7.0

CVSS3.1

CVE-2026-23249 - xfs: check for deleted cursors when revalidating two btrees

In the Linux kernel, the following vulnerability has been resolved: xfs: check for deleted cursors when revalidating two btrees The free space and inode btree repair functions will rebuild both btrees at the same time, after which it needs to evaluate both btrees to confirm that the corruptions a…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:03 a.m.

5.5

CVSS3.1

CVE-2026-23256 - net: liquidio: Fix off-by-one error in VF setup_nic_devices() cleanup

In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Fix off-by-one error in VF setup_nic_devices() cleanup In setup_nic_devices(), the initialization loop jumps to the label setup_nic_dev_free on failure. The current cleanup loop while(i--) skip the failing index i,…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: March 27, 2026, 8:42 a.m.

0.0

CVE-2026-23266 - fbdev: rivafb: fix divide error in nv3_arb()

In the Linux kernel, the following vulnerability has been resolved: fbdev: rivafb: fix divide error in nv3_arb() A userspace program can trigger the RIVA NV3 arbitration code by calling the FBIOPUT_VSCREENINFO ioctl on /dev/fb*. When doing so, the driver recomputes FIFO arbitration parameters in …

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:03 a.m.

9.8

CVSS3.1

CVE-2026-30702 - Broken Authentication in WiFi Extender WDR201A Web Management Interface

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login page does not properly enforce session validation, allowing attackers to bypass authentication by directly accessing restricted web application endpoint…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: March 24, 2026, 10:54 a.m.

5.5

CVSS3.1

CVE-2026-23247 - tcp: secure_seq: add back ports to TS offset

In the Linux kernel, the following vulnerability has been resolved: tcp: secure_seq: add back ports to TS offset This reverts 28ee1b746f49 ("secure_seq: downgrade to per-host timestamp offsets") tcp_tw_recycle went away in 2017. Zhouyan Deng reported off-path TCP source port leakage via SYN coo…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:03 a.m.

5.5

CVSS3.1

CVE-2026-23259 - io_uring/rw: free potentially allocated iovec on cache put failure

In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: free potentially allocated iovec on cache put failure If a read/write request goes through io_req_rw_cleanup() and has an allocated iovec attached and fails to put to the rw_cache, then it may end up with an unaccoun…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: March 29, 2026, 8:29 p.m.

7.8

CVSS3.1

CVE-2026-23248 - perf/core: Fix refcount bug and potential UAF in perf_mmap

In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix refcount bug and potential UAF in perf_mmap Syzkaller reported a refcount_t: addition on 0; use-after-free warning in perf_mmap. The issue is caused by a race condition between a failing mmap() setup and a concurr…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:03 a.m.

8.8

CVSS3.1

CVE-2026-4452 - chromium-browser: Integer overflow in ANGLE

Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 2:09 p.m.

8.8

CVSS3.1

CVE-2026-4442 - chromium-browser: Heap buffer overflow in CSS

Heap buffer overflow in CSS in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 2:10 p.m.

8.2

CVSS3.1

CVE-2026-26740 - giflib: giflib: Denial of Service via buffer overflow in EGifGCBToExtension

Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without validating its allocated size.

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: March 24, 2026, 10:53 a.m.
Total resulsts: 349182
Page 1074 of 34,919
Β« previous page Β» next page
Filters