 was patched at 2026-09-16
debian: CVE-2026-80579 was patched at 2026-09-16
debian: CVE-2026-80580 was patched at 2026-09-16
debian: CVE-2026-80581 was patched at 2026-09-16
debian: CVE-2026-80583 was patched at 2026-08-29, 2026-09-16
debian: CVE-2026-80584 was patched at 2026-09-16
debian: CVE-2026-80585 was patched at 2026-09-16
debian: CVE-2026-80586 was patched at 2026-09-16
debian: CVE-2026-80587 was patched at 2026-09-16
debian: CVE-2026-80590 was patched at 2026-08-29, 2026-09-16
debian: CVE-2026-80591 was patched at 2026-09-16
debian: CVE-2026-80594 was patched at 2026-09-16
debian: CVE-2026-80595 was patched at 2026-09-16
debian: CVE-2026-80596 was patched at 2026-09-16
debian: CVE-2026-80599 was patched at 2026-09-16
debian: CVE-2026-80602 was patched at 2026-09-16
debian: CVE-2026-80607 was patched at 2026-09-16
debian: CVE-2026-80609 was patched at 2026-09-16
debian: CVE-2026-80611 was patched at 2026-09-16
debian: CVE-2026-80613 was patched at 2026-09-16
debian: CVE-2026-80616 was patched at 2026-09-16
debian: CVE-2026-80618 was patched at 2026-09-16
debian: CVE-2026-80619 was patched at 2026-09-16
debian: CVE-2026-80623 was patched at 2026-09-16
debian: CVE-2026-80626 was patched at 2026-09-16
debian: CVE-2026-80628 was patched at 2026-09-16
debian: CVE-2026-80629 was patched at 2026-09-16
debian: CVE-2026-80630 was patched at 2026-09-16
debian: CVE-2026-80631 was patched at 2026-09-16
debian: CVE-2026-80634 was patched at 2026-09-16
debian: CVE-2026-80637 was patched at 2026-09-16
debian: CVE-2026-80643 was patched at 2026-09-16
debian: CVE-2026-80644 was patched at 2026-09-16
debian: CVE-2026-80645 was patched at 2026-09-16
debian: CVE-2026-80646 was patched at 2026-09-16
debian: CVE-2026-80647 was patched at 2026-09-16
debian: CVE-2026-80649 was patched at 2026-09-16
debian: CVE-2026-80652 was patched at 2026-09-16
debian: CVE-2026-80653 was patched at 2026-09-16
debian: CVE-2026-80654 was patched at 2026-09-16
debian: CVE-2026-80659 was patched at 2026-09-16
debian: CVE-2026-80660 was patched at 2026-09-16
debian: CVE-2026-80662 was patched at 2026-09-16
debian: CVE-2026-80663 was patched at 2026-09-16
debian: CVE-2026-80667 was patched at 2026-09-16
debian: CVE-2026-80668 was patched at 2026-09-16
debian: CVE-2026-80669 was patched at 2026-09-16
debian: CVE-2026-80670 was patched at 2026-09-16
debian: CVE-2026-80676 was patched at 2026-09-16
debian: CVE-2026-80677 was patched at 2026-09-16
debian: CVE-2026-80680 was patched at 2026-09-16
debian: CVE-2026-80684 was patched at 2026-09-16
debian: CVE-2026-80686 was patched at 2026-09-16
debian: CVE-2026-80691 was patched at 2026-09-16
debian: CVE-2026-80692 was patched at 2026-09-16
debian: CVE-2026-80694 was patched at 2026-09-16
debian: CVE-2026-80695 was patched at 2026-09-16
debian: CVE-2026-80696 was patched at 2026-09-16
debian: CVE-2026-80698 was patched at 2026-09-16
debian: CVE-2026-80700 was patched at 2026-09-16
debian: CVE-2026-80702 was patched at 2026-09-16
debian: CVE-2026-80703 was patched at 2026-09-16
debian: CVE-2026-80705 was patched at 2026-09-16
debian: CVE-2026-80706 was patched at 2026-09-16
debian: CVE-2026-80707 was patched at 2026-09-16
debian: CVE-2026-80708 was patched at 2026-09-16
debian: CVE-2026-80709 was patched at 2026-09-16
debian: CVE-2026-80710 was patched at 2026-09-16
debian: CVE-2026-80711 was patched at 2026-09-16
debian: CVE-2026-80715 was patched at 2026-09-16
debian: CVE-2026-80716 was patched at 2026-09-16
debian: CVE-2026-80717 was patched at 2026-09-16
debian: CVE-2026-80718 was patched at 2026-09-16
debian: CVE-2026-80721 was patched at 2026-09-16
debian: CVE-2026-80722 was patched at 2026-09-16
debian: CVE-2026-80723 was patched at 2026-09-16
debian: CVE-2026-80727 was patched at 2026-09-16
debian: CVE-2026-80728 was patched at 2026-09-16
debian: CVE-2026-80733 was patched at 2026-09-16
debian: CVE-2026-80736 was patched at 2026-09-16
debian: CVE-2026-80737 was patched at 2026-09-16
debian: CVE-2026-80738 was patched at 2026-09-16
debian: CVE-2026-80739 was patched at 2026-09-16
debian: CVE-2026-80742 was patched at 2026-09-16
debian: CVE-2026-80744 was patched at 2026-09-16
debian: CVE-2026-80747 was patched at 2026-09-16
debian: CVE-2026-80749 was patched at 2026-09-16
debian: CVE-2026-80754 was patched at 2026-09-16
debian: CVE-2026-80755 was patched at 2026-09-16
debian: CVE-2026-80756 was patched at 2026-09-16
debian: CVE-2026-80757 was patched at 2026-09-16
debian: CVE-2026-80759 was patched at 2026-09-16
debian: CVE-2026-80761 was patched at 2026-09-16
debian: CVE-2026-80763 was patched at 2026-09-16
debian: CVE-2026-80768 was patched at 2026-09-16
debian: CVE-2026-80771 was patched at 2026-09-16
debian: CVE-2026-80774 was patched at 2026-09-16
debian: CVE-2026-80779 was patched at 2026-09-16
debian: CVE-2026-80782 was patched at 2026-09-16
debian: CVE-2026-80785 was patched at 2026-09-16
debian: CVE-2026-80786 was patched at 2026-09-16
debian: CVE-2026-80788 was patched at 2026-09-16
debian: CVE-2026-80789 was patched at 2026-09-16
debian: CVE-2026-80790 was patched at 2026-09-16
debian: CVE-2026-80791 was patched at 2026-09-16
debian: CVE-2026-80793 was patched at 2026-09-16
debian: CVE-2026-80794 was patched at 2026-09-16
debian: CVE-2026-80797 was patched at 2026-09-16
debian: CVE-2026-80799 was patched at 2026-09-16
debian: CVE-2026-80800 was patched at 2026-09-16
debian: CVE-2026-80801 was patched at 2026-09-16
debian: CVE-2026-80803 was patched at 2026-09-16
debian: CVE-2026-80805 was patched at 2026-09-16
debian: CVE-2026-80806 was patched at 2026-09-16
debian: CVE-2026-80807 was patched at 2026-09-16
debian: CVE-2026-80808 was patched at 2026-09-16
debian: CVE-2026-80809 was patched at 2026-09-16
debian: CVE-2026-80812 was patched at 2026-09-16
debian: CVE-2026-80814 was patched at 2026-09-16
debian: CVE-2026-80815 was patched at 2026-09-16
debian: CVE-2026-80819 was patched at 2026-09-16
debian: CVE-2026-80820 was patched at 2026-09-16
debian: CVE-2026-80825 was patched at 2026-09-16
debian: CVE-2026-80828 was patched at 2026-09-16
debian: CVE-2026-80829 was patched at 2026-09-16
debian: CVE-2026-80831 was patched at 2026-09-16
debian: CVE-2026-80832 was patched at 2026-09-16
debian: CVE-2026-80835 was patched at 2026-09-16
debian: CVE-2026-80838 was patched at 2026-09-16
debian: CVE-2026-80839 was patched at 2026-09-16
debian: CVE-2026-80840 was patched at 2026-09-16
debian: CVE-2026-80843 was patched at 2026-09-16
debian: CVE-2026-80845 was patched at 2026-09-16
debian: CVE-2026-80846 was patched at 2026-09-16
debian: CVE-2026-80847 was patched at 2026-09-16
debian: CVE-2026-80851 was patched at 2026-09-16
debian: CVE-2026-80854 was patched at 2026-09-16
debian: CVE-2026-80855 was patched at 2026-09-16
debian: CVE-2026-80856 was patched at 2026-09-16
debian: CVE-2026-80860 was patched at 2026-09-16
debian: CVE-2026-80861 was patched at 2026-09-16
debian: CVE-2026-80862 was patched at 2026-09-16
debian: CVE-2026-80865 was patched at 2026-09-16
debian: CVE-2026-80866 was patched at 2026-09-16
debian: CVE-2026-80867 was patched at 2026-09-16
debian: CVE-2026-80872 was patched at 2026-09-16
debian: CVE-2026-80875 was patched at 2026-09-16
debian: CVE-2026-80876 was patched at 2026-09-16
debian: CVE-2026-80877 was patched at 2026-09-16
debian: CVE-2026-80878 was patched at 2026-09-16
debian: CVE-2026-80879 was patched at 2026-09-16
debian: CVE-2026-80880 was patched at 2026-09-16
debian: CVE-2026-80881 was patched at 2026-09-16
debian: CVE-2026-80882 was patched at 2026-09-16
debian: CVE-2026-80883 was patched at 2026-09-16
debian: CVE-2026-80884 was patched at 2026-09-16
debian: CVE-2026-80887 was patched at 2026-09-16
debian: CVE-2026-80888 was patched at 2026-09-16
debian: CVE-2026-80889 was patched at 2026-09-16
