8.8

CVSS3.1

CVE-2026-31735 - iommupt: Fix short gather if the unmap goes into a large mapping

In the Linux kernel, the following vulnerability has been resolved: iommupt: Fix short gather if the unmap goes into a large mapping unmap has the odd behavior that it can unmap more than requested if the ending point lands within the middle of a large or contiguous IOPTE. In this case the gathe…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 3, 2026, 5:45 a.m.

8.8

CVSS3.1

CVE-2026-31773 - Bluetooth: SMP: derive legacy responder STK authentication from MITM state

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SMP: derive legacy responder STK authentication from MITM state The legacy responder path in smp_random() currently labels the stored STK as authenticated whenever pending_sec_level is BT_SECURITY_HIGH. That reflects w…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 3, 2026, 5:45 a.m.

7.8

CVSS3.1

CVE-2026-31768 - iio: adc: ti-adc161s626: use DMA-safe memory for spi_read()

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-adc161s626: use DMA-safe memory for spi_read() Add a DMA-safe buffer and use it for spi_read() instead of a stack memory. All SPI buffers must be DMA-safe. Since we only need up to 3 bytes, we just use a u8[] instea…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 3, 2026, 5:45 a.m.

7.1

CVSS3.1

CVE-2026-31766 - drm/amdgpu: validate doorbell_offset in user queue creation

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate doorbell_offset in user queue creation amdgpu_userq_get_doorbell_index() passes the user-provided doorbell_offset to amdgpu_doorbell_index_on_bar() without bounds checking. An arbitrarily large doorbell_offse…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 3, 2026, 5:45 a.m.

8.1

CVSS3.1

CVE-2026-31779 - wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler()

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler() The memcpy function assumes the dynamic array notif->matches is at least as large as the number of bytes to copy. Otherwise, results->matches…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 3, 2026, 5:45 a.m.

8.1

CVSS3.1

CVE-2026-43051 - HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq

In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq The wacom_intuos_bt_irq() function processes Bluetooth HID reports without sufficient bounds checking. A maliciously crafted short report can trigger an out-of-bounds read…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 3, 2026, 5:46 a.m.

7.8

CVSS3.1

CVE-2026-43047 - HID: multitouch: Check to ensure report responses match the request

In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: Check to ensure report responses match the request It is possible for a malicious (or clumsy) device to respond to a specific report's feature request using a completely different report ID. This can cause confu…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 3, 2026, 5:46 a.m.

7.8

CVSS3.1

CVE-2026-31782 - perf/x86: Fix potential bad container_of in intel_pmu_hw_config

In the Linux kernel, the following vulnerability has been resolved: perf/x86: Fix potential bad container_of in intel_pmu_hw_config Auto counter reload may have a group of events with software events present within it. The software event PMU isn't the x86_hybrid_pmu and a container_of operation i…

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 3, 2026, 5:45 a.m.

8.7

CVSS4.0

CVE-2026-7513 - UTT HiPER 1200GW formRemoteControl strcpy buffer overflow

A vulnerability has been found in UTT HiPER 1200GW up to 2.5.3-170306. The impacted element is the function strcpy of the file /goform/formRemoteControl. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

πŸ“… Published: April 30, 2026, 11:45 p.m. πŸ”„ Last Modified: May 4, 2026, 4:55 p.m.

8.7

CVSS4.0

CVE-2026-7512 - UTT HiPER 1200GW formUser strcpy buffer overflow

A flaw has been found in UTT HiPER 1200GW up to 2.5.3-1703. The affected element is the function strcpy of the file /goform/formUser. Executing a manipulation can lead to buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.

πŸ“… Published: April 30, 2026, 11:30 p.m. πŸ”„ Last Modified: April 30, 2026, 11:30 p.m.
Total resulsts: 348208
Page 83 of 34,821
Β« previous page Β» next page
Filters