{"resultsPerPage":239,"startIndex":0,"totalResults":239,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-03T02:57:13.714","vulnerabilities":[{"cve":{"id":"CVE-2026-77781","sourceIdentifier":"9b29abf9-4ab0-4765-b253-1875cd9b441e","published":"2026-08-22T00:16:46.710","lastModified":"2026-08-27T20:18:39.550","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys.\n\nThe FETCH, EXISTS and DELETE methods throw an exception when on malformed regular expressions.\n\nEach method falls back to a regex match when the key is not already stored in the hash, compiling the caller's key with a bare qr// and no eval guard. A key that is not a valid regular expression pattern, such as a single unmatched bracket, dies.\n\nAn application that looks up externally supplied strings in a tied hash will die on an invalid key."}],"affected":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","affectedData":[{"defaultStatus":"unaffected","collectionURL":"https://cpan.org/modules","packageName":"Tie-Hash-Regex","modules":["Tie::Hash::Regex"],"programFiles":["lib/Tie/Hash/Regex.pm"],"programRoutines":[{"name":"Tie::Hash::Regex::FETCH"},{"name":"Tie::Hash::Regex::EXISTS"},{"name":"Tie::Hash::Regex::DELETE"}],"repo":"https://github.com/davorg-cpan/tie-hash-regex","packageURL":"pkg:cpan/Tie-Hash-Regex","versions":[{"version":"0","lessThan":"2.0.0","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-27T19:12:36.613814Z","id":"CVE-2026-77781","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary","description":[{"lang":"en","value":"CWE-248"}]}],"references":[{"url":"https://github.com/davorg-cpan/tie-hash-regex/commit/4239732cb76233543e2ded8ff5e0f238af152e0c.patch","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://metacpan.org/release/DAVECROSS/Tie-Hash-Regex-2.0.0/source/Changes","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/22/2","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-19883","sourceIdentifier":"security@wordfence.com","published":"2026-08-22T03:16:20.833","lastModified":"2026-08-24T16:41:13.950","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the wpematico_import_settings function in all versions up to, and including, 2.8.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"etruel","product":"WPeMatico RSS Feed Fetcher","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.8.24","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:43:20.004758Z","id":"CVE-2026-19883","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-269"}]}],"references":[{"url":"https://github.com/etruel/wpematico/commit/e297f41b49c6ec76635b006dff8a964a99a1ed24","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.23/app/tools_page.php#L224","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.23/app/wpematico_functions.php#L2077","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.23/app/wpematico_functions.php#L2096","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.23/wpematico_class.php#L59","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.24/app/tools_page.php#L224","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.24/app/wpematico_functions.php#L2077","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.24/app/wpematico_functions.php#L2096","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.24/wpematico_class.php#L59","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4e591cb4-058d-4d8e-948e-d65ab01db618?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-75027","sourceIdentifier":"security@wordfence.com","published":"2026-08-22T04:18:15.057","lastModified":"2026-08-24T16:41:13.950","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the stored Themify Builder styling data (padding and margin properties) of arbitrary posts, including private and draft posts, by supplying an attacker-controlled post ID and JSON styling payload. The nonce required by the handler is automatically emitted to all frontend pages rendered by the builder via wp_localize_script, meaning any unauthenticated visitor can trivially retrieve a valid nonce from page source and satisfy the only access control in place."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"themifyme","product":"Themify Builder","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7.8.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:43:10.162003Z","id":"CVE-2026-75027","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.6/classes/class-themify-builder-stylesheet.php#L69","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.6/classes/class-themify-builder.php#L227","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.6/classes/class-themify-builder.php#L518","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.6/classes/class-themify-builder.php#L693","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.8.0/classes/class-themify-builder-stylesheet.php#L69","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.8.0/classes/class-themify-builder.php#L227","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.8.0/classes/class-themify-builder.php#L518","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.8.0/classes/class-themify-builder.php#L693","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3653841%40themify-builder&new=3653841%40themify-builder","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b1892207-0e51-4b2e-bc71-d6a0111b7041?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-76057","sourceIdentifier":"security@wordfence.com","published":"2026-08-22T04:18:17.367","lastModified":"2026-08-24T16:41:13.950","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve all ConvertKit form data configured by the site's manager account, exposing integration details intended to be restricted to plugin managers. The required nonce is localized on every admin page load, making it accessible to any authenticated user who can reach /wp-admin."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"rubengc","product":"AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"5.8.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:43:30.475584Z","id":"CVE-2026-76057","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/automatorwp/tags/5.8.4/includes/scripts.php#L161","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/automatorwp/tags/5.8.4/integrations/convertkit/includes/ajax-functions.php#L16","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/automatorwp/tags/5.8.4/integrations/convertkit/includes/ajax-functions.php#L66","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/automatorwp/tags/5.8.4/integrations/convertkit/includes/ajax-functions.php#L96","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3656285%40automatorwp&new=3656285%40automatorwp","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b0fd8e7b-1985-4265-8e15-5b3988bb0225?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-76074","sourceIdentifier":"security@wordfence.com","published":"2026-08-22T04:18:17.990","lastModified":"2026-08-24T16:41:13.950","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve the site's configured Campaign Monitor mailing list catalog, including all list IDs and names, that should be restricted to users with the plugin's manager capability. The required nonce is emitted unconditionally on every WordPress admin page via wp_localize_script, meaning any subscriber visiting /wp-admin/profile.php can obtain it without any elevated access."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"rubengc","product":"AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"5.8.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:43:00.481183Z","id":"CVE-2026-76074","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/automatorwp/tags/5.8.4/includes/scripts.php#L161","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/automatorwp/tags/5.8.4/integrations/campaign-monitor/includes/ajax-functions.php#L124","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/automatorwp/tags/5.8.4/integrations/campaign-monitor/includes/ajax-functions.php#L89","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3656285%40automatorwp&new=3656285%40automatorwp","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/daac833f-b350-453a-b56a-fe3b1dd2ed3b?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-14187","sourceIdentifier":"contact@wpscan.com","published":"2026-08-22T06:16:11.597","lastModified":"2026-08-26T16:30:52.723","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Tutor LMS  WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to read the content of private courses belonging to other instructors."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Tutor LMS","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.0.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-23T15:27:47.203670Z","id":"CVE-2026-14187","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://wpscan.com/vulnerability/fb006829-e298-4b22-9d62-293a3b917ccd/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16260","sourceIdentifier":"contact@wpscan.com","published":"2026-08-22T06:16:14.833","lastModified":"2026-08-26T16:30:52.723","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Post Grid, Slider & Carousel Ultimate  WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript that executes in the session of any administrator who opens the affected item."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Post Grid, Slider & Carousel Ultimate","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.8.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-23T15:27:37.837799Z","id":"CVE-2026-16260","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://wpscan.com/vulnerability/87c95831-d1b4-42b2-8fc7-6cba60fca400/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16612","sourceIdentifier":"contact@wpscan.com","published":"2026-08-22T06:16:15.130","lastModified":"2026-08-26T16:30:52.723","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The FiboSearch  WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumerate password-protected products and their metadata without entering the product password. Two endpoints are affected: the autocomplete search endpoint (dgwt_wcas_ajax_search) and the Details Panel endpoint (dgwt_wcas_result_details) when queried for taxonomy details."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"FiboSearch","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.34.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-23T15:27:31.365297Z","id":"CVE-2026-16612","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]}],"references":[{"url":"https://wpscan.com/vulnerability/705cf14a-2782-408a-80b1-be7a9da6bbdd/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-16738","sourceIdentifier":"contact@wpscan.com","published":"2026-08-22T06:16:15.383","lastModified":"2026-08-26T16:30:52.723","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or verify its amount, allowing unauthenticated attackers to mark arbitrary orders as paid without payment."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Conekta Payment Gateway","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"6.2.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-23T15:27:19.222935Z","id":"CVE-2026-16738","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://wpscan.com/vulnerability/89a2917e-032c-4f0f-be44-1a50b9d6fddf/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-18052","sourceIdentifier":"contact@wpscan.com","published":"2026-08-22T06:16:15.647","lastModified":"2026-08-26T16:30:52.723","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the site, including an administrator."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"ManageWP Worker","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.9.37","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-23T15:27:09.852982Z","id":"CVE-2026-18052","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]}],"references":[{"url":"https://wpscan.com/vulnerability/e1e8c313-f7ea-4f3a-85c0-4f33dfe0710d/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-19093","sourceIdentifier":"contact@wpscan.com","published":"2026-08-22T06:16:15.900","lastModified":"2026-08-26T16:30:52.723","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Tutor LMS  WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor role to read arbitrary files on the server, including files outside the web root.\n\nThe readable files include the WordPress configuration file, which exposes the database credentials and the authentication keys and salts, so authentication cookies can be forged."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Tutor LMS","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.0.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":4.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-23T15:27:00.442286Z","id":"CVE-2026-19093","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-552"}]}],"references":[{"url":"https://wpscan.com/vulnerability/9f8361a9-d424-4346-9d92-6f27ab9261c9/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-19221","sourceIdentifier":"contact@wpscan.com","published":"2026-08-22T06:16:16.130","lastModified":"2026-08-26T16:30:52.723","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Forminator Forms  WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Forminator Forms","defaultStatus":"unaffected","versions":[{"version":"1.40.0","lessThan":"1.57.0.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-23T15:26:52.351857Z","id":"CVE-2026-19221","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://wpscan.com/vulnerability/5aa85c72-2a60-4243-b370-ef0b46e98cfe/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-19222","sourceIdentifier":"contact@wpscan.com","published":"2026-08-22T06:16:16.383","lastModified":"2026-08-26T16:30:52.723","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Forminator Forms  WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Forminator Forms","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.57.0.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.7,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-23T15:26:41.613946Z","id":"CVE-2026-19222","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-269"}]}],"references":[{"url":"https://wpscan.com/vulnerability/bb3997c6-4d9a-46f6-85d7-d472dfc00829/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-76789","sourceIdentifier":"contact@wpscan.com","published":"2026-08-22T06:16:16.643","lastModified":"2026-08-26T16:30:52.723","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users to store malicious JavaScript which will be executed in the context of an administrator viewing the Slider Hero with Video Background, Animation WordPress plugin before 9.1.3's admin area, as well as any visitor of a page embedding a slider."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Slider Hero with Video Background, Animation","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"9.1.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-23T15:26:31.426153Z","id":"CVE-2026-76789","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://wpscan.com/vulnerability/f9f5485c-6231-492c-b214-8da87a2bf4d1/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-76793","sourceIdentifier":"contact@wpscan.com","published":"2026-08-22T06:16:16.900","lastModified":"2026-08-26T16:30:52.723","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including administrators."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Firebase Authentication","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.7.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-23T15:26:20.515870Z","id":"CVE-2026-76793","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]}],"references":[{"url":"https://wpscan.com/vulnerability/0414ef2b-0d97-41c7-9146-f31ace8b66b2/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-77000","sourceIdentifier":"contact@wpscan.com","published":"2026-08-22T06:16:17.150","lastModified":"2026-08-26T16:30:52.723","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by supplying that user's email address."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"WP Social Media Login","defaultStatus":"unknown","versions":[{"version":"0","lessThanOrEqual":"1.0.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-23T15:26:06.918805Z","id":"CVE-2026-77000","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]}],"references":[{"url":"https://wpscan.com/vulnerability/3051dece-7ecb-4911-bf13-291ebdc34bff/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-77001","sourceIdentifier":"contact@wpscan.com","published":"2026-08-22T06:16:17.323","lastModified":"2026-08-26T16:30:52.723","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any existing user, including administrators. In the default case a session as the site's original administrator account is obtained without needing to know any account details at all."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Social Login & Sharing buttons with Analytics By SoClever","defaultStatus":"unknown","versions":[{"version":"0","lessThanOrEqual":"1.2.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-23T15:25:52.772051Z","id":"CVE-2026-77001","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]}],"references":[{"url":"https://wpscan.com/vulnerability/01c78c78-3915-44da-824a-f68074985c75/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-77002","sourceIdentifier":"contact@wpscan.com","published":"2026-08-22T06:16:17.510","lastModified":"2026-08-26T16:30:52.723","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"SmilePass Selfie Login","defaultStatus":"unknown","versions":[{"version":"0","lessThanOrEqual":"1.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-23T15:25:40.413911Z","id":"CVE-2026-77002","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]}],"references":[{"url":"https://wpscan.com/vulnerability/51236907-a1b4-4c3b-8c39-adafcab7a2ef/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-12710","sourceIdentifier":"f45cbf4e-4146-4068-b7e1-655ffc2c548c","published":"2026-08-22T09:16:53.340","lastModified":"2026-08-31T18:50:00.053","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data.\n\n\n\n\nThe issue was patched on April 4, 2026; no customer action is required."}],"affected":[{"source":"f45cbf4e-4146-4068-b7e1-655ffc2c548c","affectedData":[{"vendor":"Google Cloud","product":"Application Integration","defaultStatus":"unaffected","versions":[{"version":"2025-04-28","lessThan":"2026-04-04","versionType":"date","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"f45cbf4e-4146-4068-b7e1-655ffc2c548c","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"CLEAR"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T19:02:17.396086Z","id":"CVE-2026-12710","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"f45cbf4e-4146-4068-b7e1-655ffc2c548c","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://cloud.google.com/application-integration/docs/release-notes#August_21_2026","source":"f45cbf4e-4146-4068-b7e1-655ffc2c548c"}]}},{"cve":{"id":"CVE-2026-78003","sourceIdentifier":"security@wordfence.com","published":"2026-08-22T09:16:53.543","lastModified":"2026-08-25T14:16:55.953","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from $_POST['addresses'], passes them through sanitize_text_field(). This makes it possible for unauthenticated attackers to make authenticated POST requests to any Mailgun API endpoint using the WordPress site's API key, including creating inbound email-forwarding routes that can intercept password reset emails, leading to administrator account takeover."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"mailgun","product":"Mailgun for WordPress","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.2.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-25T13:14:07.382843Z","id":"CVE-2026-78003","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/mailgun/tags/2.1.10/mailgun.php#L259","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mailgun/tags/2.1.10/mailgun.php#L323","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mailgun/tags/2.1.10/mailgun.php#L331","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mailgun/tags/2.1.10/mailgun.php#L557","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mailgun/trunk/mailgun.php#L259","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mailgun/trunk/mailgun.php#L323","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mailgun/trunk/mailgun.php#L331","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mailgun/trunk/mailgun.php#L557","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/110e888d-69fc-4682-b908-2b62288c5227?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-77945","sourceIdentifier":"cna@vuldb.com","published":"2026-08-22T11:16:53.243","lastModified":"2026-08-25T13:19:30.330","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.cgi of the component ssi. Performing a manipulation of the argument filename results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"TRENDnet","product":"TEW-821DAP","cpes":["cpe:2.3:o:trendnet:tew-821dap_firmware:*:*:*:*:*:*:*:*"],"modules":["ssi"],"versions":[{"version":"2.2.01b05","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"LOW","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.1,"impactScore":3.7}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-25T13:08:25.319722Z","id":"CVE-2026-77945","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Secondary","description":[{"lang":"en","value":"CWE-74"},{"lang":"en","value":"CWE-77"}]}],"references":[{"url":"https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/TEW-821DAP_ssi_Arbitrary_File_Command_Injection.md","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-77945","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/881248","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/394174","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/394174/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-77946","sourceIdentifier":"cna@vuldb.com","published":"2026-08-22T11:16:54.447","lastModified":"2026-08-26T18:17:03.530","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation of the argument system.ntp.server/system.ntp.enable_server/cameo.time.time_zone/cameo.cameo.syslog_server can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"TRENDnet","product":"TEW-821DAP","cpes":["cpe:2.3:o:trendnet:tew-821dap_firmware:*:*:*:*:*:*:*:*"],"modules":["NTP Timezone Configuration Handler"],"versions":[{"version":"2.2.01b05","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":6.0}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T17:48:38.933905Z","id":"CVE-2026-77946","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Secondary","description":[{"lang":"en","value":"CWE-119"},{"lang":"en","value":"CWE-121"}]}],"references":[{"url":"https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/TEW-821DAP_ssi_NTP_Timezone_Config_Stack_Overflow.md","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-77946","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/881252","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/394175","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/394175/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-3424","sourceIdentifier":"security@wordfence.com","published":"2026-08-22T12:16:24.677","lastModified":"2026-08-26T18:16:31.763","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10.3. This is due to the software allowing users to execute an action that does not properly validate the 'payload' value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"properfraction","product":"kk Star Ratings – Rate Post & Collect User Feedbacks","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"5.4.10.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T17:49:13.560614Z","id":"CVE-2026-3424","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/kk-star-ratings/trunk/src/core/functions/scripts/main.php#L36","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kk-star-ratings/trunk/src/core/wp/actions/wp_ajax_kk-star-ratings.php#L85","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/kk-star-ratings/trunk/src/core/wp/actions/wp_ajax_kk-star-ratings.php#L88","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3474555/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0b2e9103-16a8-4350-97ee-ae05a90850f6?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-4245","sourceIdentifier":"security@wordfence.com","published":"2026-08-22T12:16:25.400","lastModified":"2026-08-24T20:16:44.087","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.11. This is due to the `duplicate_post_permissions()` permission callback only verifying the `duplicate_posts` capability without checking whether the requesting user holds `publish_posts` or other status-gated capabilities. This makes it possible for authenticated attackers, with Contributor-level access and above, to create duplicate posts with `future` (scheduled, auto-publishes) or `private` status, bypassing editorial review. Additionally, the REST endpoint does not enforce administrator-configured post-type duplication restrictions, allowing duplication of post types that have been explicitly disabled."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"metaphorcreations","product":"Post Duplicator","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.0.11","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T20:01:25.244331Z","id":"CVE-2026-4245","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/post-duplicator/trunk/includes/api.php#L520","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/post-duplicator/trunk/includes/api.php#L624","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/post-duplicator/trunk/includes/api.php#L635","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/post-duplicator/trunk/includes/api.php#L740","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3485579/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bb671c8f-9e14-4f79-adfa-72f48ec02449?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-66916","sourceIdentifier":"security@joomla.org","published":"2026-08-22T12:16:25.547","lastModified":"2026-08-26T16:36:16.990","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0- An unauthenticated access control bypass exists in JoomGallery's category JSON view. When a gallery category is protected with a password, the HTML view correctly enforces the password gate - but the JSON view ( format=json ) skips this check entirely."}],"affected":[{"source":"security@joomla.org","affectedData":[{"vendor":"joomgalleryfriends.net","product":"JoomGallery extension for Joomla","defaultStatus":"unaffected","versions":[{"version":"4.0.0-4.3.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@joomla.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-25T19:07:42.447109Z","id":"CVE-2026-66916","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@joomla.org","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://www.joomgalleryfriends.net/","source":"security@joomla.org"}]}},{"cve":{"id":"CVE-2026-66917","sourceIdentifier":"security@joomla.org","published":"2026-08-22T12:16:25.680","lastModified":"2026-08-26T16:35:20.160","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, privileged can store an XSS payload in any image causing JS execution in every visitor's browser."}],"affected":[{"source":"security@joomla.org","affectedData":[{"vendor":"joomgalleryfriends.net","product":"JoomGallery extension for Joomla","defaultStatus":"unaffected","versions":[{"version":"4.0.0-4.3.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@joomla.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:42:42.070783Z","id":"CVE-2026-66917","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@joomla.org","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://www.joomgalleryfriends.net/","source":"security@joomla.org"}]}},{"cve":{"id":"CVE-2026-77988","sourceIdentifier":"cna@vuldb.com","published":"2026-08-22T12:16:25.817","lastModified":"2026-08-24T19:17:01.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. This vulnerability affects the function nvram_get of the component CLI Configuration Tool. This manipulation causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"TRENDnet","product":"TEW-823DRU","cpes":["cpe:2.3:a:trendnet:tew-823dru:*:*:*:*:*:*:*:*"],"modules":["CLI Configuration Tool"],"versions":[{"version":"1.1.02b01","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.0,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"LOW","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.3,"impactScore":3.7}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:M/C:P/I:P/A:P","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"MULTIPLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":6.4,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T18:43:00.860054Z","id":"CVE-2026-77988","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Secondary","description":[{"lang":"en","value":"CWE-74"},{"lang":"en","value":"CWE-77"}]}],"references":[{"url":"https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/TEW-823DRU_bin_cli_NVRAM_Command_Injection.md","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-77988","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/881256","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/394178","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/394178/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-11947","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T13:16:36.970","lastModified":"2026-08-22T13:16:36.970","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-11948","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T13:16:37.450","lastModified":"2026-08-22T13:16:37.450","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-4244","sourceIdentifier":"security@wordfence.com","published":"2026-08-22T13:16:37.523","lastModified":"2026-08-24T16:41:13.950","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `duplicate_post()` function in all versions up to, and including, 3.0.11. This is due to the function not verifying that the user has `edit_others_posts` capability before accepting a `selectedAuthorId` parameter via the `duplicate-post` REST endpoint. This makes it possible for authenticated attackers, with Contributor-level access and above, to create duplicated posts attributed to any user, including administrators."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"metaphorcreations","product":"Post Duplicator","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.0.11","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:42:26.579839Z","id":"CVE-2026-4244","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/post-duplicator/trunk/includes/api.php#L520","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/post-duplicator/trunk/includes/api.php#L550","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/post-duplicator/trunk/includes/api.php#L728","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3485579/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/64553742-ff2b-40e9-92c3-3458a9f988a2?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-56380","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T13:16:37.977","lastModified":"2026-08-26T17:07:30.163","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthenticated attackers to retrieve channel owner email addresses by supplying a public channel name parameter. Attackers can enumerate all creator email addresses by iterating through public channel names and extract them from the itunes:email and itunes:author RSS elements, enabling account takeover attempts and phishing campaigns."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"WWBN","product":"AVideo","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"9c39d8c8b4c1f75540788d6b391740852ceb0732","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T19:30:42.442722Z","id":"CVE-2026-56380","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]}],"references":[{"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-w44x-v4c8-86f6","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/avideo-feed-index-php-exposure-of-channel-owner-email-address","source":"disclosure@vulncheck.com"},{"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-w44x-v4c8-86f6","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-57944","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T13:16:38.130","lastModified":"2026-08-26T18:16:41.830","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGallery.json.php that allows attackers to modify site-wide Gallery configuration by performing unauthorized writes to plugin data. Attackers can craft a cross-site GET request carrying an administrator's session cookie to promote arbitrary channels to the front page or delete curated sections without token validation."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"WWBN","product":"AVideo","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"9c39d8c8b4c1f75540788d6b391740852ceb0732","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T17:50:04.472402Z","id":"CVE-2026-57944","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"references":[{"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-8qq4-h7xj-p2c4","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/avideo-channeltogallery-json-php-cross-site-request-forgery","source":"disclosure@vulncheck.com"},{"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-8qq4-h7xj-p2c4","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-57998","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T13:16:38.263","lastModified":"2026-08-25T17:17:33.827","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then passes that string to child_process.exec() in index.ts, which spawns a shell. A registry value containing shell metacharacters such as a semicolon, pipe, or command substitution executes arbitrary operating system commands with the privileges of the process running the audit."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"jeemok","product":"better-npm-audit","defaultStatus":"unaffected","packageURL":"pkg:npm/better-npm-audit","versions":[{"version":"0","lessThanOrEqual":"3.11.0","versionType":"semver","status":"affected"},{"version":"4.0.0-rc.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-25T16:42:59.046764Z","id":"CVE-2026-57998","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://github.com/jeemok/better-npm-audit","source":"disclosure@vulncheck.com"},{"url":"https://github.com/jeemok/better-npm-audit/blob/fd99a0f41ff4342b8a0a6fdbe5a17261de3d0544/index.ts#L34","source":"disclosure@vulncheck.com"},{"url":"https://github.com/jeemok/better-npm-audit/blob/fd99a0f41ff4342b8a0a6fdbe5a17261de3d0544/src/handlers/handleInput.ts#L30-L37","source":"disclosure@vulncheck.com"},{"url":"https://github.com/jeemok/better-npm-audit/issues/119","source":"disclosure@vulncheck.com"},{"url":"https://github.com/jeemok/better-npm-audit/pull/120","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/better-npm-audit-os-command-injection-via-registry-flag","source":"disclosure@vulncheck.com"},{"url":"https://github.com/jeemok/better-npm-audit/issues/119","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-58001","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T13:16:38.403","lastModified":"2026-08-26T17:17:08.430","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in objects/videoEditLight.php that lacks request authenticity checks and accepts GET requests. Attackers can store an img tag in a video description that transfers video ownership to an attacker-controlled account when an administrator views the video page."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"WWBN","product":"AVideo","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"9c39d8c8b4c1f75540788d6b391740852ceb0732","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T15:55:23.850662Z","id":"CVE-2026-58001","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"references":[{"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-7mqw-mqc3-ffjw","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wwbn-avideo-cross-site-request-forgery-via-videoeditlight-php","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-58002","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T13:16:38.540","lastModified":"2026-08-26T17:10:09.810","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass vulnerability in the Users_affiliations add.json.php endpoint that allows authenticated users to forge two-party consent records by supplying the counterparty's agreement timestamp. Attackers can create a forged affiliation with status='a' and then reassign video ownership to arbitrary users through the videoAddNew.json.php endpoint, which trusts the forged affiliation as an authorization term."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"WWBN","product":"AVideo","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"9c39d8c8b4c1f75540788d6b391740852ceb0732","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T18:41:51.292323Z","id":"CVE-2026-58002","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-345"}]}],"references":[{"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-rg7g-cgjq-4wx8","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wwbn-avideo-authorization-bypass-via-users-affiliations-add-json-php","source":"disclosure@vulncheck.com"},{"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-rg7g-cgjq-4wx8","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-58003","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T13:16:38.673","lastModified":"2026-08-26T17:07:30.163","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authenticity checks and accepts GET requests. Attackers can craft a malicious cross-site GET request carrying an administrator's session cookie to permanently publish any embargoed video by manipulating the videos_id parameter."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"WWBN","product":"AVideo","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"9c39d8c8b4c1f75540788d6b391740852ceb0732","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T19:31:52.339167Z","id":"CVE-2026-58003","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"references":[{"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-q8cg-7x7q-c4g2","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wwbn-avideo-cross-site-request-forgery-via-releasevideonow-json-php","source":"disclosure@vulncheck.com"},{"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-q8cg-7x7q-c4g2","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-59256","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T13:16:38.817","lastModified":"2026-08-26T18:16:42.923","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. Attackers can retrieve a token from the Gallery endpoint and use it to bypass authorization checks in other subsystems like view/hls.php to access restricted video content."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"WWBN","product":"AVideo","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"9c39d8c8b4c1f75540788d6b391740852ceb0732","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T17:51:42.538574Z","id":"CVE-2026-59256","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]}],"references":[{"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-wq57-wxcr-rx6v","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wwbn-avideo-unbound-token-authorization-bypass-via-gallery","source":"disclosure@vulncheck.com"},{"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-wq57-wxcr-rx6v","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-59808","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T13:16:38.977","lastModified":"2026-08-26T17:07:30.163","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin() converts this hash into passwordless login as the video owner. Attackers with upload permission can retrieve an administrator's video_id_hash by omitting the videos_id parameter, then use that hash in an unauthenticated request to gain administrative session access and modify system configuration."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"WWBN","product":"AVideo","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"9c39d8c8b4c1f75540788d6b391740852ceb0732","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T19:25:36.574916Z","id":"CVE-2026-59808","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-q32p-rw3q-8x3r","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/avideo-authentication-bypass-via-unkeyed-video-hash-disclosure","source":"disclosure@vulncheck.com"},{"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-q32p-rw3q-8x3r","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-59809","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T13:16:39.127","lastModified":"2026-08-26T17:17:08.580","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plaintext secret values to any public host without confirmation."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"siyuan-note","product":"siyuan","defaultStatus":"unaffected","packageURL":"pkg:golang/github.com/siyuan-note/siyuan","versions":[{"version":"0","lessThan":"3.8.0","versionType":"semver","status":"affected"},{"version":"3.8.0","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T15:55:26.241710Z","id":"CVE-2026-59809","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-201"}]}],"references":[{"url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-853m-gvvm-6rvx","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/siyuan-before-secret-exfiltration-via-http-request-url","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-60083","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T13:16:39.263","lastModified":"2026-08-26T17:10:09.810","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to sensitive workspace files protected by the HTTP API. Authenticated administrators can read plaintext publish-mode passwords from data/.siyuan/publishAccess.json and access other sensitive files like data/templates and data/snippets/conf.json."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"siyuan-note","product":"siyuan","defaultStatus":"unaffected","packageURL":"pkg:golang/github.com/siyuan-note/siyuan","versions":[{"version":"0","lessThan":"3.8.0","versionType":"semver","status":"affected"},{"version":"3.8.0","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T18:40:48.540853Z","id":"CVE-2026-60083","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-c8r8-95hg-mp34","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/siyuan-before-incomplete-path-blocklist-via-mcp-file-tool","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-60084","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T13:16:39.407","lastModified":"2026-08-26T17:07:30.163","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly to os.RemoveAll. Authenticated admin attackers can supply absolute filesystem paths to recursively delete any file or directory the kernel process has permission to remove, anywhere on the host filesystem."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"siyuan-note","product":"siyuan","defaultStatus":"unaffected","packageURL":"pkg:golang/github.com/siyuan-note/siyuan/kernel","versions":[{"version":"0","lessThan":"3.7.4","versionType":"semver","status":"affected"},{"version":"3.7.4","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T19:21:57.161119Z","id":"CVE-2026-60084","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-w938-w7m4-qrj8","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/siyuan-before-arbitrary-file-deletion-via-removetemplate","source":"disclosure@vulncheck.com"},{"url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-w938-w7m4-qrj8","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-62204","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T13:16:39.547","lastModified":"2026-08-26T18:16:43.387","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing trusted plugins by supplying mismatched packageName and repoURL parameters, achieving persistence across application restarts."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"siyuan-note","product":"siyuan","defaultStatus":"unaffected","packageURL":"pkg:golang/github.com/siyuan-note/siyuan","versions":[{"version":"0","lessThan":"3.7.4","versionType":"semver","status":"affected"},{"version":"3.7.4","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"LOW","subIntegrityImpact":"HIGH","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":0.8,"impactScore":5.3}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T17:53:08.661591Z","id":"CVE-2026-62204","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-345"}]}],"references":[{"url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-rpx2-p6hp-x5gj","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/siyuan-before-plugin-overwrite-via-bazaar-install","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-62243","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T13:16:39.687","lastModified":"2026-08-24T20:16:52.993","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsafe-based trust-manager wrapping is unavailable (Java 25+). In this configuration the OpenSSL client does not perform hostname verification, allowing a man-in-the-middle attacker to present a certificate issued for a different hostname that is accepted without validation. Fixed in 4.2.17.Final and 4.1.137.Final."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"netty","product":"netty","defaultStatus":"unaffected","packageURL":"pkg:maven/io.netty/netty-handler","versions":[{"version":"4.2.0.Final","lessThan":"4.2.16.Final","versionType":"custom","status":"affected"},{"version":"4.2.16.Final","versionType":"custom","status":"unaffected"}]},{"vendor":"netty","product":"netty","defaultStatus":"unaffected","packageURL":"pkg:maven/io.netty/netty-handler","versions":[{"version":"0","lessThan":"4.1.137.Final","versionType":"custom","status":"affected"},{"version":"4.1.137.Final","versionType":"custom","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T19:36:11.866196Z","id":"CVE-2026-62243","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-297"}]}],"references":[{"url":"https://github.com/netty/netty/security/advisories/GHSA-p85m-gvr3-788c","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/netty-through-tls-hostname-verification-bypass","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-62380","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T13:16:39.830","lastModified":"2026-08-27T20:32:22.390","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain null byte, CRLF, and credential injection vulnerabilities in the SOCKS4 (Socks4ClientEncoder) and SOCKS5 (Socks5ClientEncoder) client encoders, which fail to validate domain address and authentication (username/password) fields. An attacker able to control these fields can inject null bytes or CRLF characters to truncate or alter values, potentially enabling domain spoofing, SOCKS4 userid truncation, authentication data injection, and protocol confusion. Fixed in 4.2.17.Final and 4.1.137.Final."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"netty","product":"netty","defaultStatus":"unaffected","packageURL":"pkg:maven/io.netty/netty-codec-socks","versions":[{"version":"4.2.0.Final","lessThan":"4.2.16.Final","versionType":"custom","status":"affected"},{"version":"4.2.16.Final","versionType":"custom","status":"unaffected"}]},{"vendor":"netty","product":"netty","defaultStatus":"unaffected","packageURL":"pkg:maven/io.netty/netty-codec-socks","versions":[{"version":"0","lessThan":"4.1.137.Final","versionType":"custom","status":"affected"},{"version":"4.1.137.Final","versionType":"custom","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T15:55:28.591533Z","id":"CVE-2026-62380","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-626"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*","versionEndExcluding":"4.1.137","matchCriteriaId":"C2D95C1D-B022-435F-B4C7-33FC460064EA"},{"vulnerable":true,"criteria":"cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2.0","versionEndExcluding":"4.2.17","matchCriteriaId":"80E3B839-CD5C-45D0-81C0-CABCE7A5D9AF"}]}]}],"references":[{"url":"https://github.com/netty/netty/security/advisories/GHSA-cc6x-ffm5-83wf","source":"disclosure@vulncheck.com","tags":["Vendor Advisory"]},{"url":"https://www.vulncheck.com/advisories/netty-before-final-socks-proxy-null-byte-injection","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-62381","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T13:16:39.957","lastModified":"2026-08-24T20:16:53.430","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with a 2040-bit RSA key. For a 255-byte signature, the BIT STRING allocation is computed from the DER length encoding of 255 bytes, but the payload written after prepending the unused-bits byte is 256 bytes, requiring one additional DER length octet. As a result the allocation is 259 bytes while the tag, length, unused-bits byte, and signature require 260 bytes, and the final memcpy writes one byte beyond the heap buffer. The overflow is reachable through the exported Lua interface via create_selfsigned(); whether it is remotely exploitable depends on the embedding application. The vulnerable code is present on the openwrt-18.06 through openwrt-25.12 release branches and is absent from master, where the luci-lib-px5g package has been removed rather than patched."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"openwrt","product":"luci","defaultStatus":"unaffected","collectionURL":"https://github.com/openwrt/luci","packageName":"luci-lib-px5g","versions":[{"version":"0","lessThanOrEqual":"42d72f79cd8f057f241595abc761b39dab2d9f07","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":4.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T19:50:25.578742Z","id":"CVE-2026-62381","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-122"}]}],"references":[{"url":"https://github.com/openwrt/luci/security/advisories/GHSA-jgc3-4q3p-g6xh","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/luci-lib-px5g-2040-bit-certificate-signing-heap-buffer-overflow","source":"disclosure@vulncheck.com"},{"url":"https://github.com/openwrt/luci/security/advisories/GHSA-jgc3-4q3p-g6xh","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-62382","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T13:16:40.110","lastModified":"2026-08-31T17:17:42.067","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion logic. The ownership check compares @push.user against current_user; for an anonymously created push both values are nil, and Ruby evaluates nil == nil as true, so the check passes and the deletable_by_viewer restriction is never enforced. An attacker who knows only the secret URL can permanently delete an anonymous push even when the creator disabled viewer deletion and even without the passphrase. Only deployments that allow anonymous pushes (the default) are affected. The issue is fixed in v2.9.6."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"pglombardo","product":"PasswordPusher","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.9.6","versionType":"semver","status":"affected"},{"version":"2.9.6","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T19:23:36.042935Z","id":"CVE-2026-62382","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://github.com/pglombardo/PasswordPusher/security/advisories/GHSA-jf2m-hpj9-4qx2","source":"disclosure@vulncheck.com"},{"url":"https://tpaidakis.com/writeups/passwordpusher-nil-authorization/","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/passwordpusher-before-authentication-bypass-via-null-comparison","source":"disclosure@vulncheck.com"},{"url":"https://github.com/pglombardo/PasswordPusher/security/advisories/GHSA-jf2m-hpj9-4qx2","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-2996","sourceIdentifier":"security@wordfence.com","published":"2026-08-22T14:16:32.807","lastModified":"2026-08-24T16:41:13.950","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated attackers to bypass required paid addons and complete purchases at the base product price only, effectively stealing products by paying a fraction of the intended total. The vulnerability was partially patched in version 1.6.19."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"maartenbelmans","product":"Advanced Product Fields (Product Addons) for WooCommerce","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.6.21","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:42:18.450679Z","id":"CVE-2026-2996","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/advanced-product-fields-for-woocommerce/trunk/includes/controllers/class-product-controller.php#L130","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3477476/","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3483410/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5d9c1c3d-6882-4425-8d32-bdb57b4f133d?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-4559","sourceIdentifier":"security@wordfence.com","published":"2026-08-22T14:16:32.947","lastModified":"2026-08-24T20:16:44.510","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'delay' shortcode attribute in all versions up to, and including, 3.6.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"wpchill","product":"Image Photo Gallery Final Tiles Grid","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.6.12","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T19:19:13.282594Z","id":"CVE-2026-4559","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/final-tiles-grid-gallery-lite/trunk/lib/gallery-class.php#L235","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/final-tiles-grid-gallery-lite/trunk/lib/gallery-class.php#L34","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3490676/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/afcb5fc3-8e53-4a0e-b4b3-26786d2f67d3?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-4561","sourceIdentifier":"security@wordfence.com","published":"2026-08-22T14:16:33.080","lastModified":"2026-08-24T16:41:13.950","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form response message post meta fields (e.g., 'text_subscribed', 'text_error') in all versions up to, and including, 4.12.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"dvankooten","product":"MC4WP: Mailchimp for WordPress","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"4.12.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:42:04.075920Z","id":"CVE-2026-4561","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/mailchimp-for-wp/trunk/includes/forms/class-form-element.php#L116","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mailchimp-for-wp/trunk/includes/forms/class-form-manager.php#L104","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mailchimp-for-wp/trunk/includes/forms/class-form.php#L295","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3491781/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/641b739d-f888-4327-b1c5-c95de39ee011?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-5093","sourceIdentifier":"security@wordfence.com","published":"2026-08-22T14:16:33.210","lastModified":"2026-08-24T16:41:13.950","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 12.8.9. This is due to a missing capability check on the 'gspb_update_global_wp_settings' function that only verifies the 'edit_posts' capability instead of requiring administrative privileges. This makes it possible for authenticated attackers, with contributor-level access and above, to modify global WordPress theme color settings site-wide, leading to site defacement."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"wpsoul","product":"Greenshift – animation and page builder blocks","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"12.8.9","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:41:50.981032Z","id":"CVE-2026-5093","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/greenshift-animation-and-page-builder-blocks/tags/10.8/init.php#L2686","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/greenshift-animation-and-page-builder-blocks/tags/10.8/init.php#L3092","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/greenshift-animation-and-page-builder-blocks/tags/10.8/init.php#L3143","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/greenshift-animation-and-page-builder-blocks/trunk/init.php#L2686","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/greenshift-animation-and-page-builder-blocks/trunk/init.php#L3092","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/greenshift-animation-and-page-builder-blocks/trunk/init.php#L3143","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3494855/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/69911634-1281-487c-87f1-37f6e4b016c9?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-68769","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T14:16:33.343","lastModified":"2026-08-22T14:16:33.343","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-71513","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T14:16:33.417","lastModified":"2026-08-31T20:49:08.970","vulnStatus":"Undergoing Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside the allowlisted namespace. Attackers can craft untrusted transition-parser models that execute arbitrary commands when TransitionParser.parse loads the model through allowlisted_pickle_load."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"nltk","product":"nltk","defaultStatus":"unaffected","packageURL":"pkg:pypi/nltk","versions":[{"version":"3.10.0","lessThan":"3.10.3","versionType":"semver","status":"affected"},{"version":"3.10.3","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-25T03:56:57.129387Z","id":"CVE-2026-71513","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-502"}]}],"references":[{"url":"https://github.com/nltk/nltk","source":"disclosure@vulncheck.com"},{"url":"https://github.com/nltk/nltk/blob/v3.10.2/nltk/picklesec.py#L119-L124","source":"disclosure@vulncheck.com"},{"url":"https://github.com/nltk/nltk/commit/c3e37113742a1ebeeb4f2ca58941f320f98805ea","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/nltk-through-remote-code-execution-via-allowlistunpickler-dotted-name-bypass","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-71514","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T14:16:33.560","lastModified":"2026-09-02T17:44:12.820","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus root with crubadan_code, the column-0 value read from the corpus table.txt mapping file, and opens the result with the builtin open() rather than the pathsec-validated opener, so os.path.join discards the root when that value is absolute and the read escapes the corpus directory without the containment check nltk.pathsec applies when ENFORCE is set. An attacker who controls a corpus package can disclose file contents outside the corpus root through lang_freq, limited to paths ending in -3grams.txt whose contents parse as token count lines."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"nltk","product":"nltk","defaultStatus":"unaffected","packageURL":"pkg:pypi/nltk","versions":[{"version":"3.9.4","lessThan":"3.10.3","versionType":"semver","status":"affected"},{"version":"3.10.3","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.0,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":2.5,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.0,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":3.3,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T19:17:52.544723Z","id":"CVE-2026-71514","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9.4","versionEndIncluding":"3.10.2","matchCriteriaId":"701E22F9-F9B0-4F41-8EA1-0AF35C555D96"}]}]}],"references":[{"url":"https://github.com/nltk/nltk","source":"disclosure@vulncheck.com","tags":["Product"]},{"url":"https://github.com/nltk/nltk/blob/v3.10.2/nltk/corpus/reader/crubadan.py#L90-L98","source":"disclosure@vulncheck.com","tags":["Patch"]},{"url":"https://github.com/nltk/nltk/commit/10d34b3f4fe3fec74b76527a409eb0acbac2e8ab","source":"disclosure@vulncheck.com","tags":["Patch"]},{"url":"https://www.vulncheck.com/advisories/nltk-through-path-traversal-via-crubadancorpusreader-pathsec-bypass","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-75866","sourceIdentifier":"9b29abf9-4ab0-4765-b253-1875cd9b441e","published":"2026-08-22T14:16:33.700","lastModified":"2026-08-26T16:51:19.490","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them.\n\nPunk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client registration. token dispatches on the grant_type in the request body, so a client registered for authorization_code alone can ask for client_credentials, and that arm passes the requested scope straight to the minter, which signs it into the at+jwt access token. authorize copies the query scope into the authorization code record without comparing it against the registration, leaving the optional consent hook as the only check between an arbitrary scope and the issued code. redirect_uris on the same client row is read and enforced.\n\nA registered client can obtain a correctly signed token carrying any scope it names, and a resource server running Punk::OAuth2::Checker accepts that token and honours the scope. A client registered without a secret authenticates on its client_id alone, so anyone who knows that identifier can request one."}],"affected":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","affectedData":[{"defaultStatus":"unaffected","collectionURL":"https://cpan.org/modules","packageName":"Punk-OAuth2","modules":["Punk::OAuth2::Server"],"programFiles":["include/pox/pox_server.h"],"programRoutines":[{"name":"Punk::OAuth2::Server::token"},{"name":"Punk::OAuth2::Server::authorize"}],"packageURL":"pkg:cpan/Punk-OAuth2","versions":[{"version":"0","lessThanOrEqual":"0.03","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-25T19:29:05.610651Z","id":"CVE-2026-75866","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://datatracker.ietf.org/doc/html/rfc6749#section-3.3","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://datatracker.ietf.org/doc/html/rfc6749#section-5.2","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://metacpan.org/release/LNATION/Punk-OAuth2-0.03/view/lib/Punk/OAuth2/Server/Store.pm","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://metacpan.org/release/LNATION/Punk-OAuth2-0.04/changes","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/22/6","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-75870","sourceIdentifier":"9b29abf9-4ab0-4765-b253-1875cd9b441e","published":"2026-08-22T14:16:33.813","lastModified":"2026-08-26T16:51:19.490","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret.\n\nThe session keyword freezes its options onto the application as given: it does not require a secret, warn, or refuse to start when one is absent. The cookie read and the write-back both default that key to the empty string, so a declaration with no secret option, or with an undefined or empty one, signs and verifies with a zero-length HMAC-SHA256 key.\n\nAn attacker who knows the cookie format can then mint one offline carrying any contents the session holds, such as a user identifier or a role. Nothing marks the misconfiguration at runtime: cookies are well formed and sessions round-trip as expected."}],"affected":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","affectedData":[{"defaultStatus":"unaffected","collectionURL":"https://cpan.org/modules","packageName":"Punk","modules":["Punk"],"programFiles":["xs/app.xs","include/punk/punk_session.h"],"programRoutines":[{"name":"Punk::App::session"},{"name":"ps_load"},{"name":"ps_writeback"}],"packageURL":"pkg:cpan/Punk","versions":[{"version":"0","lessThan":"0.18","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-25T19:27:34.454527Z","id":"CVE-2026-75870","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary","description":[{"lang":"en","value":"CWE-1394"}]}],"references":[{"url":"https://metacpan.org/release/LNATION/Punk-0.17/source/include/punk/punk_session.h","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://metacpan.org/release/LNATION/Punk-0.17/view/lib/Punk.pm","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://metacpan.org/release/LNATION/Punk-0.18/source/Changes","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/22/5","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-62383","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T15:16:17.883","lastModified":"2026-08-27T21:43:41.613","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by calling channels(), domains(), categories(), or fileids() methods with the symlink filename."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"nltk","product":"nltk","defaultStatus":"unaffected","packageURL":"pkg:pypi/nltk","versions":[{"version":"3.10.0","lessThan":"3.10.2","versionType":"semver","status":"affected"},{"version":"3.10.2","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T15:55:30.683365Z","id":"CVE-2026-62383","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*","versionStartIncluding":"3.10.0","versionEndExcluding":"3.10.2","matchCriteriaId":"E99F75B8-E30B-4135-8CA1-A4EDF2737C42"}]}]}],"references":[{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-3hhw-38pf-pxj6","source":"disclosure@vulncheck.com","tags":["Exploit","Mitigation","Vendor Advisory"]},{"url":"https://www.vulncheck.com/advisories/nltk-ipipancorpusreader-symlink-arbitrary-file-read","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-62384","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T15:16:18.700","lastModified":"2026-09-02T17:52:40.223","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass the path validation guard and are resolved to files outside the intended corpus root when accessed via frame_by_name(), _lu_file(), or doc() methods."