debian: CVE-2026-80890 was patched at 2026-09-16
debian: CVE-2026-80891 was patched at 2026-09-16
debian: CVE-2026-80892 was patched at 2026-09-16
debian: CVE-2026-80893 was patched at 2026-09-16
debian: CVE-2026-80894 was patched at 2026-09-16
debian: CVE-2026-80899 was patched at 2026-09-16
debian: CVE-2026-80901 was patched at 2026-09-16
debian: CVE-2026-80902 was patched at 2026-09-16
debian: CVE-2026-80903 was patched at 2026-09-16
debian: CVE-2026-80904 was patched at 2026-09-16
debian: CVE-2026-80905 was patched at 2026-09-16
debian: CVE-2026-80906 was patched at 2026-09-16
debian: CVE-2026-80907 was patched at 2026-09-16
debian: CVE-2026-80908 was patched at 2026-09-16
debian: CVE-2026-80909 was patched at 2026-09-16
debian: CVE-2026-80910 was patched at 2026-09-16
debian: CVE-2026-80911 was patched at 2026-09-16
debian: CVE-2026-80912 was patched at 2026-09-16
debian: CVE-2026-80913 was patched at 2026-09-16
debian: CVE-2026-80915 was patched at 2026-09-16
debian: CVE-2026-80916 was patched at 2026-09-16
debian: CVE-2026-80918 was patched at 2026-09-16
debian: CVE-2026-80920 was patched at 2026-09-16
debian: CVE-2026-80921 was patched at 2026-09-16
debian: CVE-2026-80922 was patched at 2026-09-16
debian: CVE-2026-80925 was patched at 2026-09-16
debian: CVE-2026-80928 was patched at 2026-09-16
debian: CVE-2026-80930 was patched at 2026-09-16
debian: CVE-2026-80931 was patched at 2026-09-16
debian: CVE-2026-80933 was patched at 2026-09-16
debian: CVE-2026-80938 was patched at 2026-09-16
debian: CVE-2026-80939 was patched at 2026-09-16
debian: CVE-2026-80940 was patched at 2026-09-16
debian: CVE-2026-80943 was patched at 2026-09-16
debian: CVE-2026-80944 was patched at 2026-09-16
debian: CVE-2026-80945 was patched at 2026-09-16
debian: CVE-2026-80964 was patched at 2026-09-16
debian: CVE-2026-80965 was patched at 2026-09-16
debian: CVE-2026-80966 was patched at 2026-09-16
debian: CVE-2026-80967 was patched at 2026-09-16
debian: CVE-2026-80968 was patched at 2026-09-16
debian: CVE-2026-80969 was patched at 2026-09-16
debian: CVE-2026-80972 was patched at 2026-09-16
debian: CVE-2026-80973 was patched at 2026-09-16
debian: CVE-2026-80974 was patched at 2026-09-16
debian: CVE-2026-80976 was patched at 2026-09-16
debian: CVE-2026-80977 was patched at 2026-09-16
debian: CVE-2026-80978 was patched at 2026-09-16
debian: CVE-2026-80979 was patched at 2026-09-16
debian: CVE-2026-80980 was patched at 2026-09-16
debian: CVE-2026-80983 was patched at 2026-09-16
debian: CVE-2026-80984 was patched at 2026-09-16
debian: CVE-2026-80987 was patched at 2026-09-16
debian: CVE-2026-80988 was patched at 2026-09-16
debian: CVE-2026-80989 was patched at 2026-09-16
debian: CVE-2026-80990 was patched at 2026-09-16
debian: CVE-2026-80996 was patched at 2026-09-16
debian: CVE-2026-80997 was patched at 2026-09-16
debian: CVE-2026-80999 was patched at 2026-09-16
debian: CVE-2026-81002 was patched at 2026-09-16
debian: CVE-2026-81007 was patched at 2026-09-16
debian: CVE-2026-81010 was patched at 2026-09-16
debian: CVE-2026-81011 was patched at 2026-09-16
debian: CVE-2026-81012 was patched at 2026-09-16
debian: CVE-2026-81013 was patched at 2026-09-16
debian: CVE-2026-81014 was patched at 2026-09-16
debian: CVE-2026-81016 was patched at 2026-09-16
debian: CVE-2026-89438 was patched at 2026-09-16
debian: CVE-2026-89439 was patched at 2026-09-16
debian: CVE-2026-89440 was patched at 2026-09-16
debian: CVE-2026-89441 was patched at 2026-09-16
debian: CVE-2026-89443 was patched at 2026-09-16
debian: CVE-2026-89444 was patched at 2026-09-16
debian: CVE-2026-89445 was patched at 2026-09-16
debian: CVE-2026-89448 was patched at 2026-09-16
debian: CVE-2026-89451 was patched at 2026-09-16
debian: CVE-2026-89452 was patched at 2026-09-16
debian: CVE-2026-89453 was patched at 2026-09-16
debian: CVE-2026-89454 was patched at 2026-09-16
debian: CVE-2026-89456 was patched at 2026-09-16
debian: CVE-2026-89458 was patched at 2026-09-16
debian: CVE-2026-89461 was patched at 2026-09-16
debian: CVE-2026-89462 was patched at 2026-09-16
debian: CVE-2026-89464 was patched at 2026-09-16
debian: CVE-2026-89465 was patched at 2026-09-16
debian: CVE-2026-89466 was patched at 2026-09-16
debian: CVE-2026-89473 was patched at 2026-09-16
debian: CVE-2026-89474 was patched at 2026-09-16
debian: CVE-2026-89476 was patched at 2026-09-16
debian: CVE-2026-89477 was patched at 2026-09-16
debian: CVE-2026-89478 was patched at 2026-09-16
debian: CVE-2026-89480 was patched at 2026-09-16
debian: CVE-2026-89481 was patched at 2026-09-16
debian: CVE-2026-89482 was patched at 2026-09-16
debian: CVE-2026-89483 was patched at 2026-09-16
debian: CVE-2026-89484 was patched at 2026-09-16
debian: CVE-2026-89485 was patched at 2026-09-16
debian: CVE-2026-89487 was patched at 2026-09-16
debian: CVE-2026-89490 was patched at 2026-09-16
debian: CVE-2026-89491 was patched at 2026-09-16
debian: CVE-2026-89497 was patched at 2026-09-16
debian: CVE-2026-89498 was patched at 2026-09-16
debian: CVE-2026-89500 was patched at 2026-09-16
debian: CVE-2026-89501 was patched at 2026-09-16
debian: CVE-2026-89502 was patched at 2026-09-16
debian: CVE-2026-89503 was patched at 2026-09-16
debian: CVE-2026-89504 was patched at 2026-09-16
debian: CVE-2026-89510 was patched at 2026-09-16
debian: CVE-2026-89512 was patched at 2026-09-16
debian: CVE-2026-89515 was patched at 2026-09-16
debian: CVE-2026-89520 was patched at 2026-09-16
debian: CVE-2026-89524 was patched at 2026-09-16
debian: CVE-2026-89525 was patched at 2026-09-16
debian: CVE-2026-89526 was patched at 2026-09-16
debian: CVE-2026-89527 was patched at 2026-09-16
debian: CVE-2026-89530 was patched at 2026-09-16
debian: CVE-2026-89531 was patched at 2026-09-16
debian: CVE-2026-89533 was patched at 2026-09-16
debian: CVE-2026-89535 was patched at 2026-09-16
debian: CVE-2026-89536 was patched at 2026-09-16
debian: CVE-2026-89537 was patched at 2026-09-16
debian: CVE-2026-89538 was patched at 2026-09-16
debian: CVE-2026-89539 was patched at 2026-09-16
debian: CVE-2026-89540 was patched at 2026-09-16
debian: CVE-2026-89541 was patched at 2026-09-16
debian: CVE-2026-89542 was patched at 2026-09-16
debian: CVE-2026-89547 was patched at 2026-09-16
debian: CVE-2026-89549 was patched at 2026-09-16
debian: CVE-2026-89550 was patched at 2026-09-16
debian: CVE-2026-89551 was patched at 2026-09-16
debian: CVE-2026-89554 was patched at 2026-09-16
debian: CVE-2026-89557 was patched at 2026-09-16
debian: CVE-2026-89558 was patched at 2026-09-16
debian: CVE-2026-89560 was patched at 2026-09-16
debian: CVE-2026-89561 was patched at 2026-09-16
debian: CVE-2026-89562 was patched at 2026-09-16
debian: CVE-2026-89563 was patched at 2026-09-16
debian: CVE-2026-89564 was patched at 2026-09-16
debian: CVE-2026-89565 was patched at 2026-09-16
debian: CVE-2026-89566 was patched at 2026-09-16
debian: CVE-2026-89567 was patched at 2026-09-16
debian: CVE-2026-89572 was patched at 2026-09-16
debian: CVE-2026-89573 was patched at 2026-09-16
debian: CVE-2026-89574 was patched at 2026-09-16
debian: CVE-2026-89576 was patched at 2026-09-16
debian: CVE-2026-89581 was patched at 2026-09-16
debian: CVE-2026-89582 was patched at 2026-09-16
debian: CVE-2026-89583 was patched at 2026-09-16
debian: CVE-2026-89585 was patched at 2026-09-16
debian: CVE-2026-89586 was patched at 2026-09-16
debian: CVE-2026-89588 was patched at 2026-09-16
debian: CVE-2026-89589 was patched at 2026-09-16
debian: CVE-2026-89593 was patched at 2026-09-16
debian: CVE-2026-89594 was patched at 2026-09-16
debian: CVE-2026-89595 was patched at 2026-09-16
debian: CVE-2026-89597 was patched at 2026-09-16
debian: CVE-2026-89598 was patched at 2026-09-16
debian: CVE-2026-89599 was patched at 2026-09-16
debian: CVE-2026-89601 was patched at 2026-09-16
