7.5

CVSS3.1

CVE-2026-31719 - crypto: krb5enc - fix async decrypt skipping hash verification

In the Linux kernel, the following vulnerability has been resolved: crypto: krb5enc - fix async decrypt skipping hash verification krb5enc_dispatch_decrypt() sets req->base.complete as the skcipher callback, which is the caller's own completion handler. When the skcipher completes asynchronously,…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 6, 2026, 8:59 p.m.

7.1

CVSS3.1

CVE-2026-31707 - ksmbd: validate response sizes in ipc_validate_msg()

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate response sizes in ipc_validate_msg() ipc_validate_msg() computes the expected message size for each response type by adding (or multiplying) attacker-controlled fields from the daemon response to a fixed struct si…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 6, 2026, 8:26 p.m.

7.8

CVSS3.1

CVE-2026-43047 - HID: multitouch: Check to ensure report responses match the request

In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: Check to ensure report responses match the request It is possible for a malicious (or clumsy) device to respond to a specific report's feature request using a completely different report ID. This can cause confu…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 1:50 p.m.

5.5

CVSS3.1

CVE-2026-43045 - mshv: Fix error handling in mshv_region_pin

In the Linux kernel, the following vulnerability has been resolved: mshv: Fix error handling in mshv_region_pin The current error handling has two issues: First, pin_user_pages_fast() can return a short pin count (less than requested but greater than zero) when it cannot pin all requested pages.…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 2:04 p.m.

7.8

CVSS3.1

CVE-2026-43020 - Bluetooth: MGMT: validate LTK enc_size on load

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate LTK enc_size on load Load Long Term Keys stores the user-provided enc_size and later uses it to size fixed-size stack operations when replying to LE LTK requests. An enc_size larger than the 16-byte key …

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 8, 2026, 2:41 p.m.

5.5

CVSS3.1

CVE-2026-43054 - scsi: target: tcm_loop: Drain commands in target_reset handler

In the Linux kernel, the following vulnerability has been resolved: scsi: target: tcm_loop: Drain commands in target_reset handler tcm_loop_target_reset() violates the SCSI EH contract: it returns SUCCESS without draining any in-flight commands. The SCSI EH documentation (scsi_eh.rst) requires t…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 6:28 p.m.

7.8

CVSS3.1

CVE-2026-31747 - comedi: me4000: Fix potential overrun of firmware buffer

In the Linux kernel, the following vulnerability has been resolved: comedi: me4000: Fix potential overrun of firmware buffer `me4000_xilinx_download()` loads the firmware that was requested by `request_firmware()`. It is possible for it to overrun the source buffer because it blindly trusts the …

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 7:26 p.m.

5.5

CVSS3.1

CVE-2026-31738 - vxlan: validate ND option lengths in vxlan_na_create

In the Linux kernel, the following vulnerability has been resolved: vxlan: validate ND option lengths in vxlan_na_create vxlan_na_create() walks ND options according to option-provided lengths. A malformed option can make the parser advance beyond the computed option span or use a too-short sourc…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 6:58 p.m.

7.5

CVSS3.1

CVE-2026-31711 - smb: server: fix active_num_conn leak on transport allocation failure

In the Linux kernel, the following vulnerability has been resolved: smb: server: fix active_num_conn leak on transport allocation failure Commit 77ffbcac4e56 ("smb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection()") addressed the kthread_run() failure path. The earlier alloc_tra…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 6, 2026, 8:18 p.m.

7.8

CVSS3.1

CVE-2026-37525 - Privilege Escalation via Nullified Credentials in AGL app-framework-binder

AGL app-framework-binder (afb-daemon) through v19.90.0 contains a privilege escalation vulnerability in the supervision Do command. The on_supervision_call function in src/afb-supervision.c explicitly nullifies the request credentials by calling afb_context_change_cred(&xreq->context, NULL) before …

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 4, 2026, 7:44 p.m.
Total resulsts: 349182
Page 173 of 34,919
Β« previous page Β» next page
Filters