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"nltk","product":"nltk","defaultStatus":"unaffected","packageURL":"pkg:pypi/nltk","versions":[{"version":"3.10.0","lessThan":"3.10.2","versionType":"semver","status":"affected"},{"version":"3.10.2","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T18:39:17.570737Z","id":"CVE-2026-62384","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*","versionStartIncluding":"3.10.0","versionEndExcluding":"3.10.2","matchCriteriaId":"E99F75B8-E30B-4135-8CA1-A4EDF2737C42"}]}]}],"references":[{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-f833-7jw8-xwrv","source":"disclosure@vulncheck.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://www.vulncheck.com/advisories/nltk-framenetcorpusreader-symlink-sandbox-bypass-before","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]},{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-f833-7jw8-xwrv","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-62385","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T15:16:18.833","lastModified":"2026-08-31T18:50:08.490","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attackers can exploit frame_by_name, doc, lu, and header methods with crafted parameters to read arbitrary XML files accessible to the application."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"nltk","product":"nltk","defaultStatus":"unaffected","packageURL":"pkg:pypi/nltk","versions":[{"version":"0","lessThan":"3.10.0","versionType":"semver","status":"affected"},{"version":"3.10.0","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T19:07:48.518788Z","id":"CVE-2026-62385","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-73"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*","versionEndExcluding":"3.10.0","matchCriteriaId":"653A48E1-BCC5-4342-B5DF-E8D71A83BCB9"}]}]}],"references":[{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-568f-pv23-39p4","source":"disclosure@vulncheck.com","tags":["Exploit","Vendor Advisory","Mitigation"]},{"url":"https://www.vulncheck.com/advisories/nltk-path-traversal-via-framenet-and-nkjp-readers","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]},{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-568f-pv23-39p4","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Vendor Advisory","Mitigation"]}]}},{"cve":{"id":"CVE-2026-62388","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T15:16:18.967","lastModified":"2026-08-27T19:54:52.643","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"nltk","product":"nltk","defaultStatus":"unaffected","packageURL":"pkg:pypi/nltk","versions":[{"version":"0","lessThan":"3.10.0","versionType":"semver","status":"affected"},{"version":"3.10.0","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T17:53:47.950536Z","id":"CVE-2026-62388","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1188"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*","versionEndExcluding":"3.10.0","matchCriteriaId":"653A48E1-BCC5-4342-B5DF-E8D71A83BCB9"}]}]}],"references":[{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-p3m8-78j2-g5p3","source":"disclosure@vulncheck.com","tags":["Exploit","Mitigation","Vendor Advisory"]},{"url":"https://www.vulncheck.com/advisories/nltk-before-insecure-default-configuration-pathsec","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]},{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-p3m8-78j2-g5p3","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Mitigation","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-63310","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T15:16:19.100","lastModified":"2026-08-31T18:48:58.893","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"nltk","product":"nltk","defaultStatus":"unaffected","packageURL":"pkg:pypi/nltk","versions":[{"version":"0","lessThan":"3.9.3","versionType":"semver","status":"affected"},{"version":"3.9.3","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T19:05:46.890115Z","id":"CVE-2026-63310","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-494"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*","versionEndExcluding":"3.9.3","matchCriteriaId":"22061B61-87EB-4006-8152-23CD3514C2AE"}]}]}],"references":[{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-5wp5-5229-5g6q","source":"disclosure@vulncheck.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://www.vulncheck.com/advisories/nltk-before-missing-post-download-integrity-verification","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-63311","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T15:16:19.233","lastModified":"2026-08-27T19:42:17.577","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the validate_network_url() function in nltk/pathsec.py. The _resolve_hostname() helper catches OSError and ValueError during socket.getaddrinfo() and returns an empty list; when DNS resolution fails, the validation loop executes no IP checks and the function fails open, allowing urlopen() to proceed without validation. An attacker who can trigger DNS resolution failures or use DNS rebinding can bypass SSRF protections and reach restricted network resources, including cloud metadata endpoints (e.g., 169.254.169.254)."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"nltk","product":"nltk","defaultStatus":"unaffected","packageURL":"pkg:pypi/nltk","versions":[{"version":"0","lessThan":"3.10.0","versionType":"semver","status":"affected"},{"version":"3.10.0","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T15:58:19.898915Z","id":"CVE-2026-63311","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*","versionEndExcluding":"3.10.0","matchCriteriaId":"653A48E1-BCC5-4342-B5DF-E8D71A83BCB9"}]}]}],"references":[{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-3gqm-fcw5-w839","source":"disclosure@vulncheck.com","tags":["Exploit","Mitigation","Vendor Advisory"]},{"url":"https://www.vulncheck.com/advisories/nltk-before-ssrf-via-dns-resolution-failure","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-63312","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T15:16:19.367","lastModified":"2026-08-31T18:40:02.810","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"nltk","product":"nltk","defaultStatus":"unaffected","packageURL":"pkg:pypi/nltk","versions":[{"version":"0","lessThan":"3.10.0","versionType":"semver","status":"affected"},{"version":"3.10.0","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T18:34:08.045876Z","id":"CVE-2026-63312","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*","versionEndExcluding":"3.10.0","matchCriteriaId":"653A48E1-BCC5-4342-B5DF-E8D71A83BCB9"}]}]}],"references":[{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-x5ph-mj9p-rfr8","source":"disclosure@vulncheck.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://www.vulncheck.com/advisories/nltk-streambackedcorpusview-bypasses-pathsec-enforce-arbitrary-file-read","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]},{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-x5ph-mj9p-rfr8","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-65915","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T15:16:19.500","lastModified":"2026-08-31T18:39:00.647","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to nltk.data.load() to read arbitrary files accessible to the process user, including credentials and configuration files."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"nltk","product":"nltk","defaultStatus":"unaffected","packageURL":"pkg:pypi/nltk","versions":[{"version":"0","lessThan":"3.10.0","versionType":"semver","status":"affected"},{"version":"3.10.0","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T19:20:34.826563Z","id":"CVE-2026-65915","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*","versionEndExcluding":"3.10.0","matchCriteriaId":"653A48E1-BCC5-4342-B5DF-E8D71A83BCB9"}]}]}],"references":[{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-72r2-7mfr-5xr9","source":"disclosure@vulncheck.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://www.vulncheck.com/advisories/nltk-before-arbitrary-file-read-via-filesystempathpointer","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]},{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-72r2-7mfr-5xr9","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-66393","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T15:16:19.633","lastModified":"2026-08-27T14:47:55.913","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the recursion limit to trigger an unhandled RecursionError that crashes the Python process."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"nltk","product":"nltk","defaultStatus":"unaffected","packageURL":"pkg:pypi/nltk","versions":[{"version":"0","lessThan":"3.9.4","versionType":"semver","status":"affected"},{"version":"3.9.4","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T17:54:42.004486Z","id":"CVE-2026-66393","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-674"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*","versionEndExcluding":"3.9.4","matchCriteriaId":"A5471378-2B80-492B-B6BC-E6E9AE4F5179"}]}]}],"references":[{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-rf74-v2fm-23pw","source":"disclosure@vulncheck.com","tags":["Exploit","Mitigation","Vendor Advisory"]},{"url":"https://www.vulncheck.com/advisories/nltk-before-denial-of-service-via-jsontaggeddecoder","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]},{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-rf74-v2fm-23pw","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Mitigation","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-68766","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T15:16:20.633","lastModified":"2026-08-24T19:16:43.757","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files with malicious options to append attacker-controlled content to arbitrary files, enabling code execution when targeting shell startup files."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"hashcat","product":"hashcat","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T18:24:27.695544Z","id":"CVE-2026-68766","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-88"}]}],"references":[{"url":"https://github.com/hashcat/hashcat","source":"disclosure@vulncheck.com"},{"url":"https://github.com/hashcat/hashcat/blob/v7.1.2/src/restore.c#L365-L369","source":"disclosure@vulncheck.com"},{"url":"https://github.com/hashcat/hashcat/commit/fcae69f2438ff8eae0dc8e206b78067a1e465ed4","source":"disclosure@vulncheck.com"},{"url":"https://github.com/hashcat/hashcat/issues/4738","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/hashcat-through-arbitrary-file-write-via-restore-file-option-injection","source":"disclosure@vulncheck.com"},{"url":"https://github.com/hashcat/hashcat/issues/4738","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-68767","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T15:16:20.770","lastModified":"2026-08-26T17:17:09.923","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers can trigger this out-of-bounds heap write by providing a hash file, potfile, or wordlist containing a line of exactly HCBUFSIZ_LARGE bytes."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"hashcat","product":"hashcat","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T15:55:33.117805Z","id":"CVE-2026-68767","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-193"}]}],"references":[{"url":"https://github.com/hashcat/hashcat","source":"disclosure@vulncheck.com"},{"url":"https://github.com/hashcat/hashcat/blob/v7.1.2/src/filehandling.c#L1032-L1060","source":"disclosure@vulncheck.com"},{"url":"https://github.com/hashcat/hashcat/commit/93b55d37d3b2340013d4036f10181ddc67d44249","source":"disclosure@vulncheck.com"},{"url":"https://github.com/hashcat/hashcat/issues/4739","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/hashcat-through-off-by-one-out-of-bounds-heap-write-in-fgetl","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-68768","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T15:16:20.903","lastModified":"2026-08-24T19:16:44.250","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. When assembling output into a fixed-size buffer (HCBUFSIZ_LARGE, ~16 MB), the function sequentially appends the username, separator, hash, and plaintext via memcpy without validating that the accumulated length stays within the buffer capacity. When run with --username --show against a crafted hash file containing an oversized username that nearly fills the buffer, the total assembled output exceeds the buffer, causing a heap buffer overflow that can corrupt memory and crash the process."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"hashcat","product":"hashcat","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7.1.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T18:31:30.947115Z","id":"CVE-2026-68768","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"references":[{"url":"https://github.com/hashcat/hashcat","source":"disclosure@vulncheck.com"},{"url":"https://github.com/hashcat/hashcat/blob/v7.1.2/src/outfile.c#L654-L668","source":"disclosure@vulncheck.com"},{"url":"https://github.com/hashcat/hashcat/commit/68f56a2d8712867a8520bf4dcf07f6145c23df89","source":"disclosure@vulncheck.com"},{"url":"https://github.com/hashcat/hashcat/issues/4740","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/hashcat-through-heap-buffer-overflow-in-outfile-write-via-oversized-username","source":"disclosure@vulncheck.com"},{"url":"https://github.com/hashcat/hashcat/issues/4740","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-6258","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T15:16:21.033","lastModified":"2026-08-22T15:16:21.033","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-70626","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-22T15:16:21.100","lastModified":"2026-08-31T19:09:01.757","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root. The vulnerability exists because path validation is lexical and does not account for symlink resolution, enabling attackers to place symlinks inside the corpus root to access files outside the intended boundary."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"nltk","product":"nltk","defaultStatus":"unaffected","packageURL":"pkg:pypi/nltk","versions":[{"version":"0","lessThan":"3.9.4","versionType":"semver","status":"affected"},{"version":"3.9.4","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":6.2,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.5,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T19:49:24.557944Z","id":"CVE-2026-70626","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-59"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*","versionEndExcluding":"3.9.4","matchCriteriaId":"A5471378-2B80-492B-B6BC-E6E9AE4F5179"}]}]}],"references":[{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-r6gq-whwq-mvg9","source":"disclosure@vulncheck.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://www.vulncheck.com/advisories/nltk-before-symlink-escape-via-corpusreader","source":"disclosure@vulncheck.com","tags":["Vendor Advisory"]},{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-r6gq-whwq-mvg9","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-74584","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T15:16:21.230","lastModified":"2026-08-25T06:18:32.357","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: zero shared page before exposing to userspace\n\nbnxt_re_alloc_ucontext() allocates uctx->shpg via\n__get_free_page(GFP_KERNEL). The buddy allocator does not zero pages\nwithout __GFP_ZERO, so the page contains stale kernel data from\nwhatever object most recently freed it.\n\nThe page is then mapped into userspace via vm_insert_page() under\nBNXT_RE_MMAP_SH_PAGE in bnxt_re_mmap(). The driver only ever writes\n4 bytes (a u32 AVID) at offset BNXT_RE_AVID_OFFT (0x10) inside\nbnxt_re_create_ah(); the remaining 4092 bytes of the page are exposed\nto userspace unsanitised, leaking kernel memory contents.\n\nAny user with access to /dev/infiniband/uverbsX on a host with a\nbnxt_re device (typically rdma group membership) can read this data\nvia a single mmap() at pgoff 0 after IB_USER_VERBS_CMD_GET_CONTEXT.\n\nOther shared pages in the same file already use get_zeroed_page()\ncorrectly:\n\n  drivers/infiniband/hw/bnxt_re/ib_verbs.c\n      srq->uctx_srq_page = (void *)get_zeroed_page(GFP_KERNEL);\n      cq->uctx_cq_page  = (void *)get_zeroed_page(GFP_KERNEL);\n\nuctx->shpg is the only outlier. Bring it in line with the existing\nconvention by switching to get_zeroed_page()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/hw/bnxt_re/ib_verbs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1ac5a404797523cedaf424a3aaa3cf8f9548dff8","lessThan":"53c97e9882f4e747b4ac31b211317c2eba541af9","versionType":"git","status":"affected"},{"version":"1ac5a404797523cedaf424a3aaa3cf8f9548dff8","lessThan":"9896bdfd21d918e9f26a52bc6109cc77970ee0b1","versionType":"git","status":"affected"},{"version":"1ac5a404797523cedaf424a3aaa3cf8f9548dff8","lessThan":"9128c2411b83a64c0a69d2ff059c741bde25a9cc","versionType":"git","status":"affected"},{"version":"1ac5a404797523cedaf424a3aaa3cf8f9548dff8","lessThan":"c19b360fa10c521c0b681875cdaa51545d45a491","versionType":"git","status":"affected"},{"version":"1ac5a404797523cedaf424a3aaa3cf8f9548dff8","lessThan":"a3ed2daab02b2a706e882ad31b5c3c4f33cb5bb1","versionType":"git","status":"affected"},{"version":"1ac5a404797523cedaf424a3aaa3cf8f9548dff8","lessThan":"e2b143df29003d2704b51f62e9297006953dbacb","versionType":"git","status":"affected"},{"version":"1ac5a404797523cedaf424a3aaa3cf8f9548dff8","lessThan":"c75f8ce4baa29ae57fe615c6a2c5101f59b8b89a","versionType":"git","status":"affected"},{"version":"1ac5a404797523cedaf424a3aaa3cf8f9548dff8","lessThan":"f6b079629becfa977f9c51fe53ad2e6dcc55ef44","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/hw/bnxt_re/ib_verbs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.11","status":"affected"},{"version":"0","lessThan":"4.11","versionType":"semver","status":"unaffected"},{"version":"5.10.260","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.211","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.177","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.144","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.95","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.37","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.14","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.5,"impactScore":4.0}]},"references":[{"url":"https://git.kernel.org/stable/c/53c97e9882f4e747b4ac31b211317c2eba541af9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9128c2411b83a64c0a69d2ff059c741bde25a9cc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9896bdfd21d918e9f26a52bc6109cc77970ee0b1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3ed2daab02b2a706e882ad31b5c3c4f33cb5bb1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c19b360fa10c521c0b681875cdaa51545d45a491","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c75f8ce4baa29ae57fe615c6a2c5101f59b8b89a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2b143df29003d2704b51f62e9297006953dbacb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f6b079629becfa977f9c51fe53ad2e6dcc55ef44","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-76571","sourceIdentifier":"security@joomla.org","published":"2026-08-22T15:16:21.383","lastModified":"2026-08-26T16:36:16.990","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 - The condition parameter passed to a list filter is concatenated verbatim into the WHERE clause built by getFilterQuery(). An unauthenticated attacker can supply arbitrary SQL through the filter condition, giving full read of the database."}],"affected":[{"source":"security@joomla.org","affectedData":[{"vendor":"fabrikar.com","product":"Fabrik extension for Joomla","defaultStatus":"unaffected","versions":[{"version":"1.0.0-4.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@joomla.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T18:29:28.614511Z","id":"CVE-2026-76571","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@joomla.org","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://www.fabrikar.com/","source":"security@joomla.org"}]}},{"cve":{"id":"CVE-2026-76596","sourceIdentifier":"security@joomla.org","published":"2026-08-22T15:16:21.500","lastModified":"2026-08-26T16:35:20.160","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks ACL gates, a plain GET empties the target list's table"}],"affected":[{"source":"security@joomla.org","affectedData":[{"vendor":"fabrikar.com","product":"Fabrik extension for Joomla","defaultStatus":"unaffected","versions":[{"version":"1.0.0-4.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@joomla.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:40:17.501357Z","id":"CVE-2026-76596","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@joomla.org","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://www.fabrikar.com/","source":"security@joomla.org"}]}},{"cve":{"id":"CVE-2026-76597","sourceIdentifier":"security@joomla.org","published":"2026-08-22T15:16:21.620","lastModified":"2026-08-26T16:35:20.160","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 - The list email plugin controller allows to upload non-executable files to the webroot."}],"affected":[{"source":"security@joomla.org","affectedData":[{"vendor":"fabrikar.com","product":"Fabrik extension for Joomla","defaultStatus":"unaffected","versions":[{"version":"1.0.0-4.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@joomla.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:39:37.638083Z","id":"CVE-2026-76597","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@joomla.org","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://www.fabrikar.com/","source":"security@joomla.org"}]}},{"cve":{"id":"CVE-2026-76598","sourceIdentifier":"security@joomla.org","published":"2026-08-22T15:16:21.733","lastModified":"2026-08-26T16:35:20.160","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2 - The onAjax_getFolders method of the elements model allows arbitrary directory listings."}],"affected":[{"source":"security@joomla.org","affectedData":[{"vendor":"fabrikar.com","product":"Fabrik extension for Joomla","defaultStatus":"unaffected","versions":[{"version":"1.0.0-4.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@joomla.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:40:05.831722Z","id":"CVE-2026-76598","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@joomla.org","type":"Secondary","description":[{"lang":"en","value":"CWE-22"},{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://www.fabrikar.com/","source":"security@joomla.org"}]}},{"cve":{"id":"CVE-2026-76599","sourceIdentifier":"security@joomla.org","published":"2026-08-22T15:16:21.857","lastModified":"2026-08-26T16:36:16.990","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2 - The ajax_tables method of the elements model allows listings of arbitrary database tables including columns."}],"affected":[{"source":"security@joomla.org","affectedData":[{"vendor":"fabrikar.com","product":"Fabrik extension for Joomla","defaultStatus":"unaffected","versions":[{"version":"1.0.0-4.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@joomla.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T18:30:10.442619Z","id":"CVE-2026-76599","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@joomla.org","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://www.fabrikar.com/","source":"security@joomla.org"}]}},{"cve":{"id":"CVE-2026-76600","sourceIdentifier":"security@joomla.org","published":"2026-08-22T15:16:21.970","lastModified":"2026-08-26T16:35:20.160","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik < 4.7.2 - The DeleteComment endpoint did not perform any access checks."}],"affected":[{"source":"security@joomla.org","affectedData":[{"vendor":"fabrikar.com","product":"Fabrik extension for Joomla","defaultStatus":"unaffected","versions":[{"version":"1.0.0-4.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@joomla.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:40:36.921821Z","id":"CVE-2026-76600","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@joomla.org","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://www.fabrikar.com/","source":"security@joomla.org"}]}},{"cve":{"id":"CVE-2026-76601","sourceIdentifier":"security@joomla.org","published":"2026-08-22T15:16:22.090","lastModified":"2026-08-26T16:35:20.160","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugin did not perform any access checks."}],"affected":[{"source":"security@joomla.org","affectedData":[{"vendor":"fabrikar.com","product":"Fabrik extension for Joomla","defaultStatus":"unaffected","versions":[{"version":"1.0.0-4.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@joomla.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:41:35.906581Z","id":"CVE-2026-76601","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@joomla.org","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://www.fabrikar.com/","source":"security@joomla.org"}]}},{"cve":{"id":"CVE-2026-76602","sourceIdentifier":"security@joomla.org","published":"2026-08-22T15:16:22.200","lastModified":"2026-08-26T16:35:20.160","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors."}],"affected":[{"source":"security@joomla.org","affectedData":[{"vendor":"fabrikar.com","product":"Fabrik extension for Joomla","defaultStatus":"unaffected","versions":[{"version":"1.0.0-4.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@joomla.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:39:20.939174Z","id":"CVE-2026-76602","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@joomla.org","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://www.fabrikar.com/","source":"security@joomla.org"}]}},{"cve":{"id":"CVE-2026-76603","sourceIdentifier":"security@joomla.org","published":"2026-08-22T15:16:22.320","lastModified":"2026-08-26T16:36:16.990","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Joomla Extension - fabrikar.com - Unauthenticated row disclosure via form.inlineedit in Fabrik < 4.7.2 - The inineedit form controller does not perform any access checks, disclosing items to unauthorized users."}],"affected":[{"source":"security@joomla.org","affectedData":[{"vendor":"fabrikar.com","product":"Fabrik extension for Joomla","defaultStatus":"unaffected","versions":[{"version":"1.0.0-4.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@joomla.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T18:28:46.196123Z","id":"CVE-2026-76603","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@joomla.org","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://www.fabrikar.com/","source":"security@joomla.org"}]}},{"cve":{"id":"CVE-2026-76604","sourceIdentifier":"security@joomla.org","published":"2026-08-22T15:16:22.440","lastModified":"2026-08-26T16:35:20.160","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable to the execution of user provided codes."}],"affected":[{"source":"security@joomla.org","affectedData":[{"vendor":"fabrikar.com","product":"Fabrik extension for Joomla","defaultStatus":"unaffected","versions":[{"version":"1.0.0-4.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@joomla.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:40:51.127205Z","id":"CVE-2026-76604","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@joomla.org","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://www.fabrikar.com/","source":"security@joomla.org"}]}},{"cve":{"id":"CVE-2026-76605","sourceIdentifier":"security@joomla.org","published":"2026-08-22T15:16:22.563","lastModified":"2026-08-26T16:35:20.160","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2."}],"affected":[{"source":"security@joomla.org","affectedData":[{"vendor":"fabrikar.com","product":"Fabrik extension for Joomla","defaultStatus":"unaffected","versions":[{"version":"1.0.0-4.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@joomla.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:39:51.004430Z","id":"CVE-2026-76605","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@joomla.org","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://www.fabrikar.com/","source":"security@joomla.org"}]}},{"cve":{"id":"CVE-2026-76606","sourceIdentifier":"security@joomla.org","published":"2026-08-22T15:16:22.680","lastModified":"2026-08-26T16:35:20.160","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2."}],"affected":[{"source":"security@joomla.org","affectedData":[{"vendor":"fabrikar.com","product":"Fabrik extension for Joomla","defaultStatus":"unaffected","versions":[{"version":"1.0.0-4.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@joomla.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:38:46.402579Z","id":"CVE-2026-76606","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@joomla.org","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://www.fabrikar.com/","source":"security@joomla.org"}]}},{"cve":{"id":"CVE-2026-76607","sourceIdentifier":"security@joomla.org","published":"2026-08-22T15:16:22.797","lastModified":"2026-08-26T16:35:20.160","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2."}],"affected":[{"source":"security@joomla.org","affectedData":[{"vendor":"fabrikar.com","product":"Fabrik extension for Joomla","defaultStatus":"unaffected","versions":[{"version":"1.0.0-4.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@joomla.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:41:03.657315Z","id":"CVE-2026-76607","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@joomla.org","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://www.fabrikar.com/","source":"security@joomla.org"}]}},{"cve":{"id":"CVE-2026-76608","sourceIdentifier":"security@joomla.org","published":"2026-08-22T15:16:22.913","lastModified":"2026-08-26T16:35:20.160","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access checks."}],"affected":[{"source":"security@joomla.org","affectedData":[{"vendor":"fabrikar.com","product":"Fabrik extension for Joomla","defaultStatus":"unaffected","versions":[{"version":"1.0.0-4.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@joomla.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:41:24.403435Z","id":"CVE-2026-76608","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@joomla.org","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://www.fabrikar.com/","source":"security@joomla.org"}]}},{"cve":{"id":"CVE-2026-76609","sourceIdentifier":"security@joomla.org","published":"2026-08-22T15:16:23.030","lastModified":"2026-08-26T16:35:20.160","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Joomla Extension - fabrikar.com - Unauthenticated modification of any comment in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks."}],"affected":[{"source":"security@joomla.org","affectedData":[{"vendor":"fabrikar.com","product":"Fabrik extension for Joomla","defaultStatus":"unaffected","versions":[{"version":"1.0.0-4.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@joomla.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:41:15.145640Z","id":"CVE-2026-76609","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@joomla.org","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://www.fabrikar.com/","source":"security@joomla.org"}]}},{"cve":{"id":"CVE-2026-77027","sourceIdentifier":"security@joomla.org","published":"2026-08-22T15:16:23.150","lastModified":"2026-08-26T16:35:20.160","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of user supplied input in the jsactions feature leads to an stored XSS vector."}],"affected":[{"source":"security@joomla.org","affectedData":[{"vendor":"fabrikar.com","product":"Fabrik extension for Joomla","defaultStatus":"unaffected","versions":[{"version":"1.0.0-4.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@joomla.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:39:10.816252Z","id":"CVE-2026-77027","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@joomla.org","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://www.fabrikar.com/","source":"security@joomla.org"}]}},{"cve":{"id":"CVE-2026-77992","sourceIdentifier":"security@joomla.org","published":"2026-08-22T15:16:23.293","lastModified":"2026-08-26T16:35:20.160","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks."}],"affected":[{"source":"security@joomla.org","affectedData":[{"vendor":"fabrikar.com","product":"Fabrik extension for Joomla","defaultStatus":"unaffected","versions":[{"version":"1.0.0-4.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@joomla.org","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.5,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:40:27.244200Z","id":"CVE-2026-77992","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@joomla.org","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://www.fabrikar.com/","source":"security@joomla.org"}]}},{"cve":{"id":"CVE-2026-4703","sourceIdentifier":"security@wordfence.com","published":"2026-08-22T16:16:29.497","lastModified":"2026-08-24T16:41:13.950","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"westguard","product":"WS Form LITE – Drag & Drop Contact Form Builder","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.10.80","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:38:07.677721Z","id":"CVE-2026-4703","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-502"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/ws-form/trunk/includes/class-ws-form-common.php#L7154","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/ws-form/trunk/includes/core/class-ws-form-submit.php#L1061","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3489609/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/df36eae9-6f2b-432c-a765-57450939b344?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-74585","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:30.560","lastModified":"2026-08-22T16:16:30.560","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: Bound the DROM dual link port number before indexing sw->ports\n\ntb_drom_parse_entry_port() validates the device-supplied header->index\nagainst sw->config.max_port_number before indexing sw->ports[], but the\nsibling field entry->dual_link_port_nr -- a 6-bit value also read from\nthe DROM -- indexes the same array with no such check. A malicious or\nmalformed Thunderbolt device can set dual_link_port_nr beyond the\nallocated sw->ports[] (max_port_number + 1 entries), producing an\nout-of-bounds tb_port pointer that is stored and later dereferenced.\n\nReject a port entry whose dual_link_port_nr exceeds max_port_number,\nthe same bound already applied to header->index."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/thunderbolt/eeprom.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6","lessThan":"6c892ed9f4129ae40ef0f92e1bb31aa0b0ddc72c","versionType":"git","status":"affected"},{"version":"cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6","lessThan":"3d3c212b70633332ab71672aa2bc6af257d2ec83","versionType":"git","status":"affected"},{"version":"cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6","lessThan":"b98e1e28bd95b0fa33164eec1e763d26c7058b39","versionType":"git","status":"affected"},{"version":"cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6","lessThan":"50f0c8dd8c3390f851cfb97ca13116f9ee6469d1","versionType":"git","status":"affected"},{"version":"cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6","lessThan":"f28066057134aa9294caa597b670daf505ad9dce","versionType":"git","status":"affected"},{"version":"cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6","lessThan":"40d2ffb74094cf36edbe05855566a4c58b6ce808","versionType":"git","status":"affected"},{"version":"cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6","lessThan":"f32c3a9a77cfb50934a60b05d5407649af062535","versionType":"git","status":"affected"},{"version":"cd22e73bdf5eff7e68a0f8bdfbce123ad43651f6","lessThan":"d6764992f17b23d91ff93ce905ab53c2aa7191f0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/thunderbolt/eeprom.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.17","status":"affected"},{"version":"0","lessThan":"3.17","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3d3c212b70633332ab71672aa2bc6af257d2ec83","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/40d2ffb74094cf36edbe05855566a4c58b6ce808","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/50f0c8dd8c3390f851cfb97ca13116f9ee6469d1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c892ed9f4129ae40ef0f92e1bb31aa0b0ddc72c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b98e1e28bd95b0fa33164eec1e763d26c7058b39","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d6764992f17b23d91ff93ce905ab53c2aa7191f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f28066057134aa9294caa597b670daf505ad9dce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f32c3a9a77cfb50934a60b05d5407649af062535","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74586","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:30.687","lastModified":"2026-08-25T06:18:32.713","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: clear new_transport when removing a peer\n\nsctp_process_asconf_param() stores a newly added peer transport in\nasoc->new_transport. After all parameters in the ASCONF chunk have been\nprocessed, sctp_sf_do_asconf() uses this pointer to send a HEARTBEAT to the\nnew transport.\n\nAn authenticated ASCONF from a remote SCTP peer can add a transport and\nremove it again with a wildcard DEL-IP parameter in the same chunk. The\nwildcard deletion preserves the transport on which the ASCONF arrived, but\nremoves the newly added transport through\nsctp_assoc_del_nonprimary_peers(). The removal does not clear\nasoc->new_transport, leaving it pointing to the removed transport.\n\nsctp_sf_do_asconf() then creates a HEARTBEAT whose chunk->transport points\nto the removed transport without holding a transport reference. During\nlocal address replacement, src_out_of_asoc_ok keeps this HEARTBEAT on\ncontrol_chunk_list. After the transport is freed by RCU, a successful\nASCONF_ACK for the replacement address releases the queued HEARTBEAT and\nsctp_outq_select_transport() reads the freed transport's state.\n\nThe issue was found during a static audit of SCTP objects. With an\nauthenticated peer, the reproducer triggered the same KASAN report in 2\nof 2 unpatched runs on a KASAN-enabled netdev/main kernel:\n\n  BUG: KASAN: slab-use-after-free in sctp_outq_select_transport\n  Read of size 4 at addr ffff88800b9bd95c by task python3/197\n\n  Call Trace:\n   sctp_outq_select_transport+0x549/0x8b0 [sctp]\n   sctp_outq_flush+0x306/0x2c60 [sctp]\n   sctp_transport_immediate_rtx+0xaf/0x260 [sctp]\n   sctp_process_asconf_ack+0xa48/0xf70 [sctp]\n\n  Allocated by task 197:\n   sctp_transport_new+0x68/0x650 [sctp]\n   sctp_assoc_add_peer+0x258/0x12a0 [sctp]\n   sctp_process_asconf+0x5e9/0x1090 [sctp]\n\n  Last potentially related work creation:\n   __call_rcu_common.constprop.0+0x77/0xb70\n   sctp_assoc_del_nonprimary_peers+0x7c/0xd0 [sctp]\n   sctp_process_asconf+0xd9c/0x1090 [sctp]\n\nThe first invalid access was a four-byte read of transport->state at\nnet/sctp/outqueue.c:833. The same reproducer completed the full\nauthenticated ASCONF and local-address replacement sequence with this\nchange without a KASAN report or oops.\n\nClear new_transport when its peer is removed, before it can be used to\ncreate the HEARTBEAT."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sctp/associola.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6af29ccc223b0feb6fc6112281c3fa3cdb1afddf","lessThan":"c0f973bb5118dd1b146cda3fcc8af6f6057befec","versionType":"git","status":"affected"},{"version":"6af29ccc223b0feb6fc6112281c3fa3cdb1afddf","lessThan":"3b539b317cd052236fed0350364ff1268996ba46","versionType":"git","status":"affected"},{"version":"6af29ccc223b0feb6fc6112281c3fa3cdb1afddf","lessThan":"db9d8e3b670f841755bc2018f178472dc6064d27","versionType":"git","status":"affected"},{"version":"6af29ccc223b0feb6fc6112281c3fa3cdb1afddf","lessThan":"31efa656cf6aface26e88f038c14f22ee6ca1500","versionType":"git","status":"affected"},{"version":"6af29ccc223b0feb6fc6112281c3fa3cdb1afddf","lessThan":"291accf36febce751021888de5f15090f4875b56","versionType":"git","status":"affected"},{"version":"6af29ccc223b0feb6fc6112281c3fa3cdb1afddf","lessThan":"ca33df36aa0143a1d04f57d2086020c12e7eddb7","versionType":"git","status":"affected"},{"version":"6af29ccc223b0feb6fc6112281c3fa3cdb1afddf","lessThan":"163847552a571bd55094291f4ffcdc1de0f14a7b","versionType":"git","status":"affected"},{"version":"6af29ccc223b0feb6fc6112281c3fa3cdb1afddf","lessThan":"beb33f8ee1ca83acddb2a5ae80f3d22ec550b4c3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sctp/associola.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.2","status":"affected"},{"version":"0","lessThan":"3.2","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/163847552a571bd55094291f4ffcdc1de0f14a7b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/291accf36febce751021888de5f15090f4875b56","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/31efa656cf6aface26e88f038c14f22ee6ca1500","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3b539b317cd052236fed0350364ff1268996ba46","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/beb33f8ee1ca83acddb2a5ae80f3d22ec550b4c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c0f973bb5118dd1b146cda3fcc8af6f6057befec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca33df36aa0143a1d04f57d2086020c12e7eddb7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/db9d8e3b670f841755bc2018f178472dc6064d27","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74587","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:30.830","lastModified":"2026-08-25T06:18:33.087","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix use-after-free of cached ASCONF chunk\n\naddip_last_asconf caches the outstanding outbound ASCONF chunk. The normal\nASCONF-ACK completion path releases the chunk and clears the pointer.\n\nHowever, sctp_asconf_queue_teardown() releases the cached chunk without\nclearing addip_last_asconf. During peer restart handling,\nsctp_sf_do_dupcook_a() queues SCTP_CMD_PURGE_ASCONF_QUEUE, which invokes\nsctp_asconf_queue_teardown() while the association remains alive and leaves\nthe pointer dangling.\n\nA delayed authenticated ASCONF-ACK can then reach sctp_sf_do_asconf_ack(),\nwhich accesses the stale chunk and passes it to sctp_process_asconf_ack(),\ncausing a use-after-free and a second release.\n\nClearing the pointer exposes a race with T4 expiry. Peer restart handling\nqueues the timer stop before the purge, but SCTP_CMD_TIMER_STOP uses\ntimer_delete(), which does not wait for a callback already running on\nanother CPU. Such a callback can reach sctp_sf_t4_timer_expire() after\nthe purge and dereference NULL.\n\nClear addip_last_asconf after releasing the cached chunk, and make\nsctp_sf_t4_timer_expire() consume a stale T4 expiry if no outstanding\nASCONF remains."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sctp/associola.c","net/sctp/sm_statefuns.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a000c01e60e40e15304ffe48fff051d17a7bea91","lessThan":"10459b03e2d9ee12435e96f587de4d4cacdbf435","versionType":"git","status":"affected"},{"version":"a000c01e60e40e15304ffe48fff051d17a7bea91","lessThan":"e1bb114e09372fd6e03387ced9ef566da336ed6c","versionType":"git","status":"affected"},{"version":"a000c01e60e40e15304ffe48fff051d17a7bea91","lessThan":"179676f0166230c80053a392303485b37c93dd33","versionType":"git","status":"affected"},{"version":"a000c01e60e40e15304ffe48fff051d17a7bea91","lessThan":"dc67d528c2fa939cec7fe3bf7f3089c8d281ca3d","versionType":"git","status":"affected"},{"version":"a000c01e60e40e15304ffe48fff051d17a7bea91","lessThan":"618b5c6d049896fcfabb91afc072954c92cb2693","versionType":"git","status":"affected"},{"version":"a000c01e60e40e15304ffe48fff051d17a7bea91","lessThan":"07daf4f9750104960a1d60831b2353c0d41f35fb","versionType":"git","status":"affected"},{"version":"a000c01e60e40e15304ffe48fff051d17a7bea91","lessThan":"d949992bc3f00027a2c755e860a11950c75f6073","versionType":"git","status":"affected"},{"version":"a000c01e60e40e15304ffe48fff051d17a7bea91","lessThan":"8c283e7b56adce00193837f3311b06662466fb21","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sctp/associola.c","net/sctp/sm_statefuns.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.0","status":"affected"},{"version":"0","lessThan":"3.0","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/07daf4f9750104960a1d60831b2353c0d41f35fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/10459b03e2d9ee12435e96f587de4d4cacdbf435","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/179676f0166230c80053a392303485b37c93dd33","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/618b5c6d049896fcfabb91afc072954c92cb2693","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8c283e7b56adce00193837f3311b06662466fb21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d949992bc3f00027a2c755e860a11950c75f6073","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc67d528c2fa939cec7fe3bf7f3089c8d281ca3d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e1bb114e09372fd6e03387ced9ef566da336ed6c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74588","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:30.960","lastModified":"2026-08-25T06:18:33.410","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: keep chunk->transport in step with the list it is queued on\n\n__sctp_outq_flush_rtx() moves a gap-acked chunk onto another transport's\ntransmitted list without updating chunk->transport:\n\n\tif (chunk->tsn_gap_acked) {\n\t\tlist_move_tail(&chunk->transmitted_list,\n\t\t\t       &transport->transmitted);\n\t\tcontinue;\n\t}\n\nThe chunk then sits on a live transport's list while chunk->transport still\nnames a different one.  If that transport is removed - sctp_assoc_rm_peer()\nfrom an ASCONF Delete-IP - sctp_transport_free() RCU-frees it and the chunk\nis left with a dangling pointer.  sctp_assoc_rm_peer() scrubs\npeer->transmitted and asoc->outqueue.out_chunk_list, but the chunk is on\nneither.\n\nThe pointer is not followed while tsn_gap_acked is set.  A SACK that\nreneges on the TSN clears the flag, and the next SACK reaches\n\n\ttchunk->transport->flight_size -= sctp_data_size(tchunk);\n\ninside the freed transport.  KASAN reports a slab-use-after-free read in\nsctp_check_transmitted(), freed from sctp_assoc_rm_peer().  Both the\nremoval and the SACKs come from the association peer.\n\nSet chunk->transport at the move.  The ordinary resend path needs nothing:\nit reaches its list_move_tail() only after sctp_packet_append_chunk()\nreturned SCTP_XMIT_OK, and __sctp_packet_append_chunk() has rebound the\nchunk by then.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sctp/outqueue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6575fb17230814b48b471727c8410c0aadff9274","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6b9e2ea2057113f3393990ba646d2d97c719a80d","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"874a7c2b5e184f06134fdfde27e9ce9271bafe58","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1adf929121e13e0b19200bb9fef715b918d483fe","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e2e7c1de0e226ca1b7fea2de57a6c9bca408709b","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2b3b5eec8b2c30ee237e3c31a6a38de9c39d804d","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5ccf35ef0ed6059cdf8b1f4606a6584d5b67166b","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9f2cf069a9a72a2d6b97ca8b4c70e714aac99749","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sctp/outqueue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/1adf929121e13e0b19200bb9fef715b918d483fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2b3b5eec8b2c30ee237e3c31a6a38de9c39d804d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5ccf35ef0ed6059cdf8b1f4606a6584d5b67166b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6575fb17230814b48b471727c8410c0aadff9274","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b9e2ea2057113f3393990ba646d2d97c719a80d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/874a7c2b5e184f06134fdfde27e9ce9271bafe58","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f2cf069a9a72a2d6b97ca8b4c70e714aac99749","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2e7c1de0e226ca1b7fea2de57a6c9bca408709b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74589","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:31.097","lastModified":"2026-08-25T06:18:33.760","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Fix sk_redir use-after-free in send verdict\n\nsk_psock_msg_verdict() takes a socket reference for psock->sk_redir.\ntcp_bpf_send_verdict() copies that pointer while holding the source socket\nlock, but does not take a reference for the local copy before dropping the\nlock around tcp_bpf_sendmsg_redir().\n\nWhen apply_bytes keeps the cached verdict active, another sendmsg() on the\nsame source socket can consume the remaining bytes and release the cached\nreference while the first thread still holds only the raw local pointer:\n\n  CPU 0                                  CPU 1\n  sk_redir = psock->sk_redir\n  apply_bytes remains nonzero\n  release_sock(sk)\n                                         lock_sock(sk)\n                                         apply_bytes reaches zero\n                                         psock->sk_redir = NULL\n                                         release_sock(sk)\n                                         tcp_bpf_sendmsg_redir(sk_redir)\n                                         sock_put(sk_redir)\n  tcp_bpf_sendmsg_redir(sk_redir)\n\nThe final sock_put() can free sk_redir before CPU 0 dereferences it.\n\nKASAN reported:\n\n  BUG: KASAN: slab-use-after-free in tcp_bpf_sendmsg_redir+0xf39/0x1020\n  Read of size 8 at addr ffff888108537090 by task poc/87\n  Call Trace:\n   tcp_bpf_sendmsg_redir+0xf39/0x1020\n   tcp_bpf_sendmsg+0x977/0x1a50\n   __sys_sendto+0x32c/0x3a0\n   __x64_sys_sendto+0xdb/0x1b0\n  Allocated by task 85:\n   sk_prot_alloc+0x56/0x210\n   sk_clone+0x6f/0x14b0\n   inet_csk_clone_lock+0x24/0x740\n   tcp_create_openreq_child+0x25/0x2710\n   tcp_v4_syn_recv_sock+0x10a/0xe00\n  Freed by task 0:\n   __kasan_slab_free+0x43/0x70\n   slab_free_after_rcu_debug+0xa6/0x1e0\n   rcu_core+0x50a/0x1850\n  Last potentially related work creation:\n   __sk_destruct+0x3da/0x540\n   sk_psock_destroy+0x81e/0xab0\n   process_one_work+0x63a/0x1070\n\nTake a temporary socket reference while the source socket lock still\nprotects psock->sk_redir, and drop it after tcp_bpf_sendmsg_redir()\nreturns.  This keeps each unlocked use independent of cached-verdict\nownership."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/tcp_bpf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"604326b41a6fb9b4a78b6179335decee0365cd8c","lessThan":"41b7da0cb72ca5aa1e62b68dab323d0791fc6bdf","versionType":"git","status":"affected"},{"version":"604326b41a6fb9b4a78b6179335decee0365cd8c","lessThan":"9b4fbc371a6ecf1b4e43b5a629015cc0830d8de3","versionType":"git","status":"affected"},{"version":"604326b41a6fb9b4a78b6179335decee0365cd8c","lessThan":"90a19b0894ba79a699b48cf44421b36fbd566e99","versionType":"git","status":"affected"},{"version":"604326b41a6fb9b4a78b6179335decee0365cd8c","lessThan":"d192cff2a37d59206dabe6ec2e60ceac6271f274","versionType":"git","status":"affected"},{"version":"604326b41a6fb9b4a78b6179335decee0365cd8c","lessThan":"4c9d9aa809c261dc0490a0e19d675f7e8e4c85bf","versionType":"git","status":"affected"},{"version":"604326b41a6fb9b4a78b6179335decee0365cd8c","lessThan":"a14e4ef1d90c3418f01b3b6b8fd3a40a0a208a10","versionType":"git","status":"affected"},{"version":"604326b41a6fb9b4a78b6179335decee0365cd8c","lessThan":"1cec526cf0a2227395f2c2f4b671cb052ff0b00e","versionType":"git","status":"affected"},{"version":"604326b41a6fb9b4a78b6179335decee0365cd8c","lessThan":"a76624733730e541e4955fdecf506af2f6b20558","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/tcp_bpf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.20","status":"affected"},{"version":"0","lessThan":"4.20","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/1cec526cf0a2227395f2c2f4b671cb052ff0b00e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/41b7da0cb72ca5aa1e62b68dab323d0791fc6bdf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4c9d9aa809c261dc0490a0e19d675f7e8e4c85bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/90a19b0894ba79a699b48cf44421b36fbd566e99","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b4fbc371a6ecf1b4e43b5a629015cc0830d8de3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a14e4ef1d90c3418f01b3b6b8fd3a40a0a208a10","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a76624733730e541e4955fdecf506af2f6b20558","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d192cff2a37d59206dabe6ec2e60ceac6271f274","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74590","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:31.243","lastModified":"2026-08-25T06:18:34.113","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfsverity: Fix bpf_get_fsverity_digest() dynptr assumptions\n\nThe BPF verifier and the dynptr abstraction ensure that the memory space\nreferenced by a dynptr remains valid.  They do not, however, provide any\nguarantee that the contents of the memory are stable.  kfuncs are\nexpected to remain memory-safe even if concurrent modifications occur.\n\nbpf_get_fsverity_digest() didn't follow that: it could crash if\narg->digest_size was concurrently modified.\n\nFix that by using the known-good value hash_alg->digest_size instead.\n\nAlso widen 'dynptr_sz' and 'out_digest_sz' to u64 to match the return\ntype of __bpf_dynptr_size().  It doesn't appear that it can actually be\nmore than INT_MAX currently (since __bpf_dynptr_data_rw() excludes\nfile-based pointers), but the correct type might as well be used."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/verity/measure.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"67814c00de3161181cddd06c77aeaf86ac4cc584","lessThan":"1344b632cb5043e32939a84568125719111c5af3","versionType":"git","status":"affected"},{"version":"67814c00de3161181cddd06c77aeaf86ac4cc584","lessThan":"2a5cfcad1d56e26d645b7887b0ed24c371851525","versionType":"git","status":"affected"},{"version":"67814c00de3161181cddd06c77aeaf86ac4cc584","lessThan":"5bd63cad9df4328a184c409fbdad4f17944bcdb8","versionType":"git","status":"affected"},{"version":"67814c00de3161181cddd06c77aeaf86ac4cc584","lessThan":"3e8ec7c0387273329374f5c7bd61f5f38af71fe1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/verity/measure.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/1344b632cb5043e32939a84568125719111c5af3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2a5cfcad1d56e26d645b7887b0ed24c371851525","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3e8ec7c0387273329374f5c7bd61f5f38af71fe1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5bd63cad9df4328a184c409fbdad4f17944bcdb8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74591","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:31.353","lastModified":"2026-08-25T06:18:34.397","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/filemap: __filemap_add_folio() restore index before retrying\n\nIn __filemap_add_folio()'s split-a-conflict loop, xas_set_order() is\napplied repeatedly: each application modifies xas.xa_index, rounding it\ndown according to the split_order attempted at that stage: and if all goes\nas intended, it eventually (or immediately) converges on an\nxas_try_split() to the required folio_order, with xas.xa_index now the\nsame as index: then xas_store() puts the new folio into the xarray there.\n\nBut if a new node was needed, and GFP_NOWAIT allocation did not get one,\nthe lock is dropped, xas_nomem() used to allocate, and sequence retried. \nIf (that part of) the xarray is unchanged when the lock is reacquired, no\nproblem.  But what if the conflict was meanwhile resolved by another\nthread (perhaps even doing the same thing, inserting a folio at that same\nindex)?  Isn't there a danger of now putting our folio into the xarray at\nan intermediate rounded-down index?  With !folio_contains() bug to follow,\nwhen CONFIG_DEBUG_VM=y is checking for that.\n\nFix this with an xas_set_order() to restore the original xas.xa_index at\nthe bottom of the loop, so the retry does a full re-evaluation after\nreacquiring the lock, and cannot reach xas_store() with the wrong index.\n\nProduction was suffering from rare SIGILLs and SIGSEGVs, executable text\nfound a page away from where it belonged, !folio_contains() bug hit when\ndebug enabled: symptoms not seen since this patch went in."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/filemap.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"200a89c159a7a416115e6e309183c82183bf98aa","lessThan":"4917e3ebcab50f0265e8ca01c8567de4c4a47511","versionType":"git","status":"affected"},{"version":"200a89c159a7a416115e6e309183c82183bf98aa","lessThan":"267ecd2eb7759c26f1a026eb0a5b231071534c9c","versionType":"git","status":"affected"},{"version":"200a89c159a7a416115e6e309183c82183bf98aa","lessThan":"86da3f7e1e609e1e8bfbab198af68467c5a015a5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/filemap.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/267ecd2eb7759c26f1a026eb0a5b231071534c9c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4917e3ebcab50f0265e8ca01c8567de4c4a47511","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/86da3f7e1e609e1e8bfbab198af68467c5a015a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74592","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:31.460","lastModified":"2026-08-25T06:18:34.637","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nima: Instantiate file_truncate and path_truncate hooks\n\nInstantiate the file_truncate and path_truncate LSM hooks to reset the\naction cache flags (IMA_DONE_MASK) as soon as truncation is requested,\nso the file, based on policy, is re-collected, re-measured, re-audited,\nand re-appraised on next access."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["security/integrity/ima/ima_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3323eec921efd815178a23107ab63588c605c0b2","lessThan":"5f46705d96eb60587aa7035acfcbec977e08d620","versionType":"git","status":"affected"},{"version":"3323eec921efd815178a23107ab63588c605c0b2","lessThan":"dd21c96a71e876c8df9ec546b885a2c5f47bbb05","versionType":"git","status":"affected"},{"version":"3323eec921efd815178a23107ab63588c605c0b2","lessThan":"0baed1fa2184c81e4baf76f445d3faa4b738c8f7","versionType":"git","status":"affected"},{"version":"3323eec921efd815178a23107ab63588c605c0b2","lessThan":"b80bed5c871a80151351342c065579405ce77145","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["security/integrity/ima/ima_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.30","status":"affected"},{"version":"0","lessThan":"2.6.30","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}]},"references":[{"url":"https://git.kernel.org/stable/c/0baed1fa2184c81e4baf76f445d3faa4b738c8f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5f46705d96eb60587aa7035acfcbec977e08d620","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b80bed5c871a80151351342c065579405ce77145","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd21c96a71e876c8df9ec546b885a2c5f47bbb05","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74593","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:31.573","lastModified":"2026-08-23T13:16:45.993","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Take cgroup_lock() first in scx_cgroup_lock()\n\nscx_cgroup_lock() write-locks scx_cgroup_ops_rwsem and then takes\ncgroup_lock(), which can deadlock through kernfs:\n\n  scx enable/disable         cgroup rmdir           cpu.weight write\n  ------------------         ------------           ----------------\n                             cgroup_lock()\n  percpu_down_write(rwsem)\n  cgroup_lock()\n                                                    kernfs_get_active()\n                                                    percpu_down_read(rwsem)\n                             kernfs_drain()\n\nThe enable path waits for the rmdir to release cgroup_mutex. The rmdir,\ndeactivating the cpu controller's files, waits in kernfs_drain() for the\nwrite's active reference. The write, in scx_group_set_weight(), waits for\nthe rwsem behind the pending writer.\n\nTake cgroup_lock() first. The set_* paths take no cgroup locks inside the\nread side, so a pending write-lock then only waits for read sections that\nalways run to completion, and no dependency from the rwsem back to\ncgroup_mutex remains."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/sched/ext/ext.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a5bd6ba30b3364354269b81ac55c2edca9a96d6d","lessThan":"2ca6b43edf83f8fc368cc3094ee5f3b1e8e0b0f0","versionType":"git","status":"affected"},{"version":"a5bd6ba30b3364354269b81ac55c2edca9a96d6d","lessThan":"a054c9ffa9b7a0dffb763837b91ac9d381ec6d10","versionType":"git","status":"affected"},{"version":"a5bd6ba30b3364354269b81ac55c2edca9a96d6d","lessThan":"5f8b69642d18e1f3e11996707842ac530444e959","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/sched/ext/ext.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.46","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2ca6b43edf83f8fc368cc3094ee5f3b1e8e0b0f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5f8b69642d18e1f3e11996707842ac530444e959","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a054c9ffa9b7a0dffb763837b91ac9d381ec6d10","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74594","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:31.680","lastModified":"2026-08-25T06:18:34.890","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsched/psi: Shut down rtpoll_timer in psi_cgroup_free()\n\npsi_schedule_rtpoll_work() is called locklessly from the scheduler hotpath\nand can race psi_trigger_destroy() taking down the last rtpoll trigger under\nrtpoll_trigger_lock:\n\n  psi_schedule_rtpoll_work()        psi_trigger_destroy()\n\n  rcu_read_lock();\n  task = rcu_dereference(rtpoll_task);\n                                    rcu_assign_pointer(rtpoll_task, NULL);\n                                    timer_delete(&rtpoll_timer);\n  mod_timer(&rtpoll_timer, ...);\n  rcu_read_unlock();\n                                    synchronize_rcu();\n                                    kthread_stop(task_to_destroy);\n\nThe group can then be freed with the re-armed timer still pending, and\npoll_timer_fn() runs on freed memory.\n\n461daba06bdc (\"psi: eliminate kthread_worker from psi trigger scheduling\nmechanism\") deleted the timer synchronously after the synchronize_rcu(),\nwhich prevented this but raced trigger creation instead: the deletion could\ncancel the timer that a new trigger set armed during the grace period and,\nas creation also reinitialized the timer at the time, corrupt it.\n8f91efd870ea (\"psi: Fix race between psi_trigger_create/destroy\") moved the\ninitialization into group_init() and the deletion into the locked section,\ntrading the creation races for the window above.\n\nNeither placement in the destruction path works. A pending timer firing\nwhile the group is alive is harmless though. poll_timer_fn() just wakes the\nrtpoll waitqueue and doesn't re-arm itself. Bind the timer to the group's\nlifetime instead and shut it down in psi_cgroup_free(). Nothing can arm it\nby then. timer_shutdown_sync() because the timer is never armed again."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/sched/psi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6bfcb6178925b1fd28c102e53d403091b8f49396","lessThan":"4addb102154b7cf6e2310ccbe20c3c08619e520d","versionType":"git","status":"affected"},{"version":"8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83","lessThan":"894a9300d7fb2e2951da92e565ae6de7ddfb0a69","versionType":"git","status":"affected"},{"version":"8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83","lessThan":"1e5ca82eee59caca6988f9d6e859786aab8a5fa0","versionType":"git","status":"affected"},{"version":"8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83","lessThan":"310b5a537a78c358a4cd244bd767c1a517a05459","versionType":"git","status":"affected"},{"version":"8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83","lessThan":"806fcff98c1d7cb3c1dc0015e55ebdbe819e6b08","versionType":"git","status":"affected"},{"version":"8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83","lessThan":"8037c5b2b2a447df52542f4d8535895d837bdcbd","versionType":"git","status":"affected"},{"version":"8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83","lessThan":"611e7821c4f83a671455658797336faecc3a5196","versionType":"git","status":"affected"},{"version":"8f91efd870ea5d8bc10b0fcc9740db51cd4c0c83","lessThan":"5457025fa8ca3c0d2732109513de839e3e797190","versionType":"git","status":"affected"},{"version":"e1e5e263bbe0e6e9c3db36aa48a3c8acf546fa49","versionType":"git","status":"affected"},{"version":"979965c33f734a1666af67900408f997ac669c23","versionType":"git","status":"affected"},{"version":"5.10.50","lessThan":"5.10.266","versionType":"semver","status":"affected"},{"version":"5.12.17","lessThan":"5.13","versionType":"semver","status":"affected"},{"version":"5.13.2","lessThan":"5.14","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/sched/psi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"5.10.266","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.217","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/1e5ca82eee59caca6988f9d6e859786aab8a5fa0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/310b5a537a78c358a4cd244bd767c1a517a05459","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4addb102154b7cf6e2310ccbe20c3c08619e520d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5457025fa8ca3c0d2732109513de839e3e797190","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/611e7821c4f83a671455658797336faecc3a5196","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8037c5b2b2a447df52542f4d8535895d837bdcbd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/806fcff98c1d7cb3c1dc0015e55ebdbe819e6b08","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/894a9300d7fb2e2951da92e565ae6de7ddfb0a69","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74595","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:31.817","lastModified":"2026-08-25T06:18:35.173","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy()\n\nfscrypt_ioctl_set_policy() calls inode_owner_or_capable() with\n&nop_mnt_idmap before allowing an encryption policy to be set, instead\nof the idmap of the mount the ioctl was issued on.