debian: CVE-2026-89602 was patched at 2026-09-16
debian: CVE-2026-89604 was patched at 2026-09-16
debian: CVE-2026-89605 was patched at 2026-09-16
debian: CVE-2026-89606 was patched at 2026-09-16
debian: CVE-2026-89607 was patched at 2026-09-16
debian: CVE-2026-89608 was patched at 2026-09-16
debian: CVE-2026-89609 was patched at 2026-09-16
debian: CVE-2026-89611 was patched at 2026-09-16
debian: CVE-2026-89615 was patched at 2026-09-16
debian: CVE-2026-89616 was patched at 2026-09-16
debian: CVE-2026-89617 was patched at 2026-09-16
debian: CVE-2026-89618 was patched at 2026-09-16
debian: CVE-2026-89621 was patched at 2026-09-16
debian: CVE-2026-89626 was patched at 2026-09-16
debian: CVE-2026-89627 was patched at 2026-09-16
debian: CVE-2026-89628 was patched at 2026-09-16
debian: CVE-2026-89631 was patched at 2026-09-16
debian: CVE-2026-89633 was patched at 2026-09-16
debian: CVE-2026-89634 was patched at 2026-09-16
debian: CVE-2026-89639 was patched at 2026-09-16
debian: CVE-2026-89640 was patched at 2026-09-16
debian: CVE-2026-89642 was patched at 2026-09-16
debian: CVE-2026-89643 was patched at 2026-09-16
debian: CVE-2026-89644 was patched at 2026-09-16
debian: CVE-2026-89645 was patched at 2026-09-16
debian: CVE-2026-89647 was patched at 2026-09-16
debian: CVE-2026-89648 was patched at 2026-09-16
debian: CVE-2026-89649 was patched at 2026-09-16
debian: CVE-2026-89653 was patched at 2026-09-16
debian: CVE-2026-89654 was patched at 2026-09-16
debian: CVE-2026-89655 was patched at 2026-09-16
debian: CVE-2026-89656 was patched at 2026-09-16
debian: CVE-2026-89665 was patched at 2026-09-16
debian: CVE-2026-89666 was patched at 2026-09-16
debian: CVE-2026-89667 was patched at 2026-09-16
debian: CVE-2026-89672 was patched at 2026-09-16
debian: CVE-2026-89675 was patched at 2026-09-16
debian: CVE-2026-89676 was patched at 2026-09-16
debian: CVE-2026-89680 was patched at 2026-09-16
debian: CVE-2026-89683 was patched at 2026-09-16
debian: CVE-2026-89684 was patched at 2026-09-16
debian: CVE-2026-89685 was patched at 2026-09-16
debian: CVE-2026-89686 was patched at 2026-09-16
debian: CVE-2026-89691 was patched at 2026-09-16
debian: CVE-2026-89693 was patched at 2026-09-16
debian: CVE-2026-89694 was patched at 2026-09-16
debian: CVE-2026-89697 was patched at 2026-09-16
debian: CVE-2026-89698 was patched at 2026-09-16
debian: CVE-2026-89699 was patched at 2026-09-16
debian: CVE-2026-89700 was patched at 2026-09-16
debian: CVE-2026-89702 was patched at 2026-09-16
debian: CVE-2026-89704 was patched at 2026-09-16
debian: CVE-2026-89705 was patched at 2026-09-16
debian: CVE-2026-89706 was patched at 2026-09-16
debian: CVE-2026-89707 was patched at 2026-09-16
debian: CVE-2026-89710 was patched at 2026-09-16
debian: CVE-2026-89711 was patched at 2026-09-16
debian: CVE-2026-89712 was patched at 2026-09-16
debian: CVE-2026-89713 was patched at 2026-09-16
debian: CVE-2026-89717 was patched at 2026-09-16
debian: CVE-2026-89718 was patched at 2026-09-16
debian: CVE-2026-89719 was patched at 2026-09-16
debian: CVE-2026-89723 was patched at 2026-09-16
debian: CVE-2026-89732 was patched at 2026-09-16
debian: CVE-2026-89733 was patched at 2026-09-16
debian: CVE-2026-89735 was patched at 2026-09-16
debian: CVE-2026-89738 was patched at 2026-09-16
debian: CVE-2026-89740 was patched at 2026-09-16
debian: CVE-2026-89744 was patched at 2026-09-16
debian: CVE-2026-89749 was patched at 2026-09-16
debian: CVE-2026-89751 was patched at 2026-09-16
debian: CVE-2026-89752 was patched at 2026-09-16
debian: CVE-2026-89753 was patched at 2026-09-16
debian: CVE-2026-89755 was patched at 2026-09-16
debian: CVE-2026-89756 was patched at 2026-09-16
debian: CVE-2026-89757 was patched at 2026-09-16
debian: CVE-2026-89759 was patched at 2026-09-16
debian: CVE-2026-89762 was patched at 2026-09-16
debian: CVE-2026-89765 was patched at 2026-09-16
debian: CVE-2026-89766 was patched at 2026-09-16
debian: CVE-2026-89768 was patched at 2026-09-16
debian: CVE-2026-89771 was patched at 2026-09-16
debian: CVE-2026-89774 was patched at 2026-09-16
debian: CVE-2026-89776 was patched at 2026-09-16
debian: CVE-2026-89778 was patched at 2026-09-16
debian: CVE-2026-89779 was patched at 2026-09-16
debian: CVE-2026-89780 was patched at 2026-09-16
debian: CVE-2026-89784 was patched at 2026-09-16
debian: CVE-2026-89792 was patched at 2026-09-16
oraclelinux: CVE-2026-64257 was patched at 2026-09-04
oraclelinux: CVE-2026-64575 was patched at 2026-09-04
oraclelinux: CVE-2026-72333 was patched at 2026-09-04
oraclelinux: CVE-2026-72465 was patched at 2026-09-04
oraclelinux: CVE-2026-74425 was patched at 2026-09-04
oraclelinux: CVE-2026-74486 was patched at 2026-09-04
oraclelinux: CVE-2026-74580 was patched at 2026-09-04
oraclelinux: CVE-2026-74584 was patched at 2026-09-04
oraclelinux: CVE-2026-74585 was patched at 2026-09-04
oraclelinux: CVE-2026-74590 was patched at 2026-09-04
oraclelinux: CVE-2026-74592 was patched at 2026-09-04
oraclelinux: CVE-2026-74594 was patched at 2026-09-04
oraclelinux: CVE-2026-74595 was patched at 2026-09-04
oraclelinux: CVE-2026-74597 was patched at 2026-09-04
oraclelinux: CVE-2026-74598 was patched at 2026-09-04
oraclelinux: CVE-2026-74601 was patched at 2026-09-04
oraclelinux: CVE-2026-74603 was patched at 2026-09-04
oraclelinux: CVE-2026-74607 was patched at 2026-09-04
oraclelinux: CVE-2026-74612 was patched at 2026-09-04
oraclelinux: CVE-2026-74614 was patched at 2026-09-04
oraclelinux: CVE-2026-74616 was patched at 2026-09-04
oraclelinux: CVE-2026-74618 was patched at 2026-09-04
oraclelinux: CVE-2026-74619 was patched at 2026-09-04
oraclelinux: CVE-2026-74620 was patched at 2026-09-04
oraclelinux: CVE-2026-74621 was patched at 2026-09-04
oraclelinux: CVE-2026-74622 was patched at 2026-09-04
oraclelinux: CVE-2026-74624 was patched at 2026-09-04
oraclelinux: CVE-2026-74625 was patched at 2026-09-04
oraclelinux: CVE-2026-74632 was patched at 2026-09-04
oraclelinux: CVE-2026-74636 was patched at 2026-09-04
oraclelinux: CVE-2026-74641 was patched at 2026-09-04
oraclelinux: CVE-2026-74642 was patched at 2026-09-04
oraclelinux: CVE-2026-74644 was patched at 2026-09-04
oraclelinux: CVE-2026-74648 was patched at 2026-09-04
oraclelinux: CVE-2026-74649 was patched at 2026-09-04
oraclelinux: CVE-2026-74654 was patched at 2026-09-04
oraclelinux: CVE-2026-74657 was patched at 2026-09-04
oraclelinux: CVE-2026-74658 was patched at 2026-09-04
oraclelinux: CVE-2026-74663 was patched at 2026-09-04
oraclelinux: CVE-2026-74664 was patched at 2026-09-04
oraclelinux: CVE-2026-74665 was patched at 2026-09-04
oraclelinux: CVE-2026-74666 was patched at 2026-09-04
oraclelinux: CVE-2026-74667 was patched at 2026-09-04
oraclelinux: CVE-2026-74668 was patched at 2026-09-04
oraclelinux: CVE-2026-74670 was patched at 2026-09-04
oraclelinux: CVE-2026-74673 was patched at 2026-09-04
oraclelinux: CVE-2026-74675 was patched at 2026-09-04
oraclelinux: CVE-2026-74676 was patched at 2026-09-04
oraclelinux: CVE-2026-74680 was patched at 2026-09-04
oraclelinux: CVE-2026-74682 was patched at 2026-09-04
oraclelinux: CVE-2026-74683 was patched at 2026-09-04
oraclelinux: CVE-2026-74691 was patched at 2026-09-04
oraclelinux: CVE-2026-74696 was patched at 2026-09-04
oraclelinux: CVE-2026-74697 was patched at 2026-09-04
oraclelinux: CVE-2026-74701 was patched at 2026-09-04
oraclelinux: CVE-2026-74704 was patched at 2026-09-04
oraclelinux: CVE-2026-74710 was patched at 2026-09-04
oraclelinux: CVE-2026-74712 was patched at 2026-09-04
oraclelinux: CVE-2026-74717 was patched at 2026-09-04
oraclelinux: CVE-2026-74718 was patched at 2026-09-04
oraclelinux: CVE-2026-74720 was patched at 2026-09-04
oraclelinux: CVE-2026-74726 was patched at 2026-09-04
oraclelinux: CVE-2026-74748 was patched at 2026-09-04
oraclelinux: CVE-2026-80527 was patched at 2026-09-04
