0.0

CVE-2026-43288 - ext4: move ext4_percpu_param_init() before ext4_mb_init()

In the Linux kernel, the following vulnerability has been resolved: ext4: move ext4_percpu_param_init() before ext4_mb_init() When running `kvm-xfstests -c ext4/1k -C 1 generic/383` with the `DOUBLE_CHECK` macro defined, the following panic is triggered: =========================================…

πŸ“… Published: May 8, 2026, 1:11 p.m. πŸ”„ Last Modified: May 8, 2026, 1:11 p.m.

8.1

CVSS3.1

CVE-2026-41491 - Dapr: Service Invocation path traversal ACL bypass

Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. From versions 1.3.0 to before 1.15.14, 1.16.0-rc.1 to before 1.16.14, and 1.17.0-rc.1 to before 1.17.5, a vulnerability has been found in Dapr that allows bypassing access control policies for ser…

πŸ“… Published: May 8, 2026, 1:11 p.m. πŸ”„ Last Modified: May 8, 2026, 3 p.m.

0.0

CVE-2026-43287 - drm: Account property blob allocations to memcg

In the Linux kernel, the following vulnerability has been resolved: drm: Account property blob allocations to memcg DRM_IOCTL_MODE_CREATEPROPBLOB allows userspace to allocate arbitrary-sized property blobs backed by kernel memory. Currently, the blob data allocation is not accounted to the alloc…

πŸ“… Published: May 8, 2026, 1:11 p.m. πŸ”„ Last Modified: May 8, 2026, 1:11 p.m.

0.0

CVE-2026-43286 - mm/hugetlb: restore failed global reservations to subpool

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: restore failed global reservations to subpool Commit a833a693a490 ("mm: hugetlb: fix incorrect fallback for subpool") fixed an underflow error for hstate->resv_huge_pages caused by incorrectly attributing globally req…

πŸ“… Published: May 8, 2026, 1:11 p.m. πŸ”„ Last Modified: May 8, 2026, 1:11 p.m.

0.0

CVE-2026-43285 - mm/slab: do not access current->mems_allowed_seq if !allow_spin

In the Linux kernel, the following vulnerability has been resolved: mm/slab: do not access current->mems_allowed_seq if !allow_spin Lockdep complains when get_from_any_partial() is called in an NMI context, because current->mems_allowed_seq is seqcount_spinlock_t and not NMI-safe: ============…

πŸ“… Published: May 8, 2026, 1:11 p.m. πŸ”„ Last Modified: May 8, 2026, 1:11 p.m.

0.0

CVE-2025-71299 - spi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing

In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing The recent refactoring of where runtime PM is enabled done in commit f1eb4e792bb1 ("spi: spi-cadence-quadspi: Enable pm runtime earlier to avoid imbalance…

πŸ“… Published: May 8, 2026, 1:11 p.m. πŸ”„ Last Modified: May 8, 2026, 3:45 p.m.

0.0

CVE-2025-71298 - drm/tests: shmem: Hold reservation lock around madvise

In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around madvise Acquire and release the GEM object's reservation lock around calls to the object's madvide operation. The tests use drm_gem_shmem_madvise_locked(), which led to errors such a…

πŸ“… Published: May 8, 2026, 1:11 p.m. πŸ”„ Last Modified: May 8, 2026, 1:11 p.m.

0.0

CVE-2025-71297 - wifi: rtw88: 8822b: Avoid WARNING in rtw8822b_config_trx_mode()

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: 8822b: Avoid WARNING in rtw8822b_config_trx_mode() rtw8822b_set_antenna() can be called from userspace when the chip is powered off. In that case a WARNING is triggered in rtw8822b_config_trx_mode() because trying to…

πŸ“… Published: May 8, 2026, 1:11 p.m. πŸ”„ Last Modified: May 8, 2026, 3:45 p.m.

0.0

CVE-2025-71296 - drm/tests: shmem: Hold reservation lock around purge

In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around purge Acquire and release the GEM object's reservation lock around calls to the object's purge operation. The tests use drm_gem_shmem_purge_locked(), which led to errors such as show…

πŸ“… Published: May 8, 2026, 1:11 p.m. πŸ”„ Last Modified: May 8, 2026, 1:11 p.m.

8.7

CVSS4.0

CVE-2026-41423 - Angular: SSRF via protocol-relative and backslash URLs in Angular Platform-Server

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.21, 20.3.19, 21.2.9, and 22.0.0-next.8, a Server-Side Request Forgery (SSRF) vulnerability exists in @angular/platform-server due to improper ha…

πŸ“… Published: May 8, 2026, 1:06 p.m. πŸ”„ Last Modified: May 8, 2026, 3 p.m.
Total resulsts: 349182
Page 25 of 34,919
Β« previous page Β» next page
Filters