\n\nfscrypt is used by filesystems that support idmapped mounts (e.g. ext4,\nf2fs), so on such a mount this compares the caller's fsuid against the\nunmapped on-disk owner rather than the mapped owner: the actual owner\ncan be wrongly denied with -EACCES and an unrelated caller wrongly\nallowed.  Use file_mnt_idmap(filp) instead."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/crypto/policy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"14f3db5542e62bcf6fe088a09760ac52d55306c5","lessThan":"174633a468817a49bd474bcfc9067c84e54efe68","versionType":"git","status":"affected"},{"version":"14f3db5542e62bcf6fe088a09760ac52d55306c5","lessThan":"0baeb730044981f5ec5fb7d62a3763835ea606f6","versionType":"git","status":"affected"},{"version":"14f3db5542e62bcf6fe088a09760ac52d55306c5","lessThan":"33b7e810ce09955aa02f3b632455cf5e7ac990a9","versionType":"git","status":"affected"},{"version":"14f3db5542e62bcf6fe088a09760ac52d55306c5","lessThan":"6a67c460b12315033268dce597546984fe5739e7","versionType":"git","status":"affected"},{"version":"14f3db5542e62bcf6fe088a09760ac52d55306c5","lessThan":"653e888a24c87b8bbeab44d7e558a1c1a3641088","versionType":"git","status":"affected"},{"version":"14f3db5542e62bcf6fe088a09760ac52d55306c5","lessThan":"98516ba8b817f34e86bdd7a5b7a383cff75c3ddf","versionType":"git","status":"affected"},{"version":"14f3db5542e62bcf6fe088a09760ac52d55306c5","lessThan":"cf6c993c0feca7984797e634deba3c80342e199a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/crypto/policy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.12","status":"affected"},{"version":"0","lessThan":"5.12","versionType":"semver","status":"unaffected"},{"version":"5.15.217","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/0baeb730044981f5ec5fb7d62a3763835ea606f6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/174633a468817a49bd474bcfc9067c84e54efe68","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/33b7e810ce09955aa02f3b632455cf5e7ac990a9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/653e888a24c87b8bbeab44d7e558a1c1a3641088","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6a67c460b12315033268dce597546984fe5739e7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/98516ba8b817f34e86bdd7a5b7a383cff75c3ddf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf6c993c0feca7984797e634deba3c80342e199a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74596","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:31.923","lastModified":"2026-08-22T16:16:31.923","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs,fsverity: remove check for fsverity being enabled in setattr_prepare()\n\nThe check that fs-verity is available in the kernel is not necessary\nhere. Filesystems could have fsverity files even without fs-verity\nenabled. In that case, truncate on fsverity file will succeed, what this\ncheck is trying to prevent."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/attr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e9734653c523c744f03333ece6ae7a315187f05c","lessThan":"2d2b2ed7bdcc6df4942292318c5455b5e94ba525","versionType":"git","status":"affected"},{"version":"e9734653c523c744f03333ece6ae7a315187f05c","lessThan":"d2f96bcb89d36d488a10e3bcf819b98536968286","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/attr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2d2b2ed7bdcc6df4942292318c5455b5e94ba525","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2f96bcb89d36d488a10e3bcf819b98536968286","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74597","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:32.040","lastModified":"2026-08-25T06:18:35.440","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nip6_tunnel: clear skb2->cb[] in ip6ip6_err()\n\nip6ip6_err() clones an outer IPv6 ICMP error skb, pulls it to the\nquoted inner IPv6 packet, and then passes the clone to icmpv6_send().\nThe clone still carries the outer packet's inet6_skb_parm in skb->cb.\n\nIf the outer packet had a Home Address Option, IP6CB(skb2)->dsthao\nremains non-zero after skb_pull(). icmpv6_send() later calls\nmip6_addr_swap(), which uses that stale dsthao offset against the quoted\ninner packet. A malformed inner destination-options header can then make\nthe HAO lookup and address swap run past the end of the quoted packet\nand corrupt skb_shared_info.\n\nClear skb2->cb[] before pulling the quoted inner IPv6 packet so the\nreply path does not reuse metadata left by the outer IPv6 stack."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/ip6_tunnel.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e490d1d85cf5e191791979e5f260d32eb4f703a8","lessThan":"44fe898df302e91c5ee5acbc71ffa74e78e6c183","versionType":"git","status":"affected"},{"version":"e490d1d85cf5e191791979e5f260d32eb4f703a8","lessThan":"0dadb0620ab65949a8bc2439dd28ea3c942fe87d","versionType":"git","status":"affected"},{"version":"e490d1d85cf5e191791979e5f260d32eb4f703a8","lessThan":"b6816536a2990c0db44a26130a03e40b441e829b","versionType":"git","status":"affected"},{"version":"e490d1d85cf5e191791979e5f260d32eb4f703a8","lessThan":"64e41736a26f37ab6215bc2e6df125df05aceb08","versionType":"git","status":"affected"},{"version":"e490d1d85cf5e191791979e5f260d32eb4f703a8","lessThan":"484134e1eb07d700a73b1e4bbf3fb503e299be60","versionType":"git","status":"affected"},{"version":"e490d1d85cf5e191791979e5f260d32eb4f703a8","lessThan":"4eb15c465337b18f44716c499cd6ad63eee0ad54","versionType":"git","status":"affected"},{"version":"e490d1d85cf5e191791979e5f260d32eb4f703a8","lessThan":"fbf40faa0414b753212494ad197542002e66ed9e","versionType":"git","status":"affected"},{"version":"e490d1d85cf5e191791979e5f260d32eb4f703a8","lessThan":"f803c086399da277b5d0ff36a107d0f162751800","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/ip6_tunnel.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.22","status":"affected"},{"version":"0","lessThan":"2.6.22","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/0dadb0620ab65949a8bc2439dd28ea3c942fe87d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/44fe898df302e91c5ee5acbc71ffa74e78e6c183","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/484134e1eb07d700a73b1e4bbf3fb503e299be60","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4eb15c465337b18f44716c499cd6ad63eee0ad54","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/64e41736a26f37ab6215bc2e6df125df05aceb08","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6816536a2990c0db44a26130a03e40b441e829b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f803c086399da277b5d0ff36a107d0f162751800","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fbf40faa0414b753212494ad197542002e66ed9e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74598","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:32.170","lastModified":"2026-08-25T06:18:35.740","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix Route Information option length validation\n\nrt6_route_rcv() validates the Route Information option (RFC 4191) length\nagainst the prefix length, but both checks are off by one.\n\nrinfo->length is the ND option length in units of 8 octets and it\n*includes* the 8-byte option header, so an option carrying N bytes of\nprefix has length == 1 + N/8.  RFC 4191 section 2.3 requires length 3\nwhen Prefix Length is greater than 64, and 2 or 3 when it is greater\nthan 0.  The code accepts length >= 2 and length >= 1 respectively.\n\nipv6_addr_prefix() then copies prefix_len/8 bytes out of rinfo->prefix,\nso a Router Advertisement with (prefix_len=128, length=2) or\n(prefix_len=64, length=1) makes the kernel read up to 8 bytes past the\nend of the option.  Those bytes end up in the prefix of the route that\ngets installed, so they are visible to userspace:\n\n  # RA with a Route Information option (prefix_len=128, length=2)\n  # followed by a source link-layer address option, 01 01 de ad be ef ca fe\n  $ ip -6 route show\n  2001:db8:dead:beef:101:dead:beef:cafe via fe80::1234 dev veth0 proto ra\n                     ^^^^^^^^^^^^^^^^^^ the next option, read out of bounds\n\nWhen the Route Information option is the last one in the packet, those\neight bytes come from the skb tail room instead.\n\nReject the option lengths RFC 4191 does not allow."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/route.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"70ceb4f53929f73746be72f73707cd9f8753e2fc","lessThan":"2f6f94eda12430fb41b24b44a71e2ea4e93561d7","versionType":"git","status":"affected"},{"version":"70ceb4f53929f73746be72f73707cd9f8753e2fc","lessThan":"7eac87396c44a312be457ef41d4c5687883be9a2","versionType":"git","status":"affected"},{"version":"70ceb4f53929f73746be72f73707cd9f8753e2fc","lessThan":"7309529f257ae18e72112ef9f614edfd6df229bb","versionType":"git","status":"affected"},{"version":"70ceb4f53929f73746be72f73707cd9f8753e2fc","lessThan":"0b9e02f3bd31c888f2ccdc0ca08e546d6abe9c4d","versionType":"git","status":"affected"},{"version":"70ceb4f53929f73746be72f73707cd9f8753e2fc","lessThan":"ff3cb05289b8a4ef95fa7ea14c7d34818359edbb","versionType":"git","status":"affected"},{"version":"70ceb4f53929f73746be72f73707cd9f8753e2fc","lessThan":"3b2231e358d26e3aec5d8040b1fb777af03c5f05","versionType":"git","status":"affected"},{"version":"70ceb4f53929f73746be72f73707cd9f8753e2fc","lessThan":"da64ed1f346ba84df574d6469fa2e422b2511719","versionType":"git","status":"affected"},{"version":"70ceb4f53929f73746be72f73707cd9f8753e2fc","lessThan":"d1ad8fb2ac6a1afb71dc22d9ae8efb4dda96c824","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/route.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.17","status":"affected"},{"version":"0","lessThan":"2.6.17","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"references":[{"url":"https://git.kernel.org/stable/c/0b9e02f3bd31c888f2ccdc0ca08e546d6abe9c4d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2f6f94eda12430fb41b24b44a71e2ea4e93561d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3b2231e358d26e3aec5d8040b1fb777af03c5f05","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7309529f257ae18e72112ef9f614edfd6df229bb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7eac87396c44a312be457ef41d4c5687883be9a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d1ad8fb2ac6a1afb71dc22d9ae8efb4dda96c824","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/da64ed1f346ba84df574d6469fa2e422b2511719","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff3cb05289b8a4ef95fa7ea14c7d34818359edbb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74599","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:32.303","lastModified":"2026-08-23T13:16:46.343","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/ptdump: always stabilise against page table freeing using init_mm\n\nPrevious commits have established the invariant that kernel page table\nfreeing is performed while an mmap read lock on init_mm is held, which\nfixes races between ptdump and kernel page table freeing over init_mm.\n\nHowever, x86 and arm64 can perform a ptdump over an mm other than init_mm\nvia ptdump_walk_pgd() and since kernel memory ranges are shared across\nnon-kernel mm's, this means that the race still exists for these cases.\n\nFix this by acquiring a nested mmap write lock for init_mm in\nptdump_walk_pgd().\n\nThis is safe as we take this after mmap write locking the mm, and nothing\nacquires the init_mm lock first before locking an arbitrary mm, so no\ndeadlock is possible.\n\nAlso update walk_page_range_debug() to assert that init_mm is write\nlocked, add a comment explaining why and remove some redundant code, and\neliminate the unnecessary and confusing invocation of\nwalk_kernel_page_table_range().\n\nWe can safely remove the non-NULL check for walk.mm, as the mmap lock\nasserts would NULL pointer deref if it was (and of course no callers do\nthis).\n\nThe first point at which ptdump can race kernel page table freeing is\ncommit b6bdb7517c3d (\"mm/vmalloc: add interfaces to free unmapped page\ntable\"), so we target this in the Fixes tag."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/pagewalk.c","mm/ptdump.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e","lessThan":"3c0391b9a774cc0854f3152e484a9d4835b12b40","versionType":"git","status":"affected"},{"version":"b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e","lessThan":"cbd9583bb6f70733d0022a66d3546a15c76ae744","versionType":"git","status":"affected"},{"version":"b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e","lessThan":"76df4edf7d61ecb711bc517ff4c20a5e85c4e9f7","versionType":"git","status":"affected"},{"version":"b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e","lessThan":"b9c6d048bdfaae78d7d921b454f7de7baefaa2f0","versionType":"git","status":"affected"},{"version":"b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e","lessThan":"7f740664aec1f832953c2e6d9b8920cd6c8bcc0c","versionType":"git","status":"affected"},{"version":"b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e","lessThan":"4adc4c9a9a43d61fe476dfe10811f3df2e7e4106","versionType":"git","status":"affected"},{"version":"b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e","lessThan":"27c32e5538344b13c1505a08861e04620c125d47","versionType":"git","status":"affected"},{"version":"31895cfd79564111cdd5a9f48c5d491ae26a238e","versionType":"git","status":"affected"},{"version":"9c7f7bdb1932f8c1e5f80d32c717184701afe701","versionType":"git","status":"affected"},{"version":"acdb4981644c8e31ccee294bdefff475c0cf587b","versionType":"git","status":"affected"},{"version":"0454e2fad9306961540ee7e84da47a8e345b7d22","versionType":"git","status":"affected"},{"version":"4.4.125","lessThan":"4.5","versionType":"semver","status":"affected"},{"version":"4.9.91","lessThan":"4.10","versionType":"semver","status":"affected"},{"version":"4.14.31","lessThan":"4.15","versionType":"semver","status":"affected"},{"version":"4.15.14","lessThan":"4.16","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/pagewalk.c","mm/ptdump.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.16","status":"affected"},{"version":"0","lessThan":"4.16","versionType":"semver","status":"unaffected"},{"version":"5.10.266","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.217","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.6.153","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/27c32e5538344b13c1505a08861e04620c125d47","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3c0391b9a774cc0854f3152e484a9d4835b12b40","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4adc4c9a9a43d61fe476dfe10811f3df2e7e4106","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/76df4edf7d61ecb711bc517ff4c20a5e85c4e9f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f740664aec1f832953c2e6d9b8920cd6c8bcc0c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b9c6d048bdfaae78d7d921b454f7de7baefaa2f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cbd9583bb6f70733d0022a66d3546a15c76ae744","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74600","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:32.430","lastModified":"2026-08-23T13:16:46.480","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/page_table_check: skip special zero mappings\n\npage_table_check_set() and page_table_check_clear() account mappings based\non PageAnon().  Shared zero-page PTEs and huge zero PMDs are special\nmappings, but page_table_check can still account them as file-backed\npages.\n\nAn unprivileged process can populate enough zero mappings to overflow\nfile_map_count and hit the existing BUG_ON().  The PTE path can do this\nwith the shared zero page, and the PMD path can do the same with huge zero\nmappings.\n\nSkip special zero mappings in the user page-table accounting paths.  Keep\nthe PTE-side pte_special() check, and identify huge zero PMDs from the\nmapped folio instead of pmd_special().  That covers architectures where\npmd_special() is a no-op without adding huge_zero_pfn checks to the\ngeneric counter helpers."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/page_table_check.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"df4e817b710809425d899340dbfa8504a3ca4ba5","lessThan":"7755be923e325dc300f4b0c3e1ad7e91b28b3cb9","versionType":"git","status":"affected"},{"version":"df4e817b710809425d899340dbfa8504a3ca4ba5","lessThan":"b726eb3c94d23e09da0e0f46b0fa09fb2b5d99cc","versionType":"git","status":"affected"},{"version":"df4e817b710809425d899340dbfa8504a3ca4ba5","lessThan":"8db4bab826ccc9ec10fa41736a48031cd338d392","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/page_table_check.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","versionType":"semver","status":"unaffected"},{"version":"6.18.46","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/7755be923e325dc300f4b0c3e1ad7e91b28b3cb9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8db4bab826ccc9ec10fa41736a48031cd338d392","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b726eb3c94d23e09da0e0f46b0fa09fb2b5d99cc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74601","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:32.530","lastModified":"2026-08-25T06:18:36.057","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Use current_context for safe per-CPU buffer swap\n\nThe ring_buffer_swap_cpu() function currently checks the per-CPU\ncommitting counter to determine if a buffer is actively being written to\nbefore performing the swap. However, there exists a race window where\nthis check can be bypassed:\n\n    ring_buffer_lock_reserve\n        cpu_buffer = buffer->buffers[cpu];       // cpu_buffer_a\n        rb_reserve_next_event\n            rb_start_commit // inc committing\n            if (unlikely(READ_ONCE(cpu_buffer->buffer) != buffer)) {...}\n            __rb_reserve_next\n                rb_move_tail\n                    rb_end_commit(cpu_buffer);   // dec committing => 0\n                    /* interrupt hits here, successfully swaps! */\n                    local_inc(&cpu_buffer->committing);\n\n    ring_buffer_unlock_commit\n        cpu_buffer = buffer->buffers[cpu];      // cpu_buffer_b\n        rb_commit\n            rb_end_commit\n            RB_WARN_ON(cpu_buffer, !local_read(&cpu_buffer->committing))\n                                                // triggers warning\n\nThe committing counter can temporarily drop to 0 during a single write\noperation (within rb_move_tail), creating a window where swap can\nsucceed even though the write is still in progress. This leads to\ninconsistent buffer state and triggers the RB_WARN_ON in rb_commit().\n\nReplace the committing counter check with current_context checks, which\nare set at the entry of ring_buffer_lock_reserve() and remain valid\nthroughout the entire write operation, providing a reliable indicator of\nbuffer busy state during swap."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/trace/ring_buffer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4239c38fe0b3847e1e6d962c74b41b08ba0e2990","lessThan":"26662bc8fced1d668fa1aa146eda085bfc67bd0b","versionType":"git","status":"affected"},{"version":"4239c38fe0b3847e1e6d962c74b41b08ba0e2990","lessThan":"6b524e6b234e45c7f5f90d13b042c6f57f80105c","versionType":"git","status":"affected"},{"version":"4239c38fe0b3847e1e6d962c74b41b08ba0e2990","lessThan":"597f279b7b4a06412e3d965e98cc36e181cdbede","versionType":"git","status":"affected"},{"version":"4239c38fe0b3847e1e6d962c74b41b08ba0e2990","lessThan":"22709117d9ae95e52673685f98caac7c356a8227","versionType":"git","status":"affected"},{"version":"4239c38fe0b3847e1e6d962c74b41b08ba0e2990","lessThan":"ad7e10c7ea89af45ac1bf1814855d45da472703d","versionType":"git","status":"affected"},{"version":"4239c38fe0b3847e1e6d962c74b41b08ba0e2990","lessThan":"5b926fb04cb9ef3156dcf88c69a59d3d1a1c4f9f","versionType":"git","status":"affected"},{"version":"4239c38fe0b3847e1e6d962c74b41b08ba0e2990","lessThan":"5e6e2a18c20e88167d414f666032792e8bf19b80","versionType":"git","status":"affected"},{"version":"4239c38fe0b3847e1e6d962c74b41b08ba0e2990","lessThan":"f27bdc43077e4fcb5557dfc315ee8d91e741f483","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/trace/ring_buffer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.5","status":"affected"},{"version":"0","lessThan":"4.5","versionType":"semver","status":"unaffected"},{"version":"5.10.266","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.217","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.153","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/22709117d9ae95e52673685f98caac7c356a8227","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/26662bc8fced1d668fa1aa146eda085bfc67bd0b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/597f279b7b4a06412e3d965e98cc36e181cdbede","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5b926fb04cb9ef3156dcf88c69a59d3d1a1c4f9f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5e6e2a18c20e88167d414f666032792e8bf19b80","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b524e6b234e45c7f5f90d13b042c6f57f80105c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ad7e10c7ea89af45ac1bf1814855d45da472703d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f27bdc43077e4fcb5557dfc315ee8d91e741f483","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74602","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:32.650","lastModified":"2026-08-23T13:16:46.710","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Initialise reader page order in rb_allocate_cpu_buffer()\n\nIn rb_allocate_cpu_buffer(), bpage->order was omitted, leaving it as 0.\nThis is an issue for a ring-buffer with subbufs bigger than PAGE_SIZE if\nwhen freed: free_buffer_page() relies on this value. Align the value\nwith the actual allocation size (buffer::subbuf_order)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/trace/ring_buffer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f9b94daa542a8d2532f0930f01cd9aec2d19621b","lessThan":"7c620d89bae1a926ab7d626600285d3516c9f3c4","versionType":"git","status":"affected"},{"version":"f9b94daa542a8d2532f0930f01cd9aec2d19621b","lessThan":"2e37f2bf111429fbfa4d985b12df3ba496ca70aa","versionType":"git","status":"affected"},{"version":"f9b94daa542a8d2532f0930f01cd9aec2d19621b","lessThan":"3b3e0a6ee5bb3ac000f135beef26b2b7ed1a771a","versionType":"git","status":"affected"},{"version":"f9b94daa542a8d2532f0930f01cd9aec2d19621b","lessThan":"6d014e44b68ddd43f71288d2a4dbb1a259869149","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/trace/ring_buffer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2e37f2bf111429fbfa4d985b12df3ba496ca70aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3b3e0a6ee5bb3ac000f135beef26b2b7ed1a771a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d014e44b68ddd43f71288d2a4dbb1a259869149","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7c620d89bae1a926ab7d626600285d3516c9f3c4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74603","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:32.750","lastModified":"2026-08-25T06:18:36.303","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nptp: ocp: Fix board ID over-read\n\nThe EEPROM board ID is a fixed 13-byte field and is not guaranteed to\ncontain a NUL terminator. Passing it directly to\ndevlink_info_version_fixed_put() treats it as a C string and may read\nbeyond the field.\n\nFormat at most OCP_BOARD_ID_LEN bytes into the existing local buffer\nbefore reporting the ID. Use a precision limit because the snprintf()\noutput size alone does not bound the source string scan."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/ptp/ptp_ocp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4","lessThan":"72ef3ce80078199bfad32f98d055f44ba7cd0c3d","versionType":"git","status":"affected"},{"version":"0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4","lessThan":"3d965811be78473654e6e8cc8e4fb7b6b87aa6c1","versionType":"git","status":"affected"},{"version":"0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4","lessThan":"f92558bbe78d6284fedd053900f82a70f0aa8707","versionType":"git","status":"affected"},{"version":"0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4","lessThan":"5fd91dd4a143479b0575fb1f202ec1c501e71fd5","versionType":"git","status":"affected"},{"version":"0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4","lessThan":"f8d7e5751267637190eff887c971d5b468106213","versionType":"git","status":"affected"},{"version":"0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4","lessThan":"6b69f2ef10cdb018c0b127a7cab88e590bbddba4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/ptp/ptp_ocp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.2}]},"references":[{"url":"https://git.kernel.org/stable/c/3d965811be78473654e6e8cc8e4fb7b6b87aa6c1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5fd91dd4a143479b0575fb1f202ec1c501e71fd5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b69f2ef10cdb018c0b127a7cab88e590bbddba4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/72ef3ce80078199bfad32f98d055f44ba7cd0c3d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f8d7e5751267637190eff887c971d5b468106213","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f92558bbe78d6284fedd053900f82a70f0aa8707","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74604","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:32.860","lastModified":"2026-08-25T06:18:36.557","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"thermal/drivers/hwmon: Cleanup coding style a bit\"\n\nRevert commit 030a48b0f6ce (\"thermal/drivers/hwmon: Cleanup coding style\na bit\") that introduced a use-after-free into the error path of\nthermal_add_hwmon_sysfs() by removing a valid check from it."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/thermal/thermal_hwmon.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"030a48b0f6ce393d78b8d33debb1e2043b8cc156","lessThan":"2434f4765da8ccd7ef31be88b86f1bfa2e95be11","versionType":"git","status":"affected"},{"version":"030a48b0f6ce393d78b8d33debb1e2043b8cc156","lessThan":"b4c01ae6dd56d9dfd96bd1b29c28afa8fa06b366","versionType":"git","status":"affected"},{"version":"030a48b0f6ce393d78b8d33debb1e2043b8cc156","lessThan":"999e573212d5f1debf073c68be35e55bbfad12fc","versionType":"git","status":"affected"},{"version":"030a48b0f6ce393d78b8d33debb1e2043b8cc156","lessThan":"6a48ee9a5bda0f8ee501f9bef159fb9f39ff519a","versionType":"git","status":"affected"},{"version":"030a48b0f6ce393d78b8d33debb1e2043b8cc156","lessThan":"8d34019d1413629a434a7e8d9f91c76d256196a0","versionType":"git","status":"affected"},{"version":"030a48b0f6ce393d78b8d33debb1e2043b8cc156","lessThan":"6b446d335ba16e93a266dd77adf1ba51abc82df4","versionType":"git","status":"affected"},{"version":"030a48b0f6ce393d78b8d33debb1e2043b8cc156","lessThan":"ff8da20b6f47c48d46e47f93f7a59e2d56ee9107","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/thermal/thermal_hwmon.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.11","status":"affected"},{"version":"0","lessThan":"5.11","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/2434f4765da8ccd7ef31be88b86f1bfa2e95be11","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6a48ee9a5bda0f8ee501f9bef159fb9f39ff519a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b446d335ba16e93a266dd77adf1ba51abc82df4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8d34019d1413629a434a7e8d9f91c76d256196a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/999e573212d5f1debf073c68be35e55bbfad12fc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b4c01ae6dd56d9dfd96bd1b29c28afa8fa06b366","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff8da20b6f47c48d46e47f93f7a59e2d56ee9107","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74605","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:32.977","lastModified":"2026-08-25T06:18:36.947","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\neventfs: Use children field for rcu head and add memory barriers\n\nWhen an eventfs inode is freed, it sets ei->is_freed and then uses its\nei->list to add it to the srcu link list as the list field is a union with\nthe rcu list head. As the ei->list is used to iterate over an SRCU\nprotected list without taking the eventfs_mutex, there's nothing stopping\nthe iteration over that list to see the ei->rcu instead of the ei->list\nand it will read a corrupt target.\n\nTo fix this, change the union of the rcu list head with the children list.\nOn freeing the eventfs inode, set the is_free and execute a smp_wmb()\nbefore adding the eventfs inode to the SRCU list.\n\nOn iteration of the ei->children list, at the start, execute a smp_rmb()\nand then read the is_freed of the ei to see if the children list is still\nvalid. If is_freed is set, then the ei_child read is not valid and the\nloop should exit immediately."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/tracefs/event_inode.c","fs/tracefs/internal.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"704f960dbee2f1634f4b4e16f208cb16eaf41c1e","lessThan":"004f7232e49730448f91665e76bdd7dff8e0c638","versionType":"git","status":"affected"},{"version":"704f960dbee2f1634f4b4e16f208cb16eaf41c1e","lessThan":"f0ece16ffca7384787b692431961ce202907acf5","versionType":"git","status":"affected"},{"version":"f3f41f444b321ec393edbc251e024fd62658ce55","versionType":"git","status":"affected"},{"version":"305c4e4d80aca2c2d9cf2ebdea56e2eca6d3a6aa","versionType":"git","status":"affected"},{"version":"6.6.18","lessThan":"6.7","versionType":"semver","status":"affected"},{"version":"6.7.6","lessThan":"6.8","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/tracefs/event_inode.c","fs/tracefs/internal.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/004f7232e49730448f91665e76bdd7dff8e0c638","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f0ece16ffca7384787b692431961ce202907acf5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74606","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:33.077","lastModified":"2026-08-25T06:18:37.160","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\neventfs: Fix use-after-free in eventfs_remove_rec()\n\neventfs_remove_rec() recursively removes the child at the current loop\nposition. After the recursive call returns, list_for_each_entry() advances\nby reading list.next from the removed child.\n\nIf free_ei() drops the final reference, release_ei() reuses the list/rcu\nunion to queue an SRCU callback. The child may be freed before that read.\nThe eventfs_mutex serializes list updates, but it does not keep the removed\nchild alive or prevent the SRCU callback from running.\n\nUse list_for_each_entry_safe() to save the next sibling before recursively\nremoving the current child."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/tracefs/event_inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5dfb04100326f70e3b2d2872c2476ed20b804837","lessThan":"b77581b25e213e83b79ce11eb30024e55ceeb3e9","versionType":"git","status":"affected"},{"version":"43aa6f97c2d03a52c1ddb86768575fc84344bdbb","lessThan":"f161d7861a0bfdf10af6b738b3b57636204661fb","versionType":"git","status":"affected"},{"version":"43aa6f97c2d03a52c1ddb86768575fc84344bdbb","lessThan":"5635211b44969f4816e29ec4d5f8665fb39535d0","versionType":"git","status":"affected"},{"version":"43aa6f97c2d03a52c1ddb86768575fc84344bdbb","lessThan":"74bb1eaf72d185a78c879eb2678ea500f82f46a8","versionType":"git","status":"affected"},{"version":"43aa6f97c2d03a52c1ddb86768575fc84344bdbb","lessThan":"fd73b691702170d37d66f4b0278530cea8ed419a","versionType":"git","status":"affected"},{"version":"5a43badefe0eccca0c26144c0a44b8d417ce8103","versionType":"git","status":"affected"},{"version":"6.6.18","lessThan":"6.6.152","versionType":"semver","status":"affected"},{"version":"6.7.6","lessThan":"6.8","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/tracefs/event_inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/5635211b44969f4816e29ec4d5f8665fb39535d0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/74bb1eaf72d185a78c879eb2678ea500f82f46a8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b77581b25e213e83b79ce11eb30024e55ceeb3e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f161d7861a0bfdf10af6b738b3b57636204661fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fd73b691702170d37d66f4b0278530cea8ed419a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74607","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:33.183","lastModified":"2026-08-25T06:18:37.403","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SVM: Serialize accesses to the owner and mirror list with separate lock\n\nInteraction between KVM_CAP_VM_MOVE_ENC_CONTEXT_FROM and\nKVM_CAP_VM_COPY_ENC_CONTEXT_FROM can cause two separate issues:\n\n- in sev_migrate_from(), when the destination KVM is a mirror, the mirror\n  entry is moved from the source's list to the owner's mirror_vms list,\n  without holding the owner's lock unlike other writers of the owner's\n  mirror list (sev_vm_copy_enc_context_from(), sev_vm_destroy()).\n  A concurrent COPY or destroy can race with sev_migrate_from() and\n  corrupt the list.\n\n- In sev_vm_destroy(), the *owner* is still active and could receive\n  concurrently a KVM_CAP_VM_MOVE_ENC_CONTEXT_FROM that causes\n  sev->enc_context_owner to change.  In this case the incorrect VM\n  receives kvm_put_kvm().\n\nThe second issue needs particular care because the owner could disappear\naltogether (even though the race window is impossibly small) between\nreading it and locking it.  There is thus no way to perform the checks\nunder the owner lock without putting struct kvm under SLAB_TYPESAFE_BY_RCU\n(which would allow kvm_get_kvm_safe() under RCU critical section).\n\nIt is much simpler to just use a global lock, since the critical\nsections are so small and the new lock is always a leaf lock."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/x86/kvm/svm/sev.c","arch/x86/kvm/svm/svm.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b2125513dfc0dd0ec5a9605138a3c356592cfb73","lessThan":"7943ec3a6d0e7e0a2eb4943300bce089ac3e8c3e","versionType":"git","status":"affected"},{"version":"b2125513dfc0dd0ec5a9605138a3c356592cfb73","lessThan":"28afde1edbd8b20058cbf4d75fb57876471ec334","versionType":"git","status":"affected"},{"version":"b2125513dfc0dd0ec5a9605138a3c356592cfb73","lessThan":"328ab4fabe05af004d886659f8744076e320ddce","versionType":"git","status":"affected"},{"version":"b2125513dfc0dd0ec5a9605138a3c356592cfb73","lessThan":"47976eaaf0a4eb46dade48b3246779090db9e3ec","versionType":"git","status":"affected"},{"version":"b2125513dfc0dd0ec5a9605138a3c356592cfb73","lessThan":"d728baba0f20e49439fc7831bf3e4e7dee82161a","versionType":"git","status":"affected"},{"version":"b2125513dfc0dd0ec5a9605138a3c356592cfb73","lessThan":"1d78d33275ef2a16c6d080910b291d0a97a0e613","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/x86/kvm/svm/sev.c","arch/x86/kvm/svm/svm.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.153","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.0,"impactScore":6.0}]},"references":[{"url":"https://git.kernel.org/stable/c/1d78d33275ef2a16c6d080910b291d0a97a0e613","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/28afde1edbd8b20058cbf4d75fb57876471ec334","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/328ab4fabe05af004d886659f8744076e320ddce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/47976eaaf0a4eb46dade48b3246779090db9e3ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7943ec3a6d0e7e0a2eb4943300bce089ac3e8c3e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d728baba0f20e49439fc7831bf3e4e7dee82161a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74608","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:33.290","lastModified":"2026-08-25T06:18:37.637","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Fix use-after-free in cifs_try_adding_channels()\n\ncifs_try_adding_channels() takes a temporary reference to an interface\nbefore dropping iface_lock. If cifs_ses_add_channel() fails, it drops\nthat reference and then increments iface->weight_fulfilled.\n\nA concurrent interface list refresh can remove the list reference while\nchannel creation is in progress. In that case, the failure-path\nkref_put() releases the last reference and frees iface. Updating\nweight_fulfilled afterward then accesses freed memory.\n\nIncrement weight_fulfilled before dropping the temporary reference,\nkeeping iface alive for the final access."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/client/sess.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cbc53148cc0946b72d62a3c53870cb22ce4ec284","lessThan":"64d7584e62ac8cdc750455c5fdc6008fc2de4f06","versionType":"git","status":"affected"},{"version":"cff97d683a083b862a8bb24309e0f4d2d928128a","lessThan":"c292d4686f717c03e5022fc4ae7c782f39a94915","versionType":"git","status":"affected"},{"version":"6aac002bcfd554aff6d3ebb55e1660d078d70ab0","lessThan":"47dfac48bce7198ad4f1a388fc8c9491f878ac3b","versionType":"git","status":"affected"},{"version":"6aac002bcfd554aff6d3ebb55e1660d078d70ab0","lessThan":"1ffacbadc14530e55b8d86f7b917524f6a0fb891","versionType":"git","status":"affected"},{"version":"6aac002bcfd554aff6d3ebb55e1660d078d70ab0","lessThan":"1305eadc6a7d78a8d0a52eee29ddd2d9e8a27805","versionType":"git","status":"affected"},{"version":"6aac002bcfd554aff6d3ebb55e1660d078d70ab0","lessThan":"4986410316b1ae0e63c6ce418e4eb196723626e7","versionType":"git","status":"affected"},{"version":"22a6c5b3425f327e7f4c3606a72277dce82c7d83","versionType":"git","status":"affected"},{"version":"6.1.78","lessThan":"6.1.183","versionType":"semver","status":"affected"},{"version":"6.6.17","lessThan":"6.6.152","versionType":"semver","status":"affected"},{"version":"6.7.5","lessThan":"6.8","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/client/sess.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/1305eadc6a7d78a8d0a52eee29ddd2d9e8a27805","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1ffacbadc14530e55b8d86f7b917524f6a0fb891","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/47dfac48bce7198ad4f1a388fc8c9491f878ac3b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4986410316b1ae0e63c6ce418e4eb196723626e7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/64d7584e62ac8cdc750455c5fdc6008fc2de4f06","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c292d4686f717c03e5022fc4ae7c782f39a94915","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74609","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:33.407","lastModified":"2026-08-25T06:18:37.870","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: read le->link under the node lock in tipc_node_link_down()\n\ntipc_node_link_down() caches the link pointer before taking n->lock:\n\n\tstruct tipc_link *l = le->link;\t\t/* unlocked */\n\n\tif (!l)\n\t\treturn;\n\ttipc_node_write_lock(n);\n\tif (!tipc_link_is_establishing(l)) {\t/* deref l */\n\t...\n\t\ttipc_link_reset(l);\t\t/* write into l */\n\tif (delete) {\n\t\tkfree(l);\n\t\tle->link = NULL;\n\nThe delete=true caller frees that very object under n->lock, so the lock\ndoes not protect the cached pointer against it:\n\n - CPU A, delete=false: tipc_rcv() on TIPC_LINK_DOWN_EVT, or the link\n   supervision timer via tipc_node_timeout(), reads l unlocked and then\n   dereferences it under n->lock;\n - CPU B, delete=true: netlink TIPC_NL_BEARER_DISABLE -> bearer_disable()\n   -> tipc_node_delete_links() -> tipc_node_link_down(n, bearer_id, true)\n   -> kfree(l).\n\nThe link is freed with plain kfree(), not kfree_rcu(), and for UDP bearers\ndisable_media() only schedules the asynchronous cleanup_bearer() work, so\nits synchronize_net() runs after the links are already gone.  An in-flight\nCPU A that has read l therefore dereferences freed memory once B frees it:\na use-after-free read in tipc_link_is_establishing(), and a use-after-free\nwrite via tipc_link_reset() on the establishing branch.\n\nThe following trace was captured on 7.2.0-rc5-00284-gaf39eb111ce6:\n\n  BUG: KASAN: slab-use-after-free in tipc_link_is_establishing (net/tipc/link.c:285)\n  Read of size 4 at addr ffff88802e2aa068 by task swapper/2/0\n   tipc_link_is_establishing (net/tipc/link.c:285)\n   tipc_node_link_down (net/tipc/node.c:1076)\n   tipc_node_timeout (net/tipc/node.c:843)\n  Allocated by task 9549:\n   tipc_link_create (net/tipc/link.c:490)\n   tipc_node_check_dest (net/tipc/node.c:1279)\n   tipc_disc_rcv (net/tipc/discover.c:252)\n   tipc_udp_recv (net/tipc/udp_media.c:389)\n  Freed by task 9549:\n   tipc_node_link_down (net/tipc/node.c:1084)\n   tipc_node_delete_links (net/tipc/node.c:1320)\n   bearer_disable (net/tipc/bearer.c:414)\n   __tipc_nl_bearer_disable (net/tipc/bearer.c:992)\n\nMove the le->link read inside tipc_node_write_lock(), so it is serialised\nagainst the kfree() in the delete path.  A racing teardown now either has\nnot run yet, and we see a valid link, or has already run, and we see NULL."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/tipc/node.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"73f646cec35477b5099d7e952297cb9e1855be45","lessThan":"2be741ad565c610871a6a95062c12c39da7168fd","versionType":"git","status":"affected"},{"version":"73f646cec35477b5099d7e952297cb9e1855be45","lessThan":"69d209461c110388710e483a130caf051e4fd09a","versionType":"git","status":"affected"},{"version":"73f646cec35477b5099d7e952297cb9e1855be45","lessThan":"de017c22135f545ca4e65d1eada22887b64958eb","versionType":"git","status":"affected"},{"version":"73f646cec35477b5099d7e952297cb9e1855be45","lessThan":"47ba70891b10b2feb52462086b7fcd2ad75d3ce3","versionType":"git","status":"affected"},{"version":"73f646cec35477b5099d7e952297cb9e1855be45","lessThan":"a714d62513befef37f71f4ae89bb1fe173b65f2e","versionType":"git","status":"affected"},{"version":"73f646cec35477b5099d7e952297cb9e1855be45","lessThan":"c3f2347a47754eac690967cfd82cb6d559817b07","versionType":"git","status":"affected"},{"version":"73f646cec35477b5099d7e952297cb9e1855be45","lessThan":"5558a8312452ddb21eff22b1cbd84302ad951944","versionType":"git","status":"affected"},{"version":"73f646cec35477b5099d7e952297cb9e1855be45","lessThan":"cba9ccb47e9fa4cc77692fb896cc5ab57a667882","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/tipc/node.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.4","status":"affected"},{"version":"0","lessThan":"4.4","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/2be741ad565c610871a6a95062c12c39da7168fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/47ba70891b10b2feb52462086b7fcd2ad75d3ce3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5558a8312452ddb21eff22b1cbd84302ad951944","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/69d209461c110388710e483a130caf051e4fd09a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a714d62513befef37f71f4ae89bb1fe173b65f2e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c3f2347a47754eac690967cfd82cb6d559817b07","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cba9ccb47e9fa4cc77692fb896cc5ab57a667882","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/de017c22135f545ca4e65d1eada22887b64958eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74610","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:33.547","lastModified":"2026-08-25T06:18:38.140","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntls: don't leave a full plaintext sk_msg ring unpushed\n\nWhen the copy path in tls_sw_sendmsg_locked() adds the fragment that fills\nthe plaintext sk_msg ring, it does not set full_record, so the record is\nleft full and unpushed.  A later splice() then adds to an already full\nring: sk_msg_page_add() has no fullness check of its own, so sg.end wraps\nonto sg.start and the ring appears empty.  Fragments added after that\noverwrite live entries, and sg.size no longer matches what is reachable\nbetween sg.start and sg.end, so pushing the record runs the scatterwalk off\nthe end of the scatterlist.\n\nAn unprivileged user can trigger this on a loopback TCP socket with the\n\"tls\" ULP attached:\n\n  BUG: kernel NULL pointer dereference, address: 0000000000000008\n  RIP: 0010:memcpy_from_scatterwalk+0x32/0xc0\n  Call Trace:\n   skcipher_walk_next+0x1d1/0x2c0\n   gcm_encrypt_aesni_avx+0x1e9/0x220\n   bpf_exec_tx_verdict+0x3bb/0x860\n   tls_sw_sendmsg+0xa1a/0xca0\n   __sys_sendto+0x1da/0x1f0\n\nSet full_record in the copy path when the ring becomes full, and push a\nrecord that is already full on entry to the sendmsg loop."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/tls/tls_sw.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fe1e81d4f73b6cbaed4fcc476960d26770642842","lessThan":"aa8b14647721b5a4958712b35cf43e3125d47753","versionType":"git","status":"affected"},{"version":"fe1e81d4f73b6cbaed4fcc476960d26770642842","lessThan":"f634289a0b557a197c5f37284b623cefedfe73d5","versionType":"git","status":"affected"},{"version":"fe1e81d4f73b6cbaed4fcc476960d26770642842","lessThan":"3fc5044796dd87b8d68be4207046f5ce2748174c","versionType":"git","status":"affected"},{"version":"fe1e81d4f73b6cbaed4fcc476960d26770642842","lessThan":"3c5f8f2aa57c647b83add4896aab64aac5fdedad","versionType":"git","status":"affected"},{"version":"fe1e81d4f73b6cbaed4fcc476960d26770642842","lessThan":"7bca91d63341274e857f4aeaad54d229405e93dc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/tls/tls_sw.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.5","status":"affected"},{"version":"0","lessThan":"6.5","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/3c5f8f2aa57c647b83add4896aab64aac5fdedad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3fc5044796dd87b8d68be4207046f5ce2748174c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7bca91d63341274e857f4aeaad54d229405e93dc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aa8b14647721b5a4958712b35cf43e3125d47753","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f634289a0b557a197c5f37284b623cefedfe73d5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74611","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:33.670","lastModified":"2026-08-25T06:18:38.440","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntls: rx: restore msg_iter before TLS 1.3 optimistic retry\n\ntls_decrypt_sg() advances msg->msg_iter when it maps user pages for\nthe optimistic TLS 1.3 zero-copy path. If the decrypted record turns\nout not to be unpadded application data, tls_decrypt_sw() retries into\na kernel skb, but leaves the iterator advanced.\n\nThe subsequent copy from the skb then writes decrypted bytes again at\na later point in the caller iovecs while recvmsg() reports only the\npost-retry length. A TLS peer can trigger this after the receiver\nenables TLS_RX_EXPECT_NO_PAD.\n\nRevert the iterator by the number of bytes consumed by the optimistic\nmapping before retrying without zero-copy.\n\nAdd a selftest which sends a TLS 1.3 control record with\nTLS_RX_EXPECT_NO_PAD enabled and verifies that recvmsg() does not\noverwrite later iovecs beyond the returned length."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/tls/tls_sw.c","tools/testing/selftests/net/tls.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ce61327ce989b63c0bd1cc7afee00e218ee696ac","lessThan":"68787940274ec89f41dc91b1a68ee1a16a90735f","versionType":"git","status":"affected"},{"version":"ce61327ce989b63c0bd1cc7afee00e218ee696ac","lessThan":"3c837266a734e2a22b24d2d567404a501d405835","versionType":"git","status":"affected"},{"version":"ce61327ce989b63c0bd1cc7afee00e218ee696ac","lessThan":"1c8629651cb54f7b51db8fc0b1a9944e4a4b0f5e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/tls/tls_sw.c","tools/testing/selftests/net/tls.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/1c8629651cb54f7b51db8fc0b1a9944e4a4b0f5e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3c837266a734e2a22b24d2d567404a501d405835","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/68787940274ec89f41dc91b1a68ee1a16a90735f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74612","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:33.770","lastModified":"2026-08-25T06:18:38.680","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nveth: fix skb length accounting after XDP frag adjustment\n\nveth exposes non-linear skb fragments through an xdp_buff. If an XDP\nprogram adjusts the fragment area, veth_xdp_rcv_skb() copies\nxdp_frags_size back to skb->data_len but leaves skb->len containing the\nold fragment contribution.\n\nAfter a fragment shrink, this makes skb_headlen() larger than the actual\nlinear area. In the reproduced UDP receive path, __skb_datagram_iter()\ncopied 1024 bytes past the actual linear tail to userspace, starting at\nstruct skb_shared_info. The copied bytes included the affected skb's\nnr_frags, xdp_frags_size, and a kernel pointer from\nskb_shinfo(skb)->frags[0]. Real packet data was displaced by the same\namount and truncated at the end.\n\nSubtract the old data_len before replacing it and add the new data_len\nafterwards, keeping skb->len and skb->data_len synchronized.\n\nAdditionally, bpf_xdp_pull_data() can advance data_end while leaving\nfrags present. The skb is then still non-linear, so the old\n__skb_put(skb, off) triggers SKB_LINEAR_ASSERT().\n\nUse skb_set_tail_pointer() and update skb->len explicitly instead,\nfollowing bpf_prog_run_generic_xdp(). Unlike __skb_put(),\nskb_set_tail_pointer() does not require a linear skb.\n\nA 60000-byte UDP datagram on a veth pair with MTU 64000 was shortened by\n1024 bytes from its fragment area. Before the fix, all 10 runs produced\ncorrupted payloads. After the fix, all 10 runs matched the expected\npayload exactly. A forced-tailroom reproducer also exercises\nbpf_xdp_pull_data() with frags still present; the old code triggers\nSKB_LINEAR_ASSERT(), while this fix passes 10/10 runs."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/veth.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"718a18a0c8a67f97781e40bdef7cdd055c430996","lessThan":"0c3024afabb8064b141f3cedcb1ddd6ab05ad9d5","versionType":"git","status":"affected"},{"version":"718a18a0c8a67f97781e40bdef7cdd055c430996","lessThan":"2f2a7f3f8b9f1bffc9b0488aa02b6951b2aec139","versionType":"git","status":"affected"},{"version":"718a18a0c8a67f97781e40bdef7cdd055c430996","lessThan":"41b96667d42b74bb4b137f1bb78b611a953c5943","versionType":"git","status":"affected"},{"version":"718a18a0c8a67f97781e40bdef7cdd055c430996","lessThan":"cdf745b7a777f87f51666e5d8f4c6fc279bcf54d","versionType":"git","status":"affected"},{"version":"718a18a0c8a67f97781e40bdef7cdd055c430996","lessThan":"3205b0652a37255dbb7ca8f3d942c8d8aa677c21","versionType":"git","status":"affected"},{"version":"718a18a0c8a67f97781e40bdef7cdd055c430996","lessThan":"cb6379feaaff11c4e1e79c26c745ffa23182768a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/veth.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":6.0}]},"references":[{"url":"https://git.kernel.org/stable/c/0c3024afabb8064b141f3cedcb1ddd6ab05ad9d5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2f2a7f3f8b9f1bffc9b0488aa02b6951b2aec139","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3205b0652a37255dbb7ca8f3d942c8d8aa677c21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/41b96667d42b74bb4b137f1bb78b611a953c5943","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb6379feaaff11c4e1e79c26c745ffa23182768a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cdf745b7a777f87f51666e5d8f4c6fc279bcf54d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74613","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:33.890","lastModified":"2026-08-25T06:18:38.920","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: avoid refilling the RX queue after teardown\n\nCommit b917507e5ad9 (\"vsock/virtio: stop workers during the .remove()\")\nmade the RX worker jump to its common exit when rx_run is clear.  That\nexit still refills the RX queue when the buffer count is low, so work\nqueued across virtio_vsock_vqs_del() can add buffers after the virtqueues\nhave been deleted.\n\nBUG: KASAN: slab-use-after-free in virtqueue_add_sgs\nRead of size 4 by task kworker/0:1\nWorkqueue: virtio_vsock virtio_transport_rx_work\nCall Trace:\n virtqueue_add_sgs (drivers/virtio/virtio_ring.c:2796)\n virtio_vsock_rx_fill (net/vmw_vsock/virtio_transport.c:332)\n virtio_transport_rx_work (net/vmw_vsock/virtio_transport.c:701)\n process_one_work (kernel/workqueue.c:3314)\n worker_thread (kernel/workqueue.c:3478)\n kthread (kernel/kthread.c:436)\n ret_from_fork (arch/x86/kernel/process.c:158)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n...\nFreed by task 141:\n kfree (mm/slub.c:6566)\n vp_del_vq (drivers/virtio/virtio_pci_common.c:259)\n vp_del_vqs (drivers/virtio/virtio_pci_common.c:285)\n virtio_vsock_freeze (net/vmw_vsock/virtio_transport.c:912)\n virtio_device_freeze (drivers/virtio/virtio.c:658)\n virtio_pci_freeze (drivers/virtio/virtio_pci_common.c:601)\n pci_pm_freeze (drivers/pci/pci-driver.c:1098)\n device_suspend (drivers/base/power/main.c:1968)\nKernel panic - not syncing: KASAN: panic_on_warn set ...\n\nJump to a no-refill exit when rx_run is clear, leaving the normal exit\nto replenish a running queue."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/vmw_vsock/virtio_transport.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b917507e5ad983085d29069369778b16aa03a0a8","lessThan":"a7658508f5fe8f1077a65e8cb9535d3426f37a2f","versionType":"git","status":"affected"},{"version":"b917507e5ad983085d29069369778b16aa03a0a8","lessThan":"1aa21e7c8702a7c37cd7d3cace1a652cfa5e8171","versionType":"git","status":"affected"},{"version":"b917507e5ad983085d29069369778b16aa03a0a8","lessThan":"4d37e3525cc346a1421c1bdeaad5848e249fc60c","versionType":"git","status":"affected"},{"version":"b917507e5ad983085d29069369778b16aa03a0a8","lessThan":"9d80a04129a6c27a690cb69de3fe3f50be5aa8b9","versionType":"git","status":"affected"},{"version":"b917507e5ad983085d29069369778b16aa03a0a8","lessThan":"a309b74e3fc052352ab778500449cb9c3853c363","versionType":"git","status":"affected"},{"version":"b917507e5ad983085d29069369778b16aa03a0a8","lessThan":"38c7763fdc533edb34dc8f4489c260e8ba2ccae9","versionType":"git","status":"affected"},{"version":"b917507e5ad983085d29069369778b16aa03a0a8","lessThan":"e82a5faea2e3886dfb2a65ce092a132e7e896915","versionType":"git","status":"affected"},{"version":"b917507e5ad983085d29069369778b16aa03a0a8","lessThan":"a31e0ad444698d8aa7534a0f89fda543730f97a5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/vmw_vsock/virtio_transport.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/1aa21e7c8702a7c37cd7d3cace1a652cfa5e8171","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/38c7763fdc533edb34dc8f4489c260e8ba2ccae9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4d37e3525cc346a1421c1bdeaad5848e249fc60c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9d80a04129a6c27a690cb69de3fe3f50be5aa8b9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a309b74e3fc052352ab778500449cb9c3853c363","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a31e0ad444698d8aa7534a0f89fda543730f97a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a7658508f5fe8f1077a65e8cb9535d3426f37a2f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e82a5faea2e3886dfb2a65ce092a132e7e896915","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74614","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:34.023","lastModified":"2026-08-25T06:18:39.263","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: read virtqueues under worker locks\n\nCommit bd50c5dc182b (\"vsock/virtio: add support for device\nsuspend/resume\") made the *_run flags transition from false to true when\nrestore installs replacement virtqueues.  The RX, TX and event workers\nread their virtqueue before locking and checking the corresponding flag,\nso a worker delayed across freeze and restore can observe the replacement\nqueue's running state while retaining a pointer to the deleted queue.\n\nRead each virtqueue under its mutex after checking the run flag, keeping\nthe pointer and state in the same queue generation."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/vmw_vsock/virtio_transport.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"762c251c7f5c4ee5bef71460c6e822ed293fd69f","lessThan":"941329ce14c5f481223a10d1d4c8b57ea7f3048a","versionType":"git","status":"affected"},{"version":"bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c","lessThan":"29dd10583bf9d2744cd84b862e4257c0a5699570","versionType":"git","status":"affected"},{"version":"bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c","lessThan":"a1fb0c5b8a7c2753758aeced40971f99449dde0c","versionType":"git","status":"affected"},{"version":"bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c","lessThan":"eae099c764c7ebdb842eb1f638913e310bdd6513","versionType":"git","status":"affected"},{"version":"bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c","lessThan":"bd43a7ec668be428265b3209eb43647aedcf720a","versionType":"git","status":"affected"},{"version":"bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c","lessThan":"1cecb4202afdbeddcf29d59baf596ac6ab753f7f","versionType":"git","status":"affected"},{"version":"bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c","lessThan":"ebac8f6b1ef0e9278afe204b8692a7479988dace","versionType":"git","status":"affected"},{"version":"5.15.138","lessThan":"5.15.216","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/vmw_vsock/virtio_transport.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/1cecb4202afdbeddcf29d59baf596ac6ab753f7f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/29dd10583bf9d2744cd84b862e4257c0a5699570","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/941329ce14c5f481223a10d1d4c8b57ea7f3048a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a1fb0c5b8a7c2753758aeced40971f99449dde0c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd43a7ec668be428265b3209eb43647aedcf720a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eae099c764c7ebdb842eb1f638913e310bdd6513","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ebac8f6b1ef0e9278afe204b8692a7479988dace","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74615","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:34.143","lastModified":"2026-08-25T06:18:39.610","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: do not arm the ageing timer on a device that is down\n\nvxlan_changelink() arms vxlan->age_timer whenever the requested ageing\ninterval differs from the configured one:\n\n\tif (conf.age_interval != vxlan->cfg.age_interval)\n\t\tmod_timer(&vxlan->age_timer, jiffies);\n\nThere is no netif_running() test, so the timer is armed even on a device\nthat was never brought up.  The only synchronous cancel in the driver is\nthe timer_delete_sync() in vxlan_stop(), which is .ndo_stop.\nnetif_close_many() drops devices without IFF_UP before\n__dev_close_many() runs, so that cancel is skipped for such a device.\n\nvxlan_setup() sets dev->needs_free_netdev = true and age_timer is a\nmember of struct vxlan_dev, so free_netdev() releases the allocation the\ntimer lives in while it is still queued on a timer_base.\nexpire_timers() unlinks the entry before it loads timer->function, so\nthe timer core writes through the freed object's list pointers:\n\n  BUG: KASAN: slab-use-after-free in __run_timers+0x208/0x654\n  Write of size 8 at addr ffff00001adace68 by task true/192\n   __asan_store8+0x84/0xac\n   __run_timers+0x208/0x654\n   run_timer_softirq+0x154/0x18c\n  Allocated by task 189:\n   alloc_netdev_mqs+0x64/0x720\n   rtnl_create_link+0x4ac/0x520\n   rtnl_newlink+0x758/0xd00\n  Freed by task 191:\n   netdev_release+0x40/0x58\n   netdev_run_todo+0x4a4/0x8c0\n   rtnl_dellink+0x200/0x4e8\n\nThe rtnl operations involved are netns-scoped, so an unprivileged user\ncan perform them in a new user and network namespace.\n\nArming the timer on a down device never had an effect: vxlan_cleanup()\nreturns early on !netif_running(), and vxlan_open() arms the timer for\nany non-zero interval once the device is brought up.  Add the missing\ntest.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/vxlan/vxlan_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"40051c4dcad5b374156ad9cceae8d15c0ef1cb95","lessThan":"be44d79d14d7f9ae7c8ffb7272142005341b5123","versionType":"git","status":"affected"},{"version":"40051c4dcad5b374156ad9cceae8d15c0ef1cb95","lessThan":"26c179d47403d2f919ee914cc02c31d896b59fee","versionType":"git","status":"affected"},{"version":"40051c4dcad5b374156ad9cceae8d15c0ef1cb95","lessThan":"9dc561f0522c35bdd66e0646a748814a138ec4ca","versionType":"git","status":"affected"},{"version":"40051c4dcad5b374156ad9cceae8d15c0ef1cb95","lessThan":"619dd29045e439d0b0f8c6d4fec1af447a050680","versionType":"git","status":"affected"},{"version":"40051c4dcad5b374156ad9cceae8d15c0ef1cb95","lessThan":"6b095e99b9e67ea31f0c4b00260e010898253519","versionType":"git","status":"affected"},{"version":"40051c4dcad5b374156ad9cceae8d15c0ef1cb95","lessThan":"46bb297ad77680e009244f067f27d51cf5b8c7cf","versionType":"git","status":"affected"},{"version":"40051c4dcad5b374156ad9cceae8d15c0ef1cb95","lessThan":"6b4119af544996a545cf84b16f1dbce829ba0de8","versionType":"git","status":"affected"},{"version":"40051c4dcad5b374156ad9cceae8d15c0ef1cb95","lessThan":"b37971686ec59fb027fa4910ba16805e68fddb97","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/vxlan/vxlan_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.0","status":"affected"},{"version":"0","lessThan":"5.0","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.0,"impactScore":6.0}]},"references":[{"url":"https://git.kernel.org/stable/c/26c179d47403d2f919ee914cc02c31d896b59fee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/46bb297ad77680e009244f067f27d51cf5b8c7cf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/619dd29045e439d0b0f8c6d4fec1af447a050680","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b095e99b9e67ea31f0c4b00260e010898253519","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b4119af544996a545cf84b16f1dbce829ba0de8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9dc561f0522c35bdd66e0646a748814a138ec4ca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b37971686ec59fb027fa4910ba16805e68fddb97","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be44d79d14d7f9ae7c8ffb7272142005341b5123","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74616","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:34.280","lastModified":"2026-08-25T06:18:39.963","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxdp: reject clones that overrun skb_shared_info tailroom\n\nxdpf_clone() clones broadcast copies into a single page and sets\nframe_sz to PAGE_SIZE. __xdp_build_skb_from_frame() later treats that\npage like a normal XDP frame and expects the usual skb_shared_info\ntailroom at the end of the buffer.\n\nThe current check only rejects frames whose linear xdp_frame header,\nheadroom, and packet data exceed PAGE_SIZE. A source frame backed by a\nlarger allocation can still satisfy that check while extending into the\nclone's required shared-info area. When such a clone is converted back\ninto an skb, build_skb_around() places skb_shared_info over live packet\nbytes and later writes can corrupt XDP return metadata.\n\nReject clones unless their linear area fits inside\nSKB_WITH_OVERHEAD(PAGE_SIZE), matching the tailroom requirement already\nenforced by the XDP-to-skb conversion path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/core/xdp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e624d4ed4aa8cc3c69d1359b0aaea539203ed266","lessThan":"58408982fa39f9758124cec169f42854d6f98f35","versionType":"git","status":"affected"},{"version":"e624d4ed4aa8cc3c69d1359b0aaea539203ed266","lessThan":"685edea27ac68d08fe4dbd3de74b858d2ad8e830","versionType":"git","status":"affected"},{"version":"e624d4ed4aa8cc3c69d1359b0aaea539203ed266","lessThan":"ba13763d667e008e185fedf592d53846a5b457d1","versionType":"git","status":"affected"},{"version":"e624d4ed4aa8cc3c69d1359b0aaea539203ed266","lessThan":"ef4b7c7046d29a67090de15af0da0d1ae8d1b192","versionType":"git","status":"affected"},{"version":"e624d4ed4aa8cc3c69d1359b0aaea539203ed266","lessThan":"fab820f1691a9e26d9031f18aae1e9ce09078f92","versionType":"git","status":"affected"},{"version":"e624d4ed4aa8cc3c69d1359b0aaea539203ed266","lessThan":"f463b6f4957c9c3fd1c75f8d3e5af4879fa609c0","versionType":"git","status":"affected"},{"version":"e624d4ed4aa8cc3c69d1359b0aaea539203ed266","lessThan":"e48e8edbef2eb824201495daa5234560f632b23c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/core/xdp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/58408982fa39f9758124cec169f42854d6f98f35","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/685edea27ac68d08fe4dbd3de74b858d2ad8e830","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba13763d667e008e185fedf592d53846a5b457d1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e48e8edbef2eb824201495daa5234560f632b23c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef4b7c7046d29a67090de15af0da0d1ae8d1b192","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f463b6f4957c9c3fd1c75f8d3e5af4879fa609c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fab820f1691a9e26d9031f18aae1e9ce09078f92","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74617","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:34.400","lastModified":"2026-08-25T06:18:40.303","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndibs: initialise dibs->lock in dibs_dev_alloc()\n\ndibs->lock is initialised by dibs_dev_add(), but a dibs device can\nalready take interrupts before that call: ism_probe() runs\nism_dev_init(), and hence request_irq(), before it calls\ndibs_dev_add(). No client can have registered a dmb at that point, so\nno dmb interrupt can occur, but a GID event interrupt can, and\nism_handle_irq() takes dibs->lock unconditionally on entry, before it\ninspects anything else.