5.5

CVSS3.1

CVE-2026-31556 - xfs: scrub: unlock dquot before early return in quota scrub

In the Linux kernel, the following vulnerability has been resolved: xfs: scrub: unlock dquot before early return in quota scrub xchk_quota_item can return early after calling xchk_fblock_process_error. When that helper returns false, the function returned immediately without dropping dq->q_qlock,…

📅 Published: April 24, 2026, midnight 🔄 Last Modified: April 27, 2026, 8:14 p.m.

5.5

CVSS3.1

CVE-2026-31550 - pmdomain: bcm: bcm2835-power: Increase ASB control timeout

In the Linux kernel, the following vulnerability has been resolved: pmdomain: bcm: bcm2835-power: Increase ASB control timeout The bcm2835_asb_control() function uses a tight polling loop to wait for the ASB bridge to acknowledge a request. During intensive workloads, this handshake intermittentl…

📅 Published: April 24, 2026, midnight 🔄 Last Modified: April 27, 2026, 8:15 p.m.

5.5

CVSS3.1

CVE-2026-31549 - i2c: cp2615: fix serial string NULL-deref at probe

In the Linux kernel, the following vulnerability has been resolved: i2c: cp2615: fix serial string NULL-deref at probe The cp2615 driver uses the USB device serial string as the i2c adapter name but does not make sure that the string exists. Verify that the device has a serial number before acce…

📅 Published: April 24, 2026, midnight 🔄 Last Modified: April 27, 2026, 8:15 p.m.

5.5

CVSS3.1

CVE-2026-31547 - drm/xe: Fix missing runtime PM reference in ccs_mode_store

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix missing runtime PM reference in ccs_mode_store ccs_mode_store() calls xe_gt_reset() which internally invokes xe_pm_runtime_get_noresume(). That function requires the caller to already hold an outer runtime PM referenc…

📅 Published: April 24, 2026, midnight 🔄 Last Modified: April 27, 2026, 8:16 p.m.

7.5

CVSS3.1

CVE-2026-31539 - smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available

In the Linux kernel, the following vulnerability has been resolved: smb: smbdirect: introduce smbdirect_socket.recv_io.credits.available The logic off managing recv credits by counting posted recv_io and granted credits is racy. That's because the peer might already consumed a credit, but betwee…

📅 Published: April 24, 2026, midnight 🔄 Last Modified: April 27, 2026, 2:03 p.m.

7.5

CVSS3.1

CVE-2026-31538 - smb: server: make use of smbdirect_socket.recv_io.credits.available

In the Linux kernel, the following vulnerability has been resolved: smb: server: make use of smbdirect_socket.recv_io.credits.available The logic off managing recv credits by counting posted recv_io and granted credits is racy. That's because the peer might already consumed a credit, but between…

📅 Published: April 24, 2026, midnight 🔄 Last Modified: April 27, 2026, 7:15 p.m.

7.2

CVSS4.0

CVE-2026-40623 - SenseLive X3050 Missing Authorization

A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameters to be modified without sufficient validation and safety controls. Due to inadequate enforcement of constraints on sensitive functions, parameters such as IP addressing, watchdog…

📅 Published: April 23, 2026, 11:58 p.m. 🔄 Last Modified: April 24, 2026, 6:18 p.m.

6.1

CVSS3.1

CVE-2026-29050 - melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses

melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, an attacker who can influence a melange configuration file — for example through pull-request-driven CI or build-as-a-service scenarios — could set `pipeline[].uses` to a …

📅 Published: April 23, 2026, 11:58 p.m. 🔄 Last Modified: April 25, 2026, 1:38 a.m.

6.9

CVSS4.0

CVE-2026-40431 - SenseLive X3050 Cleartext transmission of sensitive information

A vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unencrypted HTTP for all administrative communication. Because management traffic, including authentication attempts and configuration data, is transmitted in cleartext, an attacker with access to the same n…

📅 Published: April 23, 2026, 11:56 p.m. 🔄 Last Modified: April 24, 2026, 6:18 p.m.

9.2

CVSS4.0

CVE-2026-27843 - SenseLive X3050 Missing authentication for critical function

A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be modified without sufficient authentication or server-side validation. By applying unsupported or disruptive values to recovery mechanisms and network settings, an attacker can in…

📅 Published: April 23, 2026, 11:54 p.m. 🔄 Last Modified: April 28, 2026, 7:32 p.m.
Total resulsts: 347066
Page 83 of 34,707
« previous page » next page
Filters