oraclelinux: CVE-2026-80528 was patched at 2026-09-04
oraclelinux: CVE-2026-80534 was patched at 2026-09-04
oraclelinux: CVE-2026-80540 was patched at 2026-09-04
oraclelinux: CVE-2026-80541 was patched at 2026-09-04
oraclelinux: CVE-2026-80558 was patched at 2026-09-04
oraclelinux: CVE-2026-80561 was patched at 2026-09-04
oraclelinux: CVE-2026-80574 was patched at 2026-09-04
oraclelinux: CVE-2026-80586 was patched at 2026-09-04
oraclelinux: CVE-2026-80590 was patched at 2026-09-04
oraclelinux: CVE-2026-80599 was patched at 2026-09-04
oraclelinux: CVE-2026-80609 was patched at 2026-09-04
oraclelinux: CVE-2026-80613 was patched at 2026-09-04
oraclelinux: CVE-2026-80630 was patched at 2026-09-04
oraclelinux: CVE-2026-80644 was patched at 2026-09-04
oraclelinux: CVE-2026-80646 was patched at 2026-09-04
oraclelinux: CVE-2026-80652 was patched at 2026-09-04
oraclelinux: CVE-2026-80659 was patched at 2026-09-04
oraclelinux: CVE-2026-80677 was patched at 2026-09-04
oraclelinux: CVE-2026-80706 was patched at 2026-09-04
oraclelinux: CVE-2026-80707 was patched at 2026-09-04
oraclelinux: CVE-2026-80715 was patched at 2026-09-04
oraclelinux: CVE-2026-80716 was patched at 2026-09-04
oraclelinux: CVE-2026-80717 was patched at 2026-09-04
oraclelinux: CVE-2026-80722 was patched at 2026-09-04
oraclelinux: CVE-2026-80733 was patched at 2026-09-04
oraclelinux: CVE-2026-80742 was patched at 2026-09-04
oraclelinux: CVE-2026-80744 was patched at 2026-09-04
oraclelinux: CVE-2026-80754 was patched at 2026-09-04
oraclelinux: CVE-2026-80756 was patched at 2026-09-04
oraclelinux: CVE-2026-80757 was patched at 2026-09-04
redhat: CVE-2026-74580 was patched at 2026-09-02
redos: CVE-2026-80594 was patched at 2026-09-16
redos: CVE-2026-80595 was patched at 2026-09-16
redos: CVE-2026-80599 was patched at 2026-09-16
redos: CVE-2026-80609 was patched at 2026-09-16
redos: CVE-2026-80613 was patched at 2026-09-16
redos: CVE-2026-80618 was patched at 2026-09-16
redos: CVE-2026-80619 was patched at 2026-09-16
redos: CVE-2026-80626 was patched at 2026-09-16
redos: CVE-2026-80630 was patched at 2026-09-16
redos: CVE-2026-80644 was patched at 2026-09-16
redos: CVE-2026-80645 was patched at 2026-09-16
redos: CVE-2026-80646 was patched at 2026-09-16
redos: CVE-2026-80647 was patched at 2026-09-16
redos: CVE-2026-80649 was patched at 2026-09-16
redos: CVE-2026-80652 was patched at 2026-09-16
redos: CVE-2026-80659 was patched at 2026-09-16
redos: CVE-2026-80660 was patched at 2026-09-16
redos: CVE-2026-80663 was patched at 2026-09-16
redos: CVE-2026-80669 was patched at 2026-09-16
redos: CVE-2026-80677 was patched at 2026-09-16
redos: CVE-2026-80865 was patched at 2026-09-16
redos: CVE-2026-80867 was patched at 2026-09-16
redos: CVE-2026-80875 was patched at 2026-09-16
redos: CVE-2026-80876 was patched at 2026-09-16
redos: CVE-2026-80877 was patched at 2026-09-16
redos: CVE-2026-80879 was patched at 2026-09-16
redos: CVE-2026-80880 was patched at 2026-09-16
redos: CVE-2026-80881 was patched at 2026-09-16
ubuntu: CVE-2026-63813 was patched at 2026-09-07, 2026-09-16
ubuntu: CVE-2026-63820 was patched at 2026-09-07, 2026-09-16
ubuntu: CVE-2026-63873 was patched at 2026-09-07, 2026-09-16
ubuntu: CVE-2026-63874 was patched at 2026-09-07, 2026-09-16
ubuntu: CVE-2026-64459 was patched at 2026-09-07, 2026-09-16
ubuntu: CVE-2026-64460 was patched at 2026-09-07, 2026-09-16
ubuntu: CVE-2026-64464 was patched at 2026-09-07, 2026-09-16
ubuntu: CVE-2026-64467 was patched at 2026-09-07, 2026-09-16
ubuntu: CVE-2026-64485 was patched at 2026-09-07, 2026-09-16
ubuntu: CVE-2026-64491 was patched at 2026-09-07, 2026-09-16
ubuntu: CVE-2026-64492 was patched at 2026-09-07, 2026-09-16
ubuntu: CVE-2026-64501 was patched at 2026-09-07, 2026-09-16
ubuntu: CVE-2026-64588 was patched at 2026-09-07, 2026-09-16
ubuntu: CVE-2026-64591 was patched at 2026-09-07, 2026-09-16
ubuntu: CVE-2026-64596 was patched at 2026-09-07, 2026-09-16
ubuntu: CVE-2026-68087 was patched at 2026-09-07, 2026-09-16
ubuntu: CVE-2026-68089 was patched at 2026-09-07, 2026-09-16
ubuntu: CVE-2026-74584 was patched at 2026-09-07, 2026-09-16
ubuntu: CVE-2026-80591 was patched at 2026-09-07, 2026-09-16
debian: CVE-2026-84303 was patched at 2026-09-16
debian: CVE-2026-84445 was patched at 2026-09-16
altlinux: CVE-2026-27775 was patched at 2026-08-27, 2026-08-29, 2026-09-04
altlinux: CVE-2026-76019 was patched at 2026-08-21
altlinux: CVE-2026-78892 was patched at 2026-08-28
altlinux: CVE-2026-78898 was patched at 2026-08-28
altlinux: CVE-2026-78907 was patched at 2026-08-28
altlinux: CVE-2026-78914 was patched at 2026-08-28
altlinux: CVE-2026-78947 was patched at 2026-08-28
altlinux: CVE-2026-78954 was patched at 2026-08-28
altlinux: CVE-2026-78958 was patched at 2026-08-28
altlinux: CVE-2026-78959 was patched at 2026-08-28
altlinux: CVE-2026-78961 was patched at 2026-08-28
altlinux: CVE-2026-78962 was patched at 2026-08-28
altlinux: CVE-2026-78965 was patched at 2026-08-28
altlinux: CVE-2026-78967 was patched at 2026-08-28
altlinux: CVE-2026-78968 was patched at 2026-08-28
altlinux: CVE-2026-78969 was patched at 2026-08-28
altlinux: CVE-2026-78974 was patched at 2026-08-28
altlinux: CVE-2026-78977 was patched at 2026-08-28
altlinux: CVE-2026-78979 was patched at 2026-08-28
altlinux: CVE-2026-78984 was patched at 2026-08-28
altlinux: CVE-2026-78986 was patched at 2026-08-28
altlinux: CVE-2026-79003 was patched at 2026-08-28
altlinux: CVE-2026-79005 was patched at 2026-08-28
altlinux: CVE-2026-79007 was patched at 2026-08-28
altlinux: CVE-2026-79009 was patched at 2026-08-28
altlinux: CVE-2026-79010 was patched at 2026-08-28
altlinux: CVE-2026-79011 was patched at 2026-08-28
altlinux: CVE-2026-79014 was patched at 2026-08-28
altlinux: CVE-2026-79021 was patched at 2026-08-28
altlinux: CVE-2026-79022 was patched at 2026-08-28
altlinux: CVE-2026-79040 was patched at 2026-08-28
altlinux: CVE-2026-79041 was patched at 2026-08-28
altlinux: CVE-2026-79042 was patched at 2026-08-28
altlinux: CVE-2026-79045 was patched at 2026-08-28
altlinux: CVE-2026-79046 was patched at 2026-08-28
altlinux: CVE-2026-79058 was patched at 2026-08-28
altlinux: CVE-2026-79060 was patched at 2026-08-28
altlinux: CVE-2026-79067 was patched at 2026-08-28
altlinux: CVE-2026-79072 was patched at 2026-08-28
altlinux: CVE-2026-79082 was patched at 2026-08-28
altlinux: CVE-2026-79085 was patched at 2026-08-28
altlinux: CVE-2026-79087 was patched at 2026-08-28
altlinux: CVE-2026-79088 was patched at 2026-08-28
altlinux: CVE-2026-79089 was patched at 2026-08-28
altlinux: CVE-2026-79093 was patched at 2026-08-28
altlinux: CVE-2026-79098 was patched at 2026-08-28
altlinux: CVE-2026-79107 was patched at 2026-08-28
altlinux: CVE-2026-79108 was patched at 2026-08-28
altlinux: CVE-2026-79116 was patched at 2026-08-28
altlinux: CVE-2026-79117 was patched at 2026-08-28
altlinux: CVE-2026-79118 was patched at 2026-08-28
altlinux: CVE-2026-79120 was patched at 2026-08-28
altlinux: CVE-2026-79137 was patched at 2026-08-28
altlinux: CVE-2026-79143 was patched at 2026-08-28
altlinux: CVE-2026-79152 was patched at 2026-08-28
altlinux: CVE-2026-79174 was patched at 2026-08-28
altlinux: CVE-2026-79177 was patched at 2026-08-28
altlinux: CVE-2026-79179 was patched at 2026-08-28
altlinux: CVE-2026-79180 was patched at 2026-08-28
altlinux: CVE-2026-79184 was patched at 2026-08-28
altlinux: CVE-2026-79190 was patched at 2026-08-28
altlinux: CVE-2026-79208 was patched at 2026-08-28
altlinux: CVE-2026-79211 was patched at 2026-08-28
altlinux: CVE-2026-79212 was patched at 2026-08-28
altlinux: CVE-2026-79221 was patched at 2026-08-28
altlinux: CVE-2026-79222 was patched at 2026-08-28
altlinux: CVE-2026-79225 was patched at 2026-08-28
altlinux: CVE-2026-79229 was patched at 2026-08-28
altlinux: CVE-2026-79238 was patched at 2026-08-28
