CVE-2026-57965
- EPSS 0.11%
- Veröffentlicht 29.06.2026 07:53:39
- Zuletzt bearbeitet 08.07.2026 03:36:51
A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This vulnerability can lead to a heap buffer overflow, causing the spice-vdagent daemon to crash and resu...
CVE-2026-53153
- EPSS 0.1%
- Veröffentlicht 25.06.2026 08:38:37
- Zuletzt bearbeitet 02.09.2026 13:18:00
In the Linux kernel, the following vulnerability has been resolved: mm/list_lru: drain before clearing xarray entry on reparent memcg_reparent_list_lrus() clears the dying memcg's xarray entry with xas_store(&xas, NULL) before reparenting its per-n...
CVE-2026-53145
- EPSS 0.1%
- Veröffentlicht 25.06.2026 08:38:32
- Zuletzt bearbeitet 15.07.2026 01:16:29
In the Linux kernel, the following vulnerability has been resolved: drm/gem: Try to fix change_handle ioctl, attempt 4 [airlied: just added some comments on how to reenable] On-list because the cat is out of the bag and we're clearly not good enoug...
CVE-2026-53009
- EPSS 0.13%
- Veröffentlicht 24.06.2026 16:29:20
- Zuletzt bearbeitet 09.09.2026 13:20:27
In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points to it and is marke...
CVE-2026-53006
- EPSS 0.4%
- Veröffentlicht 24.06.2026 16:29:17
- Zuletzt bearbeitet 16.09.2026 13:18:01
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching saddr and daddr before pskb_pull() is problematic since skb->head can change. Remove these temporary variables: - We only access &i...
CVE-2026-53002
- EPSS 0.35%
- Veröffentlicht 24.06.2026 16:29:14
- Zuletzt bearbeitet 10.09.2026 13:20:26
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Replace it with scnprintf, the buffer sizes are expected to be large enough to hold the result, no need for snprintf+overflow check. Inc...
CVE-2026-53000
- EPSS 0.13%
- Veröffentlicht 24.06.2026 16:29:12
- Zuletzt bearbeitet 17.09.2026 12:18:24
In the Linux kernel, the following vulnerability has been resolved: netfilter: nat: use kfree_rcu to release ops Florian Westphal says: "Historically this is not an issue, even for normal base hooks: the data path doesn't use the original nf_hook_...
CVE-2026-12892
- EPSS 0.12%
- Veröffentlicht 23.06.2026 19:53:23
- Zuletzt bearbeitet 06.07.2026 18:02:05
A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the ...
CVE-2026-12891
- EPSS 0.27%
- Veröffentlicht 23.06.2026 19:53:21
- Zuletzt bearbeitet 01.07.2026 18:02:08
A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a crafted aspect ratio indicator value, the H.266 parser performs an out-of-bounds read of up to 8 bytes from adjacent memory. This fla...
CVE-2026-11820
- EPSS 0.29%
- Veröffentlicht 23.06.2026 19:53:19
- Zuletzt bearbeitet 01.07.2026 18:27:53
A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the Vonage/Nexmo SMS API by encoding API credentials (api_key and api_secret) into URL query parameters and sending them via GET reque...