0.0

CVE-2026-42477 -

A heap-based out-of-bounds read vulnerability in RWObj_Reader::read in the OBJ file parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows user-assisted attackers to cause a denial of service or obtain sensitive information by persuading a victim to open a crafted OBJ file. The issue occurs bec…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 1, 2026, 2:54 p.m.

7.8

CVSS3.1

CVE-2026-43056 - net: mana: fix use-after-free in add_adev() error path

In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in add_adev() error path If auxiliary_device_add() fails, add_adev() jumps to add_fail and calls auxiliary_device_uninit(adev). The auxiliary device has its release callback set to adev_release(), w…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 7:02 p.m.

0.0

CVE-2026-43004 - spi: stm32-ospi: Fix resource leak in remove() callback

In the Linux kernel, the following vulnerability has been resolved: spi: stm32-ospi: Fix resource leak in remove() callback The remove() callback returned early if pm_runtime_resume_and_get() failed, skipping the cleanup of spi controller and other resources. Remove the early return so cleanup c…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 1, 2026, 7 p.m.

5.5

CVSS3.1

CVE-2026-42478 - Denial of Service via Crafted VRML File in Open CASCADE V8_0_0_rc5

An issue was discovered in VrmlData_IndexedFaceSet::TShape in the VRML V2.0 parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows attackers to cause a denial of service via a crafted VRML file. The issue occurs because malformed VRML input can trigger dereference of a corrupt or unvalidated po…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 2, 2026, 8:15 a.m.

7.8

CVSS3.1

CVE-2026-31695 - wifi: virt_wifi: remove SET_NETDEV_DEV to avoid use-after-free

In the Linux kernel, the following vulnerability has been resolved: wifi: virt_wifi: remove SET_NETDEV_DEV to avoid use-after-free Currently we execute `SET_NETDEV_DEV(dev, &priv->lowerdev->dev)` for the virt_wifi net devices. However, unregistering a virt_wifi device in netdev_run_todo() can hap…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 6, 2026, 7:19 p.m.

7.5

CVSS3.1

CVE-2026-42467 - Denial of Service via Crafted CAN Frame on J1939 Bus

An issue was discovered in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939_Read_Binary_Data_Transfer_DM16 causing a denial of service via crafted CAN frame on the J1939 bus.

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 4, 2026, 7:44 p.m.

7.0

CVSS3.1

CVE-2026-43050 - atm: lec: fix use-after-free in sock_def_readable()

In the Linux kernel, the following vulnerability has been resolved: atm: lec: fix use-after-free in sock_def_readable() A race condition exists between lec_atm_close() setting priv->lecd to NULL and concurrent access to priv->lecd in send_to_lecd(), lec_handle_bridge(), and lec_atm_send(). When t…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 6:21 p.m.

5.5

CVSS3.1

CVE-2026-43043 - crypto: af-alg - fix NULL pointer dereference in scatterwalk

In the Linux kernel, the following vulnerability has been resolved: crypto: af-alg - fix NULL pointer dereference in scatterwalk The AF_ALG interface fails to unmark the end of a Scatter/Gather List (SGL) when chaining a new af_alg_tsgl structure. If a sendmsg() fills an SGL exactly to MAX_SGL_EN…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 1, 2026, 7 p.m.

5.5

CVSS3.1

CVE-2026-43041 - net: qrtr: replace qrtr_tx_flow radix_tree with xarray to fix memory leak

In the Linux kernel, the following vulnerability has been resolved: net: qrtr: replace qrtr_tx_flow radix_tree with xarray to fix memory leak __radix_tree_create() allocates and links intermediate nodes into the tree one by one. If a subsequent allocation fails, the already-linked nodes remain in…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 1, 2026, 9 p.m.

7.1

CVSS3.1

CVE-2026-43042 - mpls: add seqcount to protect the platform_label{,s} pair

In the Linux kernel, the following vulnerability has been resolved: mpls: add seqcount to protect the platform_label{,s} pair The RCU-protected codepaths (mpls_forward, mpls_dump_routes) can have an inconsistent view of platform_labels vs platform_label in case of a concurrent resize (resize_plat…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 3, 2026, 8:45 a.m.
Total resulsts: 349182
Page 165 of 34,919
Β« previous page Β» next page
Filters