\n\nInitialise the lock in dibs_dev_alloc() instead, so that it is valid as\nsoon as a driver can publish the device to its interrupt handler."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/dibs/dibs_main.c","include/linux/dibs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cc21191b584c6f7836b0f10774f8278b7cbfba10","lessThan":"fe79571f40434b257d68cbfb7b3ae93a794d8a11","versionType":"git","status":"affected"},{"version":"cc21191b584c6f7836b0f10774f8278b7cbfba10","lessThan":"2926031acba100d0c18fcfaa7a2ed29609318848","versionType":"git","status":"affected"},{"version":"cc21191b584c6f7836b0f10774f8278b7cbfba10","lessThan":"c27e360545373b7aee9862a5beef3b9fb3df0c25","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/dibs/dibs_main.c","include/linux/dibs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/2926031acba100d0c18fcfaa7a2ed29609318848","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c27e360545373b7aee9862a5beef3b9fb3df0c25","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe79571f40434b257d68cbfb7b3ae93a794d8a11","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74618","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:34.507","lastModified":"2026-08-22T16:16:34.507","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_misc: don't warn when the mount is completed from another user namespace\n\nfsopen() records the caller's user namespace in fc->user_ns and hands\nback an ordinary file descriptor. Nothing ties the task that calls\nfsconfig(FSCONFIG_CMD_CREATE) to the task that created the context. The\nfd is inherited across fork() and exec() and it can be passed over a\nunix socket.\n\nCompleting a context from another user namespace is allowed on purpose.\nvfs_cmd_create() authorizes the create with mount_capable(), which for\nFS_USERNS_MOUNT checks ns_capable(fc->user_ns, CAP_SYS_ADMIN), and that\nsucceeds for a task holding CAP_SYS_ADMIN in an ancestor of fc->user_ns.\nSo an unprivileged task can reach the WARN_ON() in bm_fill_super():\ncreate a user and a mount namespace in a child, call\nfsopen(\"binfmt_misc\") there, send the fscontext fd to the parent and let\nthe parent issue FSCONFIG_CMD_CREATE. Both namespaces come from a plain\nunshare(1) and no capability is needed anywhere:\n\n  WARNING: fs/binfmt_misc.c:938 at bm_fill_super+0xa2/0xc0 [binfmt_misc]\n  CPU: 15 UID: 1000 PID: 3243382 Comm: fswarn\n  Call Trace:\n   get_tree_keyed+0x7d/0xb0\n   bm_get_tree+0x34/0x90 [binfmt_misc]\n   vfs_get_tree+0x2a/0x100\n   vfs_cmd_create+0x60/0xf0\n   __do_sys_fsconfig+0x4b2/0x500\n\nThe child needs the mount namespace because fsopen() itself gates on\nmay_mount(), which asks for CAP_SYS_ADMIN in the user namespace owning\nthe caller's mount namespace. fsconfig() doesn't repeat that check.\n\nIt is a WARN_ON() and not a WARN_ON_ONCE(), so the condition can be\nraised in a loop to taint the kernel and flood the log, and it panics a\nkernel booted with panic_on_warn.\n\nKeep refusing the mount and stop warning about it. Nothing in\nbm_fill_super() depends on the two namespaces matching, it derives\neverything from sb->s_user_ns."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/binfmt_misc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"21ca59b365c091d583f36ac753eaa8baf947be6f","lessThan":"37cf5cf1320a84a17225a1690547b8a0812ca94e","versionType":"git","status":"affected"},{"version":"21ca59b365c091d583f36ac753eaa8baf947be6f","lessThan":"24e95a24f151ce40d5fc1b3a6cefbcda8ded736c","versionType":"git","status":"affected"},{"version":"21ca59b365c091d583f36ac753eaa8baf947be6f","lessThan":"047f927f54c6c17593e93aafe82dcb7acdda2a71","versionType":"git","status":"affected"},{"version":"21ca59b365c091d583f36ac753eaa8baf947be6f","lessThan":"79fdf39f1a31f88cb3833b6f8091fbf6acdca2c6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/binfmt_misc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/047f927f54c6c17593e93aafe82dcb7acdda2a71","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/24e95a24f151ce40d5fc1b3a6cefbcda8ded736c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/37cf5cf1320a84a17225a1690547b8a0812ca94e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/79fdf39f1a31f88cb3833b6f8091fbf6acdca2c6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74619","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:34.623","lastModified":"2026-08-22T16:16:34.623","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\novl: don't warn when the mount is completed from another user namespace\n\nfsopen() records the caller's user namespace in fc->user_ns and hands\nback an ordinary file descriptor. Nothing ties the task that calls\nfsconfig(FSCONFIG_CMD_CREATE) to the task that created the context. The\nfd is inherited across fork() and exec() and it can be passed over a\nunix socket.\n\nCompleting a context from another user namespace is allowed on purpose.\nvfs_cmd_create() authorizes the create with mount_capable(), which for\nFS_USERNS_MOUNT checks ns_capable(fc->user_ns, CAP_SYS_ADMIN), and that\nsucceeds for a task holding CAP_SYS_ADMIN in an ancestor of fc->user_ns.\nSo an unprivileged task can reach the WARN_ON() in ovl_fill_super():\ncreate a user and a mount namespace in a child, call fsopen(\"overlay\")\nthere, send the fscontext fd to the parent and let the parent issue\nFSCONFIG_CMD_CREATE. Both namespaces come from a plain unshare(1) and no\ncapability is needed anywhere:\n\n  WARNING: fs/overlayfs/super.c:1551 at ovl_fill_super+0x7b9/0x1e20 [overlay]\n  CPU: 3 UID: 1000 PID: 3243376 Comm: fswarn\n  Call Trace:\n   get_tree_nodev+0x71/0xa0\n   ovl_get_tree+0x15/0x20 [overlay]\n   vfs_get_tree+0x2a/0x100\n   vfs_cmd_create+0x60/0xf0\n   __do_sys_fsconfig+0x4b2/0x500\n\nThe child needs the mount namespace because fsopen() itself gates on\nmay_mount(), which asks for CAP_SYS_ADMIN in the user namespace owning\nthe caller's mount namespace. fsconfig() doesn't repeat that check.\n\nIt is a WARN_ON() and not a WARN_ON_ONCE(), so the condition can be\nraised in a loop to taint the kernel and flood the log, and it panics a\nkernel booted with panic_on_warn.\n\nKeep refusing the mount and stop warning about it. ovl_parse_param()\nalready spells a user namespace check this way for Opt_override_creds."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/overlayfs/super.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1784fbc2ed9c888ea4e895f30a53207ed7ee8208","lessThan":"513478092966dc9818d96dd2b3ed613fd2f6e30e","versionType":"git","status":"affected"},{"version":"1784fbc2ed9c888ea4e895f30a53207ed7ee8208","lessThan":"494346f2aab2489d379d43ff614aea447cf4e94d","versionType":"git","status":"affected"},{"version":"1784fbc2ed9c888ea4e895f30a53207ed7ee8208","lessThan":"be161fa31e3e9cc828a3c1bd935edca461e8a7a1","versionType":"git","status":"affected"},{"version":"1784fbc2ed9c888ea4e895f30a53207ed7ee8208","lessThan":"42d99fcd8006007e2f708bede6789f37f3910b30","versionType":"git","status":"affected"},{"version":"1784fbc2ed9c888ea4e895f30a53207ed7ee8208","lessThan":"63981fc786daaa626cb14d9be1406f674d79f98f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/overlayfs/super.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.5","status":"affected"},{"version":"0","lessThan":"6.5","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/42d99fcd8006007e2f708bede6789f37f3910b30","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/494346f2aab2489d379d43ff614aea447cf4e94d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/513478092966dc9818d96dd2b3ed613fd2f6e30e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/63981fc786daaa626cb14d9be1406f674d79f98f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be161fa31e3e9cc828a3c1bd935edca461e8a7a1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74620","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:34.753","lastModified":"2026-08-23T13:16:47.047","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_gact, act_police: range check the fallback control action\n\ntcf_action_check_ctrlact() range checks the primary control action:\n\n\tif (!opcode)\n\t\tret = action > TC_ACT_VALUE_MAX ? -EINVAL : 0;\n\nTC_ACT_VALUE_MAX is TC_ACT_TRAP, so kernel-internal verdicts above it\ncannot be set that way. But act_gact and act_police each carry a second,\nindependent control action supplied by user space that never reaches that\nhelper - TCA_GACT_PROB.paction and TCA_POLICE_RESULT. Both only reject\nTC_ACT_GOTO_CHAIN, so any other value is stored verbatim and returned\nverbatim from the action.\n\nIn particular user space can store TC_ACT_CONSUMED, which is\nTC_ACT_VALUE_MAX + 1 and is deliberately not part of the UAPI value\nrange. That verdict tells every caller the action took ownership of the\nskb, so nobody frees it: sch_handle_ingress(), sch_handle_egress() and\ntcf_qevent_handle() all deliberately skip the free for it. The result is\none leaked sk_buff plus its data buffer per packet traversing the filter,\nunbounded, for all traffic on the chain including kernel-generated\npackets.\n\nBoth are trivially deterministic. act_gact clamps tcfg_pval to >= 1, so\nwith pval = 1 gact_determ() returns the fallback for every packet.\nact_police has no mandatory rate, so rate = 0 leaves tcfp_mtu = ~0 and\ntcf_police_mtu_check() always passes.\n\nTC_ACT_CONSUMED was added by commit 720f22fed81b (\"net: sched: refactor\nreinsert action\"), after both goto-chain guards were written:\ncommit 9469f375ab09 (\"net/sched: act_gact: disallow 'goto chain' on\nfallback control action\") and\ncommit c08f5ed5d625 (\"net/sched: act_police: disallow 'goto chain' on\nfallback control action\"). Neither guard was widened when the new\nverdict appeared.\n\nFactor the existing range test out of tcf_action_check_ctrlact() as\ntcf_action_valid() and apply it to both fallbacks. The helper cannot call\ntcf_action_check_ctrlact() directly because that also allocates a\ngoto_chain, which is exactly what these two sites must not do.\n\nReproduced on v7.2-rc6: kmemleak reports one leaked 232-byte\nskbuff_head_cache object plus its 704-byte data buffer per packet. With\nthis patch both configurations are rejected with -EINVAL and kmemleak\nreports none."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/act_api.h","net/sched/act_gact.c","net/sched/act_police.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"720f22fed81bc6fd1765db7014651b6718887bea","lessThan":"5f038affdacaffedf6a85a06cf59ec0a852d36a7","versionType":"git","status":"affected"},{"version":"720f22fed81bc6fd1765db7014651b6718887bea","lessThan":"efa58aeb6a99028b1fbc3ab2f31ba3a881211ad4","versionType":"git","status":"affected"},{"version":"720f22fed81bc6fd1765db7014651b6718887bea","lessThan":"725efc2ab4a40affc4e285a2dc4896d103948a6c","versionType":"git","status":"affected"},{"version":"720f22fed81bc6fd1765db7014651b6718887bea","lessThan":"6bcb8839aa2d686964a4154650afc4db91e1c514","versionType":"git","status":"affected"},{"version":"720f22fed81bc6fd1765db7014651b6718887bea","lessThan":"5344e01179baa37547ab29fd7b8614f83faa190c","versionType":"git","status":"affected"},{"version":"720f22fed81bc6fd1765db7014651b6718887bea","lessThan":"92f00f1d4d204a428b38e26fce3baee144b6955d","versionType":"git","status":"affected"},{"version":"720f22fed81bc6fd1765db7014651b6718887bea","lessThan":"2e8df8c9190335475a3b64a159d3efd8cdd1cb73","versionType":"git","status":"affected"},{"version":"720f22fed81bc6fd1765db7014651b6718887bea","lessThan":"883b56ae58fe657d8497806c7059646e9ba6dbd0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/act_api.h","net/sched/act_gact.c","net/sched/act_police.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","versionType":"semver","status":"unaffected"},{"version":"5.10.266","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2e8df8c9190335475a3b64a159d3efd8cdd1cb73","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5344e01179baa37547ab29fd7b8614f83faa190c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5f038affdacaffedf6a85a06cf59ec0a852d36a7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6bcb8839aa2d686964a4154650afc4db91e1c514","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/725efc2ab4a40affc4e285a2dc4896d103948a6c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/883b56ae58fe657d8497806c7059646e9ba6dbd0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/92f00f1d4d204a428b38e26fce3baee144b6955d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/efa58aeb6a99028b1fbc3ab2f31ba3a881211ad4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74621","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:34.897","lastModified":"2026-08-25T06:18:40.510","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_ct: fix sk_buff leak when the header checks reject a packet\n\ntcf_ct_handle_fragments() runs its header sanity checks before handing\nanything to the defragmentation engine:\n\n\tif (family == NFPROTO_IPV4)\n\t\terr = tcf_ct_ipv4_is_fragment(skb, &frag);\n\telse\n\t\terr = tcf_ct_ipv6_is_fragment(skb, &frag);\n\tif (err || !frag)\n\t\treturn err;\n\ntcf_ct_ipv4_is_fragment() returns -EINVAL or -ENOMEM;\ntcf_ct_ipv6_is_fragment() adds -EPROTO when ipv6_find_hdr() fails. None of\nthem frees or queues the skb, so on that path the caller still owns it.\n\ntcf_ct_act() however funnels every non-zero return into the\nownership-transfer exit:\n\n\terr = tcf_ct_handle_fragments(net, skb, family, p->zone, &defrag);\n\tif (err)\n\t\tgoto out_frag;\n\t...\nout_frag:\n\tif (err != -EINPROGRESS)\n\t\ttcf_action_inc_drop_qstats(&c->common);\n\treturn TC_ACT_CONSUMED;\n\nTC_ACT_CONSUMED means the action took ownership of the skb, so no caller\nfrees it - sch_handle_ingress(), sch_handle_egress() and\ntcf_qevent_handle() all deliberately skip the free for that verdict. The\nskb is therefore orphaned: one sk_buff plus its data buffer is leaked per\nmalformed packet, unbounded. Note the drop counter is already incremented\nfor these errors, so the statistics claim a drop that never happens.\n\nThree different ownership states reach out_frag: today - the skb may be\nqueued by the defrag engine (-EINPROGRESS), already freed by\nnf_ct_handle_fragments(), or still owned by us. Tell the caller which of\nthose it is, and free the packet ourselves in the last case, which\nrestores the TC_ACT_SHOT behaviour that predated the Fixes: commit.\n\nReproduced on v7.2-rc6 with a 54-byte frame carrying a 40-byte IPv6\nheader with nexthdr = 0 (hop-by-hop) and nothing after it, on a\nclsact ingress chain with \"action ct\". kmemleak reports one leaked\n232-byte skbuff_head_cache object plus its 704-byte data buffer per\npacket; with this patch it reports none."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sched/act_ct.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"172ba7d46c202e679f3ccb10264c67416aaeb1c4","lessThan":"b5dbecc2016e1692fd1c2532af9c41ba729cb747","versionType":"git","status":"affected"},{"version":"0b5b831122fc3789fff75be433ba3e4dd7b779d4","lessThan":"23e97d594ddd0153020c506d5041048fbde1beb4","versionType":"git","status":"affected"},{"version":"73f7da5fd124f2cda9161e2e46114915e6e82e97","lessThan":"737873a59905a54ca0d2d127ef882f3f88bf4379","versionType":"git","status":"affected"},{"version":"3f14b377d01d8357eba032b4cabc8c1149b458b6","lessThan":"47d99828591d0fe8be4b9c8992ff3b8e47968db9","versionType":"git","status":"affected"},{"version":"3f14b377d01d8357eba032b4cabc8c1149b458b6","lessThan":"b47bb899e04b5407c5a63fe88d4b6676586a6e84","versionType":"git","status":"affected"},{"version":"3f14b377d01d8357eba032b4cabc8c1149b458b6","lessThan":"439d3e404f9d5e515911cc8132cde198b337c19e","versionType":"git","status":"affected"},{"version":"3f14b377d01d8357eba032b4cabc8c1149b458b6","lessThan":"8a7ed561671aa6a911a2de99e59ef670a4d0b1df","versionType":"git","status":"affected"},{"version":"f5346df0591d10bc948761ca854b1fae6d2ef441","versionType":"git","status":"affected"},{"version":"5.15.148","lessThan":"5.15.217","versionType":"semver","status":"affected"},{"version":"6.1.75","lessThan":"6.1.184","versionType":"semver","status":"affected"},{"version":"6.6.14","lessThan":"6.6.152","versionType":"semver","status":"affected"},{"version":"6.7.2","lessThan":"6.8","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sched/act_ct.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"5.15.217","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"references":[{"url":"https://git.kernel.org/stable/c/23e97d594ddd0153020c506d5041048fbde1beb4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/439d3e404f9d5e515911cc8132cde198b337c19e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/47d99828591d0fe8be4b9c8992ff3b8e47968db9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/737873a59905a54ca0d2d127ef882f3f88bf4379","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8a7ed561671aa6a911a2de99e59ef670a4d0b1df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b47bb899e04b5407c5a63fe88d4b6676586a6e84","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5dbecc2016e1692fd1c2532af9c41ba729cb747","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74622","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:35.027","lastModified":"2026-08-22T16:16:35.027","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: atlantic: free RX pages of consumed but not refilled buffers\n\naq_ring_rx_deinit() only walks [sw_head, sw_tail), the region posted to\nhardware. Since the page reuse strategy was added, a cleaned RX buffer\nkeeps its page (and its DMA mapping) in the ring for reuse, and refill\nis batched: aq_ring_rx_fill() returns early until AQ_CFG_RX_REFILL_THRES\nslots are free. Slots that were consumed but not yet reposted therefore\nsit in the complementary [sw_tail, sw_head) gap with a live page, and\nthe deinit walk never visits them: up to a refill batch worth of pages\nand DMA mappings leak on every interface down.\n\nWalk the whole ring instead and release whatever is still there. Also\nbail out if the buffer ring is already gone: a partial\naq_ptp_ring_alloc() failure frees the ring but leaves aq_nic set, so\naq_ptp_ring_deinit() still gets here on the unwind path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/aquantia/atlantic/aq_ring.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86","lessThan":"1e58b0bab40dcbdfc04acaba6a221d40801c3770","versionType":"git","status":"affected"},{"version":"46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86","lessThan":"30c473ea097ef0c93b064281b3e295c97d17e28b","versionType":"git","status":"affected"},{"version":"46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86","lessThan":"17c99dd86f169c7a3e73d6778e79ef5b1ed3ceac","versionType":"git","status":"affected"},{"version":"46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86","lessThan":"ff451bc4290b79c04f1c5cfa928d448f9d47ecf5","versionType":"git","status":"affected"},{"version":"46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86","lessThan":"64e1346bc66b947eb80b848e4c8d9828ba50e0fe","versionType":"git","status":"affected"},{"version":"46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86","lessThan":"782cc40b7ade4614a8aec0b948b8cf95c69f8d4b","versionType":"git","status":"affected"},{"version":"46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86","lessThan":"24d87dc28ddd3771dd0e88719209811809729439","versionType":"git","status":"affected"},{"version":"46f4c29d9de6e4a9d4ed7de9a37dd42501d89f86","lessThan":"e8e7471ef686b6c002218fee9671cc61992ae01a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/aquantia/atlantic/aq_ring.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.2","status":"affected"},{"version":"0","lessThan":"5.2","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/17c99dd86f169c7a3e73d6778e79ef5b1ed3ceac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1e58b0bab40dcbdfc04acaba6a221d40801c3770","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/24d87dc28ddd3771dd0e88719209811809729439","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/30c473ea097ef0c93b064281b3e295c97d17e28b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/64e1346bc66b947eb80b848e4c8d9828ba50e0fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/782cc40b7ade4614a8aec0b948b8cf95c69f8d4b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e8e7471ef686b6c002218fee9671cc61992ae01a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff451bc4290b79c04f1c5cfa928d448f9d47ecf5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74623","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:35.157","lastModified":"2026-08-23T13:16:47.317","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: atlantic: free stranded TX buffers on ring deinit\n\naq_vec_deinit() drains the TX rings with a single aq_ring_tx_clean()\ncall, which frees at most AQ_CFG_TX_CLEAN_BUDGET (256) descriptors and\nstops at hw_head, which no longer moves once aq_vec_stop() has stopped\nthe hardware and NAPI. Completed descriptors beyond the budget and\neverything still posted in [hw_head, sw_tail) keep their skb or\nxdp_frame when the interface goes down: aq_vec_ring_free() then frees\nthe buffer ring and the references are lost for good.\n\nToday this is a silent memory leak on every interface down under\nTX/XDP_TX load. With the conversion of the RX path to page_pool posted\nfor net-next it becomes much more visible: XDP_TX frames carry fragment\nreferences on the RX ring's page_pool, so a single stranded frame keeps\nthe pool's inflight count above zero forever. page_pool_destroy() then\nnever completes, the pool is leaked together with its pages, and\n\"page_pool_release_retry() stalled pool shutdown\" is warned every 60\nseconds from that point on, on every ifdown, XDP detach or ring resize\nunder XDP_TX load.\n\nBring back aq_ring_tx_deinit() as it was before the removal and use it\nfor teardown again, with one extension: TX rings can hold xdp_frames\nnowadays, so release those too. They are returned with\nxdp_return_frame() since this runs in process context."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/aquantia/atlantic/aq_ring.c","drivers/net/ethernet/aquantia/atlantic/aq_ring.h","drivers/net/ethernet/aquantia/atlantic/aq_vec.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"eb36bedf28be6d986bdbcfa375bab08ffa45efd8","lessThan":"a14ceebd13bf857bfca052bc5a6bd49e737912be","versionType":"git","status":"affected"},{"version":"eb36bedf28be6d986bdbcfa375bab08ffa45efd8","lessThan":"4f1c20873f70b4b22ef86dc38dad1fda8e169bcd","versionType":"git","status":"affected"},{"version":"eb36bedf28be6d986bdbcfa375bab08ffa45efd8","lessThan":"307d80193b4a4a75b8dc4e0d3162be3755abbed7","versionType":"git","status":"affected"},{"version":"eb36bedf28be6d986bdbcfa375bab08ffa45efd8","lessThan":"7a3e1481f4ee6c581bccc6bfc6c970aac5be7b0c","versionType":"git","status":"affected"},{"version":"eb36bedf28be6d986bdbcfa375bab08ffa45efd8","lessThan":"3447641d361dcc5511841d986ad4d849b2900d9b","versionType":"git","status":"affected"},{"version":"eb36bedf28be6d986bdbcfa375bab08ffa45efd8","lessThan":"b13202d401e1a20fec89b0cda733dcbaf279f79d","versionType":"git","status":"affected"},{"version":"eb36bedf28be6d986bdbcfa375bab08ffa45efd8","lessThan":"dd633280de7fdfd60dc4fcf63d04e2ad95b43269","versionType":"git","status":"affected"},{"version":"eb36bedf28be6d986bdbcfa375bab08ffa45efd8","lessThan":"452636ea5410a96e02ebaaf80b21e3620b98e0dd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/aquantia/atlantic/aq_ring.c","drivers/net/ethernet/aquantia/atlantic/aq_ring.h","drivers/net/ethernet/aquantia/atlantic/aq_vec.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.11","status":"affected"},{"version":"0","lessThan":"4.11","versionType":"semver","status":"unaffected"},{"version":"5.10.266","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.217","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/307d80193b4a4a75b8dc4e0d3162be3755abbed7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3447641d361dcc5511841d986ad4d849b2900d9b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/452636ea5410a96e02ebaaf80b21e3620b98e0dd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4f1c20873f70b4b22ef86dc38dad1fda8e169bcd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7a3e1481f4ee6c581bccc6bfc6c970aac5be7b0c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a14ceebd13bf857bfca052bc5a6bd49e737912be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b13202d401e1a20fec89b0cda733dcbaf279f79d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd633280de7fdfd60dc4fcf63d04e2ad95b43269","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74624","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:35.280","lastModified":"2026-08-25T06:18:40.723","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack: defer invalid log until after unlock\n\nTCP and SCTP conntrack paths can emit invalid-packet logs while ct->lock\nis still held.\n\nWhen invalid logging is routed to nfnetlink_log and conntrack export is\nenabled, the log path can re-enter conntrack netlink glue and dump the\nsame conntrack again. Protocol attribute dumping may take ct->lock, so\nlogging while holding that lock can deadlock.\n\nDefer the TCP invalid logs by storing only the minimal log context while\nct->lock is held and emitting the log after unlocking. Also make the TCP\ntimeout-lowering invalid path return whether a log is needed, then emit\nthat log after unlocking.\n\nDo the same for the SCTP invalid state-transition log that can be reached\nwhile ct->lock is held.\n\nAdd a lockdep assertion to nf_ct_l4proto_log_invalid() so future callers\nthat log invalid conntracks while holding ct->lock are caught outside TCP\nand SCTP as well."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/nf_conntrack_proto.c","net/netfilter/nf_conntrack_proto_sctp.c","net/netfilter/nf_conntrack_proto_tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d9a6f0d0df1899ff9086a57abc600e414f4b8cdd","lessThan":"ca97360eba4b3dc67f1804625542f4ccc774242a","versionType":"git","status":"affected"},{"version":"d9a6f0d0df1899ff9086a57abc600e414f4b8cdd","lessThan":"63853eb20bba4e00b7cd0b8cfc19337bbaaf5037","versionType":"git","status":"affected"},{"version":"d9a6f0d0df1899ff9086a57abc600e414f4b8cdd","lessThan":"9480fcf70a5aa9d320088a01c95df0e5e6391f4a","versionType":"git","status":"affected"},{"version":"d9a6f0d0df1899ff9086a57abc600e414f4b8cdd","lessThan":"0424186d570aa4d1ad17f516afb86bd9eaa4f42e","versionType":"git","status":"affected"},{"version":"d9a6f0d0df1899ff9086a57abc600e414f4b8cdd","lessThan":"c0224327b7cbed9d3198e8dbec847281053dcd06","versionType":"git","status":"affected"},{"version":"d9a6f0d0df1899ff9086a57abc600e414f4b8cdd","lessThan":"2d19b95c9723001f214f7a47d67b09f46238f200","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/nf_conntrack_proto.c","net/netfilter/nf_conntrack_proto_sctp.c","net/netfilter/nf_conntrack_proto_tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.1","status":"affected"},{"version":"0","lessThan":"6.1","versionType":"semver","status":"unaffected"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"references":[{"url":"https://git.kernel.org/stable/c/0424186d570aa4d1ad17f516afb86bd9eaa4f42e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2d19b95c9723001f214f7a47d67b09f46238f200","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/63853eb20bba4e00b7cd0b8cfc19337bbaaf5037","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9480fcf70a5aa9d320088a01c95df0e5e6391f4a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c0224327b7cbed9d3198e8dbec847281053dcd06","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca97360eba4b3dc67f1804625542f4ccc774242a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74625","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:35.390","lastModified":"2026-08-25T06:18:40.927","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: release template ct on non-IP path\n\nA bridge nftables ct zone set rule can attach a conntrack template to\nan skb before nf_ct_bridge_pre() sees it. For non-IPv4 and non-IPv6\nEtherTypes, nf_ct_bridge_pre() currently overwrites skb->_nfct with\nIP_CT_UNTRACKED without releasing the existing template reference.\n\nThat makes the per-cpu template, and any temporary templates allocated\nfor concurrent use, unreachable and leaks memory until the host runs out\nof slab.\n\nReset the skb conntrack state before marking the frame untracked so the\nexisting template reference is dropped on the non-IP path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bridge/netfilter/nf_conntrack_bridge.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3c171f496ef57774f8e5d509923372549734877f","lessThan":"fc90df37540627d092af770215fb4b7befe9409b","versionType":"git","status":"affected"},{"version":"3c171f496ef57774f8e5d509923372549734877f","lessThan":"daa6e070f8e1e7a4dddec8b64ca37663f8cda917","versionType":"git","status":"affected"},{"version":"3c171f496ef57774f8e5d509923372549734877f","lessThan":"bd7b16494dacf87e9336a1dcfdada83b9e40edd6","versionType":"git","status":"affected"},{"version":"3c171f496ef57774f8e5d509923372549734877f","lessThan":"6ea88401e10e04e0b3bb7a7adea54932fb60b93b","versionType":"git","status":"affected"},{"version":"3c171f496ef57774f8e5d509923372549734877f","lessThan":"46d559f00b1ab1d114f92d2f16c5ef0093b3b9dd","versionType":"git","status":"affected"},{"version":"3c171f496ef57774f8e5d509923372549734877f","lessThan":"c58d34fe8b7e47bb0b350a7625023b1261342be5","versionType":"git","status":"affected"},{"version":"3c171f496ef57774f8e5d509923372549734877f","lessThan":"7cff440d702616022769f2643168d7f9820547a0","versionType":"git","status":"affected"},{"version":"3c171f496ef57774f8e5d509923372549734877f","lessThan":"d45cc8020d7c0a9f01dee42ff5c40bc14c9af72f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bridge/netfilter/nf_conntrack_bridge.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"references":[{"url":"https://git.kernel.org/stable/c/46d559f00b1ab1d114f92d2f16c5ef0093b3b9dd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6ea88401e10e04e0b3bb7a7adea54932fb60b93b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7cff440d702616022769f2643168d7f9820547a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd7b16494dacf87e9336a1dcfdada83b9e40edd6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c58d34fe8b7e47bb0b350a7625023b1261342be5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d45cc8020d7c0a9f01dee42ff5c40bc14c9af72f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/daa6e070f8e1e7a4dddec8b64ca37663f8cda917","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc90df37540627d092af770215fb4b7befe9409b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74626","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:35.517","lastModified":"2026-08-27T13:18:34.740","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNTB: ntb_netdev: Preserve RX queue depth on allocation failure\n\nntb_netdev_rx_handler() hands the received skb to the network stack\nbefore allocating its replacement. If the allocation fails, nothing is\nreposted. Every failure therefore takes one buffer out of the RX queue\nwhile the interface remains up, and enough failures eventually stall\nreception.\n\nA retry path could refill the queue later, but ntb_netdev has none.\nAllocate the replacement first instead. If that fails, drop the packet\nand repost the same skb. This keeps the queue full and lets packet\ndelivery resume as soon as memory is available again."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ntb_netdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"548c237c0a9972df5d1afaca38aa733ee577128d","lessThan":"6d7f8a23c130d768c0976c2578b214353674e18f","versionType":"git","status":"affected"},{"version":"548c237c0a9972df5d1afaca38aa733ee577128d","lessThan":"18781cc0bfb5c7f2a51ac6d678a28f101b7c35c5","versionType":"git","status":"affected"},{"version":"548c237c0a9972df5d1afaca38aa733ee577128d","lessThan":"272df0fbe6f3e04e22bc67fbdd9ac24586b942f4","versionType":"git","status":"affected"},{"version":"548c237c0a9972df5d1afaca38aa733ee577128d","lessThan":"fcaf8ba7e56bb73319ac107a63b907d59536192c","versionType":"git","status":"affected"},{"version":"548c237c0a9972df5d1afaca38aa733ee577128d","lessThan":"3f2a15f33f86f7bd5b920669fd40c06725d72a1e","versionType":"git","status":"affected"},{"version":"548c237c0a9972df5d1afaca38aa733ee577128d","lessThan":"a4e340971fe8ccd245d206db4d43b2a0eec240bd","versionType":"git","status":"affected"},{"version":"548c237c0a9972df5d1afaca38aa733ee577128d","lessThan":"755fd7843f300d724caceabdf9bb13adc8701540","versionType":"git","status":"affected"},{"version":"548c237c0a9972df5d1afaca38aa733ee577128d","lessThan":"d2121faf133ac3bf9531b53a7e21273649a08517","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ntb_netdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.9","status":"affected"},{"version":"0","lessThan":"3.9","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.46","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"references":[{"url":"https://git.kernel.org/stable/c/18781cc0bfb5c7f2a51ac6d678a28f101b7c35c5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/272df0fbe6f3e04e22bc67fbdd9ac24586b942f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3f2a15f33f86f7bd5b920669fd40c06725d72a1e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d7f8a23c130d768c0976c2578b214353674e18f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/755fd7843f300d724caceabdf9bb13adc8701540","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4e340971fe8ccd245d206db4d43b2a0eec240bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2121faf133ac3bf9531b53a7e21273649a08517","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fcaf8ba7e56bb73319ac107a63b907d59536192c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74627","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:35.630","lastModified":"2026-08-25T06:18:41.313","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: devmem: prevent net-iov / page mixing\n\nWe should either have net_iov or page backed frags in a single skb,\notherwise it blows up down the stack. Don't allow mixing in\nzerocopy_fill_skb_from_devmem()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/core/datagram.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bd61848900bff597764238f3a8ec67c815cd316e","lessThan":"e9bfe12b1d04c34c6fedcba21d9709b65c08aa33","versionType":"git","status":"affected"},{"version":"bd61848900bff597764238f3a8ec67c815cd316e","lessThan":"ed08011ae0be88f16cceae190535d6c790c83b0c","versionType":"git","status":"affected"},{"version":"bd61848900bff597764238f3a8ec67c815cd316e","lessThan":"53a43508ee332d8bffe40590c3d189c92a551f9f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/core/datagram.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/53a43508ee332d8bffe40590c3d189c92a551f9f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e9bfe12b1d04c34c6fedcba21d9709b65c08aa33","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed08011ae0be88f16cceae190535d6c790c83b0c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74628","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:35.737","lastModified":"2026-08-27T13:18:34.940","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/x25: fix use-after-free of the socket by its timers\n\nThe x25 timers are armed with mod_timer() and cancelled with\ntimer_delete(), so a pending timer holds no reference on the socket and a\ncancel does not wait for a callback already running on another CPU.\n\nx25_heartbeat_expiry() also rearms unconditionally, so it can reinstall\nsk->sk_timer after __x25_destroy_socket() has passed its cancel point.\nThe following __sock_put() frees the socket while the timer is still\nqueued, and the next expiry uses freed memory.  KASAN reports a\nslab-use-after-free on the kmalloc-2k object freed by close().\n\ntimer_delete_sync() cannot be used here: x25_heartbeat_expiry() and\nx25_timer_expiry() both reach the cancels from inside the timer they\nwould wait on, through __x25_destroy_socket() and x25_disconnect().\n\nArm the timers with sk_reset_timer() and cancel them with sk_stop_timer()\nso that an armed timer owns a reference, and release it in both expiry\nhandlers.  Rearm the heartbeat only while sk_hashed(sk) is still true,\nsince __x25_destroy_socket() unlinks the socket before dropping it.  Arm\nthe deferred destroy timer the same way and drop its reference in\nx25_destroy_timer().\n\nReproduced on net with KASAN, with the heartbeat period shortened so the\nwindow recurs.  With this patch the reproducer no longer triggers a\nreport and /proc/net/x25 drains.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/x25/af_x25.c","net/x25/x25_timer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ba925a2e98ce967a0e71c5bcbcf5dbd3facaf0c8","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6b79659590f0f82a9b8efd2ffd55ec6399ebfc33","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"fdd9ac50b9b61ef2b2d52c5156aff788be91454d","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1fc9f6d2c7c9fdb341bfe8ca449c990632299ea6","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3c4919be5d910db4beebca420953858606fba7d8","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"4bc522b33438fefc3272840ae5988771863a4f1f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e92c7e2b41d1528a830bc64c5e4e46dfa8133dda","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2195424c3da2ef1829a63b807e3a900a90e57d85","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/x25/af_x25.c","net/x25/x25_timer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.217","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.153","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/1fc9f6d2c7c9fdb341bfe8ca449c990632299ea6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2195424c3da2ef1829a63b807e3a900a90e57d85","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3c4919be5d910db4beebca420953858606fba7d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4bc522b33438fefc3272840ae5988771863a4f1f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b79659590f0f82a9b8efd2ffd55ec6399ebfc33","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba925a2e98ce967a0e71c5bcbcf5dbd3facaf0c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e92c7e2b41d1528a830bc64c5e4e46dfa8133dda","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fdd9ac50b9b61ef2b2d52c5156aff788be91454d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74629","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:35.840","lastModified":"2026-08-25T06:18:41.710","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/dibs: Correct freeing of dmb_clientid_arr\n\nA dibs device interrupt handler can be active after dibs_dev_del() and\nmay still access dmb_clientid_arr. (UAF)\n\nIn case of a failure in dibs_dev_add() being called by dibs_lo_dev_probe()\ndmb_clientid_arr is freed twice (double free).\n\nFree dmb_clientid_arr in dibs_dev_release() after last reference is gone.\nNote that allocating in dibs_dev_add() instead of dibs_dev_alloc() is ok\nfor now, because no dmbs can be registered before dibs_dev_add()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/dibs/dibs_loopback.c","drivers/dibs/dibs_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cc21191b584c6f7836b0f10774f8278b7cbfba10","lessThan":"ece6426b61241e9bfb41aa131f235168f55229b1","versionType":"git","status":"affected"},{"version":"cc21191b584c6f7836b0f10774f8278b7cbfba10","lessThan":"7a1df20a8d2cc89e3a442b6e0b43b1cacde8d403","versionType":"git","status":"affected"},{"version":"cc21191b584c6f7836b0f10774f8278b7cbfba10","lessThan":"9e6869be49064915edb6c8776b27c376cfdb0df5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/dibs/dibs_loopback.c","drivers/dibs/dibs_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/7a1df20a8d2cc89e3a442b6e0b43b1cacde8d403","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9e6869be49064915edb6c8776b27c376cfdb0df5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ece6426b61241e9bfb41aa131f235168f55229b1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74630","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:35.943","lastModified":"2026-08-25T06:18:41.893","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: prevent in6_dev_get() from resurrecting inet6_dev\n\nin6_dev_get() reads dev->ip6_ptr under RCU and then unconditionally\nincrements its refcount. Device teardown can clear the pointer and drop\nthe last reference between these operations. The increment then\nresurrects an object whose RCU free has already been queued, so callers\ncan use it after it is freed.\n\nUse refcount_inc_not_zero() and return NULL when the object has already\nreached zero. RCU keeps the memory accessible through the attempted\nreference acquisition, and a successful increment pins the object for\nthe caller.\n\nAn independent run on the exact unpatched 6f5156d7a31a (v7.2-rc3)\nkernel reproduced the invalid reference acquisition as UID 1000:\n\n  refcount_t: addition on 0; use-after-free.\n  ip6_mc_source+0xef4/0x17e0\n\nIt was followed by the corresponding reference underflow in\nip6_mc_source(). The supplied trace from the same unpatched revision\nadditionally shows the access after the RCU read-side section ends:\n\n  BUG: KASAN: slab-use-after-free in mutex_lock+0x76/0xe0\n  Write of size 8 at addr ffff888015b50240 by task poc/1219\n\nBug found and triaged by OpenAI Security Research and\nvalidated by Trail of Bits."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/addrconf.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8814c4b533817df825485ff32ce6ac406c3a54d1","lessThan":"785d908f8d21c8bc78b6fb2c2932ab662bf6918a","versionType":"git","status":"affected"},{"version":"8814c4b533817df825485ff32ce6ac406c3a54d1","lessThan":"aedcfefdb5b7ed7f8a6196a3e68a25bdbe51d2f8","versionType":"git","status":"affected"},{"version":"8814c4b533817df825485ff32ce6ac406c3a54d1","lessThan":"145812b678de9f3b59780173be3c0d22ed60dd93","versionType":"git","status":"affected"},{"version":"8814c4b533817df825485ff32ce6ac406c3a54d1","lessThan":"cc5bd568f9b7683e60841b6fd02c10d64535bd6e","versionType":"git","status":"affected"},{"version":"8814c4b533817df825485ff32ce6ac406c3a54d1","lessThan":"1c206d461c680c3151daa3c89fc26eaf5bf98a7f","versionType":"git","status":"affected"},{"version":"8814c4b533817df825485ff32ce6ac406c3a54d1","lessThan":"680fbd7942185448eadb990a3d10a53eb946b702","versionType":"git","status":"affected"},{"version":"8814c4b533817df825485ff32ce6ac406c3a54d1","lessThan":"14e812ab41df0cac033479da835ec9a5de633404","versionType":"git","status":"affected"},{"version":"8814c4b533817df825485ff32ce6ac406c3a54d1","lessThan":"0e243671bc7b8eaf00f83dd2f4367436dc0cff98","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/addrconf.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.19","status":"affected"},{"version":"0","lessThan":"2.6.19","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/0e243671bc7b8eaf00f83dd2f4367436dc0cff98","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/145812b678de9f3b59780173be3c0d22ed60dd93","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/14e812ab41df0cac033479da835ec9a5de633404","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1c206d461c680c3151daa3c89fc26eaf5bf98a7f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/680fbd7942185448eadb990a3d10a53eb946b702","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/785d908f8d21c8bc78b6fb2c2932ab662bf6918a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aedcfefdb5b7ed7f8a6196a3e68a25bdbe51d2f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cc5bd568f9b7683e60841b6fd02c10d64535bd6e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74631","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:36.080","lastModified":"2026-08-25T06:18:42.167","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: smc: fix splice entry lifetime imbalance in smc_rx_splice\n\nsmc_rx_splice() passes pages to splice_to_pipe() before taking the\nreferences that cover the lifetime of each splice entry. In the\nVM-backed RMB path, splice_to_pipe() may drop unqueued entries through\nsmc_rx_spd_release(), while queued entries are released later via the\npipe buffer callback.\n\nThe old post-splice accounting also derives the number of queued VM pages\nfrom an offset mutated while building the descriptor, and a multi-page\nsplice pairs one sock_hold() with multiple sock_put() calls.\n\nTake the page and socket references for every candidate entry before\nsplice_to_pipe(), and drop the matching private state, page reference,\nand socket reference from smc_rx_spd_release() for entries that never\nget queued. This fixes a refcount imbalance that can underflow page\nrefcounts and trigger a use-after-free."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/smc/smc_rx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9014db202cb764b8e14c53e7bacc81f9a1a2ba7f","lessThan":"7ddc7af2ae7fc5a0c0635b245c0824c8b76de5cb","versionType":"git","status":"affected"},{"version":"9014db202cb764b8e14c53e7bacc81f9a1a2ba7f","lessThan":"07ad246529d136d5ef441d5ab4c305d132ff3090","versionType":"git","status":"affected"},{"version":"9014db202cb764b8e14c53e7bacc81f9a1a2ba7f","lessThan":"c841789e456ec6751342fa800639ce8e82ff0e6b","versionType":"git","status":"affected"},{"version":"9014db202cb764b8e14c53e7bacc81f9a1a2ba7f","lessThan":"af02c67ce654356c58db20a0bb2db33ace3b07a8","versionType":"git","status":"affected"},{"version":"9014db202cb764b8e14c53e7bacc81f9a1a2ba7f","lessThan":"ca8342b5fc24c249fdb998468f6a168b457c67e5","versionType":"git","status":"affected"},{"version":"9014db202cb764b8e14c53e7bacc81f9a1a2ba7f","lessThan":"0b7d54cedea5cb158e21925ae0c6c2f5c87ed2a0","versionType":"git","status":"affected"},{"version":"9014db202cb764b8e14c53e7bacc81f9a1a2ba7f","lessThan":"4515c78f4d9fd577270f012efeb062ea58b3682d","versionType":"git","status":"affected"},{"version":"9014db202cb764b8e14c53e7bacc81f9a1a2ba7f","lessThan":"5d9686af2976741bbd79b150d1c9e60b81e7f12e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/smc/smc_rx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.18","status":"affected"},{"version":"0","lessThan":"4.18","versionType":"semver","status":"unaffected"},{"version":"5.10.266","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.217","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/07ad246529d136d5ef441d5ab4c305d132ff3090","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0b7d54cedea5cb158e21925ae0c6c2f5c87ed2a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4515c78f4d9fd577270f012efeb062ea58b3682d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5d9686af2976741bbd79b150d1c9e60b81e7f12e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7ddc7af2ae7fc5a0c0635b245c0824c8b76de5cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af02c67ce654356c58db20a0bb2db33ace3b07a8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c841789e456ec6751342fa800639ce8e82ff0e6b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca8342b5fc24c249fdb998468f6a168b457c67e5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74632","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:36.217","lastModified":"2026-08-27T13:18:35.130","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/huge_memory: fix huge_zero_pfn race\n\nPatch series \"mm/huge_memory: fix huge_zero_pfn race\", v2.\n\nThere is a subtle race in the reference-counted huge_zero_folio\nimplementation.\n\nThe fast path atomic logic fails to account for the fact that the shrinker\n(which drops the final huge_zero_refcount pin) can overwrite huge_zero_pfn\nwith the ~0UL sentinel value in shrink_huge_zero_folio_scan() after a\nracing get_huge_zero_folio() installed a valid value there.\n\nThis results in huge_zero_folio being correctly set but huge_zero_pfn\nbeing set incorrectly and thus is_huge_zero_pfn() and consequently\nis_huge_zero_pmd() will misidentify the huge zero folio as being an\nordinary THP folio.\n\nThis can result in the huge zero folio being split and otherwise treated\nincorrectly.\n\nThe solution to this is very subtle as there is an atomic fast path, and\nthus ordering in weakly ordered architectures has to be treated very\ncarefully.\n\nThe first commit fixes the issue by introducing a spinlock around\nhuge_zero_[pfn, folio, refcount] write, with careful consideration paid to\nload/store ordering in the fast path.  It is placed first and kept as\nsmall as possible so that it can be backported on its own.\n\nThe second commit is a pure cleanup which reworks the\nCONFIG_PERSISTENT_HUGE_ZERO_FOLIO logic to better separate the persistent\nlogic from the dynamically allocated one.\n\n\nThis patch (of 2):\n\nIf !CONFIG_PERSISTENT_HUGE_ZERO_FOLIO, the huge_zero_folio is refcounted\nby huge_zero_refcount and returned by mm_get_huge_zero_folio().\n\nWhen the caller is done with the huge zero page, its reference count is\ndecremented.  Only a shrinker can set the reference count to zero.\n\nA race can unfortunately occur between a shrinker decrementing the\nreference count to zero and a concurrent page fault.\n\nThis is because shrink_huge_zero_folio_scan() might, if very unlucky, be\npreempted between setting huge_zero_refcount to zero and writing an\ninvalid value.\n\nDuring this time get_huge_zero_folio() could write to huge_zero_pfn before\nshrink_huge_zero_folio_scan() resumes.\n\nIn this event the huge zero folio will be persistently misidentified\ncausing the THP code path to be entered inappropriately for the huge zero\nfolio:\n\n                CPU 0                                   CPU 1\n=======================================|=================================\nshrink_huge_zero_folio_scan()          |\n   atomic_cmpxchg() sets refcount to 0 |\n   xchg() sets huge_zero_folio to NULL | get_huge_zero_folio()\n                 |                     |    atomic_inc_not_zero() -> zero\n      preempted for a long time        |    Allocate new huge zero folio\n                 |                     |    Write valid huge_zero_folio\n                 v                     |    Write valid huge_zero_pfn\n  Overwrite huge_zero_pfn with ~0UL   <--- Invalid overwrite!\n\nThis results in is_huge_zero_pfn() and is_huge_zero_pmd() incorrectly\nreturning false for a huge zero page which could result in issues like the\nhuge zero folio being incorrectly split.\n\nNote that the issue is with huge_zero_pfn not huge_zero_folio, as\nget_huge_zero_folio() uses cmpxchg() gated on huge_zero_folio being NULL\nwith a retry loop and shrink_huge_zero_folio_scan() uses xchg() to set\nhuge_zero_folio.\n\nFix the issue by introducing a spinlock, huge_zero_lock, to prevent\nconcurrent write of huge_zero_folio, huge_zero_pfn and huge_zero_refcount.\n\nThere needs to be significant care taken here to ensure correctness:\n\nThe fast path in get_huge_zero_folio() uses atomic_inc_not_zero(), which\nis outside of the critical section, and means huge zero allocation is\ngated on zero huge_zero_refcount.\n\nThe fast path doesn't use huge_zero_lock, so the critical section is\nirrelevant to it.\n\nSo invariants are required - huge_zero_refcount MUST:\n\n* Only be set in the huge_zero_lock critical section to ensure\n  serialisation of huge_zero_pfn, huge_zero_folio and\n---truncated---"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/huge_memory.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6527d8ef68c3ca3c455e38ae2a37cd7810caec73","lessThan":"9c0fd1802ce06d7709f0bae4edeb085288f28764","versionType":"git","status":"affected"},{"version":"3b77e8c8cde581dadab9a0f1543a347e24315f11","lessThan":"b7041ba61c5da4e0b56f9be58cfb87d7689724e4","versionType":"git","status":"affected"},{"version":"3b77e8c8cde581dadab9a0f1543a347e24315f11","lessThan":"9332b080ad57650d1dc582e54517f9fc78ef89cc","versionType":"git","status":"affected"},{"version":"3b77e8c8cde581dadab9a0f1543a347e24315f11","lessThan":"f3a874a903053c53fb53ba287ea9eacda69c68e8","versionType":"git","status":"affected"},{"version":"3b77e8c8cde581dadab9a0f1543a347e24315f11","lessThan":"6024f6d0d9b9ca5138bfc4ac6f6e4bdf616e42b3","versionType":"git","status":"affected"},{"version":"3b77e8c8cde581dadab9a0f1543a347e24315f11","lessThan":"105d04edbec83010df5728f74d17fd9c108e7553","versionType":"git","status":"affected"},{"version":"3b77e8c8cde581dadab9a0f1543a347e24315f11","lessThan":"ab7e4b407c7f58d1a003134eff3841f303d5ccc2","versionType":"git","status":"affected"},{"version":"3b77e8c8cde581dadab9a0f1543a347e24315f11","lessThan":"33192a26cddea7a7e4ca66e5c3eebd36fa8be2bb","versionType":"git","status":"affected"},{"version":"fc1fbc5b017b6f5ef24a4a93f33cd022225e01c8","versionType":"git","status":"affected"},{"version":"bd092a0f19423d7e9e81182314a96ecd6a14f3b7","versionType":"git","status":"affected"},{"version":"b1daf8f862136894a4595770a44e4508808fb806","versionType":"git","status":"affected"},{"version":"5.10.47","lessThan":"5.10.267","versionType":"semver","status":"affected"},{"version":"4.19.197","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.4.129","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"5.12.14","lessThan":"5.13","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/huge_memory.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.153","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/105d04edbec83010df5728f74d17fd9c108e7553","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/33192a26cddea7a7e4ca66e5c3eebd36fa8be2bb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6024f6d0d9b9ca5138bfc4ac6f6e4bdf616e42b3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9332b080ad57650d1dc582e54517f9fc78ef89cc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c0fd1802ce06d7709f0bae4edeb085288f28764","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ab7e4b407c7f58d1a003134eff3841f303d5ccc2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b7041ba61c5da4e0b56f9be58cfb87d7689724e4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f3a874a903053c53fb53ba287ea9eacda69c68e8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74633","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:36.380","lastModified":"2026-08-22T16:16:36.380","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix NULL pointer dereference in module event cache removal\n\nA module-only event filter such as \":mod:foo\" is cached with a NULL\nevent_mod->match when foo has not been loaded. If a later write tries to\nremove a specific match from the same module, remove_cache_mod() passes\nthe NULL cached match to strcmp(), causing a NULL pointer dereference.\n\nThe issue can be reproduced from userspace:\n\n  echo ':mod:trace_events_kunit_missing' > /sys/kernel/tracing/set_event\n  echo '!foo_bar:mod:trace_events_kunit_missing' >> /sys/kernel/tracing/set_event\n\nThe second write must be a concatenation (\">>\") to not include O_TRUNC as\nthat would cause ftrace_clear_events() to clear the cached modules lines.\n\nThe crash was reproduced on x86_64 QEMU while KUnit workers contended on\nthe event tracing path:\n\n  BUG: kernel NULL pointer dereference, address: 0000000000000000\n  #PF: supervisor read access in kernel mode\n  RIP: 0010:strcmp+0x10/0x30\n  Call Trace:\n   __ftrace_set_clr_event_nolock+0x373/0x4a0\n   ftrace_set_clr_event+0xf0/0x180\n   ftrace_event_write+0xdf/0x110\n   vfs_write+0xf6/0x440\n   ksys_write+0x68/0xe0\n   do_syscall_64+0xf9/0x540\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nCheck event_mod->match before comparing it, consistent with the existing\nNULL checks for the cached system and event fields. The mismatched removal\ncontinues to return -EINVAL; a broad cached module filter is removed with\n\"!:mod:<module>\"."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/trace/trace_events.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b355247df104ef6644288884afd2c08b7bf49897","lessThan":"152a00440dc6ef62c6e4cf9bd881a7e6bb81fda9","versionType":"git","status":"affected"},{"version":"b355247df104ef6644288884afd2c08b7bf49897","lessThan":"ad4e9dd5fec7a322a471ff36fb9c76214e3c6992","versionType":"git","status":"affected"},{"version":"b355247df104ef6644288884afd2c08b7bf49897","lessThan":"b69859204d4db3acd86c1c2dadcef0d77b451933","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/trace/trace_events.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/152a00440dc6ef62c6e4cf9bd881a7e6bb81fda9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ad4e9dd5fec7a322a471ff36fb9c76214e3c6992","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b69859204d4db3acd86c1c2dadcef0d77b451933","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74634","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:36.487","lastModified":"2026-08-25T06:18:42.647","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Prevent subbuf order change when resizing is disabled\n\nBecause ring_buffer_subbuf_order_set() frees buffer pages, we can't\nallow it when resizing is disabled. A non-consuming reader is at risk of\nuse-after-free (rb_advance_iter()).\n\nReturn -EBUSY on resize_disabled, matching ring_buffer_resize()\nbehaviour."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/trace/ring_buffer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f9b94daa542a8d2532f0930f01cd9aec2d19621b","lessThan":"b45b91db41379ee5fb36c187d6d7c37b725cbe8e","versionType":"git","status":"affected"},{"version":"f9b94daa542a8d2532f0930f01cd9aec2d19621b","lessThan":"62978cf6347972c04130e4e841ba404504d92b32","versionType":"git","status":"affected"},{"version":"f9b94daa542a8d2532f0930f01cd9aec2d19621b","lessThan":"7568e9e717e7540bd05bcc007f5d76fcaff3cdff","versionType":"git","status":"affected"},{"version":"f9b94daa542a8d2532f0930f01cd9aec2d19621b","lessThan":"bf98d7b0d5a99991e47e66cee4eb1d3fa514be97","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/trace/ring_buffer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/62978cf6347972c04130e4e841ba404504d92b32","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7568e9e717e7540bd05bcc007f5d76fcaff3cdff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b45b91db41379ee5fb36c187d6d7c37b725cbe8e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf98d7b0d5a99991e47e66cee4eb1d3fa514be97","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74635","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:36.590","lastModified":"2026-08-25T06:18:42.897","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: bitblit: bound-check glyph index in bit_cursor()\n\nbit_cursor() fetches the glyph under the cursor with\n\n\tc = scr_readw(vc_pos);\n\tsrc = vc_font.data + ((c & charmask) * w * height);\n\nwhere charmask is 0x1ff when vc_hi_font_mask is set. The screen buffer\nvalue comes directly from scr_readw() and may be larger than the current\nfont's glyph count.\n\nSyzkaller triggers this via vcs_write(). The Call Trace shows\nvcs_write() in vc_screen.c writing an arbitrary 16-bit value with\nwritev() to /dev/vcsa, which vcs_write_buf() in vc_screen.c stores via\nvcs_scr_writew() without checking charcount. The stored value is later\nread in bit_cursor() in bitblit.c.\n\nWhen the font is changed from a font with 512 glyphs to a font with\n256 glyphs, the screen buffer can retain characters with the high\nbit set from the previous mode, which could also produce the same\nout-of-bounds access.\n\n  BUG: KASAN: global-out-of-bounds in soft_cursor+0x378/0x6bc drivers/video/fbdev/core/softcursor.c:70\n  Read of size 16 at addr ffff800086c57970\n\n  Call Trace:\n   soft_cursor+0x378/0x6bc drivers/video/fbdev/core/softcursor.c:70\n   bit_cursor+0xa90/0x1108 drivers/video/fbdev/core/bitblit.c:365\n   fbcon_cursor+0x344/0x498 drivers/video/fbdev/core/fbcon.c:1427\n   hide_cursor+0xdc/0x2d0 drivers/tty/vt/vt.c:883\n   update_region+0x100/0x18c drivers/tty/vt/vt.c:669\n   vcs_write+0x8ec/0xaf0 drivers/tty/vt/vc_screen.c:685\n\nbit_putcs_aligned() and bit_putcs_unaligned() already clamp the glyph\nindex to vc_font.charcount. Apply the same clamp in bit_cursor() after\nextracting the attribute and masking, before indexing fontdata.\n\nThe fix completes the bounds checking started in commit 18c4ef4e765a\n(\"fbdev: bitblit: bound-check glyph index in bit_putcs*\"), which missed\nthe cursor path.\n\nThis change should be safe because the clamp reuses the existing\ncontract from fbcon: charcount is maintained under console_lock in\ncon_font_set() and fbcon_font_set(), and hi_font_mask is cleared when\nswitching from 512 to 256 glyphs. When stale screen data with high bits\nremains after a font switch, or when vcs_write() stores an arbitrary\nvalue, clamping the index to 0 prevents the out-of-bounds read without\nchanging cursor semantics — the same fallback bit_putcs uses."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/video/fbdev/core/bitblit.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0998a6cb232674408a03e8561dc15aa266b2f53b","lessThan":"250159ace2dc53c1bdad267aa8da51b638748700","versionType":"git","status":"affected"},{"version":"db5c9a162d2f42bcc842b76b3d935dcc050a0eec","lessThan":"46336f476484f36145e5117e72d7b590f47433ee","versionType":"git","status":"affected"},{"version":"c12003bf91fdff381c55ef54fef3e961a5af2545","lessThan":"bf750cfeacf4e47ac72dadc7f05839696efb8576","versionType":"git","status":"affected"},{"version":"9ba1a7802ca9a2590cef95b253e6526f4364477f","lessThan":"94134d70abf9273b70499d97d0adc9185ef21091","versionType":"git","status":"affected"},{"version":"901f44227072be60812fe8083e83e1533c04eed1","lessThan":"c1e7351767dd30fc574395c82121e4c67b882da3","versionType":"git","status":"affected"},{"version":"18c4ef4e765a798b47980555ed665d78b71aeadf","lessThan":"bc9db0d879c655d5dfd8add32fd60f13e65d132c","versionType":"git","status":"affected"},{"version":"18c4ef4e765a798b47980555ed665d78b71aeadf","lessThan":"9ea879862e66e354e616028c31b39aa3eb6d35d8","versionType":"git","status":"affected"},{"version":"18c4ef4e765a798b47980555ed665d78b71aeadf","lessThan":"e033cbf3975a8465f879ebd5989dc35b04423a4d","versionType":"git","status":"affected"},{"version":"a10cede006f9614b465cf25609a8753efbfd45cc","versionType":"git","status":"affected"},{"version":"efaf89a75a29b2d179bf4fe63ca62852e93ad620","versionType":"git","status":"affected"},{"version":"5.10.247","lessThan":"5.10.265","versionType":"semver","status":"affected"},{"version":"5.15.197","lessThan":"5.15.216","versionType":"semver","status":"affected"},{"version":"6.1.159","lessThan":"6.1.183","versionType":"semver","status":"affected"},{"version":"6.6.117","lessThan":"6.6.152","versionType":"semver","status":"affected"},{"version":"6.12.58","lessThan":"6.12.104","versionType":"semver","status":"affected"},{"version":"5.4.302","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"6.17.8","lessThan":"6.18","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/video/fbdev/core/bitblit.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/250159ace2dc53c1bdad267aa8da51b638748700","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/46336f476484f36145e5117e72d7b590f47433ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/94134d70abf9273b70499d97d0adc9185ef21091","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ea879862e66e354e616028c31b39aa3eb6d35d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bc9db0d879c655d5dfd8add32fd60f13e65d132c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf750cfeacf4e47ac72dadc7f05839696efb8576","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c1e7351767dd30fc574395c82121e4c67b882da3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e033cbf3975a8465f879ebd5989dc35b04423a4d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74636","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:36.750","lastModified":"2026-08-22T16:16:36.750","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix race between update_event_fields and, event_define_fields\n\nThe following sequence may leads race between event_define_fields()\nand update_event_fields():\n\n CPU0 (loads module A)                      CPU1 (loads module B)\n ===============================            ===============================\n load_module(A)                             load_module(B)\n   notifier_call_chain                        notifier_call_chain\n     trace_module_notify                        trace_module_notify\n       mutex_lock(&event_mutex)                   trace_event_update_all()\n         trace_module_add_events(A)                 down_write(&trace_event_sem)\n            __register_event(call_A)\n              __add_event_to_tracers(call_A)\n                event_define_fields(call_A)\n                  for each f:                         list_for_each_entry(field,\n                    list_add(&f->link,                                    &class->fields, link)\n                             &class->fields)            field = class->fields->next;\n\nWhere access to the class->fields is not protected by the event_mutex in\ntrace_event_update_all().