altlinux: CVE-2026-79248 was patched at 2026-08-28
altlinux: CVE-2026-79258 was patched at 2026-08-28
altlinux: CVE-2026-79267 was patched at 2026-08-28
altlinux: CVE-2026-79269 was patched at 2026-08-28
altlinux: CVE-2026-79270 was patched at 2026-08-28
altlinux: CVE-2026-79273 was patched at 2026-08-28
altlinux: CVE-2026-79284 was patched at 2026-08-28
altlinux: CVE-2026-79285 was patched at 2026-08-28
altlinux: CVE-2026-84328 was patched at 2026-09-03
altlinux: CVE-2026-84329 was patched at 2026-09-03
altlinux: CVE-2026-84331 was patched at 2026-09-03
altlinux: CVE-2026-84355 was patched at 2026-09-03
altlinux: CVE-2026-85044 was patched at 2026-09-05
altlinux: CVE-2026-87429 was patched at 2026-09-17
altlinux: CVE-2026-87432 was patched at 2026-09-17
altlinux: CVE-2026-87434 was patched at 2026-09-17
altlinux: CVE-2026-87436 was patched at 2026-09-17
altlinux: CVE-2026-87442 was patched at 2026-09-17
altlinux: CVE-2026-87446 was patched at 2026-09-17
altlinux: CVE-2026-87452 was patched at 2026-09-17
altlinux: CVE-2026-87453 was patched at 2026-09-17
altlinux: CVE-2026-87456 was patched at 2026-09-17
altlinux: CVE-2026-87458 was patched at 2026-09-17
altlinux: CVE-2026-87462 was patched at 2026-09-17
altlinux: CVE-2026-87465 was patched at 2026-09-17
altlinux: CVE-2026-87473 was patched at 2026-09-17
altlinux: CVE-2026-87485 was patched at 2026-09-17
altlinux: CVE-2026-87498 was patched at 2026-09-17
altlinux: CVE-2026-87502 was patched at 2026-09-17
altlinux: CVE-2026-87507 was patched at 2026-09-17
altlinux: CVE-2026-87511 was patched at 2026-09-17
altlinux: CVE-2026-87517 was patched at 2026-09-17
altlinux: CVE-2026-87519 was patched at 2026-09-17
altlinux: CVE-2026-87522 was patched at 2026-09-17
altlinux: CVE-2026-87534 was patched at 2026-09-17
altlinux: CVE-2026-87549 was patched at 2026-09-17
altlinux: CVE-2026-87550 was patched at 2026-09-17
altlinux: CVE-2026-87555 was patched at 2026-09-17
altlinux: CVE-2026-87557 was patched at 2026-09-17
altlinux: CVE-2026-87559 was patched at 2026-09-17
altlinux: CVE-2026-87564 was patched at 2026-09-17
altlinux: CVE-2026-87567 was patched at 2026-09-17
altlinux: CVE-2026-87569 was patched at 2026-09-17
altlinux: CVE-2026-87576 was patched at 2026-09-17
altlinux: CVE-2026-87611 was patched at 2026-09-17
altlinux: CVE-2026-87614 was patched at 2026-09-17
altlinux: CVE-2026-87624 was patched at 2026-09-17
altlinux: CVE-2026-87627 was patched at 2026-09-17
altlinux: CVE-2026-87631 was patched at 2026-09-17
altlinux: CVE-2026-87647 was patched at 2026-09-17
altlinux: CVE-2026-87649 was patched at 2026-09-17
altlinux: CVE-2026-87651 was patched at 2026-09-17
altlinux: CVE-2026-87652 was patched at 2026-09-17
altlinux: CVE-2026-91708 was patched at 2026-09-17
altlinux: CVE-2026-91713 was patched at 2026-09-17
altlinux: CVE-2026-91720 was patched at 2026-09-17
altlinux: CVE-2026-91730 was patched at 2026-09-17
altlinux: CVE-2026-91732 was patched at 2026-09-17
altlinux: CVE-2026-91733 was patched at 2026-09-17
altlinux: CVE-2026-91739 was patched at 2026-09-17
altlinux: CVE-2026-91740 was patched at 2026-09-17
altlinux: CVE-2026-91742 was patched at 2026-09-17
debian: CVE-2026-76019 was patched at 2026-08-25, 2026-08-27
debian: CVE-2026-78892 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78898 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78907 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78914 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78947 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78954 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78958 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78959 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78961 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78962 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78965 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78967 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78968 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78969 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78974 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78977 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78979 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78984 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-78986 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79003 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79005 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79007 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79009 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79010 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79011 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79014 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79021 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79022 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79040 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79041 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79042 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79045 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79046 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79058 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79060 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79067 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79072 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79082 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79085 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79087 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79088 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79089 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79093 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79098 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79107 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79108 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79116 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79117 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79118 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79120 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79137 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79143 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79152 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79174 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79177 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79179 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79180 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79184 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79190 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79208 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79211 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79212 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79221 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79222 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79225 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79229 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79238 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79248 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79258 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79267 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79269 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79270 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79273 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79284 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-79285 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84328 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84329 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84331 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-84355 was patched at 2026-09-03, 2026-09-16
