7.0

CVSS3.1

CVE-2026-23458 - netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct()

In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() ctnetlink_dump_exp_ct() stores a conntrack pointer in cb->data for the netlink dump callback ctnetlink_exp_ct_dump_table(), but drops the conntrack reference imm…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

0.0

CVE-2026-23459 - ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS

In the Linux kernel, the following vulnerability has been resolved: ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS Blamed commits forgot that vxlan/geneve use udp_tunnel[6]_xmit_skb() which call iptunnel_xmit_stats(). iptunnel_xmit_stats() was assuming tunnels were only using …

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

0.0

CVE-2025-59709 - Directory Traversal Allowing Super User File Read in Biztalk360

An issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read by the server, a Super User attacker is able to read files on the system and/or coerce an authentication from the service, aka Directory Traversal.

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 6, 2026, 9:23 p.m.

7.0

CVSS3.1

CVE-2026-31393 - Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access l2cap_information_rsp() checks that cmd_len covers the fixed l2cap_info_rsp header (type + result, 4 bytes) but then reads rsp->data without verifying that th…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:16 a.m.

5.5

CVSS3.1

CVE-2026-23421 - drm/xe/configfs: Free ctx_restore_mid_bb in release

In the Linux kernel, the following vulnerability has been resolved: drm/xe/configfs: Free ctx_restore_mid_bb in release ctx_restore_mid_bb memory is allocated in wa_bb_store(), but xe_config_device_release() only frees ctx_restore_post_bb. Free ctx_restore_mid_bb[0].cs as well to avoid leaking t…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:54 a.m.

5.5

CVSS3.1

CVE-2026-23444 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure ieee80211_tx_prepare_skb() has three error paths, but only two of them free the skb. The first error path (ieee80211_tx_prepare() returning TX_DROP) does not f…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

0.0

CVE-2026-23424 - accel/amdxdna: Validate command buffer payload count

In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Validate command buffer payload count The count field in the command header is used to determine the valid payload size. Verify that the valid payload does not exceed the remaining buffer space.

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:54 a.m.

8.3

CVSS3.1

CVE-2025-59711 - Directory Traversal Leading to Unauthorized File Write in Biztalk360

An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in an upload mechanism, an authenticated attacker is able to write files outside of the destination directory and/or coerce an authentication from the service, aka Directory Traversal.

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 6, 2026, 9:23 p.m.

5.5

CVSS3.1

CVE-2026-31390 - drm/xe: Fix memory leak in xe_vm_madvise_ioctl

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix memory leak in xe_vm_madvise_ioctl When check_bo_args_are_sane() validation fails, jump to the new free_vmas cleanup label to properly free the allocated resources. This ensures proper cleanup in this error path. (ch…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:17 a.m.

5.5

CVSS3.1

CVE-2026-31400 - sunrpc: fix cache_request leak in cache_release

In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix cache_request leak in cache_release When a reader's file descriptor is closed while in the middle of reading a cache_request (rp->offset != 0), cache_release() decrements the request's readers count but never checks w…

πŸ“… Published: April 3, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:16 a.m.
Total resulsts: 342654
Page 63 of 34,266
Β« previous page Β» next page
Filters