\n\nThis produces the following panic:\n   Unable to handle kernel access ... at virtual address 0000000000000018\n   pc : update_event_fields+0xf8/0x368\n   Call trace:\n    update_event_fields+0xf8/0x368\n    trace_event_update_all+0x7c/0x2b4\n    trace_module_notify+0x4c/0x1dc\n    notifier_call_chain+0x84/0x168\n    blocking_notifier_call_chain_robust+0x64/0xd4\n    load_module+0x10c8/0x123c\n    __arm64_sys_finit_module+0x230/0x31c\n\nFix by taking event_mutex in trace_event_update_all() before\ntrace_event_sem."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/trace/trace_events.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7c6bd60999f32138e3b73fd97ea11ef47a94de25","lessThan":"4e39f7b4d9d36508c53e89e6cbc640728df870b5","versionType":"git","status":"affected"},{"version":"b3bc8547d3be60898818885f5bf22d0a62e2eb48","lessThan":"a30d421468300b1e7b2f233136aeb2db8013f555","versionType":"git","status":"affected"},{"version":"b3bc8547d3be60898818885f5bf22d0a62e2eb48","lessThan":"e5f1d301b4bdaa4206db251fdc691f623162b0a8","versionType":"git","status":"affected"},{"version":"b3bc8547d3be60898818885f5bf22d0a62e2eb48","lessThan":"fdeb190b0905a6aaed1e5d6adfb8613214748d7d","versionType":"git","status":"affected"},{"version":"b3bc8547d3be60898818885f5bf22d0a62e2eb48","lessThan":"ed49684e69f846bf50b5050651ccdb87cfd152c0","versionType":"git","status":"affected"},{"version":"b3bc8547d3be60898818885f5bf22d0a62e2eb48","lessThan":"f128740f39ab28d1f4ad5bdd10f3e117eec0c374","versionType":"git","status":"affected"},{"version":"b3bc8547d3be60898818885f5bf22d0a62e2eb48","lessThan":"c3730b8373bb5059d735509b9e6a00d7eb337d7c","versionType":"git","status":"affected"},{"version":"55defdf935fab9f2989a197aae1042c082d9a343","versionType":"git","status":"affected"},{"version":"0c53a5c80e6e286733381a1d9f255ba4039e2e45","versionType":"git","status":"affected"},{"version":"5.15.33","lessThan":"5.15.216","versionType":"semver","status":"affected"},{"version":"5.16.19","lessThan":"5.17","versionType":"semver","status":"affected"},{"version":"5.17.2","lessThan":"5.18","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/trace/trace_events.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4e39f7b4d9d36508c53e89e6cbc640728df870b5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a30d421468300b1e7b2f233136aeb2db8013f555","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c3730b8373bb5059d735509b9e6a00d7eb337d7c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5f1d301b4bdaa4206db251fdc691f623162b0a8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed49684e69f846bf50b5050651ccdb87cfd152c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f128740f39ab28d1f4ad5bdd10f3e117eec0c374","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fdeb190b0905a6aaed1e5d6adfb8613214748d7d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74637","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:36.890","lastModified":"2026-08-27T13:18:35.347","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf/core: Fix group leader use-after-free after sibling detach\n\nperf_group_detach() handles leader and sibling detach differently. When the\ngroup leader is detached, all siblings are promoted to singleton events and\ntheir group_leader pointer is reset to themselves. When a sibling is\ndetached, it is removed from the leader's sibling_list, but its\ngroup_leader pointer is left pointing at the old leader.\n\nThat is harmless when the sibling is being closed and freed immediately, as\nin the DETACH_DEAD path. It is not safe when the sibling is detached but\nkept alive, such as during CPU hotplug with DETACH_GROUP. In that case the\nsibling is removed from the context, while its file descriptor can still\nkeep it alive.\n\nA typical failing sequence is:\n\n  - A group contains leader L and sibling S.\n  - CPU hot-unplug detaches S with DETACH_GROUP, removing it from\n    L->sibling_list but leaving S->group_leader == L.\n  - L is later closed and freed.\n  - A PERF_IOC_FLAG_GROUP ioctl on S follows S->group_leader and\n    dereferences the freed leader.\n\nThis was reproduced by running the perf event fuzzer, CPU hotplug, and a\nstress workload concurrently:\n\n  Unable to handle kernel paging request at virtual address 006b6b6b6b6b6cdb\n  CPU: 2 PID: 12489 Comm: perf_fuzzer 6.18.7 PREEMPT\n  pc : perf_ioctl+0x34c/0xc68\n  x20: ffffff89a3fa2c70 x8 : 6b6b6b6b6b6b6b6b\n  Code: 943c4a0e 340047a0 f9404a94 f9411e88 (f940b908)\n  Call trace:\n  perf_ioctl+0x34c/0xc68 (P)\n  __arm64_sys_ioctl+0xa0/0xf4\n  invoke_syscall+0x58/0xe4\n  el0_svc_common+0xa8/0xdc\n  do_el0_svc+0x1c/0x28\n  el0_svc+0x40/0xc0\n  el0t_64_sync_handler+0x68/0xdc\n  el0t_64_sync+0x1c4/0x1c8\n\nThe fault happened in perf_ioctl(), where perf_event_for_each() follows\nthe stale group_leader pointer and perf_event_for_each_child() then\ndereferences the freed leader's context.\n\nFix the use-after-free by promoting the detached sibling to a singleton.\nAlso fix __event_disable() cgroup accounting and event state change."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/events/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8a49542c0554af7d0073aac0ee73ee65b807ef34","lessThan":"8f867c0e8da4c2303d91adf45acb6b1820966c27","versionType":"git","status":"affected"},{"version":"8a49542c0554af7d0073aac0ee73ee65b807ef34","lessThan":"8e92e03984364d93e0d5b0acd81c95eca773f034","versionType":"git","status":"affected"},{"version":"8a49542c0554af7d0073aac0ee73ee65b807ef34","lessThan":"f8a07021679aadfb6d63b209207ccc41f26982d1","versionType":"git","status":"affected"},{"version":"8a49542c0554af7d0073aac0ee73ee65b807ef34","lessThan":"80c6054a4c40a0ffad82acef9f9a0dee108d152a","versionType":"git","status":"affected"},{"version":"8a49542c0554af7d0073aac0ee73ee65b807ef34","lessThan":"b42948f9e0d1ea4dbd5742ce1dfc7688de5d4a35","versionType":"git","status":"affected"},{"version":"8a49542c0554af7d0073aac0ee73ee65b807ef34","lessThan":"a979a642402d0b1f856c7a729b4cb2d92de4cf2f","versionType":"git","status":"affected"},{"version":"8a49542c0554af7d0073aac0ee73ee65b807ef34","lessThan":"1e7abfeb23c12bf46f6457e4a3e1a1a300d50619","versionType":"git","status":"affected"},{"version":"8a49542c0554af7d0073aac0ee73ee65b807ef34","lessThan":"42c5ca1f0a288a52878bd72a5595b08261057438","versionType":"git","status":"affected"},{"version":"e732ebc42aea321ee84514330eb3a675307fcc83","versionType":"git","status":"affected"},{"version":"2.6.34.14","lessThan":"2.6.35","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/events/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.35","status":"affected"},{"version":"0","lessThan":"2.6.35","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/1e7abfeb23c12bf46f6457e4a3e1a1a300d50619","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/42c5ca1f0a288a52878bd72a5595b08261057438","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/80c6054a4c40a0ffad82acef9f9a0dee108d152a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8e92e03984364d93e0d5b0acd81c95eca773f034","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f867c0e8da4c2303d91adf45acb6b1820966c27","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a979a642402d0b1f856c7a729b4cb2d92de4cf2f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b42948f9e0d1ea4dbd5742ce1dfc7688de5d4a35","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f8a07021679aadfb6d63b209207ccc41f26982d1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74638","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:37.007","lastModified":"2026-08-25T06:18:43.493","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Serialize the scheduler timeout handlers\n\nV3D exposes several independent hardware queues (BIN, RENDER, TFU and\nCSD) but has only a single, global reset. A timeout on any one queue\ntherefore has to stop, reset and restart the schedulers of every other\nqueue as well. That makes concurrent timeout handlers unsafe.\n\n`reset_lock` was never able to make them safe, as a driver-side lock can\nonly cover the driver's &drm_sched_backend_ops.timedout_job callback.\nThe scheduler handles the timed out job and its pending list around that\ncallback, outside of the driver's control, so a global reset triggered\nby one queue can still interfere with another queue that is in the\nmiddle of handling a timeout of its own.\n\nConsequently, if a reset happens in the CSD queue while a CL-intensive\napplication is running, the global reset stops and restarts the CL\nqueue's scheduler while that queue is handling a timeout of its own. As\ndrm_sched_stop() and drm_sched_start() subtract and add the credits of\nevery job sitting on the pending list of the scheduler they are called\non, and as the CL queue's handler concurrently takes its job off that\nsame list and puts it back, the stop and the start no longer see the\nsame set of jobs. The CL queue is left with more credits in flight than\nits limit:\n\n[  327.302739] ------------[ cut here ]------------\n[  327.302744] WARNING: CPU: 2 PID: 43 at drivers/gpu/drm/scheduler/sched_main.c:102 drm_sched_run_job_work+0x238/0x4d0 [gpu_sched]\n[  327.302884] CPU: 2 UID: 0 PID: 43 Comm: kworker/u16:1 Not tainted 6.18.39-v8-16k+ #3 PREEMPT\n[  327.302889] Hardware name: Raspberry Pi 5 Model B Rev 1.0 (DT)\n[  327.302893] Workqueue: v3d_bin drm_sched_run_job_work [gpu_sched]\n[  327.302984] Call trace:\n[  327.302987]  drm_sched_run_job_work+0x238/0x4d0 [gpu_sched] (P)\n[  327.302997]  process_scheduled_works+0x180/0x3d0\n[  327.303010]  worker_thread+0x268/0x3e8\n[  327.303016]  kthread+0x140/0x250\n[  327.303022]  ret_from_fork+0x10/0x20\n[  327.303031] ---[ end trace 0000000000000000 ]---\n\nFrom that point on, the credit count of the CL queue is broken, causing\na complete GPU hang and UI freeze.\n\nThe DRM scheduler already provides a mechanism to serialize the timeout\nhandlers of different schedulers: an ordered workqueue passed as\ndrm_sched_init()'s @timeout_wq parameter. By default, each scheduler\nqueues its timeout work on the system workqueue, which runs the handlers\nconcurrently. Give all of the queues a shared ordered workqueue instead,\nas recommended by the DRM scheduler documentation for hardware that has\ndistinct queues but resets globally."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/v3d/v3d_drv.h","drivers/gpu/drm/v3d/v3d_sched.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"35e4079bf1a2570abffce6ababa631afcf8ea0e5","lessThan":"5884851a096d8afcdf91f0e542bac193035183a6","versionType":"git","status":"affected"},{"version":"35e4079bf1a2570abffce6ababa631afcf8ea0e5","lessThan":"c22a45817b9c92aa0391db60e2ed467c7e6027d7","versionType":"git","status":"affected"},{"version":"35e4079bf1a2570abffce6ababa631afcf8ea0e5","lessThan":"4da94744707b27a3ae1197bdd7127da4505dc5b1","versionType":"git","status":"affected"},{"version":"5235b56b7e5449d990d21d78723b1a5e7bb5738e","versionType":"git","status":"affected"},{"version":"12125f7d9c15e6d8ac91d10373b2db2f17dcf767","versionType":"git","status":"affected"},{"version":"a5f162727b91e480656da1876247a91f651f76de","versionType":"git","status":"affected"},{"version":"422a8b10ba42097a704d6909ada2956f880246f2","versionType":"git","status":"affected"},{"version":"6.1.139","lessThan":"6.2","versionType":"semver","status":"affected"},{"version":"6.6.91","lessThan":"6.7","versionType":"semver","status":"affected"},{"version":"6.12.29","lessThan":"6.13","versionType":"semver","status":"affected"},{"version":"6.14.7","lessThan":"6.15","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/v3d/v3d_drv.h","drivers/gpu/drm/v3d/v3d_sched.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4da94744707b27a3ae1197bdd7127da4505dc5b1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5884851a096d8afcdf91f0e542bac193035183a6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c22a45817b9c92aa0391db60e2ed467c7e6027d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74639","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:37.143","lastModified":"2026-08-22T16:16:37.143","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: us144mkii: re-anchor capture URBs on resubmission\n\ncapture_urb_complete() resubmits each capture URB without anchoring it:\n\n\tusb_get_urb(urb);\n\tret = usb_submit_urb(urb, GFP_ATOMIC);\n\nAnchoring is a property of a submission, not of the URB.  The giveback\npath calls usb_unanchor_urb() before urb->complete(), so an URB\nresubmitted from its own completion handler is off the anchor.  The\ncapture URBs are anchored once, at stream start, so from the first\ncompletion onward tascam->capture_anchor is empty.\n\ntascam_free_urbs(), tascam_disconnect(), tascam_suspend() and the\nstop-work path all call usb_kill_anchored_urbs(&tascam->capture_anchor)\nto reap the capture URBs before anything is freed.  With the anchor empty\nthose calls return immediately and the URBs stay queued on the host\ncontroller.\n\ntascam_free_urbs() then returns the capture transfer buffers with\nusb_free_coherent(), and snd_card_free() releases the snd_card\nallocation that embeds tascam (card->private_data).  The controller\ncompletes the queued URBs afterwards, writing device-supplied data into\nthe freed transfer buffer, and capture_urb_complete() dereferences the\nfreed driver object.\n\nKASAN on 7.2.0-rc5 (arm64):\n\n  BUG: KASAN: slab-use-after-free in dummy_timer\n  Write of size 512 at addr ffff000015b62000\n   __asan_memcpy\n   dummy_timer\n   hrtimer_run_softirq\n  Allocated by task 64:\n   usb_alloc_coherent\n   tascam_alloc_urbs\n   tascam_probe\n  Freed by task 170:\n   usb_free_coherent\n   tascam_free_urbs\n   tascam_disconnect\n   usb_unbind_interface\n\n  BUG: KASAN: slab-use-after-free in capture_urb_complete\n  Read of size 4 at addr ffff0000170ee878\n  Freed by task 170:\n   release_card_device\n   snd_card_free\n   tascam_disconnect\n\nRestore the usb_anchor_urb() between the reference count bump and the\nresubmission.  That also makes the handler's usb_unanchor_urb() failure\narm meaningful again and restores usb_kill_anchored_urbs() as a barrier\non the disconnect, suspend and stop-work paths.\n\nThe anchoring was removed on the premise that the URB is already anchored\nfrom the initial submission, which does not hold once the first giveback\nhas run.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/usb/usx2y/us144mkii_capture.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"16f14f55141d4c55c3f321f93c328fff7cd6860a","lessThan":"7779249561d14b8a17c0c83783225794e24a587d","versionType":"git","status":"affected"},{"version":"ab1db64912428cdf06a4f9542e16e0575e9ad59f","lessThan":"a5548ce916594c811bd90ce33d67baa3557a6791","versionType":"git","status":"affected"},{"version":"5cff1529a2f9b3461a7f5a6e36a86682fc290534","lessThan":"2615f0fb90df8cf5a96133ca4be74294ed288604","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/usb/usx2y/us144mkii_capture.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18.39","lessThan":"6.18.45","versionType":"semver","status":"affected"},{"version":"7.1.4","lessThan":"7.1.9","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2615f0fb90df8cf5a96133ca4be74294ed288604","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7779249561d14b8a17c0c83783225794e24a587d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a5548ce916594c811bd90ce33d67baa3557a6791","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74640","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:37.267","lastModified":"2026-08-25T06:18:43.770","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: FCP: fix OOB write in fcp_meter_ctl_get()\n\nfcp_ioctl_set_meter_map() bounds the user-supplied Level Meter map size\nby the driver's own limit of 255\n\n\tif (map.map_size < 1 || map.map_size > 255 ||\n\t    map.meter_slots < 1 || map.meter_slots > 255)\n\t\treturn -EINVAL;\n\nand passes it to fcp_add_new_ctl() as the control's channel count, where\nit is stored as elem->channels.\n\nEvery control read writes into struct snd_ctl_elem_value, whose integer\narray is declared long value[128], so the limit is 128, not 255.\nfcp_meter_ctl_get() stores one 64-bit word per channel into that array\nwith no bound of its own:\n\n\tfor (i = 0; i < elem->channels; i++) {\n\t\tint idx = private->meter_level_map[i];\n\t\tint value = idx < 0 ? 0 : le32_to_cpu(resp[idx]);\n\n\t\tucontrol->value.integer.value[i] = value;\n\t}\n\nsnd_ctl_elem_read_user() serves that object from\nmemdup_user(_control, sizeof(*control)), 1224 bytes on LP64 out of\nkmalloc-2048.  offsetof(struct snd_ctl_elem_value, value) is 72, so\nelement i is written at byte 72 + 8 * i and element 144 already lands\npast the allocation.  At map_size 255 the last store ends at byte 2112,\n888 bytes past the object and 64 bytes into the adjacent slab object.\nThe stored words come from the device and meter_level_map[] selects\nwhich word lands in which slot, so extent and contents are both\ncontrolled.\n\nThe core does not catch this.  snd_ctl_check_elem_info() is reached only\nfrom __snd_ctl_elem_info(), which snd_ctl_elem_read() calls under\nCONFIG_SND_CTL_DEBUG; without that option snd_ctl_skip_validation() is a\ncompile-time true.  __snd_ctl_add_replace() validates kcontrol->count and\nnever inspects elem->channels.\n\nInstalling an oversized map needs CAP_SYS_RAWIO, but the control outlives\nthe hwdep descriptor that created it, so the out-of-bounds stores are\nissued by any process able to read controls on /dev/snd/controlC0.\n\nKASAN on 7.2.0-rc5 (arm64), triggered by an unprivileged control read:\n\n  BUG: KASAN: slab-out-of-bounds in fcp_meter_ctl_get\n  Write of size 8 at addr ffff000017af04c8 by task fcp_trigger/185\n   __asan_store8\n   fcp_meter_ctl_get\n   snd_ctl_elem_read\n   snd_ctl_ioctl\n  Allocated by task 185:\n   memdup_user\n   snd_ctl_ioctl\n  The buggy address is located 0 bytes to the right of\n   allocated 1224-byte region [ffff000017af0000, ffff000017af04c8)\n\nBound the map size by the ABI limit rather than by 255, and bound the\nstore loop at the sink so it cannot run past the value array whatever\nelem->channels holds.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/usb/fcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"46757a3e7d50dac923888e7fbe68377736f13c70","lessThan":"bb30e35c36ed00f24fa39aded811f64230a913b0","versionType":"git","status":"affected"},{"version":"46757a3e7d50dac923888e7fbe68377736f13c70","lessThan":"bb61dc2ae59026f76db26e1909746908bc5b6f31","versionType":"git","status":"affected"},{"version":"46757a3e7d50dac923888e7fbe68377736f13c70","lessThan":"620f1e52a46f604635efd0fb78138afd6a513b5d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/usb/fcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/620f1e52a46f604635efd0fb78138afd6a513b5d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb30e35c36ed00f24fa39aded811f64230a913b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb61dc2ae59026f76db26e1909746908bc5b6f31","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74641","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:37.383","lastModified":"2026-08-25T06:18:43.980","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usx2y: bound the hwdep mmap fault offset\n\nsnd_us428ctls_vm_fault() turns the faulting page offset into a kernel\naddress with no bound of any kind:\n\n\toffset = vmf->pgoff << PAGE_SHIFT;\n\tvaddr = (char *)(...)->us428ctls_sharedmem + offset;\n\tpage = virt_to_page(vaddr);\n\tget_page(page);\n\tvmf->page = page;\n\n\treturn 0;\n\nsnd_us428ctls_mmap() checks only the length of the mapping, never the\noffset, and us428ctls_sharedmem is a single page from\nalloc_pages_exact().  For a character device file_mmap_size_max()\nreturns ULONG_MAX, so the mm layer imposes no ceiling either.  Every page\noffset above zero resolves to a struct page outside the object, and the\nhandler installs it into the caller's address space read-write; the vma\nis not marked read-only.\n\nThe caller picks the page frame with a single mmap() argument and gets\nread-write access to a page of kernel memory it does not own; an offset\nthat lands in an unpopulated vmemmap region oopses instead.\n\nA process that can open the hwdep node of an attached US-X2Y reaches\nthis after loading the FPGA image through the same node; no capability\ncheck is involved.\n\nOn 7.2.0-rc5 (arm64), mmap() with a large offset:\n\n  Unable to handle kernel paging request at virtual address fffffdffc45d5ac8\n  pc : snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y]\n  Call trace:\n   snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y]\n   __do_fault\n   __handle_mm_fault\n   handle_mm_fault\n   el0_da\n\nReject any offset outside the shared region.  The pcm hwdep handler in\nusx2yhwdeppcm.c computes its address the same way and needs the same\nbound.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/usb/usx2y/usX2Yhwdep.c","sound/usb/usx2y/usx2yhwdeppcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ad6fedea65c6e90eda00d716c8bf20cdc437ed10","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"10a87401fb3148c388e55df0148295b3b137da07","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"34ab56ed854baa73a731cfd99af689f0b1bac444","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"4208db2453e1ea71b8048a5b7802360cb29a53f1","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f613b4a2d87247b51a1b2b330f2e083a454125f2","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f75d6f61f0d9c5c1ea725104014e10d26d1e3a00","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5bf5ccddf00b59f1e3ea7e65d76a5f5b5c21cc2e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2ca1eea3cd17930daffe9e429a7c89232036ec24","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/usb/usx2y/usX2Yhwdep.c","sound/usb/usx2y/usx2yhwdeppcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.266","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/10a87401fb3148c388e55df0148295b3b137da07","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2ca1eea3cd17930daffe9e429a7c89232036ec24","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/34ab56ed854baa73a731cfd99af689f0b1bac444","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4208db2453e1ea71b8048a5b7802360cb29a53f1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5bf5ccddf00b59f1e3ea7e65d76a5f5b5c21cc2e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ad6fedea65c6e90eda00d716c8bf20cdc437ed10","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f613b4a2d87247b51a1b2b330f2e083a454125f2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f75d6f61f0d9c5c1ea725104014e10d26d1e3a00","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74642","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:37.513","lastModified":"2026-08-22T16:16:37.513","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb: Fix UAF at delayed release of MIDI2 EPs\n\nThe recent fix for UAF in ump_to_endpoint() caused another UAF because\nit tries to dereference the UMP endpoint object, but this might be\nexecuted at a delayed context where the endpoint has been already\nreleased.\n\nAdd private_free to clear the associated data for avoiding the further\ndereference for delayed releases."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/usb/midi2.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"49eccef6d6e1c00dac6fb2e7eb6f9206c33e1c37","lessThan":"d431941825d357be7d9ab0cb7505e3a1963bd89e","versionType":"git","status":"affected"},{"version":"8a7a33b846d6ba695891b8d0040027cdbad8cd52","lessThan":"422d8a02de5ce6a29d616d55e5ead5dec69ac1d7","versionType":"git","status":"affected"},{"version":"cc014ebf803174f0e5d15956dfc5a38413c945ae","lessThan":"d217d723c5e43881b952cdb978477f7f2dc0b6d7","versionType":"git","status":"affected"},{"version":"ae388c0e1bf727972096f770f82d12e4f748d1b6","lessThan":"f9d492a39ebeb1a56f13ec6dd165a18a48dec812","versionType":"git","status":"affected"},{"version":"4a05b2d1b4642df74f30b6f54843e825c4a2bfd3","lessThan":"f8a80cfb68613fb7e6452b66447dbc63f435d140","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/usb/midi2.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6.151","lessThan":"6.6.152","versionType":"semver","status":"affected"},{"version":"6.12.103","lessThan":"6.12.104","versionType":"semver","status":"affected"},{"version":"6.18.44","lessThan":"6.18.45","versionType":"semver","status":"affected"},{"version":"7.1.8","lessThan":"7.1.9","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/422d8a02de5ce6a29d616d55e5ead5dec69ac1d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d217d723c5e43881b952cdb978477f7f2dc0b6d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d431941825d357be7d9ab0cb7505e3a1963bd89e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f8a80cfb68613fb7e6452b66447dbc63f435d140","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f9d492a39ebeb1a56f13ec6dd165a18a48dec812","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74643","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:37.617","lastModified":"2026-08-22T16:16:37.617","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsamples/damon/mtier: error out for zero quota goal target values\n\nPatch series \"mm/damon: avoid division by zero from damos_quota_score()\".\n\nDAMON_SAMPLE_MTIER and DAMON_LRU_SORT allow the user to trigger division\nby zero in damos_quota_score().  Avoid it by adding parameters validation\nchecks.\n\n\nThis patch (of 2):\n\ndamos_quota_score() can trigger division by zero if the target_value is\nzero.  DAMON_SAMPLE_MTIER lets users set the target_value via\nnode0_mem_{used,free}_bp parameters.  It doesn't guard zero value case,\nthough.  As a result, users can trigger division by zero.  Fix the issue\nby returning an error when the user tries to start DAMON with zero\nnode0_mem_{used,free}_bp parameter values.\n\nDAMON_SAMPLE_MTIER is just a sample module, but the consequence is quite\nbad.  Also the zero node0_mem_free_bp parameter might look like a\nreasonable setup to some users.  Hence, the issue might really happen in\nthe real world.\n\nOne reliable way to reproduce the issue is like below:\n\n    # cd /sys/module/damon_sample_mtier/parameters\n    # echo 4096 > node0_start_addr\n    # echo 8192 > node0_end_addr\n    # echo 8192 > node1_start_addr\n    # echo 81920 > node1_end_addr\n    # echo 0 > node0_mem_free_bp\n    # echo Y > enabled\n    # dmesg -w\n    [...]\n    [18792.235916] Oops: divide error: 0000 [#1] SMP NOPTI\n    [...]\n    [18792.242787] RIP: 0010:damos_quota_score+0x6f/0x480\n    [...]\n\nThis issue was discovered [1] by Sashiko."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["samples/damon/mtier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c5e67d40a10234541e220750297304df79aaedd0","lessThan":"e16b8d640ec99b28bc827560edcf9706e610c3aa","versionType":"git","status":"affected"},{"version":"c5e67d40a10234541e220750297304df79aaedd0","lessThan":"684f271210becd7b8c4088f06c442499e48a43a0","versionType":"git","status":"affected"},{"version":"c5e67d40a10234541e220750297304df79aaedd0","lessThan":"a16fd3ad9d89b05475864da97327870464611736","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["samples/damon/mtier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/684f271210becd7b8c4088f06c442499e48a43a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a16fd3ad9d89b05475864da97327870464611736","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e16b8d640ec99b28bc827560edcf9706e610c3aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74644","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:37.730","lastModified":"2026-08-23T13:16:48.353","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/ops-common: putback folios on invalid migrate nid\n\ndamon_pa_migrate() and damos_va_migrate() isolate folios into a local list\nand then call damon_migrate_pages().  When target_nid is invalid\n(including the scheme default NUMA_NO_NODE / -1), damon_migrate_pages()\nreturns early without putting the folios back to the LRU.\n\nCallers then discard the list head while those folios remain isolated with\nan extra reference taken by folio_isolate_lru().  The pages stay off the\nLRU for as long as the mapping exists (anon active+inactive counts drop\nwhile RSS does not), and the leftover references can pin the pages after\nthe mapping is gone.\n\nPut the folios back on the invalid-nid path so ignored migration requests\nstill return them to the LRU."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/damon/ops-common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7c303fa1f311aadc17fa82b7bbf776412adf45de","lessThan":"7001c0a1bc9018cd5b2b72ebebb216d738b2ec81","versionType":"git","status":"affected"},{"version":"7e6c3130690a01076efdf45aa02ba5d5c16849a0","lessThan":"460181e4bb47a57776c64f0832c2096de8878cb3","versionType":"git","status":"affected"},{"version":"7e6c3130690a01076efdf45aa02ba5d5c16849a0","lessThan":"cfef454862b7d2776e0955b873dd59af6b47cfcb","versionType":"git","status":"affected"},{"version":"7e6c3130690a01076efdf45aa02ba5d5c16849a0","lessThan":"5deb65c34e682e7c5f5df417a70e223e8fcc5f5a","versionType":"git","status":"affected"},{"version":"9d0c2d15aff96746f99a7c97221bb8ce5b62db19","versionType":"git","status":"affected"},{"version":"6.12.44","lessThan":"6.12.105","versionType":"semver","status":"affected"},{"version":"6.16.4","lessThan":"6.17","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/damon/ops-common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/460181e4bb47a57776c64f0832c2096de8878cb3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5deb65c34e682e7c5f5df417a70e223e8fcc5f5a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7001c0a1bc9018cd5b2b72ebebb216d738b2ec81","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cfef454862b7d2776e0955b873dd59af6b47cfcb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74645","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:37.837","lastModified":"2026-08-22T16:16:37.837","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/lru_sort: error out for >10000 active_mem_bp\n\ndamos_quota_score() can trigger division by zero if the target value is\nzero.  DAMON_LRU_SORT lets users set the target value for the hot memory\nscheme via active_mem_bp parameter.  It avoids setting it as the target\nvalue if the parameter value is zero.  However, it also sets the cold\nmemory scheme with a target value that is calculated as '10000 -\nactive_mem_bp + 2'.  Hence, if a user sets active_mem_bp 10002, the cold\nmemory scheme's quota goal target value can be zero.  As a result,\ndivision by zero can be triggered.  Fix by returning an error when the\nuser tries to start DAMON with >10000 active_mem_bp parameter value.\n\nIt makes no sense to set active_mem_bp with 10002.  It also requires\nmodule parameters write permission to reproduce the issue.  That said, the\nconsequence is quite bad.\n\nOne reliable way to reproduce the issue is like below:\n\n    # cd /sys/module/damon_lru_sort/parameters\n    # echo 1000 > wmarks_high\n    # echo 995 > wmarks_mid\n    # echo 0 > wmarks_low\n    # echo 10002 > active_mem_bp\n    # echo Y > enabled\n    # dmesg -w\n    [...]\n    [  597.421247] Oops: divide error: 0000 [#1] SMP NOPTI\n    [  597.428848] RIP: 0010:damos_quota_score+0x6f/0x480\n\nThis issue was discovered [1] by Sashiko."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/damon/lru_sort.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"40d98d31cd7060228e03303c5c34ae7101020416","lessThan":"e7e5e5e0dfe2ea171044c24c263efae4ee882b3f","versionType":"git","status":"affected"},{"version":"40d98d31cd7060228e03303c5c34ae7101020416","lessThan":"06befa61c427e74319781e6f35a364cfc32dbae8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/damon/lru_sort.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/06befa61c427e74319781e6f35a364cfc32dbae8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e7e5e5e0dfe2ea171044c24c263efae4ee882b3f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74646","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:37.940","lastModified":"2026-08-25T06:18:44.283","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: take fl->lock when moving mmaps on interrupted invoke\n\nWhen an invoke is interrupted by a signal,\nwait_for_completion_interruptible() returns -ERESTARTSYS and\nfastrpc_internal_invoke() moves every buffer from fl->mmaps onto\ncctx->invoke_interrupted_mmaps. This list_del()/list_add_tail() walk\nruns without holding fl->lock, the lock that serialises fl->mmaps in\nfastrpc_req_mmap() and fastrpc_req_munmap() everywhere else.\n\nTake fl->lock around the move, matching every other fl->mmaps accessor."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/misc/fastrpc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"76e8e4ace1ed2c97dba3b1370e0e105e07c572bc","lessThan":"3f265e405e5ef85030c3777262e18bb556bc8724","versionType":"git","status":"affected"},{"version":"76e8e4ace1ed2c97dba3b1370e0e105e07c572bc","lessThan":"a902fe1f80f58a2335b6be1131866f827ec44d1a","versionType":"git","status":"affected"},{"version":"76e8e4ace1ed2c97dba3b1370e0e105e07c572bc","lessThan":"af6345159abcbaa550518f31990d2a9558c2d369","versionType":"git","status":"affected"},{"version":"76e8e4ace1ed2c97dba3b1370e0e105e07c572bc","lessThan":"efd02f8d1a7449f15809bc18d3cd41aafea75d7e","versionType":"git","status":"affected"},{"version":"76e8e4ace1ed2c97dba3b1370e0e105e07c572bc","lessThan":"b85a0e91d7d6cd06a53c881a46f749cfcef416a2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/misc/fastrpc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.2","status":"affected"},{"version":"0","lessThan":"6.2","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/3f265e405e5ef85030c3777262e18bb556bc8724","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a902fe1f80f58a2335b6be1131866f827ec44d1a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af6345159abcbaa550518f31990d2a9558c2d369","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b85a0e91d7d6cd06a53c881a46f749cfcef416a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/efd02f8d1a7449f15809bc18d3cd41aafea75d7e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74647","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:38.050","lastModified":"2026-08-27T13:18:35.540","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: Remove buffer from list prior to unmap operation\n\nfastrpc_req_munmap_impl() is called to unmap any buffer. The buffer is\ngetting removed from the list after it is unmapped from DSP. This can\ncreate potential race conditions if multiple threads invoke unmap\nconcurrently, where one thread may remove the entry from the list while\nanother thread's unmap operation is still ongoing.\n\nFix this by removing the buffer entry from the list before calling the\nunmap operation. If the unmap fails, the entry is re-added to the list\nso that userspace can retry the unmap, or alternatively, the buffer\nwill be cleaned up during device release when the DSP process is torn\ndown and all DSP-side mappings are freed along with remaining buffers\nin the list."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/misc/fastrpc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2419e55e532de14fdf336e09e453aa2831c73a25","lessThan":"1edb654b2b41baee2ab5cf418baaf6e57dfbd802","versionType":"git","status":"affected"},{"version":"2419e55e532de14fdf336e09e453aa2831c73a25","lessThan":"4716c23c206a2f99ca54ebfdd8b5ba9dd0102240","versionType":"git","status":"affected"},{"version":"2419e55e532de14fdf336e09e453aa2831c73a25","lessThan":"99f8de36c84cb9b872157aa6c3578c2480cee4b8","versionType":"git","status":"affected"},{"version":"2419e55e532de14fdf336e09e453aa2831c73a25","lessThan":"97273624f7b356eaf8261609a75cfcb8738a165a","versionType":"git","status":"affected"},{"version":"2419e55e532de14fdf336e09e453aa2831c73a25","lessThan":"fe70329055977fc1e8dc6291318d0dd75470795a","versionType":"git","status":"affected"},{"version":"2419e55e532de14fdf336e09e453aa2831c73a25","lessThan":"9bf22a7d950cec2d1efeca7f16bb20fcca84c36a","versionType":"git","status":"affected"},{"version":"2419e55e532de14fdf336e09e453aa2831c73a25","lessThan":"0beaa9bd7eb10d9b5e6352ed5161f3f3bbd4c3c5","versionType":"git","status":"affected"},{"version":"2419e55e532de14fdf336e09e453aa2831c73a25","lessThan":"6102ceb4eab845743ee57acd3863fbd06e93c927","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/misc/fastrpc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.5","status":"affected"},{"version":"0","lessThan":"5.5","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/0beaa9bd7eb10d9b5e6352ed5161f3f3bbd4c3c5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1edb654b2b41baee2ab5cf418baaf6e57dfbd802","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4716c23c206a2f99ca54ebfdd8b5ba9dd0102240","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6102ceb4eab845743ee57acd3863fbd06e93c927","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/97273624f7b356eaf8261609a75cfcb8738a165a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/99f8de36c84cb9b872157aa6c3578c2480cee4b8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9bf22a7d950cec2d1efeca7f16bb20fcca84c36a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe70329055977fc1e8dc6291318d0dd75470795a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74648","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:38.160","lastModified":"2026-08-25T06:18:44.883","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: validate monitor transmit frame lengths\n\nrtw_cfg80211_monitor_if_xmit_entry() removes the radiotap header and\nthen reads the 802.11 frame control field without checking that a base\n802.11 header remains.\n\nThe data path also pulls the calculated 802.11, QoS and SNAP header\nspan before confirming that the skb contains it. A truncated frame can\ntherefore cause out-of-bounds reads or leave insufficient data for the\nEthernet address writes.\n\nReject frames that do not contain the base 802.11 header and data\nframes that do not contain their complete calculated header span."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"f03398d835f5249c49546f0eb0d0df6792b95d5f","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"a3ac6d849de5f7abe14761d741bbb843ac793454","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"7edd3adb0c80d70b4237640275c559610f438476","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"c5e5d78743992e235b76d2ebe5a403d60315aa8a","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"7b0f62d2986a28e5e4188366bc2f4e2868b14790","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"8b3e4ed9c35d3d3b64fcc23f4a1f22b37c1865b1","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"bd88f6289b7e483216a9c1df15a0460ef9b02cb6","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"6829665d050983907b560173e49dcc6c11cb2730","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/6829665d050983907b560173e49dcc6c11cb2730","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7b0f62d2986a28e5e4188366bc2f4e2868b14790","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7edd3adb0c80d70b4237640275c559610f438476","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b3e4ed9c35d3d3b64fcc23f4a1f22b37c1865b1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3ac6d849de5f7abe14761d741bbb843ac793454","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd88f6289b7e483216a9c1df15a0460ef9b02cb6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c5e5d78743992e235b76d2ebe5a403d60315aa8a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f03398d835f5249c49546f0eb0d0df6792b95d5f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74649","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:38.290","lastModified":"2026-08-25T06:18:45.130","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix missing shared-key auth challenge length check\n\nThe WEP shared-key authentication handler uses the challenge-text\nelement's attacker-controlled length without checking it against the\nfixed 128-byte chg_txt buffer.\n\nIn OnAuthClient() the length from rtw_get_ie() - up to 255 - is used\nto perform memcpy() into the 128-byte pmlmeinfo->chg_txt, so a\nmalicious AP sending a malformed WLAN_EID_CHALLENGE element can\noverflow/underfill chg_txt by up to 127 bytes. It is reachable over the\nair, before association, during shared-key authentication. In the case\nof an overflow, the driver can write out of bounds. In the case of an\nunderfill, the driver can echo stale buffer memory.\n\nThe challenge text is defined to be exactly 128 octets, which is\nalready provided as the WLAN_AUTH_CHALLENGE_LEN define; require the\nelement to be exactly that length before use."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/staging/rtl8723bs/core/rtw_mlme_ext.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"39ae1033071001af9bb4573ebdbb43bbbe88f749","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"4d018e7d7d908bdfcb5ecfa922b1d5cb9ddb3722","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"4ba402fd47009d20e51dbfc934abb562098ea35b","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"87c2f073d2aaea041d531b8e579c47570b54b3b7","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"a28a4b0592e4a37ea471bc0d308513a93133ce7e","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"6235b5156b48ed5d1ce3410d8f0b2fd67d30d944","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"2c56ef658ac8c6bca36bc5574715e8f717207c6c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/staging/rtl8723bs/core/rtw_mlme_ext.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/2c56ef658ac8c6bca36bc5574715e8f717207c6c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/39ae1033071001af9bb4573ebdbb43bbbe88f749","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4ba402fd47009d20e51dbfc934abb562098ea35b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4d018e7d7d908bdfcb5ecfa922b1d5cb9ddb3722","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6235b5156b48ed5d1ce3410d8f0b2fd67d30d944","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/87c2f073d2aaea041d531b8e579c47570b54b3b7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a28a4b0592e4a37ea471bc0d308513a93133ce7e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74650","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:38.413","lastModified":"2026-08-27T13:18:35.720","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB read in WMM_param_handler()\n\nWMM_param_handler() copies a fixed-size WMM parameter element out of a\nreceived information element without checking that the element is long\nenough, causing an out-of-bounds read for a short WMM IE.\n\nThe handler reads sizeof(struct WMM_para_element) (18) bytes at\npIE->data + 6, so it requires pIE->length to be at least 24\n(WLAN_WMM_LEN), but it never validates the length. Two of its three\ncallers reach it after matching only the WMM OUI: OnAssocRsp() in\nrtw_mlme_ext.c matches a 6-byte OUI, and join_cmd_hdl() matches a\n4-byte OUI, before calling the handler. A vendor-specific IE carrying\nthe WMM OUI but a length between 6 and 23, placed in an association\nresponse or in the IE blob handed to join_cmd_hdl(), passes the OUI\ncheck and then makes the memcmp() and memcpy() at pIE->data + 6 read\npast the end of the element. OnAssocRsp() parses a frame received from\nthe AP, so this is reachable from a remote peer.\n\nThe remaining caller in rtw_wlan_util.c already guards the handler with\n\"pIE->length == WLAN_WMM_LEN\". Move the equivalent check into the\nhandler itself so every caller is covered; the sibling IE handlers in\nthe same parsing loop (HT_caps_handler(), HT_info_handler(),\nERP_IE_handler()) likewise bound their accesses by pIE->length."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/staging/rtl8723bs/core/rtw_wlan_util.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"5df2fd06567df5f178c8faae0bdaefd203618d21","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"6cdca4c8b64c15a3ab9ad7a85f482e9519eadf93","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"2bee6f7a0f0125238951e31da2e96d06fe359043","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"1158b9931207392d6dd136aa0c4be18893b50fa1","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"ce2399717de242344880044b91a20a712644fdfb","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"e5b7610008f4e6a80c8b071aa77ddbd5e17ea472","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"e429c6dfd5d2324cd866daaf4c29d5cfe4dea0e4","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"ae21407350151bddfd4fea7aa39bd0643c0ca9d3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/staging/rtl8723bs/core/rtw_wlan_util.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1158b9931207392d6dd136aa0c4be18893b50fa1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2bee6f7a0f0125238951e31da2e96d06fe359043","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5df2fd06567df5f178c8faae0bdaefd203618d21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6cdca4c8b64c15a3ab9ad7a85f482e9519eadf93","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae21407350151bddfd4fea7aa39bd0643c0ca9d3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ce2399717de242344880044b91a20a712644fdfb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e429c6dfd5d2324cd866daaf4c29d5cfe4dea0e4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5b7610008f4e6a80c8b071aa77ddbd5e17ea472","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74651","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:38.543","lastModified":"2026-08-25T06:18:45.437","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB read in rtw_get_wpa_ie()\n\nrtw_get_wpa_ie() reads bytes at fixed offsets into a vendor-specific\ninformation element without checking that the element is long enough,\ncausing an out-of-bounds read for a short trailing IE.\n\nThe function locates a vendor-specific IE (EID 221) with rtw_get_ie()\nand then compares a 4-byte OUI+type at pbuf + 2 and reads a 2-byte\nversion word at pbuf + 6. Those accesses require the IE body to be at\nleast 6 bytes, but rtw_get_ie() only guarantees that the element fits\nwithin the buffer; it does not enforce a minimum body length. A\nvendor-specific IE whose length byte is 0 to 5, placed at the end of\nthe buffer, therefore makes these reads run past the end of the IE and\npast the end of the buffer itself.\n\nThe buffer holds information elements taken from received management\nframes and from the IE blob passed to rtw_cfg80211_set_wpa_ie(), which\nis kmemdup'd to its exact length, so the read can run off the end of\nthe allocation.\n\nThe sibling helpers rtw_get_sec_ie(), rtw_get_wapi_ie() and\nrtw_get_wps_ie() in this file already reject too-short vendor-specific\nIEs before their OUI memcmp(); rtw_get_wpa_ie() was never brought in\nline with them, and needs a minimum of 6 rather than 4 bytes because\nof the version word. Add the missing length check."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/staging/rtl8723bs/core/rtw_ieee80211.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"4fc459c5cd8767ca4d9bf2f7becbd562639ba4d9","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"b45be82387bf759931acdd21ca7dfe740f16eb97","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"c9068f82a0906b29c905e8788edb62c3208c7c8a","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"0d19f0600fbb610c42f2a86f95c35706dc04691b","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"42c5a0d454aa5b54fec17162d9a1f8c30f8af45a","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"e167a38a8a8f50f137721fef1a1fbba0f4588b5d","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"01ab275f8f3e497a13ebbe4ded44ec0623bccde3","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"1c3e23e78862493e8cf1adad02b10ffcb8b9921c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/staging/rtl8723bs/core/rtw_ieee80211.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2}]},"references":[{"url":"https://git.kernel.org/stable/c/01ab275f8f3e497a13ebbe4ded44ec0623bccde3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0d19f0600fbb610c42f2a86f95c35706dc04691b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1c3e23e78862493e8cf1adad02b10ffcb8b9921c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/42c5a0d454aa5b54fec17162d9a1f8c30f8af45a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4fc459c5cd8767ca4d9bf2f7becbd562639ba4d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b45be82387bf759931acdd21ca7dfe740f16eb97","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9068f82a0906b29c905e8788edb62c3208c7c8a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e167a38a8a8f50f137721fef1a1fbba0f4588b5d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74652","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:38.693","lastModified":"2026-08-25T06:18:45.730","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nserial: amba-pl011: cancel RS485 hrtimers after freeing IRQ\n\nThe RS485 trigger hrtimers are embedded in the devm-managed port and can\nfire after it is freed. The IRQ handler can arm a timer, so free the IRQ\nfirst and then cancel both timers.\n\nComplete the RS485 stop without arming a timer, and cancel the timers\nin remove() for the suspend-then-unbind path, where shutdown is not\ncalled.\n\nThis issue was found by an in-house static analysis tool."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/tty/serial/amba-pl011.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2c1fd53af21b8cb13878b054894d33d3383eb1f3","lessThan":"759ead98a39fb625be302f9aa66290985dcaa325","versionType":"git","status":"affected"},{"version":"2c1fd53af21b8cb13878b054894d33d3383eb1f3","lessThan":"e57f0aa5c35be37218ba0e4887b241584dd4b2d2","versionType":"git","status":"affected"},{"version":"2c1fd53af21b8cb13878b054894d33d3383eb1f3","lessThan":"36672c8d7d14e9c43287528455d2c97b526ea6ad","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/tty/serial/amba-pl011.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/36672c8d7d14e9c43287528455d2c97b526ea6ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/759ead98a39fb625be302f9aa66290985dcaa325","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e57f0aa5c35be37218ba0e4887b241584dd4b2d2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74653","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:38.827","lastModified":"2026-08-27T13:18:35.877","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nserial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx\n\nThe NXP LPC32xx UART (PORT_LPC3220) can latch an RX character-timeout\ninterrupt while the RX FIFO is empty: IIR reports UART_IIR_RX_TIMEOUT\n(0x0c) but LSR.DR is clear. A character timeout is only cleared by\nreading RHR, but serial8250_rx_chars() reads RHR only when LSR.DR is\nset, so nothing ever clears the condition. The interrupt is\nlevel-triggered and re-fires immediately, so on a single-core ARM926\nthe resulting interrupt storm livelocks the CPU.\n\nIt is reproducible when userspace repeatedly opens the front-panel port\n(ttyS1): serial8250_do_set_termios() re-enables interrupts on unlock and\nthe handler then spins forever with iir=0xcc lsr=0x60 ier=0x05, tripping\nthe soft-lockup detector in serial8250_handle_irq_locked().\n\nLPC32xx has no dedicated 8250 glue driver, it's driven by the generic\n8250_of. Add a hardware specific handle_irq for PORT_LPC3220, wired up\nin of_platform_serial_setup() the same way fsl8250_handle_irq is\ninstalled. The handler follows dw8250_handle_irq(): on an RX timeout\nwith an empty FIFO (LSR.DR and LSR.BI clear) it does one throwaway RHR\nread to clear the condition, then calls serial8250_handle_irq_locked().\nNo real received data is ever discarded, and it is a no-op on healthy\nUARTs which never report a timeout with DR clear.\n\nThis is the same class of bug already worked around in other 8250 drivers;\nsee commit 424d79183af0 (\"serial: 8250_dw: Avoid \"too much work\" from bogus rx timeout interrupt\")\nwhich reports the identical iir=0xcc/lsr=0x60. See also\nUART_RX_TIMEOUT_QUIRK in 8250_omap, and the note in 8250_bcm7271."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/tty/serial/8250/8250_of.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e6e912c4964ce5976e508881207dfa96d5f856d7","lessThan":"c321dc5172c8c66e21ffbeeb7a2ebb88ae6fd4c3","versionType":"git","status":"affected"},{"version":"e6e912c4964ce5976e508881207dfa96d5f856d7","lessThan":"3ce24bc4d115336218e59b7e286fd3a79f4fc4c6","versionType":"git","status":"affected"},{"version":"e6e912c4964ce5976e508881207dfa96d5f856d7","lessThan":"7795e8abedc86438cae0454602cbf9038b94bf38","versionType":"git","status":"affected"},{"version":"e6e912c4964ce5976e508881207dfa96d5f856d7","lessThan":"1423415471274abda87024967d7fe2206ceee0ea","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/tty/serial/8250/8250_of.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.36","status":"affected"},{"version":"0","lessThan":"2.6.36","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1423415471274abda87024967d7fe2206ceee0ea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3ce24bc4d115336218e59b7e286fd3a79f4fc4c6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7795e8abedc86438cae0454602cbf9038b94bf38","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c321dc5172c8c66e21ffbeeb7a2ebb88ae6fd4c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74654","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:38.937","lastModified":"2026-08-22T16:16:38.937","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nserial: 8250_dma: Clear stale RX state on shutdown\n\nserial8250_release_dma() terminates RX DMA and releases the channel, but\nleaves rx_running set.  If the port is closed while an RX transfer is\nactive, the stale state remains while rxchan is NULL until the channel is\nrequested again on the next open.\n\nThe DesignWare BUSY workaround added by commit a7b9ce39fbe4\n(\"serial: 8250_dw: Ensure BUSY is deasserted\") calls\nserial8250_rx_dma_flush() from the LCR write path during startup.  This\nhappens before serial8250_request_dma() obtains a new RX channel.  On\nreopen, the stale rx_running state therefore makes the flush path pass a\nNULL channel to dmaengine_pause(), causing a kernel Oops.\n\nClear rx_running after terminating RX DMA, matching the TX cleanup.  Also\nmake the flush helper return if the DMA object or RX channel is not\navailable so startup and teardown paths cannot pass a NULL channel to the\nDMAengine API."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/tty/serial/8250/8250_dma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0fcb7901f9d61a325b4c5b88c600383bcbeb97fe","lessThan":"bf4fb620e02962b2b52500a4b3d8420f351eb46a","versionType":"git","status":"affected"},{"version":"0fcb7901f9d61a325b4c5b88c600383bcbeb97fe","lessThan":"e10f06ee050a08930e2339b6fec7148fd0b2a8f6","versionType":"git","status":"affected"},{"version":"0fcb7901f9d61a325b4c5b88c600383bcbeb97fe","lessThan":"d06cfb1add4a2d5b393e9e31f49ebbd168beea49","versionType":"git","status":"affected"},{"version":"0fcb7901f9d61a325b4c5b88c600383bcbeb97fe","lessThan":"e7a5d792cf64a2096e18f1d573cc3d01cba15e92","versionType":"git","status":"affected"},{"version":"0fcb7901f9d61a325b4c5b88c600383bcbeb97fe","lessThan":"9f2444f4c0e4b06f61bae38da87c9c94c78efa86","versionType":"git","status":"affected"},{"version":"0fcb7901f9d61a325b4c5b88c600383bcbeb97fe","lessThan":"ae05d9e50b6b9f246c110b3bdc03676145c2d0d4","versionType":"git","status":"affected"},{"version":"0fcb7901f9d61a325b4c5b88c600383bcbeb97fe","lessThan":"e7e3cc6709caa49d1d6ce6c1f7cb305e38675cc9","versionType":"git","status":"affected"},{"version":"0fcb7901f9d61a325b4c5b88c600383bcbeb97fe","lessThan":"e2fe6a0efecbef00e3ecc2db64dd5afa8c212b41","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/tty/serial/8250/8250_dma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.19","status":"affected"},{"version":"0","lessThan":"3.19","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/9f2444f4c0e4b06f61bae38da87c9c94c78efa86","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae05d9e50b6b9f246c110b3bdc03676145c2d0d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf4fb620e02962b2b52500a4b3d8420f351eb46a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d06cfb1add4a2d5b393e9e31f49ebbd168beea49","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e10f06ee050a08930e2339b6fec7148fd0b2a8f6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2fe6a0efecbef00e3ecc2db64dd5afa8c212b41","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e7a5d792cf64a2096e18f1d573cc3d01cba15e92","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e7e3cc6709caa49d1d6ce6c1f7cb305e38675cc9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74655","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:39.067","lastModified":"2026-08-27T13:18:35.997","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nserial: qcom-geni: fix TX DMA buffer flush\n\nWhen transmit flushing a qcom-geni UART during an ongoing TX DMA, the\nUART gets stuck infinitely repeating corrupted TX DMA frames.\n\nThe DMA-mode uart_ops does not provide a flush_buffer callback, so an\nin-flight transfer can complete after serial core has reset the transmit\nkfifo, underflowing its length and resubmitting page-sized transfers\nindefinitely. Add one that stops the transfer and clears tx_remaining\nand tx_queued.\n\nThe stop path was also broken: it unmapped the buffer while the serial\nengine could still read it, and never reset the TX DMA state machine.\nCancel the main sequencer command first, then reset the state machine\nand wait for it before unmapping. Drop the early return so a pending\nmapping is also cleaned up when the main command is inactive.\n\nThe bug can be triggered from userspace with a large write immediately\nfollowed by TCOFLUSH. A following tcdrain will hang forever. The bug was\nreproduced and this fix was validated on Arduino Uno Q (QRB2210)\nusing /dev/ttyHS1."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/tty/serial/qcom_geni_serial.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2aaa43c7077833301c237684cd7bc9ae5e3dec95","lessThan":"1606abb7ce8c0cfef98c7e556b83c14e5d73c1bf","versionType":"git","status":"affected"},{"version":"2aaa43c7077833301c237684cd7bc9ae5e3dec95","lessThan":"313ae287442e5e8d3f7b53b73f37d384bda072d0","versionType":"git","status":"affected"},{"version":"2aaa43c7077833301c237684cd7bc9ae5e3dec95","lessThan":"1c31e2377f4c1bb110ca7f6e597b2253a7440c37","versionType":"git","status":"affected"},{"version":"2aaa43c7077833301c237684cd7bc9ae5e3dec95","lessThan":"b1801c0d40f62778b613334de5840aba10a564d5","versionType":"git","status":"affected"},{"version":"2aaa43c7077833301c237684cd7bc9ae5e3dec95","lessThan":"e3c04834ae1ab5e9cfbe8ac54ec734aa4774249d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/tty/serial/qcom_geni_serial.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.3","status":"affected"},{"version":"0","lessThan":"6.3","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.0,"impactScore":6.0}]},"references":[{"url":"https://git.kernel.org/stable/c/1606abb7ce8c0cfef98c7e556b83c14e5d73c1bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1c31e2377f4c1bb110ca7f6e597b2253a7440c37","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/313ae287442e5e8d3f7b53b73f37d384bda072d0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b1801c0d40f62778b613334de5840aba10a564d5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e3c04834ae1ab5e9cfbe8ac54ec734aa4774249d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74656","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:39.177","lastModified":"2026-08-25T06:18:46.560","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: fix use-after-free in fib_nhc_update_mtu()\n\nfib_nhc_update_mtu() walks the nexthop exception table under RTNL, but\nRTNL does not serialize this walk with PMTU exception updates. The walk\nuses rcu_dereference_protected() with a constant true condition without\nholding fnhe_lock.\n\nThe following interleaving can therefore occur:\n\n  CPU 0                              CPU 1\n  fib_nhc_update_mtu()               update_or_create_fnhe()\n    load fnhe                          spin_lock_bh(&fnhe_lock)\n                                       fnhe_remove_oldest()\n                                         unlink fnhe\n                                         kfree_rcu(fnhe, rcu)\n    <quiescent state>\n    access fnhe after grace period\n\nKASAN reported:\n\n  BUG: KASAN: slab-use-after-free in fib_nhc_update_mtu+0x3df/0x410\n  Read of size 8 at addr ffff888107d49000 by task poc/90\n  Call Trace:\n   fib_nhc_update_mtu+0x3df/0x410\n   fib_sync_mtu+0x7a/0xd0\n   fib_netdev_event+0x229/0x3f0\n   netif_set_mtu_ext+0x33a/0x570\n   dev_set_mtu+0x88/0x120\n\nThe same walk updates fnhe_pmtu and fnhe_mtu_locked. These fields form a\npair and other writers serialize them with fnhe_lock. RCU alone prevents\nreclamation, but would still allow concurrent writers to leave a mixed\npair.\n\nWalk the table under RCU and acquire fnhe_lock only while updating each\nexception. RCU keeps the current entry alive while the short critical\nsection serializes its paired PMTU fields. This avoids holding the global\nlock while scanning all 2048 buckets for every nexthop."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/route.h","net/ipv4/fib_semantics.c","net/ipv4/route.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"af7d6cce53694a88d6a1bb60c9a239a6a5144459","lessThan":"fd39e711866498ae94fcf9acf6f422a4f045b681","versionType":"git","status":"affected"},{"version":"af7d6cce53694a88d6a1bb60c9a239a6a5144459","lessThan":"e1e602d6b22d5cb1641c4459c487eb18bf569e0a","versionType":"git","status":"affected"},{"version":"af7d6cce53694a88d6a1bb60c9a239a6a5144459","lessThan":"e00f7d2b5f2540a3415a229c982af7a25ff6362e","versionType":"git","status":"affected"},{"version":"af7d6cce53694a88d6a1bb60c9a239a6a5144459","lessThan":"dfe388da13aa784851e5ebbea90afbb099075761","versionType":"git","status":"affected"},{"version":"af7d6cce53694a88d6a1bb60c9a239a6a5144459","lessThan":"5a28a4b22dde92f9d293b94236314b8d6181dc4a","versionType":"git","status":"affected"},{"version":"af7d6cce53694a88d6a1bb60c9a239a6a5144459","lessThan":"63996ffc594d128ccec8fc0983f91effd2d3adc4","versionType":"git","status":"affected"},{"version":"af7d6cce53694a88d6a1bb60c9a239a6a5144459","lessThan":"ed503eaad62f20cdd5122d7c3078a648a99c8f16","versionType":"git","status":"affected"},{"version":"af7d6cce53694a88d6a1bb60c9a239a6a5144459","lessThan":"bc5bde9ce3cc36502839dfe98e068f7303a50982","versionType":"git","status":"affected"},{"version":"b427832009b97a3ee412ef643a80b15372a7754d","versionType":"git","status":"affected"},{"version":"2b7e4c735933be79882aba2bed9afa789e03c62f","versionType":"git","status":"affected"},{"version":"8d59c3a6376bbc6dd3f7303968a719ffba75a4f1","versionType":"git","status":"affected"},{"version":"9b4869cf385aa16f89c0f019eed4ec4e36aa441c","versionType":"git","status":"affected"},{"version":"ff34695ced21e2dfa04d0fa1c5f6c35011fa8117","versionType":"git","status":"affected"},{"version":"3.16.62","lessThan":"3.17","versionType":"semver","status":"affected"},{"version":"4.4.162","lessThan":"4.5","versionType":"semver","status":"affected"},{"version":"4.9.134","lessThan":"4.10","versionType":"semver","status":"affected"},{"version":"4.14.77","lessThan":"4.15","versionType":"semver","status":"affected"},{"version":"4.18.15","lessThan":"4.19","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/route.h","net/ipv4/fib_semantics.c","net/ipv4/route.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.19","status":"affected"},{"version":"0","lessThan":"4.19","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/5a28a4b22dde92f9d293b94236314b8d6181dc4a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/63996ffc594d128ccec8fc0983f91effd2d3adc4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bc5bde9ce3cc36502839dfe98e068f7303a50982","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dfe388da13aa784851e5ebbea90afbb099075761","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e00f7d2b5f2540a3415a229c982af7a25ff6362e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e1e602d6b22d5cb1641c4459c487eb18bf569e0a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed503eaad62f20cdd5122d7c3078a648a99c8f16","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fd39e711866498ae94fcf9acf6f422a4f045b681","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74657","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:39.333","lastModified":"2026-08-27T13:18:36.153","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops\n\nfib_nlmsg_size() still estimates nexthop space as if every gateway is\nencoded as an IPv4 RTA_GATEWAY attribute. IPv4 routes can also carry an\nIPv6 gateway, which fib_nexthop_info() dumps as RTA_VIA.\n\nAs a result, route notifications can allocate an skb that is too small.\nfib_dump_info() then fails with -EMSGSIZE and rtmsg_fib() hits the\nWARN_ON() that marks such failures as a fib_nlmsg_size() bug. With\npanic_on_warn set, this becomes a kernel panic.\n\nMirror the actual nexthop dump layout in fib_nlmsg_size(): account for\nIPv6 nexthop gateways dumped as RTA_VIA, for the no-header rtnexthop\nlayout used inside RTA_MULTIPATH, and for RTA_FLOW only when it is\nactually present."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/fib_semantics.