7.5

CVSS3.1

CVE-2026-43029 - mptcp: fix soft lockup in mptcp_recvmsg()

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix soft lockup in mptcp_recvmsg() syzbot reported a soft lockup in mptcp_recvmsg() [0]. When receiving data with MSG_PEEK | MSG_WAITALL flags, the skb is not removed from the sk_receive_queue. This causes sk_wait_data() …

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 3, 2026, 5:46 a.m.

7.5

CVSS3.1

CVE-2026-37530 - Stack Buffer Overflow in agl-service-can-low-level Enables Remote Code Execution via CAN Bus on 32-…

AGL agl-service-can-low-level thru 17.1.12 contains a stack buffer overflow in the uds-c library. The send_diagnostic_request function in uds.c allocates a 6-byte stack buffer (MAX_DIAGNOSTIC_PAYLOAD_SIZE=6) but copies up to 7 bytes (MAX_UDS_REQUEST_PAYLOAD_LENGTH=7) via memcpy at an offset of 1+pi…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 4, 2026, 7:44 p.m.

7.5

CVSS3.1

CVE-2026-42485 - Stack Buffer Overflow in AGL agl-service-can-low-level UDS Library Enables Remote Code Execution on…

AGL agl-service-can-low-level contains a stack buffer overflow in the uds-c library. The send_diagnostic_request function in uds.c allocates a 6-byte stack buffer (MAX_DIAGNOSTIC_PAYLOAD_SIZE=6) but copies up to 7 bytes (MAX_UDS_REQUEST_PAYLOAD_LENGTH=7) via memcpy at an offset of 1+pid_length (2-3…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 4, 2026, 7:44 p.m.

6.1

CVSS3.1

CVE-2025-69606 -

Cross-Site Scripting (XSS) vulnerability was discovered in the GSVoIP web panel version 2.0.90. The `msg` parameter in the `/painel/gateways.php/error` endpoint does not properly sanitize user-supplied input, allowing attackers to inject arbitrary JavaScript into the HTML response. A remote attacke…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 4, 2026, 7:45 p.m.

0.0

CVE-2026-31785 - drm/xe/xe_pagefault: Disallow writes to read-only VMAs

In the Linux kernel, the following vulnerability has been resolved: drm/xe/xe_pagefault: Disallow writes to read-only VMAs The page fault handler should reject write/atomic access to read only VMAs. Add code to handle this in xe_pagefault_service after the VMA lookup. v2: - Apply max line lengt…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 1, 2026, 11:30 p.m.

9.8

CVSS3.1

CVE-2026-37531 - Archive Extraction Path Traversal with TOCTOU in Automotive Linux Widget Installation

AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the widget installation flow. The is_valid_filename function in wgtpkg-zip.c validates ZIP entry names but does not check for dot notation directory trave…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 4, 2026, 7:44 p.m.

7.8

CVSS3.1

CVE-2026-31700 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd()

In the Linux kernel, the following vulnerability has been resolved: net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() In tpacket_snd(), when PACKET_VNET_HDR is enabled, vnet_hdr points directly into the mmap'd TX ring buffer shared with userspace. The kernel validates the header via…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 6, 2026, 7:01 p.m.

9.8

CVSS3.1

CVE-2026-43037 - ip6_tunnel: clear skb2->cb[] in ip4ip6_err()

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the IPv6 receive path as struct inet6_skb_parm. icmp_send() passes …

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 4, 2026, 8 p.m.

5.5

CVSS3.1

CVE-2026-31721 - usb: gadget: f_hid: move list and spinlock inits from bind to alloc

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_hid: move list and spinlock inits from bind to alloc There was an issue when you did the following: - setup and bind an hid gadget - open /dev/hidg0 - use the resulting fd in EPOLL_CTL_ADD - unbind the UDC - bind t…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 6, 2026, 8:56 p.m.

9.8

CVSS3.1

CVE-2026-31705 - ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment smb2_get_ea() applies 4-byte alignment padding via memset() after writing each EA entry. The bounds check on buf_free_len is performed before the value memcpy, but the …

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 3, 2026, 8 a.m.
Total resulsts: 349182
Page 174 of 34,919
Β« previous page Β» next page
Filters