debian: CVE-2026-85044 was patched at 2026-09-05, 2026-09-16
debian: CVE-2026-87429 was patched at 2026-09-16
debian: CVE-2026-87432 was patched at 2026-09-16
debian: CVE-2026-87434 was patched at 2026-09-16
debian: CVE-2026-87436 was patched at 2026-09-16
debian: CVE-2026-87442 was patched at 2026-09-16
debian: CVE-2026-87446 was patched at 2026-09-16
debian: CVE-2026-87452 was patched at 2026-09-16
debian: CVE-2026-87453 was patched at 2026-09-16
debian: CVE-2026-87456 was patched at 2026-09-16
debian: CVE-2026-87458 was patched at 2026-09-16
debian: CVE-2026-87462 was patched at 2026-09-16
debian: CVE-2026-87465 was patched at 2026-09-16
debian: CVE-2026-87473 was patched at 2026-09-16
debian: CVE-2026-87485 was patched at 2026-09-16
debian: CVE-2026-87498 was patched at 2026-09-16
debian: CVE-2026-87502 was patched at 2026-09-16
debian: CVE-2026-87507 was patched at 2026-09-16
debian: CVE-2026-87511 was patched at 2026-09-16
debian: CVE-2026-87517 was patched at 2026-09-16
debian: CVE-2026-87519 was patched at 2026-09-16
debian: CVE-2026-87522 was patched at 2026-09-16
debian: CVE-2026-87534 was patched at 2026-09-16
debian: CVE-2026-87549 was patched at 2026-09-16
debian: CVE-2026-87550 was patched at 2026-09-16
debian: CVE-2026-87555 was patched at 2026-09-16
debian: CVE-2026-87557 was patched at 2026-09-16
debian: CVE-2026-87559 was patched at 2026-09-16
debian: CVE-2026-87564 was patched at 2026-09-16
debian: CVE-2026-87567 was patched at 2026-09-16
debian: CVE-2026-87569 was patched at 2026-09-16
debian: CVE-2026-87576 was patched at 2026-09-16
debian: CVE-2026-87611 was patched at 2026-09-16
debian: CVE-2026-87614 was patched at 2026-09-16
debian: CVE-2026-87624 was patched at 2026-09-16
debian: CVE-2026-87627 was patched at 2026-09-16
debian: CVE-2026-87631 was patched at 2026-09-16
debian: CVE-2026-87647 was patched at 2026-09-16
debian: CVE-2026-87649 was patched at 2026-09-16
debian: CVE-2026-87651 was patched at 2026-09-16
debian: CVE-2026-87652 was patched at 2026-09-16
debian: CVE-2026-91708 was patched at 2026-09-16
debian: CVE-2026-91713 was patched at 2026-09-16
debian: CVE-2026-91720 was patched at 2026-09-16
debian: CVE-2026-91730 was patched at 2026-09-16
debian: CVE-2026-91732 was patched at 2026-09-16
debian: CVE-2026-91733 was patched at 2026-09-16
debian: CVE-2026-91739 was patched at 2026-09-16
debian: CVE-2026-91740 was patched at 2026-09-16
debian: CVE-2026-91742 was patched at 2026-09-16
debian: CVE-2026-75595 was patched at 2026-08-25
debian: CVE-2026-75596 was patched at 2026-08-25
redos: CVE-2026-48480 was patched at 2026-09-04
debian: CVE-2026-83608 was patched at 2026-09-16
debian: CVE-2026-83610 was patched at 2026-09-16
debian: CVE-2026-83611 was patched at 2026-09-16
debian: CVE-2026-19499 was patched at 2026-09-16
debian: CVE-2026-19542 was patched at 2026-08-25
ubuntu: CVE-2026-19499 was patched at 2026-09-08, 2026-09-16
ubuntu: CVE-2026-19542 was patched at 2026-09-08, 2026-09-16
altlinux: CVE-2026-74956 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-74966 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-74984 was patched at 2026-08-20, 2026-08-27, 2026-08-28, 2026-09-03
altlinux: CVE-2026-92005 was patched at 2026-09-16
altlinux: CVE-2026-92016 was patched at 2026-09-16
altlinux: CVE-2026-92018 was patched at 2026-09-16
altlinux: CVE-2026-92019 was patched at 2026-09-16
altlinux: CVE-2026-92022 was patched at 2026-09-16
altlinux: CVE-2026-92023 was patched at 2026-09-16
altlinux: CVE-2026-92024 was patched at 2026-09-16
altlinux: CVE-2026-92025 was patched at 2026-09-16
altlinux: CVE-2026-92026 was patched at 2026-09-16
altlinux: CVE-2026-92027 was patched at 2026-09-16
altlinux: CVE-2026-92028 was patched at 2026-09-16
altlinux: CVE-2026-92029 was patched at 2026-09-16
altlinux: CVE-2026-92030 was patched at 2026-09-16
altlinux: CVE-2026-92031 was patched at 2026-09-16
altlinux: CVE-2026-92032 was patched at 2026-09-16
altlinux: CVE-2026-92034 was patched at 2026-09-16
altlinux: CVE-2026-92035 was patched at 2026-09-16
altlinux: CVE-2026-92036 was patched at 2026-09-16
altlinux: CVE-2026-92037 was patched at 2026-09-16
altlinux: CVE-2026-92038 was patched at 2026-09-16
altlinux: CVE-2026-92039 was patched at 2026-09-16
altlinux: CVE-2026-92040 was patched at 2026-09-16
altlinux: CVE-2026-92041 was patched at 2026-09-16
altlinux: CVE-2026-92042 was patched at 2026-09-16
altlinux: CVE-2026-92044 was patched at 2026-09-16
altlinux: CVE-2026-92045 was patched at 2026-09-16
altlinux: CVE-2026-92046 was patched at 2026-09-16
altlinux: CVE-2026-92048 was patched at 2026-09-16
altlinux: CVE-2026-92049 was patched at 2026-09-16
altlinux: CVE-2026-92052 was patched at 2026-09-16
altlinux: CVE-2026-92056 was patched at 2026-09-16
altlinux: CVE-2026-92057 was patched at 2026-09-16
altlinux: CVE-2026-92058 was patched at 2026-09-16
altlinux: CVE-2026-92059 was patched at 2026-09-16
altlinux: CVE-2026-92060 was patched at 2026-09-16
altlinux: CVE-2026-92061 was patched at 2026-09-16
altlinux: CVE-2026-92063 was patched at 2026-09-16
altlinux: CVE-2026-92064 was patched at 2026-09-16
altlinux: CVE-2026-92065 was patched at 2026-09-16
altlinux: CVE-2026-92066 was patched at 2026-09-16
altlinux: CVE-2026-92067 was patched at 2026-09-16
altlinux: CVE-2026-92068 was patched at 2026-09-16
altlinux: CVE-2026-92070 was patched at 2026-09-16
altlinux: CVE-2026-92071 was patched at 2026-09-16
altlinux: CVE-2026-92072 was patched at 2026-09-16
altlinux: CVE-2026-92074 was patched at 2026-09-16
altlinux: CVE-2026-92075 was patched at 2026-09-16
altlinux: CVE-2026-92076 was patched at 2026-09-16
altlinux: CVE-2026-92077 was patched at 2026-09-16
altlinux: CVE-2026-92078 was patched at 2026-09-16
altlinux: CVE-2026-92079 was patched at 2026-09-16
debian: CVE-2026-92005 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92016 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92018 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92019 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92021 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92022 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92023 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92024 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92025 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92026 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92027 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92028 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92029 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92030 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92031 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92032 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-87776 was patched at 2026-09-16
debian: CVE-2026-87859 was patched at 2026-09-16
debian: CVE-2026-88038 was patched at 2026-09-16
debian: CVE-2026-84939 was patched at 2026-09-16
altlinux: CVE-2026-65183 was patched at 2026-08-26, 2026-08-27, 2026-09-11, 2026-09-16
altlinux: CVE-2026-73180 was patched at 2026-08-26, 2026-08-27, 2026-09-11, 2026-09-16
altlinux: CVE-2026-73511 was patched at 2026-08-28, 2026-08-31
debian: CVE-2026-65183 was patched at 2026-09-16
debian: CVE-2026-73180 was patched at 2026-09-16
altlinux: CVE-2026-73638 was patched at 2026-08-26, 2026-08-27
debian: CVE-2026-15743 was patched at 2026-08-25
debian: CVE-2026-16028 was patched at 2026-09-16
debian: CVE-2026-73638 was patched at 2026-08-20
debian: CVE-2026-75589 was patched at 2026-08-20
debian: CVE-2026-77781 was patched at 2026-08-25
debian: CVE-2026-78030 was patched at 2026-09-16
debian: CVE-2026-81928 was patched at 2026-09-16
altlinux: CVE-2026-15571 was patched at 2026-08-20, 2026-08-26, 2026-08-28
