6.5

CVSS3.1

CVE-2026-43504 -

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in a paused scenario, relaying of unauthenticated traffic can occur.

πŸ“… Published: May 1, 2026, 2:40 p.m. πŸ”„ Last Modified: May 1, 2026, 2:48 p.m.

7.8

CVSS3.1

CVE-2026-43056 - net: mana: fix use-after-free in add_adev() error path

In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in add_adev() error path If auxiliary_device_add() fails, add_adev() jumps to add_fail and calls auxiliary_device_uninit(adev). The auxiliary device has its release callback set to adev_release(), w…

πŸ“… Published: May 1, 2026, 2:15 p.m. πŸ”„ Last Modified: May 3, 2026, 5:46 a.m.

0.0

CVE-2026-43053 - xfs: close crash window in attr dabtree inactivation

In the Linux kernel, the following vulnerability has been resolved: xfs: close crash window in attr dabtree inactivation When inactivating an inode with node-format extended attributes, xfs_attr3_node_inactive() invalidates all child leaf/node blocks via xfs_trans_binval(), but intentionally does…

πŸ“… Published: May 1, 2026, 2:15 p.m. πŸ”„ Last Modified: May 1, 2026, 2:15 p.m.

0.0

CVE-2026-43052 - wifi: mac80211: check tdls flag in ieee80211_tdls_oper

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: check tdls flag in ieee80211_tdls_oper When NL80211_TDLS_ENABLE_LINK is called, the code only checks if the station exists but not whether it is actually a TDLS station. This allows the operation to proceed for no…

πŸ“… Published: May 1, 2026, 2:15 p.m. πŸ”„ Last Modified: May 1, 2026, 2:15 p.m.

0.0

CVE-2026-43050 - atm: lec: fix use-after-free in sock_def_readable()

In the Linux kernel, the following vulnerability has been resolved: atm: lec: fix use-after-free in sock_def_readable() A race condition exists between lec_atm_close() setting priv->lecd to NULL and concurrent access to priv->lecd in send_to_lecd(), lec_handle_bridge(), and lec_atm_send(). When t…

πŸ“… Published: May 1, 2026, 2:15 p.m. πŸ”„ Last Modified: May 1, 2026, 2:15 p.m.

0.0

CVE-2026-43049 - HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure

In the Linux kernel, the following vulnerability has been resolved: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure Presently, if the force feedback initialisation fails when probing the Logitech G920 Driving Force Racing Wheel for Xbox One, an error number wi…

πŸ“… Published: May 1, 2026, 2:15 p.m. πŸ”„ Last Modified: May 1, 2026, 2:15 p.m.

0.0

CVE-2026-43046 - btrfs: reject root items with drop_progress and zero drop_level

In the Linux kernel, the following vulnerability has been resolved: btrfs: reject root items with drop_progress and zero drop_level [BUG] When recovering relocation at mount time, merge_reloc_root() and btrfs_drop_snapshot() both use BUG_ON(level == 0) to guard against an impossible state: a non-…

πŸ“… Published: May 1, 2026, 2:15 p.m. πŸ”„ Last Modified: May 1, 2026, 2:15 p.m.

0.0

CVE-2026-43045 - mshv: Fix error handling in mshv_region_pin

In the Linux kernel, the following vulnerability has been resolved: mshv: Fix error handling in mshv_region_pin The current error handling has two issues: First, pin_user_pages_fast() can return a short pin count (less than requested but greater than zero) when it cannot pin all requested pages.…

πŸ“… Published: May 1, 2026, 2:15 p.m. πŸ”„ Last Modified: May 1, 2026, 2:15 p.m.

0.0

CVE-2026-43043 - crypto: af-alg - fix NULL pointer dereference in scatterwalk

In the Linux kernel, the following vulnerability has been resolved: crypto: af-alg - fix NULL pointer dereference in scatterwalk The AF_ALG interface fails to unmark the end of a Scatter/Gather List (SGL) when chaining a new af_alg_tsgl structure. If a sendmsg() fills an SGL exactly to MAX_SGL_EN…

πŸ“… Published: May 1, 2026, 2:15 p.m. πŸ”„ Last Modified: May 1, 2026, 2:15 p.m.

0.0

CVE-2026-43041 - net: qrtr: replace qrtr_tx_flow radix_tree with xarray to fix memory leak

In the Linux kernel, the following vulnerability has been resolved: net: qrtr: replace qrtr_tx_flow radix_tree with xarray to fix memory leak __radix_tree_create() allocates and links intermediate nodes into the tree one by one. If a subsequent allocation fails, the already-linked nodes remain in…

πŸ“… Published: May 1, 2026, 2:15 p.m. πŸ”„ Last Modified: May 1, 2026, 2:15 p.m.
Total resulsts: 347742
Page 15 of 34,775
Β« previous page Β» next page
Filters