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d15662682db232da77136cd348f4c9df312ca6f9","lessThan":"57195f0ab5cfbb5ee0864e5aff15ceb48f5a5e28","versionType":"git","status":"affected"},{"version":"d15662682db232da77136cd348f4c9df312ca6f9","lessThan":"0f0ca602941d0a81ae9514943ca06c55159c6385","versionType":"git","status":"affected"},{"version":"d15662682db232da77136cd348f4c9df312ca6f9","lessThan":"5307a53599fa762c06e475ee4a375252074fd324","versionType":"git","status":"affected"},{"version":"d15662682db232da77136cd348f4c9df312ca6f9","lessThan":"7f80ad373ce4a7af5367ff273cea0f16e91387f3","versionType":"git","status":"affected"},{"version":"d15662682db232da77136cd348f4c9df312ca6f9","lessThan":"4a5dfbae5179f6574695012a980476254df2d295","versionType":"git","status":"affected"},{"version":"d15662682db232da77136cd348f4c9df312ca6f9","lessThan":"a59edda6eda1252340354322d8ab318b2e9052fb","versionType":"git","status":"affected"},{"version":"d15662682db232da77136cd348f4c9df312ca6f9","lessThan":"9b22f13524fa0de0d963bbd3002df6c28bae3395","versionType":"git","status":"affected"},{"version":"d15662682db232da77136cd348f4c9df312ca6f9","lessThan":"4ff9548d84945d2cbf9e4c207288063a200ea397","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/fib_semantics.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.2","status":"affected"},{"version":"0","lessThan":"5.2","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0f0ca602941d0a81ae9514943ca06c55159c6385","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4a5dfbae5179f6574695012a980476254df2d295","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4ff9548d84945d2cbf9e4c207288063a200ea397","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5307a53599fa762c06e475ee4a375252074fd324","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/57195f0ab5cfbb5ee0864e5aff15ceb48f5a5e28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f80ad373ce4a7af5367ff273cea0f16e91387f3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b22f13524fa0de0d963bbd3002df6c28bae3395","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a59edda6eda1252340354322d8ab318b2e9052fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74658","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:39.453","lastModified":"2026-08-22T16:16:39.453","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfutex: Prevent robust futex exit race some more\n\nA robust futex unlock stores 0 over the whole futex value - wiping\nFUTEX_WAITERS - and wakes a single waiter. That wakeup is a one-shot\nnotification: the protocol relies on its recipient to either acquire the\nfutex (and eventually unlock while aware of the remaining contention) or\nre-arm FUTEX_WAITERS before sleeping again.  If the woken waiter is killed\nbefore it can do either, the kernel must jump in and wake the next task\ndown the line.\n\nThis is a known complication of the futex protocol with a previous\npartial fix in commit ca16d5bee598 (\"futex: Prevent robust futex exit\nrace\"). Unfortunately, that fix is insufficient.\n\nIf a third task re-acquired the futex through the uncontended fast\npath in the meantime, the notification is lost: robust exit processing\nsees that it is owned by another task and does nothing, while the new\nowner sees no FUTEX_WAITERS when it unlocks and wakes nobody.\nThe remaining waiters sleep forever behind a free futex:\n\n  A owns the futex, B and C sleep in FUTEX_WAIT\n                                        uval == A | FUTEX_WAITERS\n  A robust unlock: store 0, FUTEX_WAKE(1) wakes B\n                                        uval == 0\n  D fast path acquire: cmpxchg(0 -> D)\n                                        uval == D, no FUTEX_WAITERS\n  B killed before acting on the wakeup\n  B exit walk, pending op: owner D != B -> no action\n  D unlock: no FUTEX_WAITERS -> no wake\n                                        C sleeps forever\n\nThis is clearly a shortcoming in the implementation, which fails to keep\nthe FUTEX_WAITERS bit consistent.\n\nWork around this by augmenting the robust list exit processing to also\nperform the extra wakeup if the futex word is owned by another thread but\nFUTEX_WAITERS is not set.\n\nThis does not fix the problem of a non-contended take over/release and free\nsequence, which has been discussed for years and has been addressed by\ncommit 3ca9595d9fb6 (\"futex: Add support for unlocking robust futexes\") and\nsubsequent changes, but failed to take the problem described above into\naccount.\n\nA more complete solution which is based on the in kernel unlock of\ncontended robust futexes has been discussed in the context of this change\nand should show up in mainline sooner than later.\n\n[ tglx: Amend change log slightly and fixup coding style ]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/futex/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ca16d5bee59807bf04deaab0a8eccecd5061528c","lessThan":"83b0f71d5a313a765754acab51d2ecc5de76e0b9","versionType":"git","status":"affected"},{"version":"ca16d5bee59807bf04deaab0a8eccecd5061528c","lessThan":"a1c2b7b86a946b6b172bce44d74553da2323a36c","versionType":"git","status":"affected"},{"version":"ca16d5bee59807bf04deaab0a8eccecd5061528c","lessThan":"33bfa85458105d6169ebdb697f692b8bb8025bae","versionType":"git","status":"affected"},{"version":"ca16d5bee59807bf04deaab0a8eccecd5061528c","lessThan":"aa5c571901c6b22b58373693a4bf889ecab11ff5","versionType":"git","status":"affected"},{"version":"ca16d5bee59807bf04deaab0a8eccecd5061528c","lessThan":"925628656b73b70930972ccde421de4f758d8650","versionType":"git","status":"affected"},{"version":"ca16d5bee59807bf04deaab0a8eccecd5061528c","lessThan":"7b8c53263f8878bdd12c87e147ac6feca5c05211","versionType":"git","status":"affected"},{"version":"ca16d5bee59807bf04deaab0a8eccecd5061528c","lessThan":"7cf710e70f9bb8ea75f759ebed09871801315992","versionType":"git","status":"affected"},{"version":"ca16d5bee59807bf04deaab0a8eccecd5061528c","lessThan":"6d4514ca9cdf61fec4ec634cf50386f6f7e69748","versionType":"git","status":"affected"},{"version":"8dd558881e0f4d6942c19bd8f7b1a7c19becb59e","versionType":"git","status":"affected"},{"version":"b90aa237f469c3575190a5e6a855b76ad1d2ce94","versionType":"git","status":"affected"},{"version":"3e24098da750991f75819069c79e090dfd029219","versionType":"git","status":"affected"},{"version":"2819f4030f43057238992a4adcd950d7c95aff65","versionType":"git","status":"affected"},{"version":"2c60b44d8ba9d62c2693d2692f118177f212b1a8","versionType":"git","status":"affected"},{"version":"82ca3ab31b9cf23b86436a85381e4c5757bc6b80","versionType":"git","status":"affected"},{"version":"3.16.82","lessThan":"3.17","versionType":"semver","status":"affected"},{"version":"4.9.264","lessThan":"4.10","versionType":"semver","status":"affected"},{"version":"4.14.158","lessThan":"4.15","versionType":"semver","status":"affected"},{"version":"4.19.87","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.3.14","lessThan":"5.4","versionType":"semver","status":"affected"},{"version":"5.4.1","lessThan":"5.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/futex/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.5","status":"affected"},{"version":"0","lessThan":"5.5","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/33bfa85458105d6169ebdb697f692b8bb8025bae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d4514ca9cdf61fec4ec634cf50386f6f7e69748","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7b8c53263f8878bdd12c87e147ac6feca5c05211","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7cf710e70f9bb8ea75f759ebed09871801315992","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/83b0f71d5a313a765754acab51d2ecc5de76e0b9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/925628656b73b70930972ccde421de4f758d8650","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a1c2b7b86a946b6b172bce44d74553da2323a36c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aa5c571901c6b22b58373693a4bf889ecab11ff5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74659","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:39.613","lastModified":"2026-08-22T16:16:39.613","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: mrp: fix uninitialised bytes on the wire\n\nbr_mrp_alloc_test_skb() builds MRP test frames on an skb from\ndev_alloc_skb(), which does not clear the linear data area.  On the MRA\nring-role branch the sub-option TLV header is appended with\n\n\tsub_tlv = skb_put(skb, sizeof(*sub_tlv));\n\tsub_tlv->type = BR_MRP_SUB_TLV_HEADER_TEST_AUTO_MGR;\n\nso sub_tlv->length is never written, and the two trailing alignment bytes\nare appended with a bare skb_put() that does not clear them either.  The\nneighbouring oui and sub_opt regions are explicitly zeroed, so three\nuninitialised bytes are left in every MRA MRP_Test frame that goes out.\n\nPut the sub-option TLV header and the alignment padding in a single\nskb_put_zero(), which clears both.  The AUTO_MGR sub-TLV carries no\npayload, so the zeroed length field is already the value it should have."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bridge/br_mrp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f7458934b0791c39a001e4d902fc3bf697b439b5","lessThan":"014c062d23c63ec77ef2cf17a0d9363c7441cc94","versionType":"git","status":"affected"},{"version":"f7458934b0791c39a001e4d902fc3bf697b439b5","lessThan":"7ebc23ff03668042e0b0e4034bb1518d36198d9e","versionType":"git","status":"affected"},{"version":"f7458934b0791c39a001e4d902fc3bf697b439b5","lessThan":"06d58b8d2f053ced82e01efaeb6e7c82891eed58","versionType":"git","status":"affected"},{"version":"f7458934b0791c39a001e4d902fc3bf697b439b5","lessThan":"a5e385eeb2d6dbbbdebfa050e67c34734ae12693","versionType":"git","status":"affected"},{"version":"f7458934b0791c39a001e4d902fc3bf697b439b5","lessThan":"5912cf1822fbe53ae275c147868740eb384a5d3e","versionType":"git","status":"affected"},{"version":"f7458934b0791c39a001e4d902fc3bf697b439b5","lessThan":"e08665218040f8e312abe40f74543186f3c2c941","versionType":"git","status":"affected"},{"version":"f7458934b0791c39a001e4d902fc3bf697b439b5","lessThan":"63488dba65ef91373ef616575b32eb0eb21459f4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bridge/br_mrp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/014c062d23c63ec77ef2cf17a0d9363c7441cc94","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/06d58b8d2f053ced82e01efaeb6e7c82891eed58","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5912cf1822fbe53ae275c147868740eb384a5d3e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/63488dba65ef91373ef616575b32eb0eb21459f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7ebc23ff03668042e0b0e4034bb1518d36198d9e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a5e385eeb2d6dbbbdebfa050e67c34734ae12693","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e08665218040f8e312abe40f74543186f3c2c941","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74660","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:39.743","lastModified":"2026-08-25T06:18:46.943","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ebt_nflog: pin the NFLOG backend\n\nnf_log_unregister() runs after the per-net teardown so its final RCU\ngrace period also drains readers that obtained the logger from a per-net\nbinding.  However, ebt_nflog passes an explicit ULOG log type to\nnf_log_packet() without holding a reference on the selected logger module,\nunlike the xt_NFLOG and nft_log frontends.\n\nAn ebtables nflog rule can therefore remain callable while nfnetlink_log\nis unloaded.  The resulting interleaving is:\n\n  CPU 0                               CPU 1\n  nfnetlink_log_fini()\n    unregister_pernet_subsys()\n      kfree(nfnl_log_pernet(net))\n                                      ebt_nflog_tg()\n                                        nf_log_packet()\n                                          nfulnl_log_packet()\n                                            instance_lookup_get_rcu()\n\nThe global ULOG logger is still registered at this point, so CPU 1\ndereferences the per-net state after CPU 0 has freed it.  KASAN reported:\n\n  BUG: KASAN: slab-use-after-free in instance_lookup_get_rcu\n  Read of size 8 at addr ff110001052e6210 by task poc/92\n  Call Trace:\n   instance_lookup_get_rcu+0x1ce/0x1f0 [nfnetlink_log]\n   nfulnl_log_packet+0x248/0x2fb0 [nfnetlink_log]\n   nf_log_packet+0x204/0x300\n   ebt_nflog_tg+0x351/0x550\n   ebt_do_table+0xedf/0x22b0\n  Allocated by task 90:\n   __kmalloc_noprof+0x186/0x470\n   ops_init+0x6d/0x420\n   register_pernet_operations+0x2f6/0x670\n   register_pernet_subsys+0x23/0x40\n  Freed by task 93:\n   kfree+0x131/0x3c0\n   ops_undo_list+0x3e3/0x700\n   unregister_pernet_operations+0x232/0x490\n   unregister_pernet_subsys+0x1c/0x30\n   nfnetlink_log_fini+0x34/0x450 [nfnetlink_log]\n\nAcquire the ULOG logger module reference when an ebt_nflog rule is\nvalidated and release it when the rule is destroyed.  Request the NFLOG\nbackend for legacy callers when needed, matching xt_NFLOG.  This prevents\nmodule teardown until all ebt_nflog rules have stopped using the logger."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bridge/netfilter/ebt_nflog.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c83fa19603bdaeef17b815713dbbe3230c8a34ee","lessThan":"3bcce49d617c593c7606083bfdb464a1761fa68d","versionType":"git","status":"affected"},{"version":"c83fa19603bdaeef17b815713dbbe3230c8a34ee","lessThan":"394d7939c6b2b9e6bea0844c89efb5913168d898","versionType":"git","status":"affected"},{"version":"c83fa19603bdaeef17b815713dbbe3230c8a34ee","lessThan":"2cac4294f184c9bc19ff82552c62b80498694c39","versionType":"git","status":"affected"},{"version":"c83fa19603bdaeef17b815713dbbe3230c8a34ee","lessThan":"9d8a94b48b393885e7f876c8ef68ed4da5012078","versionType":"git","status":"affected"},{"version":"c83fa19603bdaeef17b815713dbbe3230c8a34ee","lessThan":"6809379a860b9fccbb5435bf08343f6d081ac68d","versionType":"git","status":"affected"},{"version":"c83fa19603bdaeef17b815713dbbe3230c8a34ee","lessThan":"47a119ec8a7e2d5c8c4e86fb1a56c4e696e500fb","versionType":"git","status":"affected"},{"version":"c83fa19603bdaeef17b815713dbbe3230c8a34ee","lessThan":"e2ab7e878bdbe80104c879c31fd2d82a476703b8","versionType":"git","status":"affected"},{"version":"c83fa19603bdaeef17b815713dbbe3230c8a34ee","lessThan":"30825970339c107bacaf7f61af90fcdb1f597ca1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bridge/netfilter/ebt_nflog.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/2cac4294f184c9bc19ff82552c62b80498694c39","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/30825970339c107bacaf7f61af90fcdb1f597ca1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/394d7939c6b2b9e6bea0844c89efb5913168d898","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3bcce49d617c593c7606083bfdb464a1761fa68d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/47a119ec8a7e2d5c8c4e86fb1a56c4e696e500fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6809379a860b9fccbb5435bf08343f6d081ac68d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9d8a94b48b393885e7f876c8ef68ed4da5012078","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2ab7e878bdbe80104c879c31fd2d82a476703b8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74661","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:39.883","lastModified":"2026-08-25T06:18:47.263","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmac802154: fix netdev use-after-free in beacon worker\n\nmac802154_beacon_worker() reads local->beacon_req under RCU and derives\nthe sub-interface from the request, but then drops the RCU read lock and\ncontinues to use both sdata and the embedded wpan_dev.\n\nmac802154_stop_beacons_locked() cancels only pending beacon work, clears\nlocal->beacon_req and frees the request.  A beacon worker that is already\nrunning can therefore continue after interface teardown and dereference\nthe freed netdev private area.\n\nThe scan worker already pins the netdev before leaving RCU.  Apply the\nsame lifetime rule to the beacon worker: take a netdev reference while\nthe request is still protected by RCU, and release it on all paths that\ncontinue after the reference is acquired."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/mac802154/scan.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3accf4762734a69ebd03cba989249c78ac7dfc7e","lessThan":"fe820dcc1d8ff77783a9d2bcc93b98c99ac6d517","versionType":"git","status":"affected"},{"version":"3accf4762734a69ebd03cba989249c78ac7dfc7e","lessThan":"e5fb0e03bc7f45508c182a427357bf6b389a9033","versionType":"git","status":"affected"},{"version":"3accf4762734a69ebd03cba989249c78ac7dfc7e","lessThan":"e6cd416a899edc912b428c4ba399bd73f516cb31","versionType":"git","status":"affected"},{"version":"3accf4762734a69ebd03cba989249c78ac7dfc7e","lessThan":"9d067e581597c462c51fee8a30b51bc48a68c4e1","versionType":"git","status":"affected"},{"version":"3accf4762734a69ebd03cba989249c78ac7dfc7e","lessThan":"5f26a690e8efa54315e4922368daf54e0b8f5515","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/mac802154/scan.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.3","status":"affected"},{"version":"0","lessThan":"6.3","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/5f26a690e8efa54315e4922368daf54e0b8f5515","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9d067e581597c462c51fee8a30b51bc48a68c4e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5fb0e03bc7f45508c182a427357bf6b389a9033","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e6cd416a899edc912b428c4ba399bd73f516cb31","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe820dcc1d8ff77783a9d2bcc93b98c99ac6d517","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74662","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:39.993","lastModified":"2026-08-27T13:18:36.303","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ninet: frags: publish queues before arming timer\n\ninet_frag_create() arms the fragment queue timer before inserting the\nqueue into the fqdir rhashtable. If the namespace fragment timeout is\nzero or negative, the timer can run before the queue is published.\n\nThe timer callback then marks the queue complete, tries to remove a node\nthat is not in the hash table yet, and drops the anticipated hash\nreference. Creation can subsequently publish the completed queue without\nrestoring that reference, leaving a stale hash node after the caller drops\nthe remaining reference.\n\nPublish the queue first and arm the timer while holding the queue lock.\nThis makes timer expiry wait until the queue is visible in the hash table,\nso inet_frag_kill() can remove the node and balance the hash reference."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/inet_fragment.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"648700f76b03b7e8149d13cc2bdb3355035258a9","lessThan":"f4e4dab62181b7fe7c011bed6fbef9fc3d48c769","versionType":"git","status":"affected"},{"version":"648700f76b03b7e8149d13cc2bdb3355035258a9","lessThan":"4ed0681dc2c1e0538b79d2fc56190ffcb369dacd","versionType":"git","status":"affected"},{"version":"648700f76b03b7e8149d13cc2bdb3355035258a9","lessThan":"08a04d7bfb9c103432561aff8a62b6872e694a6a","versionType":"git","status":"affected"},{"version":"648700f76b03b7e8149d13cc2bdb3355035258a9","lessThan":"d3ffb89b2944672cf7bdd8e9ee577d2043b4a956","versionType":"git","status":"affected"},{"version":"648700f76b03b7e8149d13cc2bdb3355035258a9","lessThan":"39c6c4b267b65f00e0b0335a2ae00cbe9e3174f0","versionType":"git","status":"affected"},{"version":"648700f76b03b7e8149d13cc2bdb3355035258a9","lessThan":"9f904dd3e455750e5d4ec9b2f134835811b85a2f","versionType":"git","status":"affected"},{"version":"648700f76b03b7e8149d13cc2bdb3355035258a9","lessThan":"928128865e43b197e30688dc1bc991592c97edcf","versionType":"git","status":"affected"},{"version":"648700f76b03b7e8149d13cc2bdb3355035258a9","lessThan":"653d7ddf6cba867777a3d14c4f83ace008c5ad13","versionType":"git","status":"affected"},{"version":"493107105843f299662b3b664a83804645564f12","versionType":"git","status":"affected"},{"version":"4.4.174","lessThan":"4.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/inet_fragment.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.17","status":"affected"},{"version":"0","lessThan":"4.17","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/08a04d7bfb9c103432561aff8a62b6872e694a6a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/39c6c4b267b65f00e0b0335a2ae00cbe9e3174f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4ed0681dc2c1e0538b79d2fc56190ffcb369dacd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/653d7ddf6cba867777a3d14c4f83ace008c5ad13","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/928128865e43b197e30688dc1bc991592c97edcf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f904dd3e455750e5d4ec9b2f134835811b85a2f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3ffb89b2944672cf7bdd8e9ee577d2043b4a956","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f4e4dab62181b7fe7c011bed6fbef9fc3d48c769","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74663","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:40.103","lastModified":"2026-08-27T13:18:36.473","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: reject overly deep qdisc hierarchies\n\nDeep qdisc hierarchies can lead to excessive recursion in qdisc tree\nwalkers and exhaust the kernel stack. The existing loop check does not\ncover the create-and-graft path, so a hierarchy can still be extended by\ncreating a new child qdisc below an already deep parent.\n\nStore the hierarchy depth in struct Qdisc and update it when qdiscs are\ngrafted. Reject new child qdiscs once the parent is already at the maximum\nallowed depth."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/sch_generic.h","net/sched/sch_api.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"08dc49df1527b09d9ea225a7265bbf6c237097bf","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a627d36c2a94e18c8c105ae68008786dfd85592e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9f69bb9fdaa2fe64b68bb62fb84d405784bee540","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"8ca8cdb74939581339e1ae370193c0adb5a85336","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2759acf08a3454866660edcd3ef4e64139f254a6","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a4b14a4df29d36458a943f9b521ddd0f940363cc","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e2d658c6427844cee5bc654b436ca68d680b6148","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"dedd34b0f2310e28c5f6d4875cfbf4b7ed821c01","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/sch_generic.h","net/sched/sch_api.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/08dc49df1527b09d9ea225a7265bbf6c237097bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2759acf08a3454866660edcd3ef4e64139f254a6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8ca8cdb74939581339e1ae370193c0adb5a85336","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f69bb9fdaa2fe64b68bb62fb84d405784bee540","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4b14a4df29d36458a943f9b521ddd0f940363cc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a627d36c2a94e18c8c105ae68008786dfd85592e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dedd34b0f2310e28c5f6d4875cfbf4b7ed821c01","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2d658c6427844cee5bc654b436ca68d680b6148","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74664","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:40.220","lastModified":"2026-08-22T16:16:40.220","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: reallocate update replies for mismatched IDs\n\novs_flow_cmd_new() preallocates the optional reply skb before it takes\novs_mutex and before it knows which existing flow will be updated.\n\nThat is normally fine because the skb is sized from the request flow\nidentifier.  That identifier also becomes the inserted flow's identifier.\nFor updates, however, a request with a UFID may miss the UFID lookup and\nthen fall back to the flow key lookup.  That lookup can legitimately find\nan existing key-identified flow.  UFIDs are optional and the flow key is\nthe primary identifier.\n\nFor echoed replies, ovs_flow_cmd_fill_info() writes the matched flow's\nidentifier, not the request identifier used for the preallocation.  A short\nrequest UFID can therefore leave too little room for the key identifier.\nThe fill can then fail with -EMSGSIZE and hit the BUG_ON(error < 0) in the\nupdate path.\n\nOnce the update target has been resolved, reallocate the reply skb if the\nmatched flow needs a larger reply than the request identifier allowed.  Do\nthis before replacing the actions so the request can still fail cleanly if\nthe rare extra allocation fails."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/openvswitch/datapath.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"74ed7ab9264c54471c7f057409d352052820d750","lessThan":"bd8ca84d48cd9a4f6fc63df26512c55e1d339927","versionType":"git","status":"affected"},{"version":"74ed7ab9264c54471c7f057409d352052820d750","lessThan":"00f987f066e802793a37dd2167459e67cf2cf2ec","versionType":"git","status":"affected"},{"version":"74ed7ab9264c54471c7f057409d352052820d750","lessThan":"696a0b9435fce9cf4f1e9ba7f6afa6bee96c97fc","versionType":"git","status":"affected"},{"version":"74ed7ab9264c54471c7f057409d352052820d750","lessThan":"87d0c0040b5d4b61de51ae39132c4c46709f2f77","versionType":"git","status":"affected"},{"version":"74ed7ab9264c54471c7f057409d352052820d750","lessThan":"69f40ccf85074981340847d650a9cbf9adabfbbe","versionType":"git","status":"affected"},{"version":"74ed7ab9264c54471c7f057409d352052820d750","lessThan":"23716dd9d8d46a5908536b73dc085e62f2b5c237","versionType":"git","status":"affected"},{"version":"74ed7ab9264c54471c7f057409d352052820d750","lessThan":"20751193d83be2e9735d4faee71375691c09cd13","versionType":"git","status":"affected"},{"version":"74ed7ab9264c54471c7f057409d352052820d750","lessThan":"5d1c224dd914579524a183a514c12b95095d12ce","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/openvswitch/datapath.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.0","status":"affected"},{"version":"0","lessThan":"4.0","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/00f987f066e802793a37dd2167459e67cf2cf2ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/20751193d83be2e9735d4faee71375691c09cd13","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/23716dd9d8d46a5908536b73dc085e62f2b5c237","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5d1c224dd914579524a183a514c12b95095d12ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/696a0b9435fce9cf4f1e9ba7f6afa6bee96c97fc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/69f40ccf85074981340847d650a9cbf9adabfbbe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/87d0c0040b5d4b61de51ae39132c4c46709f2f77","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd8ca84d48cd9a4f6fc63df26512c55e1d339927","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74665","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:40.357","lastModified":"2026-08-25T06:18:48.067","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix skb length accounting after generic XDP frag adjustment\n\nGeneric XDP exposes non-linear skb fragments through an xdp_buff. If an\nXDP program adjusts the fragment area, bpf_prog_run_generic_xdp() copies\nxdp_frags_size back to skb->data_len but leaves skb->len containing the\nold fragment contribution.\n\nAfter a fragment shrink, this makes skb_headlen() larger than the actual\nlinear area. In the reproduced UDP receive path, __skb_datagram_iter()\ncopied 1024 bytes past the actual linear tail to userspace, starting at\nstruct skb_shared_info. The copied bytes included the affected skb's\nnr_frags, xdp_frags_size and a kernel pointer from\nskb_shinfo(skb)->frags[0]. Real packet data was displaced by the same\namount and truncated at the end.\n\nSubtract the old data_len before replacing it and add the new data_len\nafterwards, keeping skb->len and skb->data_len synchronized.\n\nA 60000-byte UDP datagram on a veth pair with MTU 64000 was shortened by\n1024 bytes from its fragment area. Before the fix, all 10 runs produced\ncorrupted payloads. After the fix, all 10 runs matched the expected\npayload exactly."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/core/dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e6d5dbdd20aa6a86974af51deb9414cd2e7794cb","lessThan":"72468efcc089782fa047afddd10856b11a14ef5b","versionType":"git","status":"affected"},{"version":"e6d5dbdd20aa6a86974af51deb9414cd2e7794cb","lessThan":"5f30f9c302cea1f2ebf97abe574c1826544223d7","versionType":"git","status":"affected"},{"version":"e6d5dbdd20aa6a86974af51deb9414cd2e7794cb","lessThan":"ea1ccd6d1c6370868e3b032a3fc575b9c397f2e1","versionType":"git","status":"affected"},{"version":"e6d5dbdd20aa6a86974af51deb9414cd2e7794cb","lessThan":"33f2b2eb33d666ecac68031e0f31424fb70528db","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/core/dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}]},"references":[{"url":"https://git.kernel.org/stable/c/33f2b2eb33d666ecac68031e0f31424fb70528db","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5f30f9c302cea1f2ebf97abe574c1826544223d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/72468efcc089782fa047afddd10856b11a14ef5b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea1ccd6d1c6370868e3b032a3fc575b9c397f2e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74666","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:40.467","lastModified":"2026-08-27T13:18:36.643","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\npacket: synchronize pressure clearing with ring reconfiguration\n\npacket_set_ring() updates the RX ring state under sk_receive_queue.lock,\nbut used to publish the tpacket receive mode through po->prot_hook.func\nafter releasing that lock. packet_poll() and packet_recvmsg() can then\nrun the pressure clearing path after the ring has been cleared while\nstill seeing tpacket_rcv, causing __packet_rcv_has_room() to dereference\nstale or NULL ring storage.\n\nMove the existing receive hook assignment into the same\nsk_receive_queue.lock section as the ring state update. Keep the\nassignment otherwise unchanged, including on TX ring reconfiguration, to\navoid adding behavior changes that are not required for the fix.\n\nSerialize packet_recvmsg() pressure clearing with the same queue lock\nonly after PACKET_SOCK_PRESSURE has been observed. If the flag is clear\nand the socket has moved away from tpacket_rcv, packet_set_ring() has\nalready detached the socket and waited for synchronize_net(), so no new\npacket input can set the flag again.\n\npacket_poll() already holds sk_receive_queue.lock, so it uses the new\nunlocked helper directly."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/packet/af_packet.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2ccdbaa6d55b0656244ba57c4b56765a0af76c0a","lessThan":"bf3c8e86bc8ad111be3f3136125e255344bcb3da","versionType":"git","status":"affected"},{"version":"2ccdbaa6d55b0656244ba57c4b56765a0af76c0a","lessThan":"8cfb2e71926a682f36c4240067d424074dd8f70f","versionType":"git","status":"affected"},{"version":"2ccdbaa6d55b0656244ba57c4b56765a0af76c0a","lessThan":"f015c9de92b731814059a343b765c60c0196225c","versionType":"git","status":"affected"},{"version":"2ccdbaa6d55b0656244ba57c4b56765a0af76c0a","lessThan":"cf8189b82bb93f219ab740e0346c919ad65ada62","versionType":"git","status":"affected"},{"version":"2ccdbaa6d55b0656244ba57c4b56765a0af76c0a","lessThan":"ad740b4990347521f0db260d381f9f74e7b340ba","versionType":"git","status":"affected"},{"version":"2ccdbaa6d55b0656244ba57c4b56765a0af76c0a","lessThan":"2c7b5eb87b2b288cdbde825f21d2b83b2f5da747","versionType":"git","status":"affected"},{"version":"2ccdbaa6d55b0656244ba57c4b56765a0af76c0a","lessThan":"a08196c3cc105947746ec21309edfbb60275fcdb","versionType":"git","status":"affected"},{"version":"2ccdbaa6d55b0656244ba57c4b56765a0af76c0a","lessThan":"1a35da325cac4d5bcad76a2aa943408a6f1d9000","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/packet/af_packet.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.2","status":"affected"},{"version":"0","lessThan":"4.2","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/1a35da325cac4d5bcad76a2aa943408a6f1d9000","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2c7b5eb87b2b288cdbde825f21d2b83b2f5da747","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8cfb2e71926a682f36c4240067d424074dd8f70f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a08196c3cc105947746ec21309edfbb60275fcdb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ad740b4990347521f0db260d381f9f74e7b340ba","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf3c8e86bc8ad111be3f3136125e255344bcb3da","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf8189b82bb93f219ab740e0346c919ad65ada62","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f015c9de92b731814059a343b765c60c0196225c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74667","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:40.580","lastModified":"2026-08-25T06:18:48.573","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/packet: reset the MAC header on the packet-socket transmit path\n\npacket_parse_headers() resets the MAC header only for a SOCK_RAW frame\nwhose socket did not bind a protocol. A protocol-bound SOCK_RAW socket,\nany SOCK_DGRAM frame, and the legacy SOCK_PACKET path therefore leave\nskb->mac_header unset here.\n\nFor frames sent via __dev_queue_xmit() this is harmless: it resets the\nMAC header unconditionally. But the packet-socket PACKET_QDISC_BYPASS\npath uses dev_direct_xmit(), which does not, so the frame reaches\nndo_start_xmit() with the MAC header unset. A driver that reads\neth_hdr(skb) on transmit then dereferences skb->head + (u16)~0, an\nout-of-bounds access ~64 KiB past the head -- the same class fixed for\none consumer in commit f5089008f90c (\"macsec: do not read an unset MAC\nheader in macsec_encrypt()\").\n\npacket_parse_headers() runs only on the transmit path, where skb->data\npoints at the start of the L2 header for every packet-socket type\nregardless of its length: SOCK_RAW and SOCK_PACKET carry a user-supplied\nheader and SOCK_DGRAM has one built by dev_hard_header(). Reset the MAC\nheader unconditionally, mirroring __dev_queue_xmit(), so the frame is\nanchored on the bypass path too.\n\nFound by 0sec (https://0sec.ai) using automated source analysis;\nverified against source and matched to the macsec KASAN report in\nf5089008f90c. Compile-tested."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/packet/af_packet.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"75c65772c3d18447d62d3aca5f91b06c16cc25e4","lessThan":"1e43a1d66615f411d427f9df1f46dd049d9e3681","versionType":"git","status":"affected"},{"version":"75c65772c3d18447d62d3aca5f91b06c16cc25e4","lessThan":"4057853a91fb796c4f47c7d1baf1aa085394148e","versionType":"git","status":"affected"},{"version":"75c65772c3d18447d62d3aca5f91b06c16cc25e4","lessThan":"2610ed4e86a4590234a9d70518c469751c5af231","versionType":"git","status":"affected"},{"version":"75c65772c3d18447d62d3aca5f91b06c16cc25e4","lessThan":"b47ba8fe6e1d2df8c92048de5afafd059447dc30","versionType":"git","status":"affected"},{"version":"75c65772c3d18447d62d3aca5f91b06c16cc25e4","lessThan":"284f3e7a3f1a743fdf89e304fd1f19d5ffcff46d","versionType":"git","status":"affected"},{"version":"75c65772c3d18447d62d3aca5f91b06c16cc25e4","lessThan":"971aa7d99242bbf09513e27b7a243f0b29ff23ae","versionType":"git","status":"affected"},{"version":"75c65772c3d18447d62d3aca5f91b06c16cc25e4","lessThan":"fdd4d7d52358a58e351dd9d82530c04eba8ccd7a","versionType":"git","status":"affected"},{"version":"75c65772c3d18447d62d3aca5f91b06c16cc25e4","lessThan":"c2707480cfbf19c7619acc9c089d17f20869821f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/packet/af_packet.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.1","status":"affected"},{"version":"0","lessThan":"5.1","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/1e43a1d66615f411d427f9df1f46dd049d9e3681","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2610ed4e86a4590234a9d70518c469751c5af231","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/284f3e7a3f1a743fdf89e304fd1f19d5ffcff46d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4057853a91fb796c4f47c7d1baf1aa085394148e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/971aa7d99242bbf09513e27b7a243f0b29ff23ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b47ba8fe6e1d2df8c92048de5afafd059447dc30","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c2707480cfbf19c7619acc9c089d17f20869821f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fdd4d7d52358a58e351dd9d82530c04eba8ccd7a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74668","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:40.720","lastModified":"2026-08-27T13:18:36.817","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\npacket: use consistent hard_header_len in TX_RING send path\n\ntpacket_snd() reads dev->hard_header_len independently for skb\nallocation and header construction in tpacket_fill_skb(). Concurrent\nnetdevice reconfiguration can therefore make the reserved headroom\nsmaller than the amount later pushed, or make copylen - hard_header_len\nnegative.\n\nSnapshot hard_header_len once before processing ring frames and use it\nfor the frame limit, headroom allocation, copy length, and skb\nconstruction. Pass the snapshot to tpacket_fill_skb().\n\nThe separate SOCK_DGRAM consistency problem between hard_header_len and\nheader_ops->create is not addressed here."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/packet/af_packet.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1","lessThan":"9c7e8ff48c377bef18c3d178748aea0575b69ede","versionType":"git","status":"affected"},{"version":"69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1","lessThan":"2a73b2c37ee3060a880b53cd24783d93fc7be5f8","versionType":"git","status":"affected"},{"version":"69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1","lessThan":"e79f59a8527a49078cfaf8fe8fb5fcefc20c76d2","versionType":"git","status":"affected"},{"version":"69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1","lessThan":"d85d2fd54e901637c81d847811e03c662aee13cd","versionType":"git","status":"affected"},{"version":"69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1","lessThan":"016763e829cac37b3234eace86fd0a4c560de4a7","versionType":"git","status":"affected"},{"version":"69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1","lessThan":"27e068d1b35dbec10a3cf268887c94407be4badc","versionType":"git","status":"affected"},{"version":"69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1","lessThan":"d48ea5c9c4c34dc0df621f0e39ed3a16b644621a","versionType":"git","status":"affected"},{"version":"69e3c75f4d541a6eb151b3ef91f34033cb3ad6e1","lessThan":"21b5953e7494c16a42e6cd8cf110e18d13ae4a6b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/packet/af_packet.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.31","status":"affected"},{"version":"0","lessThan":"2.6.31","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/016763e829cac37b3234eace86fd0a4c560de4a7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/21b5953e7494c16a42e6cd8cf110e18d13ae4a6b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/27e068d1b35dbec10a3cf268887c94407be4badc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2a73b2c37ee3060a880b53cd24783d93fc7be5f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c7e8ff48c377bef18c3d178748aea0575b69ede","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d48ea5c9c4c34dc0df621f0e39ed3a16b644621a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d85d2fd54e901637c81d847811e03c662aee13cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e79f59a8527a49078cfaf8fe8fb5fcefc20c76d2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74669","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:40.827","lastModified":"2026-08-25T06:18:49.053","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: clear IPv4 options after rebasing tunnel ICMP errors\n\nip_vs_in_icmp() rebases an skb from the outer ICMP packet to the\nquoted original request before passing it to icmp_send(). However,\nIPCB(skb)->opt still describes the outer IPv4 header.\n\nA timestamp option in the outer header can therefore leave an offset\nthat points into the quoted transport header after the rebase.\n__ip_options_echo() treats a byte at that stale location as the option\nlength and copies it into the fixed-size option storage on the\n__icmp_send() stack, causing a stack out-of-bounds write.\n\nClear the stale option metadata after resetting the network header.\nKeep the remaining control block fields, including the ingress\ninterface used by the ICMP response path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/ipvs/ip_vs_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e","lessThan":"79ffa99202c944467e28b13b513bf2998732edff","versionType":"git","status":"affected"},{"version":"f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e","lessThan":"c9413b50204738fbc429bb86bf01353c393a6c28","versionType":"git","status":"affected"},{"version":"f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e","lessThan":"37c61b3745129cbd682c557b51345828120972e5","versionType":"git","status":"affected"},{"version":"f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e","lessThan":"ed246dd85ebf27c1f6b7897834d40786c0ca3006","versionType":"git","status":"affected"},{"version":"f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e","lessThan":"6f46fc460e9316062bdcdf89199eb5d7a33da33b","versionType":"git","status":"affected"},{"version":"f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e","lessThan":"75eec935444db4af2123e0491936f6e273d7ea00","versionType":"git","status":"affected"},{"version":"f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e","lessThan":"384b4dae14277d369221d187e9b3af56c79d2e50","versionType":"git","status":"affected"},{"version":"f2edb9f7706dcb2c0d9a362b2ba849efe3a97f5e","lessThan":"e0ba936287dfe9783426aac27e5fd76fe35b38c9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/ipvs/ip_vs_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.7","status":"affected"},{"version":"0","lessThan":"3.7","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/37c61b3745129cbd682c557b51345828120972e5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/384b4dae14277d369221d187e9b3af56c79d2e50","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6f46fc460e9316062bdcdf89199eb5d7a33da33b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/75eec935444db4af2123e0491936f6e273d7ea00","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/79ffa99202c944467e28b13b513bf2998732edff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9413b50204738fbc429bb86bf01353c393a6c28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e0ba936287dfe9783426aac27e5fd76fe35b38c9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed246dd85ebf27c1f6b7897834d40786c0ca3006","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74670","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:40.953","lastModified":"2026-08-25T06:18:49.380","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: stop estimator after disabled calc phase\n\nIPVS estimator kthread 0 starts with zeroed chain and tick limits until\nits initial calculation phase completes. If network namespace teardown\nclears ipvs->enable during that phase, ip_vs_est_calc_phase() can return\nwithout installing positive limits.\n\nThe kthread can then continue into its main loop and drain\nest_temp_list with zero chain_max, tick_max and est_max_count values.\nEach enqueue consumes one available tick row, but est_count never\nreaches the zero est_max_count value. After all rows are consumed, the\nrow lookup returns IPVS_EST_NTICKS and ip_vs_enqueue_estimator() writes\npast the ticks and tick_len arrays.\n\nExit kthread 0 after the calculation phase if the kthread is stopping or\nIPVS has been disabled. That keeps temporary estimators from being\ndrained after the limits failed to initialize.\n\nEstimator kthreads can now self-exit before teardown or reload stops\nkd->task. Keep an extra task reference after creation and release it\nwith kthread_stop_put(), so kd->task remains valid until the stop paths\nconsume that reference."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/ipvs/ip_vs_est.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"705dd34440812735ece298eb5bc153fde9544d42","lessThan":"d5122a2b2601145975d387006e517c56896e310e","versionType":"git","status":"affected"},{"version":"705dd34440812735ece298eb5bc153fde9544d42","lessThan":"de98dc5ef94b83bbb444c670c253ea02ca0f5e43","versionType":"git","status":"affected"},{"version":"705dd34440812735ece298eb5bc153fde9544d42","lessThan":"e7f34f29b330265d456943bf0b984dcecfcef9af","versionType":"git","status":"affected"},{"version":"705dd34440812735ece298eb5bc153fde9544d42","lessThan":"2335dedc1922dfa889ca1f9f70370924e8e79a08","versionType":"git","status":"affected"},{"version":"705dd34440812735ece298eb5bc153fde9544d42","lessThan":"558f67f1340f803a346ecd14a69c49653111c5f4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/ipvs/ip_vs_est.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.2","status":"affected"},{"version":"0","lessThan":"6.2","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/2335dedc1922dfa889ca1f9f70370924e8e79a08","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/558f67f1340f803a346ecd14a69c49653111c5f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d5122a2b2601145975d387006e517c56896e310e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/de98dc5ef94b83bbb444c670c253ea02ca0f5e43","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e7f34f29b330265d456943bf0b984dcecfcef9af","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74671","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:41.063","lastModified":"2026-08-22T16:16:41.063","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nima: fix out-of-bounds read in xattr_verify()\n\nThe digest-length check in xattr_verify() mixes int and size_t:\n\n\tif (xattr_len - sizeof(xattr_value->type) - hash_start >=\n\t\t\tiint->ima_hash->length)\n\nsizeof() yields size_t, so the usual arithmetic conversions promote\nthe whole left-hand side to unsigned 64-bit before the subtraction\nruns. For a truncated xattr this underflows instead of going negative:\na 1-byte IMA_XATTR_DIGEST_NG xattr (xattr_len == 1, hash_start == 1)\nturns \"1 - 1 - 1\" into SIZE_MAX, which is trivially >= ima_hash->length.\nThe check then passes and the following memcmp() reads\niint->ima_hash->length bytes starting past the end of the buffer\nvfs_getxattr_alloc() allocated for it.\n\nNothing upstream clamps xattr_len back into a safe range first:\nima_get_hash_algo() only special-cases xattr_len < 2 to pick a default\nalgorithm, and evm_verifyxattr() returns INTEGRITY_UNKNOWN rather than\nfailing when no HMAC key is loaded, so a truncated security.ima value\nreaches the length check as-is.\n\nRewrite the comparison so every operand stays a signed int and no\nimplicit conversion to size_t can occur."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["security/integrity/ima/ima_appraise.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3ea7a56067e663278470c04fd655adf809e72d4d","lessThan":"d823b5f4557083d1dd92096f796a78a2b1b06d10","versionType":"git","status":"affected"},{"version":"3ea7a56067e663278470c04fd655adf809e72d4d","lessThan":"caeb105c15ea2431fa8da7ecfa242d0c68272426","versionType":"git","status":"affected"},{"version":"3ea7a56067e663278470c04fd655adf809e72d4d","lessThan":"a784b4732ac7e51862b9b210c2d8b2ab9e83568c","versionType":"git","status":"affected"},{"version":"3ea7a56067e663278470c04fd655adf809e72d4d","lessThan":"b6cb134707a2127d90a58d69dd818679cae8033c","versionType":"git","status":"affected"},{"version":"3ea7a56067e663278470c04fd655adf809e72d4d","lessThan":"7e515b6c9aab452a4f0734bd7208e4e780e164ca","versionType":"git","status":"affected"},{"version":"3ea7a56067e663278470c04fd655adf809e72d4d","lessThan":"27f3924061592d0ef6b04e16f48754b6cb6adf27","versionType":"git","status":"affected"},{"version":"3ea7a56067e663278470c04fd655adf809e72d4d","lessThan":"dd04114af0d451091f7b8cbd26d9e37d011e9131","versionType":"git","status":"affected"},{"version":"3ea7a56067e663278470c04fd655adf809e72d4d","lessThan":"5ff232d31106f45ac87c3b64e1d35a0667777797","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["security/integrity/ima/ima_appraise.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.13","status":"affected"},{"version":"0","lessThan":"3.13","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/27f3924061592d0ef6b04e16f48754b6cb6adf27","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5ff232d31106f45ac87c3b64e1d35a0667777797","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7e515b6c9aab452a4f0734bd7208e4e780e164ca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a784b4732ac7e51862b9b210c2d8b2ab9e83568c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6cb134707a2127d90a58d69dd818679cae8033c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/caeb105c15ea2431fa8da7ecfa242d0c68272426","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d823b5f4557083d1dd92096f796a78a2b1b06d10","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd04114af0d451091f7b8cbd26d9e37d011e9131","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74672","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:41.200","lastModified":"2026-08-23T13:16:48.460","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF\n\nPatch series \"mm: fix UAF caused by race between ptdump and vmap pgtable\nfreeing\", v6.\n\nKernel page table walkers fall into two broad categories - those ranges\nwhere no exclusion is required via walk_kernel_page_table_range_lockless()\nand those where exclusion is required via walk_kernel_page_table_range()\nor walk_page_range_debug().\n\nThe former category is used only by arm64 arch code operating on ranges it\nboth wholly owns and does not concurrently write.\n\nThe latter category consists of kernel page table walkers operating on\nranges that are wholly owned (but which need exclusion against concurrent\nwriters).\n\nThe lock used for exclusion is the mmap lock, and for kernel ranges this\nis the mmap lock on init_mm.\n\nptdump is a special case being both the only user of\nwalk_page_range_debug(), and the only case in which it walks ranges it\ndoes not own.\n\nThis presents a problem, as page tables may be freed under ptdump.  And\nindeed there is a use-after-free bug in the kernel as a result, which this\nseries addresses.\n\nvmap promotes page tables to huge leaf entries where possible, freeing the\nlower page table when it does.  It does this with no meaningful locks held\nagainst concurrent ptdump walks.\n\nAs a result, use-after-free can currently occur.  This series addresses\nthe issue by having the vmap huge promotion logic acquire the mmap read\nlock while both setting the huge page table entry and freeing the prior\nleaf page table.\n\nThe ptdump code already acquires the mmap write lock, so by doing so we\nensure that the ptdump walker only ever observes either the huge page\ntable entry or the existing page table entry, and nothing is freed\nunderneath it.\n\nA mitigation for this issue was already applied for arm64 in commit\nfa93b45fd397 (\"arm64: Enable vmalloc-huge with ptdump\"), which this series\nhas to deal with carefully.\n\nThis mitigation resolves the issue by acquiring the mmap read lock on\ninit_mm on vmap page table free if a ptdump is in progress.\n\nHowever the fix in this series would cause a deadlock if we were to simply\napply it for arm64 without also reverting the change.\n\nThis is because vmap may acquire the read lock before ptdump attempts to\nacquire the write lock, which then gets queued, and rwsem starvation rules\nmean that the (unacknowledged) nested mmap read lock in the arm64 code\nwould also block, meaning the original read lock is never released and\nthus deadlock.\n\nThis series works around this by #ifndef CONFIG_ARM64'ing the mmap read\nlock in vmap logic, then partially reverting commit fa93b45fd397 (\"arm64:\nEnable vmalloc-huge with ptdump\"), keeping the enablement of huge vmap\nsupport, and removing the ifdeffery with the partial revert patch.\n\nThere are related issues that are also addressed in this series:\n\n* x86 page attribute logic, specifically Change Page Attributes (CPA),\n  implements a feature whereby huge ranges can be collapsed into huge leaf\n  entries. This can similarly cause a UAF when done in parallel with a\n  ptdump walk, so similarly acquire the init_mm mmap lock to avoid this.\n\n* The CPA logic allows concurrent page table manipulation and CPA\n  collapse, meaning the former risks accessing a page table the latter\n  frees. Fix this by acquiring mmap write lock on init_mm across the\n  whole CPA collapse operation and read lock on the page table\n  manipulation.\n\n* x86 and arm64 permit walks of non-kernel mm's (both allowing efi mm\n  walks, and in x86's case arbitrary mm's), so we ensure kernel mappings\n  remain stable by locking the init_mm as well as the mm being walked.\n\nThe ordering of patches is established for both strict dependencies (the\narm64 partial revert in particular has to be done after the vmap changes)\nand logical ones (the non-kernel mm fix only makes sense once the vmap/CPA\nfixes are in place).\n\n\nThis patch (of 3):\n\nCurrently there is a nasty ra\n---truncated---"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/linux/mmap_lock.h","mm/pagewalk.c","mm/vmalloc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e","lessThan":"39c6772b56a6bbdd62794833f74232971d94d7c9","versionType":"git","status":"affected"},{"version":"b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e","lessThan":"8d7f560f4b0482d469de962fbe4b59c37561052e","versionType":"git","status":"affected"},{"version":"b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e","lessThan":"7ac8a333dd41ba5e1b4e8c6edbc48b15446c5468","versionType":"git","status":"affected"},{"version":"b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e","lessThan":"c5bf8cd148cfea948cfa3db71da427294b20db0f","versionType":"git","status":"affected"},{"version":"b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e","lessThan":"3cc26c8907db0f5d1ff8043b5851ee572e9b3c98","versionType":"git","status":"affected"},{"version":"b6bdb7517c3d3f41f20e5c2948d6bc3f8897394e","lessThan":"26444eb71465c9934d9d418ef69c43f61185329b","versionType":"git","status":"affected"},{"version":"31895cfd79564111cdd5a9f48c5d491ae26a238e","versionType":"git","status":"affected"},{"version":"9c7f7bdb1932f8c1e5f80d32c717184701afe701","versionType":"git","status":"affected"},{"version":"acdb4981644c8e31ccee294bdefff475c0cf587b","versionType":"git","status":"affected"},{"version":"0454e2fad9306961540ee7e84da47a8e345b7d22","versionType":"git","status":"affected"},{"version":"4.4.125","lessThan":"4.5","versionType":"semver","status":"affected"},{"version":"4.9.91","lessThan":"4.10","versionType":"semver","status":"affected"},{"version":"4.14.31","lessThan":"4.15","versionType":"semver","status":"affected"},{"version":"4.15.14","lessThan":"4.16","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/linux/mmap_lock.h","mm/pagewalk.c","mm/vmalloc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.16","status":"affected"},{"version":"0","lessThan":"4.16","versionType":"semver","status":"unaffected"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.153","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/26444eb71465c9934d9d418ef69c43f61185329b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/39c6772b56a6bbdd62794833f74232971d94d7c9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3cc26c8907db0f5d1ff8043b5851ee572e9b3c98","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7ac8a333dd41ba5e1b4e8c6edbc48b15446c5468","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8d7f560f4b0482d469de962fbe4b59c37561052e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c5bf8cd148cfea948cfa3db71da427294b20db0f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74673","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:41.347","lastModified":"2026-08-25T06:18:49.673","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: evdev - fix information leak in evdev_pass_values()\n\nIn evdev_pass_values(), the input_event structure is allocated on the\nkernel stack and populated field-by-field. However, it is never fully\ninitialized. On architectures where struct input_event contains explicit\nor implicit padding (such as the 32-bit __pad field on SPARC64), these\npadding bytes are left uninitialized.\n\nWhen this event structure is subsequently passed to the client buffer\nand later copied to userspace, the uninitialized padding bytes leak\nkernel stack memory, potentially exposing sensitive information.\n\nSimilar issues exist in __evdev_queue_syn_dropped and __pass_event.\n\nFix this by explicitly zeroing the entire event structure with memset()\nbefore populating its fields. This ensures all padding bytes are cleared\nbefore the data crosses the security boundary."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/input/evdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6addb1d6de1968b84852f54561cc9a999909b5a9","lessThan":"d2e3839419ac4047835762c4d7712bda1101b57e","versionType":"git","status":"affected"},{"version":"6addb1d6de1968b84852f54561cc9a999909b5a9","lessThan":"c6d5fa46c1ee25d068fc730fd377f0f54188d290","versionType":"git","status":"affected"},{"version":"6addb1d6de1968b84852f54561cc9a999909b5a9","lessThan":"e748811d9b80a3e101110ff4b3c612e5fca54d98","versionType":"git","status":"affected"},{"version":"6addb1d6de1968b84852f54561cc9a999909b5a9","lessThan":"06a286b320236508d02ab2ccc9496352748652a8","versionType":"git","status":"affected"},{"version":"6addb1d6de1968b84852f54561cc9a999909b5a9","lessThan":"7d17e9454a9af3ec7aebb88b41a9deedd5b19a6b","versionType":"git","status":"affected"},{"version":"6addb1d6de1968b84852f54561cc9a999909b5a9","lessThan":"bd3c4108a56de34380edab670065e86283cb3029","versionType":"git","status":"affected"},{"version":"6addb1d6de1968b84852f54561cc9a999909b5a9","lessThan":"7e55ca1080f09d9f7112c7f20ac31f682c1f2374","versionType":"git","status":"affected"},{"version":"6addb1d6de1968b84852f54561cc9a999909b5a9","lessThan":"90f305f2c7a30257c683e13f4bf7c798eea992a0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/input/evdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.24","status":"affected"},{"version":"0","lessThan":"2.6.24","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/06a286b320236508d02ab2ccc9496352748652a8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d17e9454a9af3ec7aebb88b41a9deedd5b19a6b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7e55ca1080f09d9f7112c7f20ac31f682c1f2374","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/90f305f2c7a30257c683e13f4bf7c798eea992a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd3c4108a56de34380edab670065e86283cb3029","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c6d5fa46c1ee25d068fc730fd377f0f54188d290","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2e3839419ac4047835762c4d7712bda1101b57e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e748811d9b80a3e101110ff4b3c612e5fca54d98","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74674","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:41.480","lastModified":"2026-08-25T06:18:49.990","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm: fix incorrect flush address in direct page table reclaim\n\nWhen zap_pte_range reclaims a page table, it does:\n\n    pte_free_tlb(tlb, pmd_pgtable(pmdval), addr);\n\nand this is unconditionally wrong: if this code executes, addr *always*\npoints one past the end of the range covered by the table.  The addr\nparameter is used to flush the TLB (really the paging-structure-cache)\nto drop references to the to-be-freed table, and any architecture that\ncares about the parameter will flush the wrong address.  (But they'll\nstill free the correct page).\n\nI think it's worth contemplating why the kernel works at all.\n\nIf we hit the offending line of code, we will first clear the PMD entry\n(line 1954, zap_empty_pte_table), then we will issue pending flushes if\nforce_flush is set (tlb_flush_mmu_tlbonly(tlb)), then we will skip the\nretry on line 1979 (phew!), and then we will do the offending\npte_free_tlb call.  *Or* we will clear the PMD entry immediately before\npte_free_tlb (line 1983, zap_pte_table_if_empty).\n\nIf we have any pending flushes (i.e. we actually zapped any last-level\nentries) at the time we clear the PMD entry, then the flush really ought\nto flush all references to the table (Linus certainly seems to think it\nwill on all architectures [0]).\n\nThe condition under which we have no accumulated flushes at the time of\nthe clear is very complex (the whole zap_pte_range function has absurdly\ncomplex control flow).  If we do hit the bad case, then we will end up\nclearing the PMD entry after the last time the range is flushed, and any\nCPU is free to cache a reference to the (empty) page table.  If this\nhappens due to an ordinary read or write, it would segfault, so it would\nbe rare.  But the cache could be speculatively filled as well.  Then\nwe'll flush the wrong address and then free and possibly reuse the\ntable.\n\nOn x86, even flushing the wrong address works on non-KPTI Intel systems\nbecause INVLPG flushes *all* paging-structure-caches, not just the ones\nfor the target address.  But INVPCID does not, and flush_tlb_one_user\nwill use INVPCID if it's available.  And then we're toast.  AMD systems\nare more susceptible: we set the EFER.TCE bit, which makes even INVLPG\nonly flush the target address.\n\nI think this might fix an issue in ripgrep reported here:\nhttps://github.com/BurntSushi/ripgrep/issues/3494\n\n[0] https://lore.kernel.org/all/CA+55aFzBggoXtNXQeng5d_mRoDnaMBE5Y+URs+PHR67nUpMtaw@mail.gmail.com/T/#u"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/memory.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4c640eb4181cf8de74c8b9e7c9cf16bf8d26b73e","lessThan":"0b8ff21cbda8808c86b18f1b0ca2d0025af9a80a","versionType":"git","status":"affected"},{"version":"4c640eb4181cf8de74c8b9e7c9cf16bf8d26b73e","lessThan":"478a1c3abebfc717db0d1281a9cdd7befafee542","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/memory.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/0b8ff21cbda8808c86b18f1b0ca2d0025af9a80a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/478a1c3abebfc717db0d1281a9cdd7befafee542","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74675","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:41.590","lastModified":"2026-08-25T06:18:50.237","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvt: stabilize tty reference in kbd_keycode with tty_port_tty_get\n\nkbd_keycode() reads vc->port.tty without acquiring a tty reference,\nracing against con_shutdown() which clears port.tty under a different\nlock. Use tty_port_tty_get()/tty_kref_put() to hold a proper reference\nfor the duration the tty pointer is needed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/tty/vt/keyboard.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b84fd400f80adf4d1c88fbce50ae1cf2f8119e65","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"38400673c9bfb39cfc87539e1a072087e98f4e4f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"cab5a342f0589334046741006d8a280514f94235","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"38a0aa593ebc275aea6f79534d07f44e43768ce6","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3f6b1d3fcfc26dc3fc85262f753439df93b055b4","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b664592e9ba8c47c9e23408db7ba52eb9f946c8a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"cc4a1a2ce0c58eafd477effb055863935260ddc1","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e25d47a526939ad44b75f778b8a7500562b84fc1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/tty/vt/keyboard.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/38400673c9bfb39cfc87539e1a072087e98f4e4f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/38a0aa593ebc275aea6f79534d07f44e43768ce6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3f6b1d3fcfc26dc3fc85262f753439df93b055b4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b664592e9ba8c47c9e23408db7ba52eb9f946c8a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b84fd400f80adf4d1c88fbce50ae1cf2f8119e65","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cab5a342f0589334046741006d8a280514f94235","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cc4a1a2ce0c58eafd477effb055863935260ddc1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e25d47a526939ad44b75f778b8a7500562b84fc1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74676","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:41.710","lastModified":"2026-08-25T06:18:50.527","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvt: add permission check for KDSKBMETA ioctl\n\nKDSKBMETA modifies keyboard meta mode but lacks the !perm check that all\nother keyboard setter ioctls in vt_k_ioctl() enforce, allowing a process\nto change meta mode on a non-controlling console without authorization."