altlinux: CVE-2026-15945 was patched at 2026-08-20, 2026-08-26, 2026-08-28
altlinux: CVE-2026-16089 was patched at 2026-09-01, 2026-09-04, 2026-09-07
altlinux: CVE-2026-16105 was patched at 2026-09-01, 2026-09-04, 2026-09-07
altlinux: CVE-2026-16106 was patched at 2026-09-01, 2026-09-04, 2026-09-07
altlinux: CVE-2026-17059 was patched at 2026-09-01, 2026-09-04, 2026-09-07
altlinux: CVE-2026-18201 was patched at 2026-09-01, 2026-09-04, 2026-09-07
altlinux: CVE-2026-18209 was patched at 2026-09-01, 2026-09-04, 2026-09-07
altlinux: CVE-2026-18214 was patched at 2026-09-01, 2026-09-04, 2026-09-07
altlinux: CVE-2026-18218 was patched at 2026-09-01, 2026-09-04, 2026-09-07
altlinux: CVE-2026-18570 was patched at 2026-09-01, 2026-09-04, 2026-09-07
altlinux: CVE-2026-18571 was patched at 2026-09-01, 2026-09-04, 2026-09-07
altlinux: CVE-2026-18572 was patched at 2026-09-01, 2026-09-04, 2026-09-07
altlinux: CVE-2026-18573 was patched at 2026-09-01, 2026-09-04, 2026-09-07
altlinux: CVE-2026-79652 was patched at 2026-09-01, 2026-09-04, 2026-09-07
altlinux: CVE-2026-59888 was patched at 2026-08-20, 2026-08-26, 2026-08-28
altlinux: CVE-2026-59889 was patched at 2026-08-20, 2026-08-26, 2026-08-28
debian: CVE-2026-54552 was patched at 2026-08-25
altlinux: CVE-2026-73513 was patched at 2026-08-28, 2026-08-31
debian: CVE-2026-78410 was patched at 2026-09-16
altlinux: CVE-2026-28740 was patched at 2026-08-27, 2026-08-29, 2026-09-04
altlinux: CVE-2026-78124 was patched at 2026-09-11
debian: CVE-2026-62243 was patched at 2026-08-25
debian: CVE-2026-78124 was patched at 2026-09-07, 2026-09-16
debian: CVE-2026-17084 was patched at 2026-08-20
debian: CVE-2026-82617 was patched at 2026-09-16
debian: CVE-2026-72709 was patched at 2026-09-16
debian: CVE-2026-55701 was patched at 2026-09-16
altlinux: CVE-2026-84639 was patched at 2026-09-03, 2026-09-09
altlinux: CVE-2026-84640 was patched at 2026-09-03, 2026-09-09
altlinux: CVE-2026-84642 was patched at 2026-09-03, 2026-09-09
debian: CVE-2026-84639 was patched at 2026-09-04, 2026-09-16
debian: CVE-2026-84640 was patched at 2026-09-04, 2026-09-16
debian: CVE-2026-59696 was patched at 2026-09-16
debian: CVE-2026-66835 was patched at 2026-09-16
debian: CVE-2026-70405 was patched at 2026-09-16
debian: CVE-2026-70409 was patched at 2026-09-16
debian: CVE-2026-73270 was patched at 2026-09-16
debian: CVE-2026-47892 was patched at 2026-09-16
debian: CVE-2026-47893 was patched at 2026-09-16
debian: CVE-2026-59283 was patched at 2026-09-16
debian: CVE-2026-59313 was patched at 2026-09-16
debian: CVE-2026-59314 was patched at 2026-09-16
altlinux: CVE-2026-18690 was patched at 2026-08-26
altlinux: CVE-2026-18696 was patched at 2026-08-26
altlinux: CVE-2026-18698 was patched at 2026-08-26
altlinux: CVE-2026-18709 was patched at 2026-08-26
altlinux: CVE-2026-18712 was patched at 2026-08-26
altlinux: CVE-2026-82053 was patched at 2026-09-09, 2026-09-10
altlinux: CVE-2026-82060 was patched at 2026-09-09, 2026-09-10
altlinux: CVE-2026-82067 was patched at 2026-09-09, 2026-09-10
altlinux: CVE-2026-82074 was patched at 2026-09-09, 2026-09-10
debian: CVE-2026-81521 was patched at 2026-09-16
debian: CVE-2026-81523 was patched at 2026-09-16
debian: CVE-2026-81524 was patched at 2026-09-16
debian: CVE-2026-84963 was patched at 2026-09-16
debian: CVE-2026-88029 was patched at 2026-09-16
debian: CVE-2026-88030 was patched at 2026-09-16
debian: CVE-2026-88031 was patched at 2026-09-16
debian: CVE-2026-88033 was patched at 2026-09-16
debian: CVE-2026-88036 was patched at 2026-09-16
debian: CVE-2026-18149 was patched at 2026-09-16
debian: CVE-2026-19534 was patched at 2026-09-16
debian: CVE-2026-85014 was patched at 2026-09-16
debian: CVE-2026-85024 was patched at 2026-09-16
altlinux: CVE-2026-73512 was patched at 2026-08-28, 2026-08-31
altlinux: CVE-2026-73546 was patched at 2026-08-28, 2026-08-31
altlinux: CVE-2026-73548 was patched at 2026-08-28, 2026-08-31
altlinux: CVE-2026-73549 was patched at 2026-08-28, 2026-08-31
altlinux: CVE-2026-73550 was patched at 2026-08-28, 2026-08-31
altlinux: CVE-2026-73551 was patched at 2026-08-28, 2026-08-31
altlinux: CVE-2026-73552 was patched at 2026-08-28, 2026-08-31
altlinux: CVE-2026-73553 was patched at 2026-08-28, 2026-08-31
debian: CVE-2026-86469 was patched at 2026-09-16
debian: CVE-2026-87876 was patched at 2026-09-16
debian: CVE-2026-62437 was patched at 2026-09-16
debian: CVE-2026-80158 was patched at 2026-09-16
debian: CVE-2026-88264 was patched at 2026-09-16
debian: CVE-2026-77341 was patched at 2026-09-16
debian: CVE-2026-82417 was patched at 2026-09-16
debian: CVE-2026-48501 was patched at 2026-09-16
debian: CVE-2026-34399 was patched at 2026-08-25, 2026-08-26
debian: CVE-2026-68939 was patched at 2026-08-20
debian: CVE-2026-84366 was patched at 2026-09-16
altlinux: CVE-2026-88016 was patched at 2026-09-09
altlinux: CVE-2026-88017 was patched at 2026-09-09
debian: CVE-2026-79777 was patched at 2026-09-16
debian: CVE-2026-79779 was patched at 2026-09-16
debian: CVE-2026-79782 was patched at 2026-09-16
debian: CVE-2026-79783 was patched at 2026-09-16
debian: CVE-2026-88016 was patched at 2026-09-16
altlinux: CVE-2025-24912 was patched at 2026-08-31
debian: CVE-2026-82398 was patched at 2026-09-16
debian: CVE-2026-75931 was patched at 2026-08-25
debian: CVE-2026-84292 was patched at 2026-09-16
altlinux: CVE-2026-86422 was patched at 2026-08-31
altlinux: CVE-2026-86424 was patched at 2026-08-31
debian: CVE-2026-70651 was patched at 2026-08-25
debian: CVE-2026-86424 was patched at 2026-09-16
debian: CVE-2026-79769 was patched at 2026-09-16
debian: CVE-2026-84308 was patched at 2026-09-16
debian: CVE-2026-84450 was patched at 2026-09-16
debian: CVE-2026-84451 was patched at 2026-09-16
altlinux: CVE-2026-78127 was patched at 2026-09-11
altlinux: CVE-2026-78131 was patched at 2026-09-11
debian: CVE-2026-78127 was patched at 2026-09-07, 2026-09-16
debian: CVE-2026-78131 was patched at 2026-09-07, 2026-09-16
debian: CVE-2026-82249 was patched at 2026-09-16
debian: CVE-2026-82252 was patched at 2026-09-16
debian: CVE-2026-91986 was patched at 2026-09-16
debian: CVE-2026-15603 was patched at 2026-09-16
debian: CVE-2026-5078 was patched at 2026-09-16
debian: CVE-2026-89161 was patched at 2026-09-16
altlinux: CVE-2026-8149 was patched at 2026-09-12
debian: CVE-2026-77014 was patched at 2026-08-25
debian: CVE-2026-86472 was patched at 2026-09-16
debian: CVE-2026-86818 was patched at 2026-09-16
debian: CVE-2026-53939 was patched at 2026-09-15, 2026-09-16
debian: CVE-2022-42917 was patched at 2026-09-16
debian: CVE-2026-75883 was patched at 2026-09-14, 2026-09-16
debian: CVE-2026-79772 was patched at 2026-09-16
debian: CVE-2025-30153 was patched at 2026-08-20
debian: CVE-2026-61909 was patched at 2026-09-16
debian: CVE-2026-61910 was patched at 2026-09-16
debian: CVE-2026-61911 was patched at 2026-09-16
debian: CVE-2026-82660 was patched at 2026-09-16
debian: CVE-2026-82661 was patched at 2026-09-16
almalinux: CVE-2026-69159 was patched at 2026-08-31
altlinux: CVE-2026-15809 was patched at 2026-09-11, 2026-09-14, 2026-09-16
altlinux: CVE-2026-17113 was patched at 2026-09-11, 2026-09-14
altlinux: CVE-2026-25946 was patched at 2026-08-27, 2026-08-29, 2026-09-04
altlinux: CVE-2026-33606 was patched at 2026-08-29, 2026-09-01
altlinux: CVE-2026-49275 was patched at 2026-09-02
altlinux: CVE-2026-52681 was patched at 2026-08-29, 2026-09-01
altlinux: CVE-2026-58438 was patched at 2026-08-27, 2026-08-29, 2026-09-04
altlinux: CVE-2026-59678 was patched at 2026-08-25, 2026-09-02
altlinux: CVE-2026-60008 was patched at 2026-08-27, 2026-08-29, 2026-09-04
altlinux: CVE-2026-60010 was patched at 2026-09-04, 2026-09-07
altlinux: CVE-2026-60018 was patched at 2026-09-04, 2026-09-07
