5.5

CVSS3.1

CVE-2026-23286 - atm: lec: fix null-ptr-deref in lec_arp_clear_vccs

In the Linux kernel, the following vulnerability has been resolved: atm: lec: fix null-ptr-deref in lec_arp_clear_vccs syzkaller reported a null-ptr-deref in lec_arp_clear_vccs(). This issue can be easily reproduced using the syzkaller reproducer. In the ATM LANE (LAN Emulation) module, the same…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 9:16 a.m.

5.5

CVSS3.1

CVE-2026-23282 - smb: client: fix oops due to uninitialised var in smb2_unlink()

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix oops due to uninitialised var in smb2_unlink() If SMB2_open_init() or SMB2_close_init() fails (e.g. reconnect), the iovs set @rqst will be left uninitialised, hence calling SMB2_open_free(), SMB2_close_free() or …

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:03 a.m.

0.0

CVE-2026-23281 - wifi: libertas: fix use-after-free in lbs_free_adapter()

In the Linux kernel, the following vulnerability has been resolved: wifi: libertas: fix use-after-free in lbs_free_adapter() The lbs_free_adapter() function uses timer_delete() (non-synchronous) for both command_timer and tx_lockup_timer before the structure is freed. This is incorrect because ti…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 9:16 a.m.

7.8

CVSS3.1

CVE-2026-23280 - accel/amdxdna: Prevent ubuf size overflow

In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Prevent ubuf size overflow The ubuf size calculation may overflow, resulting in an undersized allocation and possible memory corruption. Use check_add_overflow() helpers to validate the size calculation before all…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:03 a.m.

9.8

CVSS3.1

CVE-2025-70888 - osslsigncode: Osslsigncode: Remote privilege escalation

An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the osslsigncode.c component

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 9:39 a.m.

5.5

CVSS3.1

CVE-2026-23289 - IB/mthca: Add missed mthca_unmap_user_db() for mthca_create_srq()

In the Linux kernel, the following vulnerability has been resolved: IB/mthca: Add missed mthca_unmap_user_db() for mthca_create_srq() Fix a user triggerable leak on the system call failure path.

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 9:16 a.m.

7.8

CVSS3.1

CVE-2026-23319 - bpf: Fix a UAF issue in bpf_trampoline_link_cgroup_shim

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a UAF issue in bpf_trampoline_link_cgroup_shim The root cause of this bug is that when 'bpf_link_put' reduces the refcount of 'shim_link->link.link' to zero, the resource is considered released but may still be reference…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 9:05 p.m.

9.8

CVSS3.1

CVE-2026-26833 -

thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is concatenated into a shell command string passed to child_process.exec() without proper sanitization or escaping.

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 8:58 p.m.

5.5

CVSS3.1

CVE-2026-23301 - ASoC: SDCA: Add allocation failure check for Entity name

In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: Add allocation failure check for Entity name Currently find_sdca_entity_iot() can allocate a string for the Entity name but it doesn't check if that allocation succeeded. Add the missing NULL check after the allocatio…

πŸ“… Published: March 25, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:03 a.m.

5.3

CVSS4.0

CVE-2026-4781 - SourceCodester Sales and Inventory System HTTP GET Parameter update_purchase.php sql injection

A flaw has been found in SourceCodester Sales and Inventory System 1.0. The affected element is an unknown function of the file update_purchase.php of the component HTTP GET Parameter Handler. Executing a manipulation of the argument sid can lead to sql injection. The attack may be performed from r…

πŸ“… Published: March 24, 2026, 11:11 p.m. πŸ”„ Last Modified: April 8, 2026, 8:01 p.m.
Total resulsts: 349182
Page 932 of 34,919
Β« previous page Β» next page
Filters