7.2

CVSS3.1

CVE-2024-51347 - Buffer Overflow in LSC Smart Indoor IP Camera ONVIF Time Zone Configuration

A buffer overflow vulnerability in the dgiot binary in LSC Smart Indoor IP Camera V7.6.32. The flaw exists in the handling of the Time Zone (TZ) parameter within the ONVIF configuration interface. The time zone (TZ) parameter does not have its length properly validated before being copied into a fi…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 26, 2026, 11:51 a.m.

9.8

CVSS3.1

CVE-2026-26832 - node‑tesseract‑ocr OS Command Injection via Unsanitized File Path

node-tesseract-ocr is an npm package that provides a Node.js wrapper for Tesseract OCR. In all versions through 2.2.1, the recognize() function in src/index.js is vulnerable to OS Command Injection. The file path parameter is concatenated into a shell command string and passed to child_process.exec…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 26, 2026, 3:13 p.m.

7.0

CVSS3.1

CVE-2026-23375 - mm: thp: deny THP for files on anonymous inodes

In the Linux kernel, the following vulnerability has been resolved: mm: thp: deny THP for files on anonymous inodes file_thp_enabled() incorrectly allows THP for files on anonymous inodes (e.g. guest_memfd and secretmem). These files are created via alloc_file_pseudo(), which does not call get_wr…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 26, 2026, 11:43 a.m.

5.5

CVSS3.1

CVE-2026-23357 - can: mcp251x: fix deadlock in error path of mcp251x_open

In the Linux kernel, the following vulnerability has been resolved: can: mcp251x: fix deadlock in error path of mcp251x_open The mcp251x_open() function call free_irq() in its error path with the mpc_lock mutex held. But if an interrupt already occurred the interrupt handler will be waiting for t…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 27, 2026, 9:49 a.m.

5.5

CVSS3.1

CVE-2026-23355 - ata: libata: cancel pending work after clearing deferred_qc

In the Linux kernel, the following vulnerability has been resolved: ata: libata: cancel pending work after clearing deferred_qc Syzbot reported a WARN_ON() in ata_scsi_deferred_qc_work(), caused by ap->ops->qc_defer() returning non-zero before issuing the deferred qc. ata_scsi_schedule_deferred_…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 27, 2026, 9:49 a.m.

0.0

CVE-2026-23322 - ipmi: Fix use-after-free and list corruption on sender error

In the Linux kernel, the following vulnerability has been resolved: ipmi: Fix use-after-free and list corruption on sender error The analysis from Breno: When the SMI sender returns an error, smi_work() delivers an error response but then jumps back to restart without cleaning up properly: 1. i…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 29, 2026, 8:28 p.m.

5.5

CVSS3.1

CVE-2026-23321 - mptcp: pm: in-kernel: always mark signal+subflow endp as used

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: in-kernel: always mark signal+subflow endp as used Syzkaller managed to find a combination of actions that was generating this warning: msk->pm.local_addr_used == 0 WARNING: net/mptcp/pm_kernel.c:1071 at __mark_su…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 27, 2026, 9:49 a.m.

5.5

CVSS3.1

CVE-2026-23329 - libie: don't unroll if fwlog isn't supported

In the Linux kernel, the following vulnerability has been resolved: libie: don't unroll if fwlog isn't supported The libie_fwlog_deinit() function can be called during driver unload even when firmware logging was never properly initialized. This led to call trace: [ 148.576156] Oops: Oops: 0000…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 27, 2026, 9:49 a.m.

0.0

CVE-2026-23309 - tracing: Add NULL pointer check to trigger_data_free()

In the Linux kernel, the following vulnerability has been resolved: tracing: Add NULL pointer check to trigger_data_free() If trigger_data_alloc() fails and returns NULL, event_hist_trigger_parse() jumps to the out_free error path. While kfree() safely handles a NULL pointer, trigger_data_free() …

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 26, 2026, 12:16 p.m.

0.0

CVE-2026-23305 - accel/rocket: fix unwinding in error path in rocket_probe

In the Linux kernel, the following vulnerability has been resolved: accel/rocket: fix unwinding in error path in rocket_probe When rocket_core_init() fails (as could be the case with EPROBE_DEFER), we need to properly unwind by decrementing the counter we just incremented and if this is the first…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 27, 2026, 9:50 a.m.
Total resulsts: 341475
Page 154 of 34,148
Β« previous page Β» next page
Filters