altlinux: CVE-2026-60021 was patched at 2026-09-04, 2026-09-07
altlinux: CVE-2026-62146 was patched at 2026-09-11, 2026-09-14, 2026-09-16
altlinux: CVE-2026-62925 was patched at 2026-09-04, 2026-09-07
altlinux: CVE-2026-63021 was patched at 2026-09-04, 2026-09-07
altlinux: CVE-2026-63792 was patched at 2026-09-04, 2026-09-07
altlinux: CVE-2026-66849 was patched at 2026-09-04, 2026-09-07
altlinux: CVE-2026-66853 was patched at 2026-09-04, 2026-09-07
altlinux: CVE-2026-66874 was patched at 2026-09-04, 2026-09-07
altlinux: CVE-2026-66877 was patched at 2026-09-04, 2026-09-07
altlinux: CVE-2026-67577 was patched at 2026-09-04, 2026-09-07
altlinux: CVE-2026-68546 was patched at 2026-09-02
altlinux: CVE-2026-68547 was patched at 2026-09-02
altlinux: CVE-2026-68957 was patched at 2026-09-04, 2026-09-07
altlinux: CVE-2026-68964 was patched at 2026-09-04, 2026-09-07
altlinux: CVE-2026-73278 was patched at 2026-08-27, 2026-08-29, 2026-09-04
altlinux: CVE-2026-73535 was patched at 2026-08-27, 2026-08-29, 2026-09-04
altlinux: CVE-2026-73539 was patched at 2026-08-27, 2026-08-29, 2026-09-04
altlinux: CVE-2026-73800 was patched at 2026-08-27, 2026-08-29, 2026-09-04
altlinux: CVE-2026-73804 was patched at 2026-08-27, 2026-08-29, 2026-09-04
altlinux: CVE-2026-73814 was patched at 2026-08-27, 2026-08-29, 2026-09-04
altlinux: CVE-2026-77679 was patched at 2026-09-12
altlinux: CVE-2026-77682 was patched at 2026-09-12
altlinux: CVE-2026-78433 was patched at 2026-09-04, 2026-09-07
debian: CVE-2024-58384 was patched at 2026-09-16
debian: CVE-2025-70291 was patched at 2026-09-16
debian: CVE-2025-70292 was patched at 2026-09-16
debian: CVE-2026-15264 was patched at 2026-09-16
debian: CVE-2026-15806 was patched at 2026-08-20
debian: CVE-2026-16288 was patched at 2026-09-16
debian: CVE-2026-16658 was patched at 2026-09-16
debian: CVE-2026-17495 was patched at 2026-09-16
debian: CVE-2026-17516 was patched at 2026-09-16
debian: CVE-2026-18054 was patched at 2026-09-16
debian: CVE-2026-18238 was patched at 2026-09-16
debian: CVE-2026-33606 was patched at 2026-09-16
debian: CVE-2026-38819 was patched at 2026-09-16
debian: CVE-2026-49275 was patched at 2026-09-16
debian: CVE-2026-50152 was patched at 2026-08-25
debian: CVE-2026-50624 was patched at 2026-09-16
debian: CVE-2026-52681 was patched at 2026-09-16
debian: CVE-2026-54258 was patched at 2026-09-16
debian: CVE-2026-56854 was patched at 2026-09-16
debian: CVE-2026-58581 was patched at 2026-09-16
debian: CVE-2026-58582 was patched at 2026-09-16
debian: CVE-2026-61402 was patched at 2026-09-16
debian: CVE-2026-61404 was patched at 2026-09-16
debian: CVE-2026-61405 was patched at 2026-09-16
debian: CVE-2026-61406 was patched at 2026-09-16
debian: CVE-2026-61476 was patched at 2026-09-16
debian: CVE-2026-61907 was patched at 2026-09-16
debian: CVE-2026-63109 was patched at 2026-09-16
debian: CVE-2026-63110 was patched at 2026-09-16
debian: CVE-2026-63320 was patched at 2026-09-16
debian: CVE-2026-63321 was patched at 2026-09-16
debian: CVE-2026-63322 was patched at 2026-09-16
debian: CVE-2026-63323 was patched at 2026-09-16
debian: CVE-2026-63337 was patched at 2026-08-20
debian: CVE-2026-63676 was patched at 2026-09-16
debian: CVE-2026-64846 was patched at 2026-08-25
debian: CVE-2026-65107 was patched at 2026-09-09, 2026-09-16
debian: CVE-2026-65108 was patched at 2026-09-09, 2026-09-16
debian: CVE-2026-65109 was patched at 2026-09-09, 2026-09-16
debian: CVE-2026-65138 was patched at 2026-09-09, 2026-09-16
debian: CVE-2026-65139 was patched at 2026-09-09, 2026-09-16
debian: CVE-2026-65140 was patched at 2026-09-09, 2026-09-16
debian: CVE-2026-65165 was patched at 2026-09-09, 2026-09-16
debian: CVE-2026-65611 was patched at 2026-08-25
debian: CVE-2026-65612 was patched at 2026-08-25
debian: CVE-2026-65928 was patched at 2026-09-16
debian: CVE-2026-65929 was patched at 2026-09-16
debian: CVE-2026-66022 was patched at 2026-09-16
debian: CVE-2026-68546 was patched at 2026-09-16
debian: CVE-2026-68547 was patched at 2026-09-16
debian: CVE-2026-70652 was patched at 2026-08-25
debian: CVE-2026-70653 was patched at 2026-08-25
debian: CVE-2026-71196 was patched at 2026-09-16
debian: CVE-2026-71197 was patched at 2026-09-16
debian: CVE-2026-71223 was patched at 2026-09-16
debian: CVE-2026-72818 was patched at 2026-08-25
debian: CVE-2026-72847 was patched at 2026-08-25
debian: CVE-2026-74994 was patched at 2026-09-16
debian: CVE-2026-75421 was patched at 2026-09-16
debian: CVE-2026-75758 was patched at 2026-09-16
debian: CVE-2026-76878 was patched at 2026-08-25
debian: CVE-2026-77159 was patched at 2026-09-16
debian: CVE-2026-77682 was patched at 2026-08-25
debian: CVE-2026-78408 was patched at 2026-09-16
debian: CVE-2026-78409 was patched at 2026-09-16
debian: CVE-2026-79603 was patched at 2026-09-16
debian: CVE-2026-79604 was patched at 2026-09-16
debian: CVE-2026-79619 was patched at 2026-08-24, 2026-09-16
debian: CVE-2026-79699 was patched at 2026-09-16
debian: CVE-2026-80182 was patched at 2026-09-01, 2026-09-16
debian: CVE-2026-80183 was patched at 2026-09-01, 2026-09-16
debian: CVE-2026-80184 was patched at 2026-09-01, 2026-09-16
debian: CVE-2026-80220 was patched at 2026-09-16
debian: CVE-2026-81500 was patched at 2026-09-16
debian: CVE-2026-81501 was patched at 2026-09-16
debian: CVE-2026-82049 was patched at 2026-09-16
debian: CVE-2026-82373 was patched at 2026-09-16
debian: CVE-2026-82374 was patched at 2026-09-16
debian: CVE-2026-82797 was patched at 2026-09-16
debian: CVE-2026-84471 was patched at 2026-09-16
debian: CVE-2026-84828 was patched at 2026-09-16
debian: CVE-2026-85013 was patched at 2026-09-16
debian: CVE-2026-85218 was patched at 2026-09-16
debian: CVE-2026-86231 was patched at 2026-09-16
debian: CVE-2026-87735 was patched at 2026-09-16
debian: CVE-2026-87737 was patched at 2026-09-16
debian: CVE-2026-87766 was patched at 2026-08-27, 2026-09-16
debian: CVE-2026-87853 was patched at 2026-09-16
debian: CVE-2026-88265 was patched at 2026-09-16
debian: CVE-2026-88859 was patched at 2026-09-16
debian: CVE-2026-89085 was patched at 2026-09-16
debian: CVE-2026-89087 was patched at 2026-09-16
debian: CVE-2026-89088 was patched at 2026-09-16
debian: CVE-2026-89259 was patched at 2026-09-16
debian: CVE-2026-90460 was patched at 2026-09-16
debian: CVE-2026-90461 was patched at 2026-09-16
debian: CVE-2026-90467 was patched at 2026-09-16
debian: CVE-2026-90472 was patched at 2026-09-16
debian: CVE-2026-90773 was patched at 2026-09-16
debian: CVE-2026-91991 was patched at 2026-09-16
debian: CVE-2026-92238 was patched at 2026-09-16, 2026-09-17
debian: CVE-2026-92239 was patched at 2026-09-16, 2026-09-17
oraclelinux: CVE-2026-61402 was patched at 2026-09-03
oraclelinux: CVE-2026-63110 was patched at 2026-09-03
oraclelinux: CVE-2026-63320 was patched at 2026-09-03
oraclelinux: CVE-2026-65928 was patched at 2026-09-03
oraclelinux: CVE-2026-65929 was patched at 2026-09-03
oraclelinux: CVE-2026-66022 was patched at 2026-09-03
oraclelinux: CVE-2026-69159 was patched at 2026-09-01
oraclelinux: CVE-2026-74259 was patched at 2026-09-04
redhat: CVE-2026-15809 was patched at 2026-08-25, 2026-09-01, 2026-09-02, 2026-09-10
redos: CVE-2026-18654 was patched at 2026-09-07
redos: CVE-2026-58438 was patched at 2026-09-02
ubuntu: CVE-2026-79619 was patched at 2026-08-31, 2026-09-16
ubuntu: CVE-2026-85498 was patched at 2026-09-15, 2026-09-16
debian: CVE-2026-84962 was patched at 2026-09-16
debian: CVE-2026-57222 was patched at 2026-09-16
debian: CVE-2026-57229 was patched at 2026-09-16
debian: CVE-2026-89258 was patched at 2026-09-16
debian: CVE-2026-84267 was patched at 2026-09-16
debian: CVE-2026-47887 was patched at 2026-09-16
debian: CVE-2025-71405 was patched at 2026-08-25
debian: CVE-2026-53683 was patched at 2026-09-16
debian: CVE-2026-55185 was patched at 2026-08-25