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/tty/vt/vt_ioctl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9f8cbaf4b774694dcc292e60509762483ebfd9ae","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ddc4a8303347114e945b9e6e81b81d77855f7358","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1c5b67a1e2cb7d78dab321280f330b056e3bf437","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d8ead5083b203d12b8319e7cb29cc6b8836e813f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"4671c3b79e337bbae28c2d79023dc642df012bde","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a1c31e026c93e378e297a8df8328983d3013a59f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7bf32337a7103ccb686cbd240324bf26225ef2d6","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a7ad0034453ba4c353f9b8f810ee2569de33d283","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/tty/vt/vt_ioctl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1c5b67a1e2cb7d78dab321280f330b056e3bf437","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4671c3b79e337bbae28c2d79023dc642df012bde","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7bf32337a7103ccb686cbd240324bf26225ef2d6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f8cbaf4b774694dcc292e60509762483ebfd9ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a1c31e026c93e378e297a8df8328983d3013a59f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a7ad0034453ba4c353f9b8f810ee2569de33d283","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8ead5083b203d12b8319e7cb29cc6b8836e813f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ddc4a8303347114e945b9e6e81b81d77855f7358","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74677","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:41.847","lastModified":"2026-08-22T16:16:41.847","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: ipheth: fix carrier_work UAF on disconnect\n\nipheth_sndbulk_callback() re-arms the carrier-check work on any\nnon-zero URB status:\n\n\telse\n\t\tschedule_delayed_work(&dev->carrier_work, 0);\n\nNothing ties that to the interface being up, so the work can be armed\nagain after ipheth_close() has already drained it, and stay armed\nuntil the netdev whose private area embeds it is freed.\n\nOn unplug with a TX URB in flight, ipheth_disconnect() drains the work\nthrough unregister_netdev() -> ipheth_close() ->\ncancel_delayed_work_sync() and only then calls ipheth_kill_urbs().\nusb_kill_urb() completes the in-flight TX URB with -ENOENT, so\nipheth_sndbulk_callback() runs after the drain and re-arms\ncarrier_work.\n\nThe same completion also re-arms the work if the interface is only\nbrought down while a TX URB is in flight, and\nipheth_carrier_check_work() then keeps re-queueing itself once a\nsecond. unregister_netdev() does not call ipheth_close() for an\nalready-down interface, so nothing drains it on the later unplug\neither.\n\nIn both cases free_netdev() frees the netdev while carrier_work is\nstill pending, and ipheth_carrier_check_work() dereferences freed\nmemory.\n\nTie the work to the interface state instead of chasing the completion:\ndisable it in ipheth_close() and enable it in ipheth_open(), so a\nschedule_delayed_work() from the URB completion is a no-op whenever\nthe interface is not up. disable_delayed_work_sync() also waits for a\nrunning instance, so it fully replaces the cancel_delayed_work_sync()\nit takes the place of. The work starts out disabled in ipheth_probe()\nso the enable/disable counts balance from the first open.\n\nReproduced under KASAN on linux-next (next-20260731) with dummy_hcd and\nraw-gadget standing in for the device, driving the second path above (the\ninterface is already down, so unregister_netdev() does not call\nipheth_close()): 15 of 15 unpatched boots report a slab-use-after-free in\n__run_timers(), freed by ipheth_disconnect() and re-armed from\nipheth_sndbulk_callback() via queue_delayed_work_on(). The\nsame trigger on a kernel differing only by this patch reports 0 of 15,\nand the carrier check still functions across open/close cycles.\n\nThe reproducer needs an attached USB device that stops draining bulk OUT,\nplus a link down and unplug, driven as root. It is not a privilege\nboundary crossing and no exploit primitive was developed.\n\nFound by 0sec (https://0sec.ai)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/usb/ipheth.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bb1b40c7cb863f0800a6410c7dcb86cf3f28d3b1","lessThan":"d07133fe1befae9a1e4c4c5e46ef0b73d2992020","versionType":"git","status":"affected"},{"version":"bb1b40c7cb863f0800a6410c7dcb86cf3f28d3b1","lessThan":"2c7496124e94c7f9c3daa5c5b1fb563ca9d62c45","versionType":"git","status":"affected"},{"version":"bb1b40c7cb863f0800a6410c7dcb86cf3f28d3b1","lessThan":"48303f3ae0fa6e102f3fc7dbf1688cc179131962","versionType":"git","status":"affected"},{"version":"bb1b40c7cb863f0800a6410c7dcb86cf3f28d3b1","lessThan":"fde39b8a521780391fb4e5bda2c0aa4928947f12","versionType":"git","status":"affected"},{"version":"4f2df9fd07698bece3321fbf9e4b6dbcb9babccc","versionType":"git","status":"affected"},{"version":"ea7d6be58c2e6c1f426b48994bb22b2393c90963","versionType":"git","status":"affected"},{"version":"f5bca75dc46701f4c0d1dcbaae401233ae7ff06b","versionType":"git","status":"affected"},{"version":"4.4.180","lessThan":"4.5","versionType":"semver","status":"affected"},{"version":"4.9.173","lessThan":"4.10","versionType":"semver","status":"affected"},{"version":"4.14.116","lessThan":"4.15","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/usb/ipheth.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.15","status":"affected"},{"version":"0","lessThan":"4.15","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2c7496124e94c7f9c3daa5c5b1fb563ca9d62c45","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/48303f3ae0fa6e102f3fc7dbf1688cc179131962","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d07133fe1befae9a1e4c4c5e46ef0b73d2992020","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fde39b8a521780391fb4e5bda2c0aa4928947f12","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74678","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:41.980","lastModified":"2026-08-25T06:18:50.740","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()\n\nWhen the interface has NETIF_F_SG enabled and skb_linearize() fails in\nax88179_tx_fixup(), the function returns NULL without freeing the skb.\n\nusbnet_start_xmit() treats a NULL return from tx_fixup() as a drop\n(info->flags does not set FLAG_MULTI_PACKET for this driver), jumping\nto the \"drop\" label where it does `if (skb) dev_kfree_skb_any(skb)`.\nBecause tx_fixup() returned NULL, the local skb variable in\nusbnet_start_xmit() is NULL, so the original skb is never freed — a\nmemory leak on every TX frame whose linearization fails (i.e. under\nmemory pressure).\n\nFree the skb before returning, matching the error handling already used\nfor the pskb_expand_head() failure path in the same function."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/usb/ax88179_178a.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"16b1c4e01c89ba07367461e0bc4cb84993c2d027","lessThan":"83a765cbd7b4d11b0b9fa1bb9d941ae911a2159b","versionType":"git","status":"affected"},{"version":"16b1c4e01c89ba07367461e0bc4cb84993c2d027","lessThan":"1c63303659a2264bd55d9813df74cb4caeed5922","versionType":"git","status":"affected"},{"version":"16b1c4e01c89ba07367461e0bc4cb84993c2d027","lessThan":"2be5091fa693b9119ad25a8bb8c149d236a23ade","versionType":"git","status":"affected"},{"version":"16b1c4e01c89ba07367461e0bc4cb84993c2d027","lessThan":"58733b1dd46bb231d9d279c132a20ee46da1b664","versionType":"git","status":"affected"},{"version":"16b1c4e01c89ba07367461e0bc4cb84993c2d027","lessThan":"4039cd807a5a46dc5f7618fffae926b8ad8455eb","versionType":"git","status":"affected"},{"version":"16b1c4e01c89ba07367461e0bc4cb84993c2d027","lessThan":"1f428e30947395d9b9aacee03e25a4e6cfcad7a4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/usb/ax88179_178a.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"references":[{"url":"https://git.kernel.org/stable/c/1c63303659a2264bd55d9813df74cb4caeed5922","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1f428e30947395d9b9aacee03e25a4e6cfcad7a4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2be5091fa693b9119ad25a8bb8c149d236a23ade","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4039cd807a5a46dc5f7618fffae926b8ad8455eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/58733b1dd46bb231d9d279c132a20ee46da1b664","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/83a765cbd7b4d11b0b9fa1bb9d941ae911a2159b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74679","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:42.090","lastModified":"2026-08-22T16:16:42.090","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_ncm: Use unsigned int for ndp_index\n\nThe variable ndp_index is declared as a signed integer, but it stores\nthe return value of get_ncm(), which is unsigned.\n\nA malicious host can supply a large offset that overflows the signed\nndp_index, making it negative. Because ndp_index is compared against\nunsigned bounds, this negative value bypasses sanity checks and leads\nto an out-of-bounds read when calculating the address of the NDP\nblock (ntb_ptr + ndp_index).\n\nFix this by changing ndp_index to unsigned int to ensure consistent\nunsigned comparisons throughout the function."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/gadget/function/f_ncm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"370af734dfaf8336b496b386e194648e097e248a","lessThan":"9c8c6825a750fcd3efbe922847ca70ccd5a66857","versionType":"git","status":"affected"},{"version":"370af734dfaf8336b496b386e194648e097e248a","lessThan":"a1c0deeba4a46481543d6b09c665f758c54c3a1a","versionType":"git","status":"affected"},{"version":"370af734dfaf8336b496b386e194648e097e248a","lessThan":"d13f650a3485b58c124b3cda45597e8002c9c833","versionType":"git","status":"affected"},{"version":"370af734dfaf8336b496b386e194648e097e248a","lessThan":"11413d7ed42174b8f5d8d0b6a25d10dc88239b21","versionType":"git","status":"affected"},{"version":"370af734dfaf8336b496b386e194648e097e248a","lessThan":"5b2b3a3229a3f4c493ffdee53aee2f173b6f13b3","versionType":"git","status":"affected"},{"version":"370af734dfaf8336b496b386e194648e097e248a","lessThan":"d328fdc607fa1bb668ad512e1c918a120f78f337","versionType":"git","status":"affected"},{"version":"370af734dfaf8336b496b386e194648e097e248a","lessThan":"fc9e54e22845c4da29588ca0986cb7c795b5a262","versionType":"git","status":"affected"},{"version":"370af734dfaf8336b496b386e194648e097e248a","lessThan":"6b1c8a9403a26cb0fed7a648916c74dc236da591","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/gadget/function/f_ncm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.17","status":"affected"},{"version":"0","lessThan":"3.17","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/11413d7ed42174b8f5d8d0b6a25d10dc88239b21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5b2b3a3229a3f4c493ffdee53aee2f173b6f13b3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b1c8a9403a26cb0fed7a648916c74dc236da591","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c8c6825a750fcd3efbe922847ca70ccd5a66857","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a1c0deeba4a46481543d6b09c665f758c54c3a1a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d13f650a3485b58c124b3cda45597e8002c9c833","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d328fdc607fa1bb668ad512e1c918a120f78f337","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc9e54e22845c4da29588ca0986cb7c795b5a262","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74680","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:42.227","lastModified":"2026-08-22T16:16:42.227","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()\n\nIf cxacru_cm() encounters an error while submitting or waiting for snd_urb,\nit aborts and returns the error without killing the already submitted\nrcv_urb. This leaves the rcv_urb active.\n\nWhen this happens during initialization (e.g., in cxacru_atm_start()), the\ndriver may ignore the error and proceed to call cxacru_poll_status(), which\ninvokes cxacru_cm() again. Attempting to submit the still-active rcv_urb\ntriggers a warning in usb_submit_urb():\n\ncxacru 1-1:1.0: send of cm 0x84 failed (-104)\nATM dev 0: cxacru_atm_start: CHIP_ADSL_LINE_START returned -104\n------------[ cut here ]------------\nURB ffff88812658d200 submitted while active\nWARNING: drivers/usb/core/urb.c:379 at usb_submit_urb+0x79/0x18b0\ndrivers/usb/core/urb.c:379\n...\nCall Trace:\n <TASK>\n cxacru_cm+0x21a/0xf10 drivers/usb/atm/cxacru.c:631\n cxacru_cm_get_array drivers/usb/atm/cxacru.c:722 [inline]\n cxacru_poll_status+0x178/0x1110 drivers/usb/atm/cxacru.c:828\n cxacru_atm_start+0x185/0x360 drivers/usb/atm/cxacru.c:814\n usbatm_atm_init+0x144/0x3a0 drivers/usb/atm/usbatm.c:927\n usbatm_usb_probe+0x15cb/0x1db0 drivers/usb/atm/usbatm.c:1178\n cxacru_usb_probe+0x17f/0x220 drivers/usb/atm/cxacru.c:1370\n...\n\nTo fix this, ensure that rcv_urb is properly killed if cxacru_cm() aborts\nearly. We can safely call usb_kill_urb() on rcv_urb in the error path, as\nit is safe to call even if the URB is not active (e.g., if it failed to\nsubmit in the first place, or if it already completed)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/atm/cxacru.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1b0e614652344a2d39eb336f3dc07651782883bf","lessThan":"6133b461058316e3ccba7331f974d110d4c08b23","versionType":"git","status":"affected"},{"version":"1b0e614652344a2d39eb336f3dc07651782883bf","lessThan":"61093d7f1144f6a15bac505df35e5f535ade2ac1","versionType":"git","status":"affected"},{"version":"1b0e614652344a2d39eb336f3dc07651782883bf","lessThan":"645d98dbccdbfdbf0129f48822af7183492de091","versionType":"git","status":"affected"},{"version":"1b0e614652344a2d39eb336f3dc07651782883bf","lessThan":"993f7677949e3d72e360e86eed1f41c2511f75ed","versionType":"git","status":"affected"},{"version":"1b0e614652344a2d39eb336f3dc07651782883bf","lessThan":"939b6a41f681aea52af678053072ee443068e93e","versionType":"git","status":"affected"},{"version":"1b0e614652344a2d39eb336f3dc07651782883bf","lessThan":"2f73a065791d2a8e3f0bdf29248e33600359e865","versionType":"git","status":"affected"},{"version":"1b0e614652344a2d39eb336f3dc07651782883bf","lessThan":"0af047703dbed8224552587ed436f14a24371b46","versionType":"git","status":"affected"},{"version":"1b0e614652344a2d39eb336f3dc07651782883bf","lessThan":"c2f811314be351d86b6ab41e9297ae80d8da6f86","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/atm/cxacru.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.13","status":"affected"},{"version":"0","lessThan":"2.6.13","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0af047703dbed8224552587ed436f14a24371b46","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2f73a065791d2a8e3f0bdf29248e33600359e865","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/61093d7f1144f6a15bac505df35e5f535ade2ac1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6133b461058316e3ccba7331f974d110d4c08b23","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/645d98dbccdbfdbf0129f48822af7183492de091","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/939b6a41f681aea52af678053072ee443068e93e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/993f7677949e3d72e360e86eed1f41c2511f75ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c2f811314be351d86b6ab41e9297ae80d8da6f86","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74681","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:42.373","lastModified":"2026-08-22T16:16:42.373","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg\n\nibuf_len is the bulk IN (receive) buffer size, but the EMSGSIZE check\nin usbio_bulk_msg() compares it against txbuf_len — the bulk OUT\nendpoint size.  Both are taken independently from different endpoints\nin usbio_probe(), so the check is wrong when they differ.\n\nUse rxbuf_len for the IN direction.  This matches the buffer that\nactually holds the response data."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/misc/usbio.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"121a0f839dbb397af5fabb701cea3e9983223e50","lessThan":"ebfd1e82ab0a6d26efd9bdd89de899215851f5bf","versionType":"git","status":"affected"},{"version":"121a0f839dbb397af5fabb701cea3e9983223e50","lessThan":"9ad0164f78b66b0b5eca3a5748cc94dd87e28124","versionType":"git","status":"affected"},{"version":"121a0f839dbb397af5fabb701cea3e9983223e50","lessThan":"7e22c9f79b200672f3e477421b6c9050d8cf70a5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/misc/usbio.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/7e22c9f79b200672f3e477421b6c9050d8cf70a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ad0164f78b66b0b5eca3a5748cc94dd87e28124","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ebfd1e82ab0a6d26efd9bdd89de899215851f5bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74682","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:42.480","lastModified":"2026-08-22T16:16:42.480","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: fix OOB write on Type II inbound URBs\n\ndata_ep_set_params() sizes each URB transfer buffer before it adds the\nFormat Type II transfer delimiter:\n\n\tu->packets = urb_packs;\n\tu->buffer_size = maxsize * u->packets;\n\n\tif (fmt->fmt_type == UAC_FORMAT_TYPE_II)\n\t\tu->packets++; /* for transfer delimiter */\n\tu->urb = usb_alloc_urb(u->packets, GFP_KERNEL);\n\nbuffer_size is computed from the pre-increment packet count and never\nrecomputed, so for a Type II endpoint the buffer is one packet short of\nthe packet count the URB is built with.\n\nprepare_inbound_urb() then lays out one iso frame per packet and never\nconsults buffer_size:\n\n\toffs = 0;\n\tfor (i = 0; i < urb_ctx->packets; i++) {\n\t\turb->iso_frame_desc[i].offset = offs;\n\t\turb->iso_frame_desc[i].length = ep->curpacksize;\n\t\toffs += ep->curpacksize;\n\t}\n\n\turb->transfer_buffer_length = offs;\n\turb->number_of_packets = urb_ctx->packets;\n\nThe last descriptor therefore points one packet past the end of the\ntransfer buffer, where the host controller writes device data on every\ninbound transfer.  prepare_silent_urb() and prepare_playback_urb() bound\ntheir fill loops by ctx->buffer_size, so only capture is affected.\n\nfmt_type comes from the device's audio streaming descriptors, so any\ndevice advertising a Type II capture format hits this once userspace sets\nhw_params on the stream.\n\nKASAN on 7.2.0-rc5 (arm64) with a dummy_hcd/raw-gadget device, one report\nper inbound transfer:\n\n  BUG: KASAN: slab-out-of-bounds in dummy_timer\n  Write of size 64 at addr ffff0000186171c0 by task cons02/166\n   __asan_memcpy\n   dummy_timer\n   hrtimer_run_softirq\n  Allocated by task 166:\n   usb_alloc_coherent\n   snd_usb_endpoint_set_params\n  The buggy address is located 0 bytes to the right of\n   allocated 64-byte region [ffff000018617180, ffff0000186171c0)\n\nCompute buffer_size after the delimiter packet has been accounted for,\nand bound the fill loop by buffer_size, as prepare_silent_urb() already\ndoes on the outbound side.  This grows every Type II URB allocation by\none maxsize packet.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/usb/endpoint.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8fdff6a319e7dac757c558bd283dc4577e68cde7","lessThan":"6af5f29af7711233ae68d3b25c15d67478468900","versionType":"git","status":"affected"},{"version":"8fdff6a319e7dac757c558bd283dc4577e68cde7","lessThan":"f1fbb50b99311b35c2e85cc70341d62082dca4b5","versionType":"git","status":"affected"},{"version":"8fdff6a319e7dac757c558bd283dc4577e68cde7","lessThan":"137bf034740e5a2734794908d0aff1e0bd7cee6e","versionType":"git","status":"affected"},{"version":"8fdff6a319e7dac757c558bd283dc4577e68cde7","lessThan":"6607f85242577f33d4540a0d1f4a6137f5367058","versionType":"git","status":"affected"},{"version":"8fdff6a319e7dac757c558bd283dc4577e68cde7","lessThan":"ca22c94bdfc22c564ca2e11c87ba4d17ebeaaa9a","versionType":"git","status":"affected"},{"version":"8fdff6a319e7dac757c558bd283dc4577e68cde7","lessThan":"0a235379825e1a6194e43861ee6658e5fc35686d","versionType":"git","status":"affected"},{"version":"8fdff6a319e7dac757c558bd283dc4577e68cde7","lessThan":"d3ed4e6321bb453757044cb9e5ecb30a33f04903","versionType":"git","status":"affected"},{"version":"8fdff6a319e7dac757c558bd283dc4577e68cde7","lessThan":"69ee44e1a23be62318189dc4b37fa4ad94053269","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/usb/endpoint.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.5","status":"affected"},{"version":"0","lessThan":"3.5","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0a235379825e1a6194e43861ee6658e5fc35686d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/137bf034740e5a2734794908d0aff1e0bd7cee6e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6607f85242577f33d4540a0d1f4a6137f5367058","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/69ee44e1a23be62318189dc4b37fa4ad94053269","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6af5f29af7711233ae68d3b25c15d67478468900","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca22c94bdfc22c564ca2e11c87ba4d17ebeaaa9a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3ed4e6321bb453757044cb9e5ecb30a33f04903","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1fbb50b99311b35c2e85cc70341d62082dca4b5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74683","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:42.617","lastModified":"2026-08-25T06:18:51.003","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: evdev - sanitize event type index when fetching event masks\n\nThe user-supplied event type index passed to EVIOCGMASK / EVIOCSMASK\nioctls is used to index the static counts array in evdev_get_mask_cnt()\nand client evmasks array in evdev_get_mask().\n\nWhile the event type is architecturally bounded by EV_CNT, speculative\nexecution may mispredict bounds checks and perform out-of-bounds loads.\n\nSanitize the event type index in evdev_get_mask_cnt() branchlessly using\narray_index_mask_nospec(). This clamps the index to 0 for safe array\naccess and forces the returned count to 0 speculatively when the index\nis out of bounds.\n\nWe do not need additional array_index_nospec() calls in evdev_get_mask()\nbecause evdev_get_mask_cnt() speculatively forces the count (and\nresulting xfer_size) to 0 for out-of-bounds types, preventing any\nspeculative memory access to client evmasks array."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/input/evdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"06a16293f71927f756dcf37558a79c0b05a91641","lessThan":"c79b08d8fa230871a3634e34a66e591ac2d084ef","versionType":"git","status":"affected"},{"version":"06a16293f71927f756dcf37558a79c0b05a91641","lessThan":"f27fa9b39f925d26e034a1f382cb45523138f4ae","versionType":"git","status":"affected"},{"version":"06a16293f71927f756dcf37558a79c0b05a91641","lessThan":"f3fc329acad9a71b3c077237cbac20670d2358c8","versionType":"git","status":"affected"},{"version":"06a16293f71927f756dcf37558a79c0b05a91641","lessThan":"5db341189bb7ff041d570dbe36ecca7e32913927","versionType":"git","status":"affected"},{"version":"06a16293f71927f756dcf37558a79c0b05a91641","lessThan":"433913b4a92214d76e9f0c03ad9128fec943d5f8","versionType":"git","status":"affected"},{"version":"06a16293f71927f756dcf37558a79c0b05a91641","lessThan":"4034ef247a9dde3f56660b01f0c3280dac6b1274","versionType":"git","status":"affected"},{"version":"06a16293f71927f756dcf37558a79c0b05a91641","lessThan":"810e1883d4815f29c30d900ad7333d03cc2515d1","versionType":"git","status":"affected"},{"version":"06a16293f71927f756dcf37558a79c0b05a91641","lessThan":"3abd29c61d2ef37c4102cf755b18be53bb9dbea6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/input/evdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.4","status":"affected"},{"version":"0","lessThan":"4.4","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3abd29c61d2ef37c4102cf755b18be53bb9dbea6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4034ef247a9dde3f56660b01f0c3280dac6b1274","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/433913b4a92214d76e9f0c03ad9128fec943d5f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5db341189bb7ff041d570dbe36ecca7e32913927","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/810e1883d4815f29c30d900ad7333d03cc2515d1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c79b08d8fa230871a3634e34a66e591ac2d084ef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f27fa9b39f925d26e034a1f382cb45523138f4ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f3fc329acad9a71b3c077237cbac20670d2358c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74684","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:42.757","lastModified":"2026-08-25T06:18:51.253","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp()\n\nThe commit 4f61f133f354 (\"net: tap: NULL pointer derefence in\ndev_parse_header_protocol when skb->dev is null\") fixed a crash in\ntap_get_user() by assigning skb->dev before calling tun_vnet_hdr_to_skb().\nThis is required because virtio_net_hdr_to_skb() may invoke\ndev_parse_header_protocol(), which dereferences skb->dev. Without the\nassignment, a NULL pointer dereference can occur.\n\nHowever, tap_get_user_xdp() still parses the virtio-net header before\nassigning skb->dev. When the vhost TX path passes an XDP buffer containing\na GSO virtio-net header but the protocol is set to zero on purpose,\ntun_vnet_hdr_to_skb() can reach dev_parse_header_protocol() while skb->dev\nis still NULL, resulting in a crash.\n\nFix this by looking up the tap device and assigning skb->dev before calling\ntun_vnet_hdr_to_skb(), matching the ordering already used in\ntap_get_user(). Preserve the existing RCU read-side critical section across\ndev_queue_xmit()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/tap.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"924a9bc362a5223cd448ca08c3dde21235adc310","lessThan":"15583b07fd691a844fbf7b3ad612cdc9e9a657c0","versionType":"git","status":"affected"},{"version":"924a9bc362a5223cd448ca08c3dde21235adc310","lessThan":"8b444b126cd8e4473e652f529753ed4dd1360a9c","versionType":"git","status":"affected"},{"version":"924a9bc362a5223cd448ca08c3dde21235adc310","lessThan":"164c31ee252ebd1ac8f44c2dfc5486b6d9a0379b","versionType":"git","status":"affected"},{"version":"924a9bc362a5223cd448ca08c3dde21235adc310","lessThan":"3874892dd27d5387aa9a06f58d9060f18f351d24","versionType":"git","status":"affected"},{"version":"ea3fb2ce5fa794d02135f5c079e05cd6fc3f545d","versionType":"git","status":"affected"},{"version":"54ef8243c3c8e90f1ea5792e6752e021a25c8eb3","versionType":"git","status":"affected"},{"version":"ca278267d6cd9544645731732455b6b20cb0e895","versionType":"git","status":"affected"},{"version":"faa3baa2828c5e1c4374f3e60041f75c64f5fcb6","versionType":"git","status":"affected"},{"version":"99b1d3f74b9ef72c2f74c8e4c078e1bc0706e748","versionType":"git","status":"affected"},{"version":"4.14.226","lessThan":"4.15","versionType":"semver","status":"affected"},{"version":"4.19.181","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.4.106","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"5.10.24","lessThan":"5.11","versionType":"semver","status":"affected"},{"version":"5.11.7","lessThan":"5.12","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/tap.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.12","status":"affected"},{"version":"0","lessThan":"5.12","versionType":"semver","status":"unaffected"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":4.0}]},"references":[{"url":"https://git.kernel.org/stable/c/15583b07fd691a844fbf7b3ad612cdc9e9a657c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/164c31ee252ebd1ac8f44c2dfc5486b6d9a0379b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3874892dd27d5387aa9a06f58d9060f18f351d24","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b444b126cd8e4473e652f529753ed4dd1360a9c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74685","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:42.870","lastModified":"2026-08-22T16:16:42.870","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (ltc4282) Clamp negative current limits\n\nWhen a negative value is passed to ltc4282_write_curr(), the signed long\nval is cast directly to u64:\n\ndrivers/hwmon/ltc4282.c:ltc4282_write_curr() {\n        /* need to pass it in millivolt */\n        u32 in = DIV_ROUND_CLOSEST_ULL((u64)val * st->rsense, DECA * MICRO);\n        ...\n}\n\nThis cast converts negative inputs into large positive values. The\nsubsequent division result overflows the u32 in variable, truncating\nto a pseudo-random positive value. When this is passed to\nltc4282_write_voltage_byte(), it is clamped to the maximum limit instead\nof zero.\n\nClamp val to 0 and to the maximum supported upper limit before the cast\nand assign the result to a 64-bit temporary variable before the division\nto avoid the underflow and an also possible overflow."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hwmon/ltc4282.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cbc29538dbf7d7400f1ffc5dd5713e6a551463a0","lessThan":"60e06c4dba696173982393252a40ceb7dd2eec18","versionType":"git","status":"affected"},{"version":"cbc29538dbf7d7400f1ffc5dd5713e6a551463a0","lessThan":"de58b90a4d1417c15b693eb04c0ce6bc925d84c6","versionType":"git","status":"affected"},{"version":"cbc29538dbf7d7400f1ffc5dd5713e6a551463a0","lessThan":"046e56b53c09375ef39903514496aa5508db9729","versionType":"git","status":"affected"},{"version":"cbc29538dbf7d7400f1ffc5dd5713e6a551463a0","lessThan":"e253dd5f9f6d875a317895bf43ec9534ed7523cb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hwmon/ltc4282.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/046e56b53c09375ef39903514496aa5508db9729","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/60e06c4dba696173982393252a40ceb7dd2eec18","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/de58b90a4d1417c15b693eb04c0ce6bc925d84c6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e253dd5f9f6d875a317895bf43ec9534ed7523cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74686","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:42.973","lastModified":"2026-08-22T16:16:42.973","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nrqspinlock: Reset tail when preserving queue on deadlock\n\nCurrently, the destruction of the waiter queue is suppressed for\nrqspinlock in cases where a deadlock is detected. Deadlock checks happen\nrelatively frequently (on entry for AA, within 1ms for ABBA), and waiter\nthreads may not be involved in locking scenarios involving deadlocks.\nThus, it is useful to not flush the queue and let other waiters take a\nstab at acquiring the lock after we detect a deadlock and exit.\n\nHowever, we need to follow the same logic as what we did previously for\nthe waitq_timeout label: reset the tail, and if we cannot, signal the\nnext waiter appropriately. In case of deadlocks, this signal would just\nmark the MCS node as unlocked, and in case of timeouts, it would signal\nRES_TIMEOUT_VAL. The difference thus is in the value propagated, which\ndecides whether the queue remains active or gets flushed.\n\nNot doing the tail reset, and waiting for the next waiter can lead to\ncases where we are the final waiter, and thus no next waiter arrives,\nleading to intermittent stalls in this path. Once the next waiter does\njoin, we will be unblocked. In the theoretical case when the next waiter\nnever joins, we risk stalling indefinitely.\n\nThis can only happen for ABBA deadlocks, since entry into the wait queue\nis guarded with AA checks. A precise sequence of executions leading up\nto this scenario can be:\n\nCPU 0 holds lock A.\nCPU 1 holds lock B.\nCPU 2 attempts lock B, becomes the pending waiter for B.\nCPU 0 attempts lock B. B has locked+pending bits set, thus CPU 0 queues.\nCPU 1 attempts lock A.\nCPU 0 detects an ABBA deadlock.\n\nOnce deadlock detection happens for CPU 0, it will sit waiting for the\nnext waiter in the queue to populate node->next, which will experience\ndelays until such a waiter arrives.\n\nFix this by adjusting the logic for the check for deadlocks preceding\nthe waitq_timeout label. It would make sense to consolidate code for\nboth cases and use 'ret' to distinguish the value being propagated, but\nthat is left as an exercise for a future refactoring task to avoid diff\nnoise in this patch."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/rqspinlock.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7bd6e5ce5be666fb3fb873bf20f77e62555b7835","lessThan":"f54667b0c16213285c9d9b8e3929f738b8f71826","versionType":"git","status":"affected"},{"version":"7bd6e5ce5be666fb3fb873bf20f77e62555b7835","lessThan":"7a3c0289c3c8eb4607dff448ae9ff9f902c813af","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/rqspinlock.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/7a3c0289c3c8eb4607dff448ae9ff9f902c813af","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f54667b0c16213285c9d9b8e3929f738b8f71826","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74687","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:43.080","lastModified":"2026-08-25T06:18:51.470","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwatchdog: at91sam9_wdt: prevent timer rearm during teardown\n\nat91_ping() rearms the watchdog timer from its callback. timer_delete()\nneither waits for a running callback nor prevents it from rearming the\ntimer, so probe failure or driver removal can leave the timer accessing the\ndevm-allocated at91wdt after it has been freed.\n\nUse timer_shutdown_sync() on both teardown paths. It waits for a running\ncallback and rejects any attempt by the callback to rearm the timer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/watchdog/at91sam9_wdt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5161b31dc39a6d6dadc95f298de48a725b73ada8","lessThan":"29fe74c9aa69d78c1c6a3930f1d9fc5db71a6eed","versionType":"git","status":"affected"},{"version":"5161b31dc39a6d6dadc95f298de48a725b73ada8","lessThan":"b7949b0a7d998013b7ec8617a0ef5b07cca80be4","versionType":"git","status":"affected"},{"version":"5161b31dc39a6d6dadc95f298de48a725b73ada8","lessThan":"8444d66aa6b6e7fe0a26fa1a00a11cb4d0523783","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/watchdog/at91sam9_wdt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.14","status":"affected"},{"version":"0","lessThan":"3.14","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/29fe74c9aa69d78c1c6a3930f1d9fc5db71a6eed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8444d66aa6b6e7fe0a26fa1a00a11cb4d0523783","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b7949b0a7d998013b7ec8617a0ef5b07cca80be4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74688","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:43.180","lastModified":"2026-08-25T06:18:51.680","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: clear control chunk transport if it is being removed\n\nsctp_make_heartbeat_ack() caches the destination transport in\nchunk->transport without taking a reference. When src_out_of_asoc_ok is\nenabled, the HEARTBEAT ACK may remain queued on control_chunk_list instead\nof being transmitted immediately.\n\nIf the peer transport is removed while the chunk is still queued,\nsctp_assoc_rm_peer() drops the transport and schedules it for RCU freeing,\nbut only clears cached transport pointers in out_chunk_list.  The queued\ncontrol chunk therefore retains a dangling transport pointer.\n\nOnce an ASCONF_ACK clears the suppression and the queued control chunk is\ntransmitted, SCTP dereferences the stale transport pointer, leading to a\nuse-after-free.\n\nFix this by also clearing chunk->transport for queued control chunks in\ncontrol_chunk_list when removing the transport."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sctp/associola.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8a07eb0a50aebc8c95478d49c28c7f8419a26cef","lessThan":"dbb3f418a8665ffb0514e1a9520ab6a1c5d4d886","versionType":"git","status":"affected"},{"version":"8a07eb0a50aebc8c95478d49c28c7f8419a26cef","lessThan":"fad4766a74220fe579c6fcaa10ba01c23529814f","versionType":"git","status":"affected"},{"version":"8a07eb0a50aebc8c95478d49c28c7f8419a26cef","lessThan":"936658ec41c28c397ef390140e02d4c91ade92f0","versionType":"git","status":"affected"},{"version":"8a07eb0a50aebc8c95478d49c28c7f8419a26cef","lessThan":"8de65194a04d2552cd39b6c67d942d490f22d174","versionType":"git","status":"affected"},{"version":"8a07eb0a50aebc8c95478d49c28c7f8419a26cef","lessThan":"6160e756db81d6cb63e3e2952efcf6c5134be385","versionType":"git","status":"affected"},{"version":"8a07eb0a50aebc8c95478d49c28c7f8419a26cef","lessThan":"18d704bdd809377dfd81a3c2f42426763b5da227","versionType":"git","status":"affected"},{"version":"8a07eb0a50aebc8c95478d49c28c7f8419a26cef","lessThan":"4d6b9cac6df5e0cfef1a66b3edd7aebdb9e4b7e7","versionType":"git","status":"affected"},{"version":"8a07eb0a50aebc8c95478d49c28c7f8419a26cef","lessThan":"c9158ceaf27780ef64534ad72f44ffde3f8ccc49","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sctp/associola.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.1","status":"affected"},{"version":"0","lessThan":"3.1","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/18d704bdd809377dfd81a3c2f42426763b5da227","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4d6b9cac6df5e0cfef1a66b3edd7aebdb9e4b7e7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6160e756db81d6cb63e3e2952efcf6c5134be385","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8de65194a04d2552cd39b6c67d942d490f22d174","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/936658ec41c28c397ef390140e02d4c91ade92f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9158ceaf27780ef64534ad72f44ffde3f8ccc49","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dbb3f418a8665ffb0514e1a9520ab6a1c5d4d886","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fad4766a74220fe579c6fcaa10ba01c23529814f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74689","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:43.303","lastModified":"2026-08-25T06:18:51.960","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/atm: fix slab-out-of-bounds read in vcc_setsockopt()\n\nvcc_setsockopt() contained an ineffective optlen check:\n  if (__SO_LEVEL_MATCH(optname, level) && optlen != __SO_SIZE(optname))\n      return -EINVAL;\n\nIf __SO_LEVEL_MATCH(optname, level) evaluated to false (e.g. if the caller\npassed a mismatched level), the length check optlen != __SO_SIZE(optname)\nwas short-circuited and bypassed. Execution then fell through to switch(optname),\ncalling copy_from_sockptr() assuming optval contained sufficient space.\n\nFurthermore, even if level matched, a cgroup BPF setsockopt filter could shrink\noptlen after entry. Because copy_from_sockptr() on kernel pointers uses memcpy(),\nthis leads to a KASAN slab-out-of-bounds read when optlen is smaller than the\nexpected structure size.\n\nFix this by using copy_safe_from_sockptr(), which unconditionally validates\nthat optlen is at least the expected size before copying. Also change the local\n'value' variable type from 'unsigned long' to 'int' so that SO_SETCLP matches\nits sizeof(int) ABI encoding on 64-bit systems."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/atm/common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b3bcd5d65ac03c15787b2a5b36c718e26a689336","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"35f258fee9ed358c6d0f57f91c30bf029c3724af","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6eb6af88710977eb529b558a07294874d8c40c4d","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9f77c1ab382188f5b51982fab6d913443b6dc59f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2c5988c7349c0b64a7e0441bfc6e1dca54f7116a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d0c80dbb970439bd2eeb0e5effff8c16a5f4e1e3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/atm/common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.2}]},"references":[{"url":"https://git.kernel.org/stable/c/2c5988c7349c0b64a7e0441bfc6e1dca54f7116a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/35f258fee9ed358c6d0f57f91c30bf029c3724af","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6eb6af88710977eb529b558a07294874d8c40c4d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f77c1ab382188f5b51982fab6d913443b6dc59f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b3bcd5d65ac03c15787b2a5b36c718e26a689336","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d0c80dbb970439bd2eeb0e5effff8c16a5f4e1e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74690","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:43.420","lastModified":"2026-08-25T06:18:52.230","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/ism: Fix UAF of sba and ieq during ism_dev_exit()\n\nA ism interrupt handler can be active in parallel with ism_dev_exit(),\naccessing freed data structures.\n\nNo new interrupts will be generated after unregister_ieq(). Drain ongoing\ninterrupt handlers by free_irq(), before freeing ism data structures."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/s390/net/ism_drv.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"684b89bc39ce4f204b1a2b180f39f2eb36a6b695","lessThan":"fc3021284050ecb3bba8a7851340cedcb5037928","versionType":"git","status":"affected"},{"version":"684b89bc39ce4f204b1a2b180f39f2eb36a6b695","lessThan":"774394d27930ec4cf4cb3eed8ab6a4d20cb2430a","versionType":"git","status":"affected"},{"version":"684b89bc39ce4f204b1a2b180f39f2eb36a6b695","lessThan":"b1896543ce59c4258625a35cf41e23a9a1f80ea2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/s390/net/ism_drv.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.19","status":"affected"},{"version":"0","lessThan":"4.19","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/774394d27930ec4cf4cb3eed8ab6a4d20cb2430a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b1896543ce59c4258625a35cf41e23a9a1f80ea2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc3021284050ecb3bba8a7851340cedcb5037928","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74691","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:43.527","lastModified":"2026-08-25T06:18:52.440","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: thunderbolt: Tear down DMA paths before stopping the rings\n\ntbnet_tear_down() stops both rings and frees their frame buffers before\ncalling tb_xdomain_disable_paths().  tb_ring_stop() zeroes the ring's\ndescriptor base and tbnet_free_buffers() unmaps and frees the pages the\nframes sit in, so by the time __tb_path_deactivate_hop() polls the hop's\n'pending' bit, anything still in flight has nowhere to drain to.\n\nThe teardown sequence has been in this order since the driver was added.\nThe setup path has not: commit ff7cd07f3064 (\"net: thunderbolt: Enable\nDMA paths only after rings are enabled\") moved the path enable to the end\nof tbnet_connected_work() and documented why:\n\n\t/* Both logins successful so enable the rings, high-speed DMA\n\t * paths and start the network device queue.\n\t *\n\t * Note we enable the DMA paths last to make sure we have primed\n\t * the Rx ring before any incoming packets are allowed to\n\t * arrive.\n\t */\n\nTeardown was never updated to match, so the rings and the paths now come\ndown in the same order they go up instead of in reverse.\n\nOn an ASMedia ASM4242 host router the 'pending' bit then never clears:\nevery teardown burns the full 500 ms timeout and\n__tb_path_deactivate_hop() returns -ETIMEDOUT.  Raising the timeout to\n5 s does not help, so the hop is not slow to drain, it never drains\nat all.\n\nThe failure is invisible above the thunderbolt core.\n__tb_path_deactivate_hops() is void and only calls tb_port_warn();\ntb_path_deactivate(), tb_tunnel_deactivate() and\n__tb_disconnect_xdomain_paths() are void as well, and\ntb_disconnect_xdomain_paths() ends in an unconditional \"return 0\".  So\ntb_xdomain_disable_paths() reports success and the netdev_warn() below\nit never fires.  Repeated teardowns eventually take the XDomain control\nchannel down, after which the peer node is gone and only a power cycle\nbrings the controller back.\n\nDeactivating the paths first fixes it.  Measured with kretprobes on a\nstock v6.17 tree with no other patches applied, on a link that was up\nand had just carried traffic:\n\n  before: __tb_path_deactivate_hop() returns 0 for the first hop, then\n          -ETIMEDOUT for the second 500335 us later\n  after:  0 for both, 525 us apart\n\nAlternating the two orderings ABBA over three load levels, four\nteardowns per arm: every teardown failed before the change (21 of 21\nthat ran), none failed after (0 of 24).  The before arms ran short\nbecause the link died partway through.  The same split shows up when\nthe interface is enslaved to a bond instead of just brought down, which\nis how I ran into this in the first place.  Throughput and latency after\nthe change are unchanged.\n\nHosts whose routers drain the hop despite the stale descriptor base see\nno functional difference, since the paths end up deactivated either way."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/thunderbolt/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e","lessThan":"7cce39109206bc5497e0953806563644b88bfc44","versionType":"git","status":"affected"},{"version":"e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e","lessThan":"0da9a6d27155ad072dd76db8cd637feead99a0e0","versionType":"git","status":"affected"},{"version":"e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e","lessThan":"b5a21615f627c48dafaa6ef82a34a5b97a4352aa","versionType":"git","status":"affected"},{"version":"e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e","lessThan":"103a9b663ac1cacb8465aeff18f84a247154a562","versionType":"git","status":"affected"},{"version":"e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e","lessThan":"4dd71cb0d23d40cb58fe4261c7bd183dca66caa0","versionType":"git","status":"affected"},{"version":"e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e","lessThan":"9a482b2b117e5fa656b6d24fc01799e8ac2d4368","versionType":"git","status":"affected"},{"version":"e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e","lessThan":"68bf02b6b4ad3f748c6db71fd77b6c0402d252f4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/thunderbolt/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.15","status":"affected"},{"version":"0","lessThan":"4.15","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/0da9a6d27155ad072dd76db8cd637feead99a0e0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/103a9b663ac1cacb8465aeff18f84a247154a562","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4dd71cb0d23d40cb58fe4261c7bd183dca66caa0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/68bf02b6b4ad3f748c6db71fd77b6c0402d252f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7cce39109206bc5497e0953806563644b88bfc44","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9a482b2b117e5fa656b6d24fc01799e8ac2d4368","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5a21615f627c48dafaa6ef82a34a5b97a4352aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74692","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:43.667","lastModified":"2026-08-25T06:18:52.767","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix TOCTOU race between smc_listen_out() and listener close\n\nsmc_listen_out() reads lsmc->sk.sk_state without the listener lock,\nthen acquires lock_sock_nested() only after the check passes. This\nopens a window where smc_close_active() can transition the listener\nto SMC_CLOSED, call smc_close_cleanup_listen() to drain the accept\nqueue, and release the lock, all between the lockless read and the\ndelayed lock acquisition:\n\n  smc_listen_work (smc_hs_wq)          smc_close_active()\n  -------------------------------      -------------------------\n  release_sock(child)\n  if (sk_state == SMC_LISTEN) TRUE\n                                        lock_sock(listener)\n                                        sk_state = SMC_CLOSED\n                                        smc_close_cleanup_listen()\n                                        release_sock(listener)\n                                        flush_work(tcp_listen_work)\n  lock_sock_nested(listener)\n  smc_accept_enqueue(listener, child) /* child enqueued on dead listener */\n\nsmc_close_active() flushes only tcp_listen_work. Work items already\ndispatched onto smc_hs_wq for the CLC handshake continue running\nunguarded. smc_accept_enqueue() takes a sock_hold() on the child that\nis never released, so the child smc_sock, its clcsock, and the\nreference all leak. A remote peer that opens TCP connections while the\nserver calls close() can exhaust kernel memory.\n\nMove lock_sock_nested() to before the sk_state check so that the test\nand the enqueue are atomic under the listener lock."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/smc/af_smc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9","lessThan":"53c7938d8bcfde3296ec1a347ba2a9393c1fdcfa","versionType":"git","status":"affected"},{"version":"fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9","lessThan":"feb71634bb1abab3e8fb5cde874b27001cc1282e","versionType":"git","status":"affected"},{"version":"fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9","lessThan":"01865e1ddb126b25ac9eba5cdd7ec49e11183a64","versionType":"git","status":"affected"},{"version":"fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9","lessThan":"00f89433777236ced4771211047fb5d4cd581cea","versionType":"git","status":"affected"},{"version":"fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9","lessThan":"78e5ebcd1c10ed7c8bda0a99e0abd5b62da86d67","versionType":"git","status":"affected"},{"version":"fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9","lessThan":"ff5bcd804b5bc5c64736b7d318c20e12ea9506b8","versionType":"git","status":"affected"},{"version":"fd57770dd198f5b2ddd5b9e6bf282cf98d63adb9","lessThan":"185a4caeecabc150106deda1da170b09f2ad803f","versionType":"git","status":"affected"},{"version":"d1d004585b40c212b338fc8a40cbaaf230ea4703","versionType":"git","status":"affected"},{"version":"4.19.299","lessThan":"4.20","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/smc/af_smc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.1","status":"affected"},{"version":"0","lessThan":"5.1","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"references":[{"url":"https://git.kernel.org/stable/c/00f89433777236ced4771211047fb5d4cd581cea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/01865e1ddb126b25ac9eba5cdd7ec49e11183a64","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/185a4caeecabc150106deda1da170b09f2ad803f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/53c7938d8bcfde3296ec1a347ba2a9393c1fdcfa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/78e5ebcd1c10ed7c8bda0a99e0abd5b62da86d67","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/feb71634bb1abab3e8fb5cde874b27001cc1282e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff5bcd804b5bc5c64736b7d318c20e12ea9506b8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74693","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:43.807","lastModified":"2026-08-22T16:16:43.807","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: prestera: validate firmware header length\n\nprestera_fw_hdr_parse() reads the firmware header before checking\nthat the firmware image contains that header.\n\nReject images shorter than struct prestera_fw_header before decoding the\nmagic and version fields."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/marvell/prestera/prestera_pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4c2703dfd7fabb0824b3bc345f9fa47e33248c14","lessThan":"38a3afbf9fd8a2e8c47fa3ca47b425a8a9623240","versionType":"git","status":"affected"},{"version":"4c2703dfd7fabb0824b3bc345f9fa47e33248c14","lessThan":"0fbcceb9d19f2d1dcdf099aee590f2517cb718bb","versionType":"git","status":"affected"},{"version":"4c2703dfd7fabb0824b3bc345f9fa47e33248c14","lessThan":"e0f382e8084117f0b11ffb070fe1079e38c0d7f9","versionType":"git","status":"affected"},{"version":"4c2703dfd7fabb0824b3bc345f9fa47e33248c14","lessThan":"6fad06bb793d7089ae05b9fcf46e11be2dfe4850","versionType":"git","status":"affected"},{"version":"4c2703dfd7fabb0824b3bc345f9fa47e33248c14","lessThan":"470ac9cce7308e60cf2dceb448749cdd006e73de","versionType":"git","status":"affected"},{"version":"4c2703dfd7fabb0824b3bc345f9fa47e33248c14","lessThan":"363e048a9d0a6c245cbc348c8a220170afed046a","versionType":"git","status":"affected"},{"version":"4c2703dfd7fabb0824b3bc345f9fa47e33248c14","lessThan":"7fa8a12296d8d5aa4b1c3904f0b354d81124cf29","versionType":"git","status":"affected"},{"version":"4c2703dfd7fabb0824b3bc345f9fa47e33248c14","lessThan":"8ae344eb540af3f457179b52bc6061416752485c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/marvell/prestera/prestera_pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0fbcceb9d19f2d1dcdf099aee590f2517cb718bb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/363e048a9d0a6c245cbc348c8a220170afed046a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/38a3afbf9fd8a2e8c47fa3ca47b425a8a9623240","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/470ac9cce7308e60cf2dceb448749cdd006e73de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6fad06bb793d7089ae05b9fcf46e11be2dfe4850","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7fa8a12296d8d5aa4b1c3904f0b354d81124cf29","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8ae344eb540af3f457179b52bc6061416752485c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e0f382e8084117f0b11ffb070fe1079e38c0d7f9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74694","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:43.920","lastModified":"2026-08-22T16:16:43.920","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length\n\nncsi_send_cmd_nl() takes the number of bytes to copy from the\nattacker-controlled ncsi_pkt_hdr.length field of the in-band packet\nheader, while the source buffer is the NCSI_ATTR_DATA netlink\nattribute whose readable size is nla_len() - sizeof(ncsi_pkt_hdr).\nThe two length sources are never cross-checked: only\nnla_len() >= sizeof(struct ncsi_pkt_hdr) is enforced.\n\nWith hdr->length set larger than the attribute payload (up to 65535\nagainst at most 2032 readable bytes), ncsi_cmd_handler_oem() copies\npast the end of the netlink attribute buffer with unsafe_memcpy(),\nleaking up to ~64KB of kernel heap memory into the transmitted NCSI\ncommand packet. The destination skb is sized by the declared payload,\nso the write side does not overflow - this is a pure OOB read /\ninformation leak, reachable with CAP_NET_ADMIN on systems with a\nregistered NCSI device (e.g. OpenBMC on Aspeed BMC SoCs, where\nNET_NCSI=y is standard).\n\nReject commands whose declared payload extends past the end of the\ndata attribute.\n\nThe issue was found by the autokbug dynamic kernel fuzzer at Tencent\nYunding Lab."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ncsi/ncsi-netlink.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392","lessThan":"e60afa01d35f8b2671b27ca93309921427144cce","versionType":"git","status":"affected"},{"version":"9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392","lessThan":"67c72b8ef63d9d9a610546fda30b116638f39745","versionType":"git","status":"affected"},{"version":"9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392","lessThan":"4489b4a17892750131e4bef4bc1d3d703c8fb5ba","versionType":"git","status":"affected"},{"version":"9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392","lessThan":"43c7d0a6917751ea898ae584d00f24f5deac46d4","versionType":"git","status":"affected"},{"version":"9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392","lessThan":"b5231ad0b376b801ab8cf2962b182cc29deaedb3","versionType":"git","status":"affected"},{"version":"9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392","lessThan":"02226af69362758046822840fc6a497f5de33f00","versionType":"git","status":"affected"},{"version":"9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392","lessThan":"3a60b5af75abe8e3494ccd074fb4ae6e601a3e55","versionType":"git","status":"affected"},{"version":"9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392","lessThan":"afa58b7384913c8773d837acdb07b035690ec5d2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ncsi/ncsi-netlink.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.20","status":"affected"},{"version":"0","lessThan":"4.20","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/02226af69362758046822840fc6a497f5de33f00","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3a60b5af75abe8e3494ccd074fb4ae6e601a3e55","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/43c7d0a6917751ea898ae584d00f24f5deac46d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4489b4a17892750131e4bef4bc1d3d703c8fb5ba","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/67c72b8ef63d9d9a610546fda30b116638f39745","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/afa58b7384913c8773d837acdb07b035690ec5d2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5231ad0b376b801ab8cf2962b182cc29deaedb3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e60afa01d35f8b2671b27ca93309921427144cce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74695","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:44.050","lastModified":"2026-08-25T06:18:53.000","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref()\n\nIncoming skbs passing through netfilter flowtable offload hooks (or XFRM\noffload path) might already carry a ref-counted dst_entry assigned during\nearlier RX or routing steps.\n\nCalling skb_dst_set_noref() when skb already holds a ref-counted dst\noverwrites skb->_skb_refdst, leaking the previous dst_entry reference\ncount and triggering a DEBUG_NET_WARN_ON_ONCE assertion in\nskb_dst_check_unset():\n\n  WARNING: at skb_dst_check_unset include/linux/skbuff.h:1170\n  WARNING: at skb_dst_set_noref include/linux/skbuff.h:1234\n  WARNING: at nf_flow_offload_ip_hook+0xf6c/0x2b60 net/netfilter/nf_flow_table_ip.c:864\n\nDrop any existing dst_entry reference with skb_dst_drop(skb) before\nsetting the non-referenced flowtable destination."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/nf_flow_table_ip.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2a79fd3908acd88e6cb0e620c314d7b1fee56a02","lessThan":"12afa450a6a6c0cce2c42b7545a9958f62d8a00c","versionType":"git","status":"affected"},{"version":"2a79fd3908acd88e6cb0e620c314d7b1fee56a02","lessThan":"538e67e8c7889cf5f93951f5309d1bcb41f86036","versionType":"git","status":"affected"},{"version":"2a79fd3908acd88e6cb0e620c314d7b1fee56a02","lessThan":"8aecf0bbcc72605592134c917c222207d8f63ab0","versionType":"git","status":"affected"},{"version":"b4b1adf2e66ecc7125c4117e7aad9ff61e2cfd27","versionType":"git","status":"affected"},{"version":"209dedf806d31095968f54323dbe62525b077b33","versionType":"git","status":"affected"},{"version":"4.16.15","lessThan":"4.17","versionType":"semver","status":"affected"},{"version":"4.17.1","lessThan":"4.18","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/nf_flow_table_ip.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.18","status":"affected"},{"version":"0","lessThan":"4.18","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"references":[{"url":"https://git.kernel.org/stable/c/12afa450a6a6c0cce2c42b7545a9958f62d8a00c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/538e67e8c7889cf5f93951f5309d1bcb41f86036","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8aecf0bbcc72605592134c917c222207d8f63ab0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74696","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:44.153","lastModified":"2026-08-25T06:18:53.137","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: fix TFO max_qlen accounting across reuseport migration\n\nA listener's TCP_FASTOPEN max_qlen stops being accurate and lets through\nfar more pending Fast Open requests than it was configured for.\n\nThis only shows up with SO_REUSEPORT listener migration, where closing a\nlistener hands its still-pending TFO children over to a surviving one.\n\nfastopenq.qlen is charged in tcp_fastopen_create_child() when the child\nis created and uncharged in reqsk_fastopen_remove() when the handshake\ncompletes.  The uncharge follows rsk_listener of the request the child\npoints at, and inet_reqsk_clone() has repointed the child at a new\nrequest owned by the new listener, so the ++ and the -- land on two\ndifferent sockets.  The new listener's qlen drifts negative and its\nlimit no longer binds.\n\nCharge the new listener during migration, like reqsk_queue_migrated()\nalready does for queue->young and queue->qlen."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/inet_connection_sock.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"54b92e84193749c9968aff2dd46e3b0f42643e18","lessThan":"e98f0d80b9cccb5f828425d2004f9686e7d1ae24","versionType":"git","status":"affected"},{"version":"54b92e84193749c9968aff2dd46e3b0f42643e18","lessThan":"b6247e0f96bd825ffb2005257f6177b5e642dee6","versionType":"git","status":"affected"},{"version":"54b92e84193749c9968aff2dd46e3b0f42643e18","lessThan":"585fc5247d14939a561056aa2addd9b7c2b1f670","versionType":"git","status":"affected"},{"version":"54b92e84193749c9968aff2dd46e3b0f42643e18","lessThan":"6e10ee56524a26b250229ad348637825646ddb88","versionType":"git","status":"affected"},{"version":"54b92e84193749c9968aff2dd46e3b0f42643e18","lessThan":"a66e869cf0c90c1e47ae75f72b6482acbfc808ff","versionType":"git","status":"affected"},{"version":"54b92e84193749c9968aff2dd46e3b0f42643e18","lessThan":"d974618b2097453778389d385e3741629c40e0a3","versionType":"git","status":"affected"},{"version":"54b92e84193749c9968aff2dd46e3b0f42643e18","lessThan":"a0ab2ba83e35159d81cec830a92e885ecf8139be","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/inet_connection_sock.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"references":[{"url":"https://git.kernel.org/stable/c/585fc5247d14939a561056aa2addd9b7c2b1f670","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e10ee56524a26b250229ad348637825646ddb88","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a0ab2ba83e35159d81cec830a92e885ecf8139be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a66e869cf0c90c1e47ae75f72b6482acbfc808ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6247e0f96bd825ffb2005257f6177b5e642dee6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d974618b2097453778389d385e3741629c40e0a3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e98f0d80b9cccb5f828425d2004f9686e7d1ae24","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74697","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:44.280","lastModified":"2026-08-25T06:18:53.313","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Disable EOP for TPA on all chips to prevent data corruption\n\nEOP (End of frame padding) on the AGG ring may cause overlapping of\nzero padding at the end of one segment with the next segment's data.\nIf Relaxed Ordering (RO) is enabled, the zero padding may overwrite\nvalid data in the next segment and corrupt the data.  Older chips\n(P5 and older) do not automatically disable RO when EOP is enabled.\nOn some ARM systems, data corruption was reported on 57508 (P5)\nchips with RO enabled.\n\nAlways disable EOP on all chips on the AGG rings when TPA is enabled\nto fix the data corruption."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/broadcom/bnxt/bnxt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bfcd8d791ec18496772d117774398e336917f56e","lessThan":"68c181af7cd1ca9cbf29acd95911073bfd3c6397","versionType":"git","status":"affected"},{"version":"bfcd8d791ec18496772d117774398e336917f56e","lessThan":"7aee22a35978b44784612c156e358e375ddf5d16","versionType":"git","status":"affected"},{"version":"bfcd8d791ec18496772d117774398e336917f56e","lessThan":"410da4428b1f47bf9a84bdc0bcaa089d73ba2048","versionType":"git","status":"affected"},{"version":"bfcd8d791ec18496772d117774398e336917f56e","lessThan":"b61c4911204a0a2f900e538d64ceb608f6c9614d","versionType":"git","status":"affected"},{"version":"bfcd8d791ec18496772d117774398e336917f56e","lessThan":"aab3b5f4d8ec8598606ee011e219ef824ae25ca0","versionType":"git","status":"affected"},{"version":"bfcd8d791ec18496772d117774398e336917f56e","lessThan":"c1962ab4645a914a91ff492735881150ddc8a79e","versionType":"git","status":"affected"},{"version":"bfcd8d791ec18496772d117774398e336917f56e","lessThan":"c3faf548a00f4c17100cc9204746975fa46a73b9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/broadcom/bnxt/bnxt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.4","status":"affected"},{"version":"0","lessThan":"5.4","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":4.2}]},"references":[{"url":"https://git.kernel.org/stable/c/410da4428b1f47bf9a84bdc0bcaa089d73ba2048","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/68c181af7cd1ca9cbf29acd95911073bfd3c6397","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7aee22a35978b44784612c156e358e375ddf5d16","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aab3b5f4d8ec8598606ee011e219ef824ae25ca0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b61c4911204a0a2f900e538d64ceb608f6c9614d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c1962ab4645a914a91ff492735881150ddc8a79e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c3faf548a00f4c17100cc9204746975fa46a73b9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74698","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:44.397","lastModified":"2026-08-22T16:16:44.397","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: fix BQL reset on SQ re-activation\n\nmlx5e_queue_start() deactivates and re-activates all channels but closes\nonly the queue being restarted. mlx5e_activate_txqsq() then\nunconditionally calls netdev_tx_reset_queue(), zeroing the BQL counters\nof channels that kept their in-flight TX WQEs. The next completion then\nover-charges and trips the BUG_ON() in dql_completed():\n\n  kernel BUG at lib/dynamic_queue_limits.c:99!