5.5

CVSS3.1

CVE-2026-23257 - net: liquidio: Fix off-by-one error in PF setup_nic_devices() cleanup

In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Fix off-by-one error in PF setup_nic_devices() cleanup In setup_nic_devices(), the initialization loop jumps to the label setup_nic_dev_free on failure. The current cleanup loop while(i--) skip the failing index i,…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: March 27, 2026, 3:48 p.m.

9.1

CVSS3.1

CVE-2026-30701 -

The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure mechanisms (in the form of Server Side Include) within multiple server-side web pages, including login.shtml and settings.shtml. These pages embed server-side execution directive…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: March 24, 2026, 10:54 a.m.

7.0

CVSS3.1

CVE-2025-71269 - btrfs: do not free data reservation in fallback from inline due to -ENOSPC

In the Linux kernel, the following vulnerability has been resolved: btrfs: do not free data reservation in fallback from inline due to -ENOSPC If we fail to create an inline extent due to -ENOSPC, we will attempt to go through the normal COW path, reserve an extent, create an ordered extent, etc.…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: April 11, 2026, 1:16 p.m.

8.8

CVSS3.1

CVE-2026-4446 - chromium-browser: Use after free in WebRTC

Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 2:10 p.m.

8.8

CVSS3.1

CVE-2026-23246 - wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration link_id is taken from the ML Reconfiguration element (control & 0x000f), so it can be 0..15. link_removal_timeout[] has IEEE80211_MLD_MAX_NUM_LINKS (15) element…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:03 a.m.

7.8

CVSS3.1

CVE-2026-23245 - net/sched: act_gate: snapshot parameters with RCU on replace

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_gate: snapshot parameters with RCU on replace The gate action can be replaced while the hrtimer callback or dump path is walking the schedule list. Convert the parameters to an RCU-protected snapshot and swap upda…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 9:16 a.m.

7.8

CVSS3.1

CVE-2026-23243 - RDMA/umad: Reject negative data_len in ib_umad_write

In the Linux kernel, the following vulnerability has been resolved: RDMA/umad: Reject negative data_len in ib_umad_write ib_umad_write computes data_len from user-controlled count and the MAD header sizes. With a mismatched user MAD header size and RMPP header length, data_len can become negative…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:02 a.m.

7.5

CVSS3.1

CVE-2026-23242 - RDMA/siw: Fix potential NULL pointer dereference in header processing

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix potential NULL pointer dereference in header processing If siw_get_hdr() returns -EINVAL before set_rx_fpdu_context(), qp->rx_fpdu can be NULL. The error path in siw_tcp_rx_data() dereferences qp->rx_fpdu->more_ddp_…

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:02 a.m.

0.0

CVE-2025-71266 - fs: ntfs3: check return value of indx_find to avoid infinite loop

In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: check return value of indx_find to avoid infinite loop We found an infinite loop bug in the ntfs3 file system that can lead to a Denial-of-Service (DoS) condition. A malformed dentry in the ntfs3 filesystem can cause …

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:02 a.m.

7.0

CVSS3.1

CVE-2026-23251 - xfs: only call xf{array,blob}_destroy if we have a valid pointer

In the Linux kernel, the following vulnerability has been resolved: xfs: only call xf{array,blob}_destroy if we have a valid pointer Only call the xfarray and xfblob destructor if we have a valid pointer, and be sure to null out that pointer afterwards. Note that this patch fixes a large number …

πŸ“… Published: March 18, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:03 a.m.
Total resulsts: 349182
Page 1076 of 34,919
Β« previous page Β» next page
Filters