7.0

CVSS3.1

CVE-2026-31624 - HID: core: clamp report_size in s32ton() to avoid undefined shift

In the Linux kernel, the following vulnerability has been resolved: HID: core: clamp report_size in s32ton() to avoid undefined shift s32ton() shifts by n-1 where n is the field's report_size, a value that comes directly from a HID device. The HID parser bounds report_size only to <= 256, so a b…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 1:57 p.m.

7.0

CVSS3.1

CVE-2026-31617 - usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb()

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb() The block_len read from the host-supplied NTB header is checked against ntb_max but has no lower bound. When block_len is smaller than opts->ndp_size, the bounds …

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 1:56 p.m.

8.8

CVSS3.1

CVE-2026-31558 - LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust kvm_get_vcpu_by_cpuid() takes a cpuid parameter whose type is int, so cpuid can be negative. Let kvm_get_vcpu_by_cpuid() return NULL for this case so as to make it more rob…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 2:04 p.m.

0.0

CVE-2026-31602 - ALSA: ctxfi: Limit PTP to a single page

In the Linux kernel, the following vulnerability has been resolved: ALSA: ctxfi: Limit PTP to a single page Commit 391e69143d0a increased CT_PTP_NUM from 1 to 4 to support 256 playback streams, but the additional pages are not used by the card correctly. The CT20K2 hardware already has multiple V…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 1:56 p.m.

7.0

CVSS3.1

CVE-2026-31583 - media: em28xx: fix use-after-free in em28xx_v4l2_open()

In the Linux kernel, the following vulnerability has been resolved: media: em28xx: fix use-after-free in em28xx_v4l2_open() em28xx_v4l2_open() reads dev->v4l2 without holding dev->lock, creating a race with em28xx_v4l2_init()'s error path and em28xx_v4l2_fini(), both of which free the em28xx_v4l2…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 1:56 p.m.

4

CVSS3.1

CVE-2026-42095 -

bookserver in KDE Arianna before 26.04.1 allows attackers to read files over a socket connection by guessing a URL.

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 24, 2026, 5:55 p.m.

5.3

CVSS3.1

CVE-2026-31052 -

An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Checkout Authentication Flow component

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 24, 2026, 4:03 p.m.

9.8

CVSS3.1

CVE-2026-31659 - batman-adv: reject oversized global TT response buffers

In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject oversized global TT response buffers batadv_tt_prepare_tvlv_global_data() builds the allocation length for a global TT response in 16-bit temporaries. When a remote originator advertises a large enough global T…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 2:04 p.m.

9.8

CVSS3.1

CVE-2026-31669 - mptcp: fix slab-use-after-free in __inet_lookup_established

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix slab-use-after-free in __inet_lookup_established The ehash table lookups are lockless and rely on SLAB_TYPESAFE_BY_RCU to guarantee socket memory stability during RCU read-side critical sections. Both tcp_prot and tcpv…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 2:04 p.m.

7.8

CVSS3.1

CVE-2026-31641 - rxrpc: Fix RxGK token loading to check bounds

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix RxGK token loading to check bounds rxrpc_preparse_xdr_yfs_rxgk() reads the raw key length and ticket length from the XDR token as u32 values and passes each through round_up(x, 4) before using the rounded value for val…

πŸ“… Published: April 24, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 2:04 p.m.
Total resulsts: 347056
Page 78 of 34,706
Β« previous page Β» next page
Filters