\n  RIP: 0010:dql_completed+0x23d/0x280\n  Call Trace:\n   <IRQ>\n   mlx5e_poll_tx_cq+0x668/0xa60\n   mlx5e_napi_poll+0x5b/0x7b0\n   net_rx_action+0x15a/0x580\n\nReset BQL only when the SQ has no bytes in flight (sq->cc == sq->pc).\n\nIn the case that reset is skipped, the outstanding WQEs will eventually\ncomplete and rebalance the dql. The dql->limit is carried across the\nreset."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/en_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b2588ea40ec9472688289c1a644627c0f4a1f33f","lessThan":"88664c48d7d1eca8e1ac92da85c89c26af741cf1","versionType":"git","status":"affected"},{"version":"b2588ea40ec9472688289c1a644627c0f4a1f33f","lessThan":"d2897717cd222e575599d903d885c48602699800","versionType":"git","status":"affected"},{"version":"b2588ea40ec9472688289c1a644627c0f4a1f33f","lessThan":"e7386770be1bf810bcd6af39d1e4bfeab3408430","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/en_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/88664c48d7d1eca8e1ac92da85c89c26af741cf1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2897717cd222e575599d903d885c48602699800","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e7386770be1bf810bcd6af39d1e4bfeab3408430","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74699","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:44.503","lastModified":"2026-08-22T16:16:44.503","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Fix memory leak in exec_queue_set_hang_replay_state()\n\nThe q->replay_state is blindly overwritten, which can potentially leak\nmemory that was previously allocated by vmemdup_user().\nReturn an error if q->replay_state is not empty.\n\nDiscovered using AI-assisted static analysis confirmed by Intel Product\nSecurity.\n\n(cherry picked from commit f6b6cc1118bdbc4265fa8b3bdf8565b26f13e56e)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/xe/xe_exec_queue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1026c1a73a9686ff35ac100039f94f0725622447","lessThan":"410596743958fbddeb845ff3efe2645397d7c7e2","versionType":"git","status":"affected"},{"version":"1026c1a73a9686ff35ac100039f94f0725622447","lessThan":"c5f500161709f27719701334190dff2325868ef0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/xe/xe_exec_queue.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/410596743958fbddeb845ff3efe2645397d7c7e2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c5f500161709f27719701334190dff2325868ef0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74700","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:44.610","lastModified":"2026-08-25T06:18:53.597","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers\n\nAnother challenge with unlocked filters.\nThere is a short window in tc_new_tfilter where a tcf_proto can be found\nand briefly referenced by a totally unrelated, unlocked classifier's request\nand cause a race.\n\nFeng created a poc which created this race with two threads, one creating a\nu32 filter and other a flower filter in the same chain/prio:\n\n1. Both threads enter tc_new_tfilter, both find the chain empty, both\n   drop filter_chain_lock\n2. u32 finishes tcf_proto_create(\"u32\") first, calls\n   tcf_chain_tp_insert_unique() -> inserts u32_tp into the chain\n3. flower finishes tcf_proto_create(\"flower\") later, calls\n   tcf_chain_tp_insert_unique() -> tcf_chain_tp_find() now sees u32_tp\n   already there, takes a reference on it, destroys flower's own tp_new\n   and returns u32_tp to the caller.\n\nFlower then hits the kind mismatch check (because it requested for kind\n\"flower\" but tp->ops->kind is \"u32\") and goes through the errout path\nwhich calls tcf_proto_put() on u32_tp. If the u32 thread has already\ngone through its own errout (its change() call failed on the PoC's empty\noptions) and dropped its create and insert refs, flower's put is the\nlast one and drops u32_tp's refcnt to zero.\n\nAt this point tp->ops->destroy() runs in a context that never took\nrtnl_lock. When that happens, it might cause a UAF like the following\n(illustrated by the PoC):\n\n[  +0.000710] BUG: KASAN: slab-use-after-free in u32_init (net/sched/cls_u32.c:393)\n[  +0.000281] Read of size 8 at addr ffff888120022f00 by task poc_feng_xue/524\n\n  Call Trace:\n   u32_init (net/sched/cls_u32.c:393)\n   tc_new_tfilter (net/sched/cls_api.c:2378)\n\n  Allocated by task 526:\n   u32_init (net/sched/cls_u32.c:378)\n   tc_new_tfilter (net/sched/cls_api.c:2378)\n\n  Freed by task 522:\n   kfree\n   u32_destroy (net/sched/cls_u32.c:662)\n   tcf_proto_destroy (net/sched/cls_api.c:446)\n   tcf_proto_put (net/sched/cls_api.c:459)\n   tc_new_tfilter (net/sched/cls_api.c:2459)\n\nFix this by having tcf_proto_destroy() take rtnl_lock around\ntp->ops->destroy() for locked classifiers whenever rtnl is not held.\n\nTo explain why I used a temp variable \"not_lockless\" I'd like to point to a\nsemi-related note on rtnl_held vs TCF_PROTO_OPS_DOIT_UNLOCKED (adding here\nfor future cleanup if deemed necessary):\nThe rtnl_held parameter and the TCF_PROTO_OPS_DOIT_UNLOCKED flag are\nredundant sources of truth for whether rtnl_lock is held. Among the nine\nclassifier destroy(..rtnl_held..) callbacks, only flower consults the\nrtnl_held parameter which it propagates to tc_setup_cb_destroy()\nand tc_setup_cb_call(). The other eight (u32, flow, bpf, cgroup, route, basic,\nfw, mall) ignore it entirely;-> those that call tc_setup_cb_destroy()\n(u32, bpf, mall) hardcode true always instead of forwarding the parameter.\n\nA future cleanup should remove the rtnl_held parameter from the destroy callback\nsignature entirely and have callers rely solely on their knowledge whether\nthey are running in an unlocked context."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sched/cls_api.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"12db03b65c2b90752e4c37666977fd4a1b5f5824","lessThan":"34e77d8e3570f9df3952496ddb402833695662fd","versionType":"git","status":"affected"},{"version":"12db03b65c2b90752e4c37666977fd4a1b5f5824","lessThan":"b648c8a56531aeabd1c14f6b5cf1891e269b3756","versionType":"git","status":"affected"},{"version":"12db03b65c2b90752e4c37666977fd4a1b5f5824","lessThan":"d6222af7274f08e7a1848131dc30319993d8f377","versionType":"git","status":"affected"},{"version":"12db03b65c2b90752e4c37666977fd4a1b5f5824","lessThan":"a81f9c44d87fb59d99fce72e29e02cab3a49a1c3","versionType":"git","status":"affected"},{"version":"12db03b65c2b90752e4c37666977fd4a1b5f5824","lessThan":"a347304b2ca1a5377d5bd2d8a72e4b4f12afe648","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sched/cls_api.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.1","status":"affected"},{"version":"0","lessThan":"5.1","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/34e77d8e3570f9df3952496ddb402833695662fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a347304b2ca1a5377d5bd2d8a72e4b4f12afe648","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a81f9c44d87fb59d99fce72e29e02cab3a49a1c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b648c8a56531aeabd1c14f6b5cf1891e269b3756","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d6222af7274f08e7a1848131dc30319993d8f377","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74701","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:44.740","lastModified":"2026-08-25T06:18:53.827","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/openvswitch: check Ethernet header length in key_extract()\n\nWhen a packet arrives on an ARPHRD_NONE device (e.g. TUN),\novs_flow_key_extract() trusts the user-provided skb->protocol field: if\nit is ETH_P_TEB, the packet is classified as MAC_PROTO_ETHERNET and\nkey_extract() is called without ensuring the skb has ETH_HLEN (14) bytes\nof linear data. key_extract() unconditionally pulls 2 * ETH_ALEN bytes\nfor MAC addresses and parse_ethertype() pulls 2 more, either of which\ntriggers a kernel BUG in __skb_pull() when the linear area is too small.\n\n  kernel BUG at include/linux/skbuff.h:2848!\n  RIP: 0010:key_extract+0xa7e/0xd90 net/openvswitch/flow.c:933\n  ovs_flow_key_extract+0x419/0xa70\n  ovs_vport_receive+0x222/0x390\n  netdev_frame_hook+0x3e0/0x630\n  tun_get_user+0x2d0c/0x38e0\n\nFixed by calling check_header() in key_extract() before accessing the\nEthernet header."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/openvswitch/flow.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"217ac77a3c2524d999730b2a80b61fcc2d0f734a","lessThan":"e85278afd4890dd190ba3c7a1b1a712b801c9fe1","versionType":"git","status":"affected"},{"version":"217ac77a3c2524d999730b2a80b61fcc2d0f734a","lessThan":"81f9b09f0ea3ba9ab966dd17e9f32625a14555e9","versionType":"git","status":"affected"},{"version":"217ac77a3c2524d999730b2a80b61fcc2d0f734a","lessThan":"831471718f6e19aed1a330b03b53190a90e06466","versionType":"git","status":"affected"},{"version":"217ac77a3c2524d999730b2a80b61fcc2d0f734a","lessThan":"d8bea341b183190ce6c055ab0e64ab78eb9a7290","versionType":"git","status":"affected"},{"version":"217ac77a3c2524d999730b2a80b61fcc2d0f734a","lessThan":"0b60b55652ba772b173dddc63f3851e1d2dd5927","versionType":"git","status":"affected"},{"version":"217ac77a3c2524d999730b2a80b61fcc2d0f734a","lessThan":"a8139285c8925efe59af28a9169bb2fda91bff15","versionType":"git","status":"affected"},{"version":"217ac77a3c2524d999730b2a80b61fcc2d0f734a","lessThan":"9b8cfbb58b85bfa7a78fac47fdc77396cd01f699","versionType":"git","status":"affected"},{"version":"217ac77a3c2524d999730b2a80b61fcc2d0f734a","lessThan":"cf6f8b29befb92173659bcef6a441d274947bfae","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/openvswitch/flow.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.10","status":"affected"},{"version":"0","lessThan":"4.10","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/0b60b55652ba772b173dddc63f3851e1d2dd5927","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/81f9b09f0ea3ba9ab966dd17e9f32625a14555e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/831471718f6e19aed1a330b03b53190a90e06466","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b8cfbb58b85bfa7a78fac47fdc77396cd01f699","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a8139285c8925efe59af28a9169bb2fda91bff15","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf6f8b29befb92173659bcef6a441d274947bfae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8bea341b183190ce6c055ab0e64ab78eb9a7290","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e85278afd4890dd190ba3c7a1b1a712b801c9fe1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74702","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:44.873","lastModified":"2026-08-25T06:18:54.117","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvhost-scsi: reject feature changes after endpoint\n\nvhost_scsi_setup_vq_cmds() runs from VHOST_SCSI_SET_ENDPOINT and allocates\neach command's protection scatterlist array (prot_sgl) according to the\nacknowledged VIRTIO_SCSI_F_T10_PI bit.  The command pools are not rebuilt\nwhen VHOST_SET_FEATURES changes that bit later.\n\nAlthough virtio feature bits must not change after feature negotiation,\nvhost_scsi_set_features() currently accepts such a request after the\nendpoint is active and updates acked_features.  Enabling T10-PI after\nendpoint setup therefore leaves prot_sgl NULL while the I/O path follows\nthe new feature bit.\n\nFor a 129-page protection payload, vhost_scsi_mapal() passes the missing\nfirst chunk to sg_alloc_table_chained():\n\n  sg_alloc_table_chained(table, 129, first_chunk=NULL,\n                         nents_first_chunk=inline_sg_cnt)\n\nsg_pool_index() then hits:\n\n  BUG_ON(nents > SG_CHUNK_SIZE);   /* 129 > 128 */\n\nThe kernel reported the following call trace and register state:\n\n  Call Trace:\n   <TASK>\n   ? __sg_alloc_table+0x1d8/0x250\n   ? __pfx_vhost_run_work_list+0x10/0x10 [vhost]\n   sg_alloc_table_chained+0x59/0xf0\n   ? __pfx_sg_pool_alloc+0x10/0x10\n   ? vhost_scsi_calc_sgls.constprop.0+0x43/0x60 [vhost_scsi]\n   vhost_scsi_handle_vq+0xf02/0x1700 [vhost_scsi]\n   ? __pfx_vhost_scsi_handle_vq+0x10/0x10 [vhost_scsi]\n   vhost_scsi_handle_kick+0x37/0x50 [vhost_scsi]\n   vhost_run_work_list+0x8e/0xd0 [vhost]\n   vhost_task_fn+0xe1/0x210\n   ret_from_fork+0x348/0x540\n   </TASK>\n\n  RIP: 0010:0x4\n  CR2 = 0x4\n  RSP: 0018:ffffc90000dbf940 EFLAGS: 00010202\n  RAX: ffffffff82396810 RBX: ffff88811dc28b80 RCX: 0000000000000000\n  RDX: 0000000000000000 RSI: 0000000000000820 RDI: 0000000000000081\n\nVHOST_F_LOG_ALL is a vhost-specific runtime feature and remains the only\nexception.\n\nReject changes to any feature other than VHOST_F_LOG_ALL while the\nendpoint is active.  This preserves the existing runtime log toggle while\npreventing feature-dependent command resources and data-path state from\nbecoming inconsistent.  Userspace must clear the endpoint before changing\nany other negotiated feature and set the endpoint up again afterward."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/vhost/scsi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bf2d650391be508dd8b5e188b65ed32300cf3489","lessThan":"a06e4611d45518896fbff4f45d9581578b107e91","versionType":"git","status":"affected"},{"version":"bf2d650391be508dd8b5e188b65ed32300cf3489","lessThan":"9a3eb77a612f9d158e4d27df43677a014e9cfa55","versionType":"git","status":"affected"},{"version":"bf2d650391be508dd8b5e188b65ed32300cf3489","lessThan":"42bc45df5905e2b7dccb72adaf7730f66cfbe03f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/vhost/scsi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.0,"impactScore":6.0}]},"references":[{"url":"https://git.kernel.org/stable/c/42bc45df5905e2b7dccb72adaf7730f66cfbe03f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9a3eb77a612f9d158e4d27df43677a014e9cfa55","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a06e4611d45518896fbff4f45d9581578b107e91","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74703","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:44.983","lastModified":"2026-08-25T06:18:54.330","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvhost-scsi: Validate T10 PI scatterlist counts\n\nWhen T10 PI is negotiated, vhost-scsi splits protection bytes from\nthe data iterator before mapping the request scatterlists. A malformed\nrequest can claim protection bytes that cover or exceed the full payload\nlength. The former leaves no data bytes to map, while the latter\nunderflows exp_data_len before advancing the iterator. Both cases can let\na zero data SGL count reach sg_alloc_table_chained(), which triggers\nBUG_ON(!nents).\n\nReject protection lengths that cover or exceed the payload before\nsubtracting prot_bytes and advancing the iterator. Also propagate\nnegative errors from the protection SGL calculation before calling the\nallocator, matching the data SGL path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/vhost/scsi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bca939d5bcd00d6faea99c47eafd60bed573ef03","lessThan":"2417a498cf3fe64d06faf87e236eda98dd4f04e0","versionType":"git","status":"affected"},{"version":"bca939d5bcd00d6faea99c47eafd60bed573ef03","lessThan":"f8fe3f8d342da750dd10361bf66009fd3072926b","versionType":"git","status":"affected"},{"version":"bca939d5bcd00d6faea99c47eafd60bed573ef03","lessThan":"d876c493fc4b811941bfeb4c80beb2dfc4bf025e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/vhost/scsi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":4.0}]},"references":[{"url":"https://git.kernel.org/stable/c/2417a498cf3fe64d06faf87e236eda98dd4f04e0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d876c493fc4b811941bfeb4c80beb2dfc4bf025e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f8fe3f8d342da750dd10361bf66009fd3072926b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74704","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:45.090","lastModified":"2026-08-25T06:18:54.583","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter\n\nThe sch_cake ACK filter parses packets to find the TCP header and filter\nduplicated ACKs if the flow is backlogged. The parsing code contains a\nWARN_ON(1) which can be triggered by a malformed IP header in certain\ncases. Depending on the system configuration, this leads either to\neither spamming dmesg with warnings, or a panic if panic_on_warn is set.\n\nThe code already correctly skips the offending packet in the branch that\ntriggers the warning, so the WARN_ON itself doesn't really serve any\npurpose. So just drop it altogether to avoid the inconvenient side\neffects."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sched/sch_cake.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8b7138814f29933898ecd31dfc83e35a30ee69f5","lessThan":"c1693b7844a6c06d31a565e5a494948034dfd235","versionType":"git","status":"affected"},{"version":"8b7138814f29933898ecd31dfc83e35a30ee69f5","lessThan":"a4b52612004a5639c4bfc30ba93ba414b8326e2a","versionType":"git","status":"affected"},{"version":"8b7138814f29933898ecd31dfc83e35a30ee69f5","lessThan":"ae1b2f8e21a41e7c7e75511bea0c4ccc59ec1bd3","versionType":"git","status":"affected"},{"version":"8b7138814f29933898ecd31dfc83e35a30ee69f5","lessThan":"0c4882bff34558d8d53fb04c3e96da5c327c7dc8","versionType":"git","status":"affected"},{"version":"8b7138814f29933898ecd31dfc83e35a30ee69f5","lessThan":"2504a76e5c0694e14e15562730e1339f2d9f9458","versionType":"git","status":"affected"},{"version":"8b7138814f29933898ecd31dfc83e35a30ee69f5","lessThan":"cd2f1d9fe8a507c2dc86ad326fe221f121c47734","versionType":"git","status":"affected"},{"version":"8b7138814f29933898ecd31dfc83e35a30ee69f5","lessThan":"a1ae353d8355407c1bea971d1c1af5e7f242bb7d","versionType":"git","status":"affected"},{"version":"8b7138814f29933898ecd31dfc83e35a30ee69f5","lessThan":"2a33516f9ef59ad11844d4fc152f889449b5daf3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sched/sch_cake.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.19","status":"affected"},{"version":"0","lessThan":"4.19","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":4.2}]},"references":[{"url":"https://git.kernel.org/stable/c/0c4882bff34558d8d53fb04c3e96da5c327c7dc8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2504a76e5c0694e14e15562730e1339f2d9f9458","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2a33516f9ef59ad11844d4fc152f889449b5daf3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a1ae353d8355407c1bea971d1c1af5e7f242bb7d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4b52612004a5639c4bfc30ba93ba414b8326e2a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae1b2f8e21a41e7c7e75511bea0c4ccc59ec1bd3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c1693b7844a6c06d31a565e5a494948034dfd235","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd2f1d9fe8a507c2dc86ad326fe221f121c47734","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74705","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:45.213","lastModified":"2026-08-25T06:18:54.870","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nudp: fix potential use-after-free in tunnel segmentation\n\n__skb_udp_tunnel_segment() gets the UDP header before ensuring the\ntunnel header is in the skb head. If the pull reallocates skb->head,\nthe saved UDP header pointer is no longer valid.\n\nGet the UDP header after the pull to avoid a potential use-after-free."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/udp_offload.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"dbef491ebe7f3a4fb1b9111878b86a426fd540b7","lessThan":"6a733a38b983d8c2e222f13968209010cf44de87","versionType":"git","status":"affected"},{"version":"dbef491ebe7f3a4fb1b9111878b86a426fd540b7","lessThan":"19d89b13a43640b2da2f277ee462d919d988cb6f","versionType":"git","status":"affected"},{"version":"dbef491ebe7f3a4fb1b9111878b86a426fd540b7","lessThan":"b3df61bb745eb5201eac22679a2839d4ccbf3442","versionType":"git","status":"affected"},{"version":"dbef491ebe7f3a4fb1b9111878b86a426fd540b7","lessThan":"1ae134c012e10384cdac420b5cc6e0615cde0b55","versionType":"git","status":"affected"},{"version":"dbef491ebe7f3a4fb1b9111878b86a426fd540b7","lessThan":"5161e67c561c4f28a5d9335a6e859b02511de92b","versionType":"git","status":"affected"},{"version":"dbef491ebe7f3a4fb1b9111878b86a426fd540b7","lessThan":"64d322c288577793eedd352b96ef75234ed380fe","versionType":"git","status":"affected"},{"version":"dbef491ebe7f3a4fb1b9111878b86a426fd540b7","lessThan":"588d4a6795d99d080f74ef0b5f391ea8c453ae5d","versionType":"git","status":"affected"},{"version":"dbef491ebe7f3a4fb1b9111878b86a426fd540b7","lessThan":"d0f86fb36eb260abd10007b62c9dcc1028e03e61","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/udp_offload.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.6","status":"affected"},{"version":"0","lessThan":"4.6","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":6.0}]},"references":[{"url":"https://git.kernel.org/stable/c/19d89b13a43640b2da2f277ee462d919d988cb6f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1ae134c012e10384cdac420b5cc6e0615cde0b55","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5161e67c561c4f28a5d9335a6e859b02511de92b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/588d4a6795d99d080f74ef0b5f391ea8c453ae5d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/64d322c288577793eedd352b96ef75234ed380fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6a733a38b983d8c2e222f13968209010cf44de87","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b3df61bb745eb5201eac22679a2839d4ccbf3442","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d0f86fb36eb260abd10007b62c9dcc1028e03e61","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74706","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:45.333","lastModified":"2026-08-22T16:16:45.333","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbnge: Fix NULL pointer dereference in aux device release\n\nIf allocation of auxr_dev fails during auxiliary device setup, the error\npath calls auxiliary_device_uninit(), which eventually invokes\nbnge_aux_dev_release().\n\nThe release callback unconditionally dereferences aux_priv->auxr_dev->pdev\nto retrieve the parent bnge_dev. Since auxr_dev has not yet been allocated\non this failure path, the dereference results in a NULL pointer exception\n\nRetrieve the parent bnge_dev from the auxiliary device's parent instead of\nauxr_dev, and free auxr_dev only when it was successfully allocated. This\nallows the release callback to correctly clean up partially initialized\nauxiliary devices."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/broadcom/bnge/bnge_auxr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8ac050ec3b1c0dcb5e89cf86fe2ebe0afcc73554","lessThan":"83ef2f3cab7fe6dd9155cd598dc64be524d963a9","versionType":"git","status":"affected"},{"version":"8ac050ec3b1c0dcb5e89cf86fe2ebe0afcc73554","lessThan":"1cb4298810e27e037d3ca07286ecbb97e89ba58d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/broadcom/bnge/bnge_auxr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1cb4298810e27e037d3ca07286ecbb97e89ba58d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/83ef2f3cab7fe6dd9155cd598dc64be524d963a9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74707","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:45.433","lastModified":"2026-08-25T06:18:55.180","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxsk: validate metadata when processing requests\n\nThe zero-copy path validates TX metadata while obtaining the descriptor\ncontext, then reads it again later when preparing the hardware request.\nUser space can change the metadata between those operations and bypass the\noriginal validation.\n\nValidate the metadata in xsk_tx_metadata_request() and use the resulting\nflags snapshot for every feature check. Read request fields once so all\nzero-copy drivers process only values observed after successful\nvalidation."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/intel/igc/igc_main.c","drivers/net/ethernet/mellanox/mlx5/core/en/xdp.c","drivers/net/ethernet/stmicro/stmmac/stmmac_main.c","include/net/libeth/xsk.h","include/net/xdp_sock_drv.h","net/xdp/xsk_buff_pool.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ca4419f15abd19ba8be1e109661b60f9f5b6c9f0","lessThan":"5fd121971912dee2f5af1efec64462ac722deb17","versionType":"git","status":"affected"},{"version":"ca4419f15abd19ba8be1e109661b60f9f5b6c9f0","lessThan":"0cc7aa6e0d19027fdd42e6fbd156267ac1e3bbba","versionType":"git","status":"affected"},{"version":"ca4419f15abd19ba8be1e109661b60f9f5b6c9f0","lessThan":"849b1664dbda1cf6c63e0fd4f9dec23782b8c851","versionType":"git","status":"affected"},{"version":"d9d736c416c9a85f84e15435ba82a177262e745b","versionType":"git","status":"affected"},{"version":"6.14.2","lessThan":"6.15","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/intel/igc/igc_main.c","drivers/net/ethernet/mellanox/mlx5/core/en/xdp.c","drivers/net/ethernet/stmicro/stmmac/stmmac_main.c","include/net/libeth/xsk.h","include/net/xdp_sock_drv.h","net/xdp/xsk_buff_pool.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/0cc7aa6e0d19027fdd42e6fbd156267ac1e3bbba","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5fd121971912dee2f5af1efec64462ac722deb17","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/849b1664dbda1cf6c63e0fd4f9dec23782b8c851","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74708","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:45.540","lastModified":"2026-08-25T06:18:55.453","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxsk: validate launch-time metadata size\n\nLaunch-time metadata extends beyond the first 16 bytes of struct\nxsk_tx_metadata. Reject the request when the registered metadata area does\nnot contain the complete field.\n\nSnapshot the validated flags for the generic transmit path and use that\nsnapshot for request and completion processing, avoiding inconsistent\ndecisions if user space changes the flags concurrently.\n\nNote that only xsk_skb_metadata is properly using the flags,\n__xsk_buff_get_metadata ignores them. Next commits address that."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/xdp_sock_drv.h","net/xdp/xsk.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ca4419f15abd19ba8be1e109661b60f9f5b6c9f0","lessThan":"af511afa1d2977f384044df78d6fbf9fba653f7a","versionType":"git","status":"affected"},{"version":"ca4419f15abd19ba8be1e109661b60f9f5b6c9f0","lessThan":"bc63d47611c07b0d5d655fe1a590861931527920","versionType":"git","status":"affected"},{"version":"ca4419f15abd19ba8be1e109661b60f9f5b6c9f0","lessThan":"439ce2dddf3d22129b9113a7881637256a35e936","versionType":"git","status":"affected"},{"version":"d9d736c416c9a85f84e15435ba82a177262e745b","versionType":"git","status":"affected"},{"version":"6.14.2","lessThan":"6.15","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/xdp_sock_drv.h","net/xdp/xsk.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/439ce2dddf3d22129b9113a7881637256a35e936","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af511afa1d2977f384044df78d6fbf9fba653f7a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bc63d47611c07b0d5d655fe1a590861931527920","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74709","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:45.640","lastModified":"2026-08-22T16:16:45.640","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxsk: clear metadata pointer when no timestamp is requested\n\nUser space can change metadata flags after request processing. Rereading\nthem during completion can therefore make the kernel write a timestamp\nthat was not requested when the packet was submitted.\n\nClear the metadata pointer during request processing unless timestamp\ncompletion is requested. Completion handling can then use the pointer\nitself instead of rereading the flags.\n\nOn the mlx5 multi-packet WQE path metadata is evaluated per batch:\nxsk_tx_metadata_request() runs only for the descriptor that starts a\nsession, just like the checksum offload that is applied once through the\nshared WQE. Only that descriptor's pointer is reset, so completion\nhandling can record a timestamp for the other descriptors of the session\nregardless of their own XDP_TXMD_FLAGS_TIMESTAMP bit. The write stays\ninside the metadata area; the single-WQE, other zero-copy, and generic\npaths reset the pointer per descriptor and are unaffected."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/xdp_sock.h","net/xdp/xsk.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ca4419f15abd19ba8be1e109661b60f9f5b6c9f0","lessThan":"0ba2e1eb07a826d021344e2f146b6716c58139eb","versionType":"git","status":"affected"},{"version":"ca4419f15abd19ba8be1e109661b60f9f5b6c9f0","lessThan":"eb4c613d4ebc3f664e70d572b8867ba114a8754e","versionType":"git","status":"affected"},{"version":"ca4419f15abd19ba8be1e109661b60f9f5b6c9f0","lessThan":"9f60a67df8d3c862503bee62bada8e7089cba438","versionType":"git","status":"affected"},{"version":"d9d736c416c9a85f84e15435ba82a177262e745b","versionType":"git","status":"affected"},{"version":"6.14.2","lessThan":"6.15","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/xdp_sock.h","net/xdp/xsk.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0ba2e1eb07a826d021344e2f146b6716c58139eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f60a67df8d3c862503bee62bada8e7089cba438","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eb4c613d4ebc3f664e70d572b8867ba114a8754e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74710","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:45.743","lastModified":"2026-08-25T06:18:55.687","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxsk: require at least 16 bytes of TX metadata\n\nAF_XDP accepts a TX metadata length as small as eight bytes, but every\nsupported request needs the flags plus at least one eight-byte request\nfield. Such short metadata also lets the kernel read beyond the registered\narea.\n\nRequire 16 bytes rather than sizeof(struct xsk_tx_metadata) to preserve\ncompatibility with applications that do not use launch-time metadata."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/xdp/xdp_umem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"341ac980eab90ac1f6c22ee9f9da83ed9604d899","lessThan":"21b8536aee819792f1b4b38b9aacf2a073025d49","versionType":"git","status":"affected"},{"version":"341ac980eab90ac1f6c22ee9f9da83ed9604d899","lessThan":"642c6e73fce17fdca93a5793c4d22359fda866d7","versionType":"git","status":"affected"},{"version":"341ac980eab90ac1f6c22ee9f9da83ed9604d899","lessThan":"cfb9d2976b277e554e28c165e3eff4b4a8ea10bd","versionType":"git","status":"affected"},{"version":"341ac980eab90ac1f6c22ee9f9da83ed9604d899","lessThan":"1bb30b181d9f0484e141f8411e15ed906d5c6780","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/xdp/xdp_umem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/1bb30b181d9f0484e141f8411e15ed906d5c6780","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/21b8536aee819792f1b4b38b9aacf2a073025d49","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/642c6e73fce17fdca93a5793c4d22359fda866d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cfb9d2976b277e554e28c165e3eff4b4a8ea10bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74711","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:45.853","lastModified":"2026-08-25T06:18:55.940","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus) Fix type confusion in notification logic\n\nSashiko reports:\n\nAt the start of the loop in pmbus_notify(), the code unconditionally casts\nevery attribute to a struct sensor_device_attribute:\n\ndrivers/hwmon/pmbus/pmbus_core.c:pmbus_notify() {\n    for (i = 0; i < data->num_attributes; i++) {\n        struct device_attribute *da = to_dev_attr(data->group.attrs[i]);\n        struct sensor_device_attribute *attr = to_sensor_dev_attr(da);\n        int index = attr->index;\n...\n}\n\nHowever, data->group.attrs can contain other types like struct\npmbus_samples_reg or struct pmbus_sensor, which only embed a base\nstruct device_attribute.\n\nIf da is a struct pmbus_samples_reg, dev_attr is the last member. Casting\nit to struct sensor_device_attribute and reading the index field appears\nto access memory past the end of the allocation, which might trigger a\nslab-out-of-bounds read.\n\nAdditionally, if da is a struct pmbus_sensor, casting it causes the index\nfield to overlap with the page, phase, and reg fields. Could this produce\na garbage mask on little-endian systems that spuriously matches the target\nreg, page, and flags during an alert?\n\nFix the problem by using struct sensor_device_attr in struct pmbus_sensor\nand struct pmbus_label. Since those attributes never trigger a\nnotification, set the value of attr->index to -1 for them. Use this value\nto distinguish from boolean attributes which _can_ trigger a notification\nand use the index field to encode mask, page, and register values."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hwmon/pmbus/pmbus_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f469bde9afd136598a0c4edc054296e6046f90ee","lessThan":"821f6416e69782fa662aff94b5ea52c943042790","versionType":"git","status":"affected"},{"version":"f469bde9afd136598a0c4edc054296e6046f90ee","lessThan":"0b121de89a99c54bcf516999b04e8531c84f08d5","versionType":"git","status":"affected"},{"version":"f469bde9afd136598a0c4edc054296e6046f90ee","lessThan":"59bd68ab05a8f9c9a60b6ec44682084184803ff4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hwmon/pmbus/pmbus_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/0b121de89a99c54bcf516999b04e8531c84f08d5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/59bd68ab05a8f9c9a60b6ec44682084184803ff4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/821f6416e69782fa662aff94b5ea52c943042790","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74712","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:45.957","lastModified":"2026-08-25T06:18:56.223","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvdpa/mlx5: Fix buffer length in create_direct_keys()\n\nWe have seen in our CI the following KASAN message:\nBUG: KASAN: slab-out-of-bounds in cmd_exec+0x550/0xca0 [mlx5_core]\nRead of size 272 at addr 0000000176795020 by task qemu-system-s39/82764\n[...]\n[<000011388ab3a7a0>] cmd_exec+0x550/0xca0 [mlx5_core]\n[<000011388ab3b61c>] mlx5_cmd_exec_cb+0x25c/0x4f0 [mlx5_core]\n[<000011388b21e82e>] mlx5_vdpa_exec_async_cmds+0x22e/0x5e0 [mlx5_vdpa]\n[<000011388b21fd44>] create_direct_keys+0x954/0xef0 [mlx5_vdpa]\n[...]\nThe buggy address is located 4128 bytes inside of\nallocated 4384-byte region [0000000176794000, 0000000176795120)\n\nSo in essence we read 16 bytes beyond 4384-byte allocation.\ncreate_direct_keys calculates the pointer and length for in and out\nbuffers.\nThe size calculation for in includes the entire structure\nsize (out + in + mtt[]) but the pointer passed to cmd_exec points only\nto the 'in' field, skipping the 'out' field.\n\nThis causes mlx5_copy_to_msg() to read beyond the allocated buffer\nby sizeof(out) bytes when copying command data.\n\nProperly calculate the input size to match the pointer and allocation size."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/vdpa/mlx5/core/mr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0071b138d44af4296bf871e6624369ce697b4b15","lessThan":"ec3bb289cf19d526224117d5d450a5fd9cbd5ab2","versionType":"git","status":"affected"},{"version":"0071b138d44af4296bf871e6624369ce697b4b15","lessThan":"cde8931a25392670dd59a0acfcab87a830ab66c5","versionType":"git","status":"affected"},{"version":"0071b138d44af4296bf871e6624369ce697b4b15","lessThan":"6c8a9f7bc00301e533a5366384f3070a8e7f8430","versionType":"git","status":"affected"},{"version":"0071b138d44af4296bf871e6624369ce697b4b15","lessThan":"727e1f569855df83579edbd73dcb4a0723543a12","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/vdpa/mlx5/core/mr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":6.0}]},"references":[{"url":"https://git.kernel.org/stable/c/6c8a9f7bc00301e533a5366384f3070a8e7f8430","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/727e1f569855df83579edbd73dcb4a0723543a12","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cde8931a25392670dd59a0acfcab87a830ab66c5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ec3bb289cf19d526224117d5d450a5fd9cbd5ab2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74713","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:46.063","lastModified":"2026-08-25T06:18:56.500","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvhost_iotlb: bound map allocation in add_range\n\nvhost_iotlb_add_range_ctx() only retires an old entry when the table\nhas a non-zero limit, has exactly reached that limit and has\nVHOST_IOTLB_FLAG_RETIRE set. Non-retiring tables can keep allocating\nentries after reaching their configured limit.\n\nExisting vhost devices allocate their IOTLB with max_iotlb_entries from\nvhost.c, which defaults to 2048 and is tunable by module parameter. Use\nthe caller-provided limit at the allocation point instead of adding a\nseparate default in the common IOTLB helper, and reject non-positive\nvalues in vhost paths that can report an error.\n\nOther vhost IOTLB users should not create zero-limit tables when entries\ncan be populated from userspace or guest-controlled requests. Add\ncaller-side max_iotlb_entries parameters for mlx5 vDPA, VDUSE and\nvhost-vDPA. Reject non-positive VDUSE and vhost-vDPA values, and require\nat least two entries for vdpa_sim and mlx5 vDPA paths that install\nfull-range mappings, since those mappings are split into two IOTLB\nentries.\n\nHandle full-range mappings in the common helper by checking that the\nIOTLB can hold both split entries before inserting the first half. This\navoids returning an error after leaving a half mapping behind.\n\nWhen the table is full, keep the existing retire behavior for retiring\ntables and return -ENOSPC for non-retiring tables. Reuse the retired map\nnode instead of freeing it and allocating a replacement, so a stream of\nIOTLB updates cannot keep forcing GFP_ATOMIC allocations after the table\nhas reached its limit. If a zero-limit IOTLB still reaches the common\nhelper, treat it as a configuration error and return -EINVAL.\n\nI found this bug myself, though the patch was written with AI assistance."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/vdpa/mlx5/core/mlx5_vdpa.h","drivers/vdpa/mlx5/core/mr.c","drivers/vdpa/mlx5/core/resources.c","drivers/vdpa/vdpa_sim/vdpa_sim.c","drivers/vdpa/vdpa_user/iova_domain.c","drivers/vhost/iotlb.c","drivers/vhost/vdpa.c","drivers/vhost/vhost.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0bbe30668d89ec8a309f28ced6d092c90fb23e8c","lessThan":"ae128dd19040ee06a4f8143c7ced4d18080d7a9a","versionType":"git","status":"affected"},{"version":"0bbe30668d89ec8a309f28ced6d092c90fb23e8c","lessThan":"1ed35ac7f3fe2b4396bdd29ac3a7f0ebc0829e94","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/vdpa/mlx5/core/mlx5_vdpa.h","drivers/vdpa/mlx5/core/mr.c","drivers/vdpa/mlx5/core/resources.c","drivers/vdpa/vdpa_sim/vdpa_sim.c","drivers/vdpa/vdpa_user/iova_domain.c","drivers/vhost/iotlb.c","drivers/vhost/vdpa.c","drivers/vhost/vhost.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.7","status":"affected"},{"version":"0","lessThan":"5.7","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":4.0}]},"references":[{"url":"https://git.kernel.org/stable/c/1ed35ac7f3fe2b4396bdd29ac3a7f0ebc0829e94","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae128dd19040ee06a4f8143c7ced4d18080d7a9a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74714","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:46.170","lastModified":"2026-08-25T06:18:56.740","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()\n\nreqsk_queue_hash_req() publishes a TCP_NEW_SYN_RECV request_sock onto\nthe ehash chain, drops the bucket lock, and only afterwards sets\nrsk_refcnt to 3.\n\nLockless readers such as __inet_lookup_established() handle this with\nrefcount_inc_not_zero(), but bpf_iter_tcp_established_batch() uses plain\nsock_hold() while holding the bucket lock, on the assumption that the\nlock guarantees sk_refcnt > 0. That assumption does not hold for\nrequest_sock:\n\n  CPU 0                                CPU 1\n  -----                                -----\n  tcp_conn_request()\n   reqsk_queue_hash_req()\n    inet_ehash_insert(req)\n     spin_lock(bucket)\n     __sk_nulls_add_node_rcu(req)      // rsk_refcnt == 0\n     spin_unlock(bucket)\n                                       bpf_iter_tcp_established_batch()\n                                        spin_lock(bucket)\n                                        sock_hold(req)   <-- addition on 0\n                                        spin_unlock(bucket)\n    refcount_set(&req->rsk_refcnt, 3)  // clobbers saturated value\n\nwhich surfaces as:\n\n  refcount_t: addition on 0; use-after-free.\n  WARNING: lib/refcount.c:25 at refcount_warn_saturate+0x48/0x90, CPU#1\n  Call Trace:\n   bpf_iter_tcp_established_batch+0x14e/0x170\n   bpf_iter_tcp_batch+0x53/0x200\n   bpf_iter_tcp_seq_next+0x27/0x70\n   bpf_seq_read+0x107/0x410\n   vfs_read+0xb9/0x380\n\nThe iterator's stolen reference is lost when the publishing CPU's\nrefcount_set() overwrites the count, leaving the socket one reference\nshort. When the last legitimate owner drops its reference the reqsk is\nfreed while still reachable, leading to use-after-free.\n\nThis reproduces in seconds with tcp_syncookies=0, a handful of threads\ndoing connect()/close() to a local listener while others read an\niter/tcp link in a tight loop.\n\nUse refcount_inc_not_zero() and skip the socket on failure. A skipped\nsocket is still part of the bucket, so keep counting it in expected.\nThe reallocations are sized from expected, and a request sock whose\nrefcount gets published while the lock is held across the last realloc\nmust already have room.\n\nA skipped socket is counted in expected but never batched, so end_sk\ncan be short of expected on a batch that is actually complete. Decide\ncompleteness by whether the walk left any socket behind instead. The\nWARN after the locked realloc checks the same, replacing an\nend_sk == expected check that could not hold on that path since\ncommit cdec67a489d4 (\"bpf: tcp: Make sure iter->batch always\ncontains a full bucket snapshot\").\n\nIf every matching socket in a bucket is mid-init (refcount 0), end_sk\nstays 0. Advance to the next bucket rather than returning a batch entry\nthat was never filled this round."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/tcp_ipv4.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"04c7820b776f1c4b48698574c47de9e940d368e8","lessThan":"cc0295f89296ed351fc4b0b48fee887ba02c5d24","versionType":"git","status":"affected"},{"version":"04c7820b776f1c4b48698574c47de9e940d368e8","lessThan":"ddbe966b5d1fe212ada749bc3d0b410f1a7dea74","versionType":"git","status":"affected"},{"version":"04c7820b776f1c4b48698574c47de9e940d368e8","lessThan":"7d2b60a4bc0499f62ff8520af6309bbe170882fd","versionType":"git","status":"affected"},{"version":"04c7820b776f1c4b48698574c47de9e940d368e8","lessThan":"cefcbbe20846a45f9a7dae868f7ef1000953e2df","versionType":"git","status":"affected"},{"version":"04c7820b776f1c4b48698574c47de9e940d368e8","lessThan":"97e74d3e45d653c07c2d406fc530a9bbe3df8396","versionType":"git","status":"affected"},{"version":"04c7820b776f1c4b48698574c47de9e940d368e8","lessThan":"e5fd3f514e27db1f05fbd72ba615d74941e23c51","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/tcp_ipv4.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/7d2b60a4bc0499f62ff8520af6309bbe170882fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/97e74d3e45d653c07c2d406fc530a9bbe3df8396","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cc0295f89296ed351fc4b0b48fee887ba02c5d24","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cefcbbe20846a45f9a7dae868f7ef1000953e2df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ddbe966b5d1fe212ada749bc3d0b410f1a7dea74","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5fd3f514e27db1f05fbd72ba615d74941e23c51","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74715","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:46.313","lastModified":"2026-08-25T06:18:57.063","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix netns reference imbalance in conntrack kfuncs\n\nThe opts argument of the BPF conntrack kfuncs can point to a shared\nmap value.  __bpf_nf_ct_lookup() and __bpf_nf_ct_alloc_entry() read\nopts->netns_id separately when acquiring and releasing the network\nnamespace reference.\n\nThe reference imbalance can occur as follows:\n\n  CPU 0                                  CPU 1\n  read opts->netns_id (-1)\n  skip get_net_ns_by_id()\n                                         write opts->netns_id (id)\n  read opts->netns_id (id)\n  put_net(net) /* no matching get */\n\nThe reverse transition leaks the reference.  Repeating the unmatched put\ncan destroy a live namespace and crash later users.\n\nThe kernel reported:\n\n  Oops: general protection fault, probably for non-canonical address\n  KASAN: null-ptr-deref in range [0x00000000000000e8-0x00000000000000ef]\n  RIP: 0010:bpf_prog_test_run_xdp+0x52c/0x1700\n  Call Trace:\n   __sys_bpf+0x1662/0x50c0\n   __x64_sys_bpf+0x73/0xb0\n   do_syscall_64+0xf9/0x540\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n  Kernel panic - not syncing: Fatal exception\n\nSnapshot every input field of opts with READ_ONCE() before validating or\nusing it.  The netns_id snapshot keeps the namespace get/put pair\nbalanced, while the other snapshots keep the remaining options from\nchanging partway through an invocation.  The individual reads can still\nobserve an inconsistent combination during a concurrent update, but each\nselected field value remains stable for that invocation."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/nf_conntrack_bpf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"aed8ee7feb44b6537af1e0b4f03365d42928be38","lessThan":"e5e060eb63d10b41ab60fd955649479d99b38210","versionType":"git","status":"affected"},{"version":"aed8ee7feb44b6537af1e0b4f03365d42928be38","lessThan":"fdeba03fea78407a8c52faa99177c9f7f29f90eb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/nf_conntrack_bpf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/e5e060eb63d10b41ab60fd955649479d99b38210","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fdeba03fea78407a8c52faa99177c9f7f29f90eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74716","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:46.443","lastModified":"2026-08-22T16:16:46.443","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\naccel/amdxdna: Fix locally exploitable BUG_ON in amdxdna_insert_pages()\n\nIn amdxdna_insert_pages(), vm_flags_mod() sets VM_MIXEDMAP and clears\nVM_PFNMAP. If an unprivileged userspace process mmaps a non-imported GEM\nobject and then calls madvise(MADV_DONTNEED), the PTEs will be\nsuccessfully cleared because VM_MIXEDMAP allows this (unlike VM_PFNMAP).\n\nWhen userspace subsequently accesses the memory, drm_gem_shmem_fault()\nhandles the page fault and attempts to map the backing shmem page via\nvmf_insert_pfn() which calls vmf_insert_pfn_prot(). Because the backing\nshmem page is normal system memory (pfn_valid(pfn) is true) and the VMA\nnow has VM_MIXEDMAP set, won't this predictably trigger the explicit\nassertion BUG_ON((vma->vm_flags & VM_MIXEDMAP) && pfn_valid(pfn))\n\nFix by removing the vm_flags_mod() call and replacing the vm_insert_pages()\npre-population with the handle_mm_fault() loop that was already used for\nthe import (dma-buf) path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/accel/amdxdna/amdxdna_gem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e486147c912f653ef4b60a6c7dbd4168a4c56a9f","lessThan":"13339132d89d00b513dff0730bff3a313b9b13b5","versionType":"git","status":"affected"},{"version":"e486147c912f653ef4b60a6c7dbd4168a4c56a9f","lessThan":"4a19f7ab5972ef608b31ae921419bc3e04b3f8ad","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/accel/amdxdna/amdxdna_gem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/13339132d89d00b513dff0730bff3a313b9b13b5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4a19f7ab5972ef608b31ae921419bc3e04b3f8ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74717","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:46.570","lastModified":"2026-08-25T06:18:57.310","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: fw_tracer, return NULL on create error\n\nTracer creation can fail by returning either NULL or ERR_PTR.\nThe return value is stored without a check on the device, and users\ntreat ERR_PTR and NULL the same way.\nThis also causes a crash in the core dump logic, which is missing the\nERR_PTR check and ends up dereferencing it, as shown in the trace below.\n\nSwitch tracer creation to return NULL on failure only, so callers only\nneed a single NULL check.\n\n  Internal error: Oops: 0000000096000006 [#1]  SMP\n  Modules linked in: mlx5_ib ib_uverbs ib_core ipv6 mlx5_core\n  CPU: 1 UID: 0 PID: 12 Comm: kworker/u16:0 Not tainted 6.19.7 #1 PREEMPT(none)\n  Workqueue: mlx5_health0001:01:00.0 mlx5_fw_reporter_err_work [mlx5_core]\n  pstate: a3400009 (NzCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\n  pc : mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core]\n  lr : mlx5_fw_tracer_trigger_core_dump_general+0x40/0xe0 [mlx5_core]\n  sp : ffff800081cf3c40\n  x29: ffff800081cf3c90 x28: 0000000000000000 x27: 0000000000000000\n  x26: ffff000080018828 x25: 0000000000000000 x24: ffff000080304a05\n  x23: ffff800081cf3d80 x22: ffff0000847e01a0 x21: 0000000000000000\n  x20: ffff0000847e01a0 x19: ffffffffffffffa1 x18: ffff80008310bbf0\n  x17: ffff800080119650 x16: ffff80008010df54 x15: ffff80008010d4ac\n  x14: ffff800079c202e4 x13: ffff80008002fe60 x12: ffff800080119650\n  x11: ffff80008010df54 x10: ffff80008010d4ac x9 : ffff800079c203d8\n  x8 : ffff800081cf3c88 x7 : 0000000000000000 x6 : 0000000000000000\n  x5 : 0000000000000000 x4 : 0000000000000008 x3 : 0000000000000030\n  x2 : 0000000000000008 x1 : 0000000000000000 x0 : 00000000c5c4000e\n  Call trace:\n   mlx5_fw_tracer_trigger_core_dump_general+0x58/0xe0 [mlx5_core] (P)\n   mlx5_fw_reporter_dump+0x30/0x2e0 [mlx5_core]\n   devlink_health_do_dump+0x9c/0x160\n   devlink_health_report+0x1c0/0x288\n   mlx5_fw_reporter_err_work+0xac/0xc0 [mlx5_core]\n   process_one_work+0x15c/0x3d8\n   worker_thread+0x18c/0x320\n   kthread+0x148/0x228\n   ret_from_fork+0x10/0x20\n  Code: b9400000 5ac00800 7a401800 540003ca (3940a260)\n  ---[ end trace 0000000000000000 ]---\n  Kernel panic - not syncing: Oops: Fatal exception\n  SMP: stopping secondary CPUs\n  Kernel Offset: disabled\n  CPU features: 0x000000,00078031,75fce5a1,35fffe67\n  Memory Limit: none\n  ---[ end Kernel panic - not syncing: Oops: Fatal exception ]---"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/diag/fw_tracer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fd1483fe1f9fd45fe312adffb0faffa57446690d","lessThan":"47fe0d2571e5b446a0f0b0c1d6b99f55e51f5cc0","versionType":"git","status":"affected"},{"version":"fd1483fe1f9fd45fe312adffb0faffa57446690d","lessThan":"ee41ea49c4ab0e4015919f52ad23ec251d3b39d3","versionType":"git","status":"affected"},{"version":"fd1483fe1f9fd45fe312adffb0faffa57446690d","lessThan":"04599570c3a18f9ae7aad36825eb46f3dcd2c4e3","versionType":"git","status":"affected"},{"version":"fd1483fe1f9fd45fe312adffb0faffa57446690d","lessThan":"9a416f000285a94c1b723877547981dec8132434","versionType":"git","status":"affected"},{"version":"fd1483fe1f9fd45fe312adffb0faffa57446690d","lessThan":"b1d6375b9a63c9dc7e5e780d3ea9b126fe30d6cb","versionType":"git","status":"affected"},{"version":"fd1483fe1f9fd45fe312adffb0faffa57446690d","lessThan":"80094352bd40ba54a33731f9c22872493983ed6d","versionType":"git","status":"affected"},{"version":"fd1483fe1f9fd45fe312adffb0faffa57446690d","lessThan":"4aafa600d93e9551c1f24e785d57cbd4adf021d5","versionType":"git","status":"affected"},{"version":"fd1483fe1f9fd45fe312adffb0faffa57446690d","lessThan":"af39eb111ce6b5eba9c08513b62c4868eb7e7fd5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/diag/fw_tracer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"references":[{"url":"https://git.kernel.org/stable/c/04599570c3a18f9ae7aad36825eb46f3dcd2c4e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/47fe0d2571e5b446a0f0b0c1d6b99f55e51f5cc0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4aafa600d93e9551c1f24e785d57cbd4adf021d5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/80094352bd40ba54a33731f9c22872493983ed6d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9a416f000285a94c1b723877547981dec8132434","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af39eb111ce6b5eba9c08513b62c4868eb7e7fd5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b1d6375b9a63c9dc7e5e780d3ea9b126fe30d6cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ee41ea49c4ab0e4015919f52ad23ec251d3b39d3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74718","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:46.710","lastModified":"2026-08-22T16:16:46.710","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndevlink: fix net namespace reference leak in reload\n\ndevlink_nl_reload_doit() calls devlink_netns_get(), which returns a net\nwith a held reference. When the requested namespace differs from the\ncurrent one and the reload action is not DRIVER_REINIT, the function\nreturns -EOPNOTSUPP without releasing the reference. Add the missing\nput_net() on this error path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/devlink/dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2edd92570441dd33246210042dc167319a5cf7e3","lessThan":"7b6552e53426ea0539c667bbc5a524fdf7feae6f","versionType":"git","status":"affected"},{"version":"2edd92570441dd33246210042dc167319a5cf7e3","lessThan":"bf0797b92be591ac71d7c0f610e695caca3c72c9","versionType":"git","status":"affected"},{"version":"2edd92570441dd33246210042dc167319a5cf7e3","lessThan":"7b02c6d2a3cd2cd669f5c16685779f84328ae60c","versionType":"git","status":"affected"},{"version":"2edd92570441dd33246210042dc167319a5cf7e3","lessThan":"eda60c85b4f4c7d66b7141a5fe020b1a7f395341","versionType":"git","status":"affected"},{"version":"2edd92570441dd33246210042dc167319a5cf7e3","lessThan":"1c4dac9bf1d2ac31da63b794bdec697777cbd0fd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/devlink/dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.3","status":"affected"},{"version":"0","lessThan":"6.3","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1c4dac9bf1d2ac31da63b794bdec697777cbd0fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7b02c6d2a3cd2cd669f5c16685779f84328ae60c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7b6552e53426ea0539c667bbc5a524fdf7feae6f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf0797b92be591ac71d7c0f610e695caca3c72c9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eda60c85b4f4c7d66b7141a5fe020b1a7f395341","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74719","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:46.830","lastModified":"2026-08-22T16:16:46.830","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler()\n\nThe SMC_LLC_CONFIRM_LINK / SMC_LLC_ADD_LINK_CONT branch in\nsmc_llc_event_handler() stores an incoming qentry into the local LLC flow\nwithout first checking whether a qentry is already pending. If a malicious or\nbuggy peer sends a second CONFIRM_LINK or ADD_LINK_CONT request while a flow is\nactive and flow->qentry is already set, smc_llc_flow_qentry_set() overwrites the\npointer without freeing the previous allocation, leaking one kmalloc-96 object\nper spurious message.\n\nThe sibling SMC_LLC_DELETE_LINK branch already has the correct !flow->qentry\nguard. Apply the same guard to the CONFIRM_LINK/ADD_LINK_CONT branch so that a\nduplicate message when qentry is already occupied falls through to break and is\nfreed by the kfree(qentry) at the out: label, rather than silently leaking the\nexisting allocation.\n\nThe response direction (smc_llc_rx_response()) is unaffected: it already guards\nwith flow->qentry at the equivalent site and drops duplicate responses\ncorrectly."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/smc/smc_llc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0fb0b02bd6fd26cba38002be4a6bbcae2228fd44","lessThan":"e384f3cba6ea709f5b2272b1770db4ce14047f78","versionType":"git","status":"affected"},{"version":"0fb0b02bd6fd26cba38002be4a6bbcae2228fd44","lessThan":"a1e980d7a9e7ee6faf4f5fd7b450413b969af26d","versionType":"git","status":"affected"},{"version":"0fb0b02bd6fd26cba38002be4a6bbcae2228fd44","lessThan":"e0eb87677c76b157cdf8eb7c1f19e56227165a33","versionType":"git","status":"affected"},{"version":"0fb0b02bd6fd26cba38002be4a6bbcae2228fd44","lessThan":"06734dfeaeba886aab1bf147249195b888ac3e4d","versionType":"git","status":"affected"},{"version":"0fb0b02bd6fd26cba38002be4a6bbcae2228fd44","lessThan":"c23c409228629107203d3c3e95fff1473173f1a6","versionType":"git","status":"affected"},{"version":"0fb0b02bd6fd26cba38002be4a6bbcae2228fd44","lessThan":"10cb31b2b74cb664c6c95cf72364d7d5c483ab82","versionType":"git","status":"affected"},{"version":"0fb0b02bd6fd26cba38002be4a6bbcae2228fd44","lessThan":"bfc336a9fbbf09805f3dfe25c195a4db90af2846","versionType":"git","status":"affected"},{"version":"0fb0b02bd6fd26cba38002be4a6bbcae2228fd44","lessThan":"976245094925bab9bc39366b2e9ab44ffcde61d0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/smc/smc_llc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.8","status":"affected"},{"version":"0","lessThan":"5.8","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/06734dfeaeba886aab1bf147249195b888ac3e4d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/10cb31b2b74cb664c6c95cf72364d7d5c483ab82","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/976245094925bab9bc39366b2e9ab44ffcde61d0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a1e980d7a9e7ee6faf4f5fd7b450413b969af26d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bfc336a9fbbf09805f3dfe25c195a4db90af2846","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c23c409228629107203d3c3e95fff1473173f1a6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e0eb87677c76b157cdf8eb7c1f19e56227165a33","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e384f3cba6ea709f5b2272b1770db4ce14047f78","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74720","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:46.957","lastModified":"2026-08-25T06:18:57.637","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Preserve pointer state for commuted arithmetic\n\nWhen scalar += pointer is handled in adjust_ptr_min_max_vals(), the\ndestination register inherits the pointer state from the source pointer.\nCopying only selected fields is fragile because pointer provenance is\ntracked by several bpf_reg_state fields.\n\nUse the caller's temporary offset register to preserve the scalar operand\nwhile replacing the destination with the full pointer state. This preserves\nthe frame number for PTR_TO_STACK registers and keeps parent identity\nfields consistent."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/verifier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f4d7e40a5b7157e1329c3c5b10f60d8289fc2941","lessThan":"86b203aadc2930e0a4f9c6277b5b80ff3664c472","versionType":"git","status":"affected"},{"version":"f4d7e40a5b7157e1329c3c5b10f60d8289fc2941","lessThan":"8109c25e0c41f5f19a1c2380bb49c991a877494e","versionType":"git","status":"affected"},{"version":"f4d7e40a5b7157e1329c3c5b10f60d8289fc2941","lessThan":"d1959028190a7649b926f5867a58de5fe221b23c","versionType":"git","status":"affected"},{"version":"f4d7e40a5b7157e1329c3c5b10f60d8289fc2941","lessThan":"8cb23101a3fcc7432b451ea3d0f14a90711f4acf","versionType":"git","status":"affected"},{"version":"f4d7e40a5b7157e1329c3c5b10f60d8289fc2941","lessThan":"29c239f8dbec5ab33a61796724d189bddee6cd4b","versionType":"git","status":"affected"},{"version":"f4d7e40a5b7157e1329c3c5b10f60d8289fc2941","lessThan":"db6382ed3361bdd8129572a3423956cba1dae829","versionType":"git","status":"affected"},{"version":"f4d7e40a5b7157e1329c3c5b10f60d8289fc2941","lessThan":"eaffa1495e4fe6330aeff9f323ea3d48b01f118a","versionType":"git","status":"affected"},{"version":"f4d7e40a5b7157e1329c3c5b10f60d8289fc2941","lessThan":"a4c6f804b44c5c790269b25e0e61cf4e9f117c86","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/verifier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.16","status":"affected"},{"version":"0","lessThan":"4.16","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/29c239f8dbec5ab33a61796724d189bddee6cd4b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8109c25e0c41f5f19a1c2380bb49c991a877494e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/86b203aadc2930e0a4f9c6277b5b80ff3664c472","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8cb23101a3fcc7432b451ea3d0f14a90711f4acf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4c6f804b44c5c790269b25e0e61cf4e9f117c86","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d1959028190a7649b926f5867a58de5fe221b23c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/db6382ed3361bdd8129572a3423956cba1dae829","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eaffa1495e4fe6330aeff9f323ea3d48b01f118a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74721","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:47.080","lastModified":"2026-08-25T06:18:57.913","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\naccel/amxdna: Fix page-insertion errors in amdxdna_insert_pages()\n\nTwo error paths in amdxdna_insert_pages() called vma->vm_ops->close(vma)\nbefore returning an error code to the caller.  This is incorrect:\namdxdna_gem_obj_mmap() registers an HMM interval notifier before calling\namdxdna_insert_pages(), and on a hard error it jumps to hmm_unreg to undo\nthat registration.  Calling vm_ops->close() manually — which drops the\nshmem pages_pin_count and the GEM object reference that backs the VMA —\nbefore the mmap syscall has even returned causes those resources to be\nreleased while the VMA is still alive.  The kernel VMA teardown will call\nvm_ops->close() a second time when the process later unmaps the range,\nproducing a reference count underflow.\n\nReplace both hard-error returns with a deferred-fault approach that keeps\nthe VMA alive and retries page insertion through the HMM range-fault path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/accel/amdxdna/amdxdna_gem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e486147c912f653ef4b60a6c7dbd4168a4c56a9f","lessThan":"1501e4d07c6fee0d50531a0d1cb2be01a63e6e75","versionType":"git","status":"affected"},{"version":"e486147c912f653ef4b60a6c7dbd4168a4c56a9f","lessThan":"8d51e0fd3e698919d2adeff71936377f0c0d4aa0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/accel/amdxdna/amdxdna_gem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/1501e4d07c6fee0d50531a0d1cb2be01a63e6e75","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8d51e0fd3e698919d2adeff71936377f0c0d4aa0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74722","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:47.183","lastModified":"2026-08-22T16:16:47.183","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix memory leak in btrfs_do_encoded_write()\n\nLocal fuzzing of 6.12.94 has found the following memory leak:\n\nUnreferenced object 0xffff888018050a80 (size 64):\n  comm \"syz.0.17\", pid 10297, jiffies 4294953601\n  hex dump (first 32 bytes):\n    00 10 00 00 00 00 00 00 01 00 00 00 00 00 00 00  ................\n    10 0a 05 18 80 88 ff ff 10 0a 05 18 80 88 ff ff  ................\n  backtrace (crc a8a6fc29):\n    kmemleak_alloc_recursive include/linux/kmemleak.h:42 [inline]\n    slab_post_alloc_hook mm/slub.c:4152 [inline]\n    slab_alloc_node mm/slub.c:4197 [inline]\n    __kmalloc_cache_noprof+0x168/0x2c0 mm/slub.c:4358\n    kmalloc_noprof include/linux/slab.h:878 [inline]\n    extent_changeset_alloc fs/btrfs/extent_io.h:207 [inline]\n    qgroup_reserve_data+0x1c5/0x7d0 fs/btrfs/qgroup.c:4305\n    btrfs_qgroup_reserve_data+0x2e/0xb0 fs/btrfs/qgroup.c:4355\n    btrfs_do_encoded_write+0x92e/0x1040 fs/btrfs/inode.c:9746\n    btrfs_encoded_write fs/btrfs/file.c:1482 [inline]\n    btrfs_do_write_iter+0x280/0x610 fs/btrfs/file.c:1507\n    btrfs_ioctl_encoded_write+0x3d6/0x490 fs/btrfs/ioctl.c:4738\n    btrfs_ioctl+0x6f9/0xc90 fs/btrfs/ioctl.c:-1\n    vfs_ioctl fs/ioctl.c:51 [inline]\n    __do_sys_ioctl fs/ioctl.c:906 [inline]\n    __se_sys_ioctl+0xf9/0x170 fs/ioctl.c:892\n    do_syscall_x64 arch/x86/entry/common.c:47 [inline]\n    do_syscall_64+0xbe/0x1a0 arch/x86/entry/common.c:78\n    entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nUnreferenced object 0xffff888018050a00 (size 64):\n  comm \"syz.0.17\", pid 10297, jiffies 4294953601\n  hex dump (first 32 bytes):\n    00 00 00 00 00 00 00 00 ff 0f 00 00 00 00 00 00  ................\n    90 0a 05 18 80 88 ff ff 90 0a 05 18 80 88 ff ff  ................\n  backtrace (crc cb5c9580):\n    kmemleak_alloc_recursive include/linux/kmemleak.h:42 [inline]\n    slab_post_alloc_hook mm/slub.c:4152 [inline]\n    slab_alloc_node mm/slub.c:4197 [inline]\n    __kmalloc_cache_noprof+0x168/0x2c0 mm/slub.c:4358\n    kmalloc_noprof include/linux/slab.h:878 [inline]\n    kzalloc_noprof include/linux/slab.h:1014 [inline]\n    ulist_prealloc+0x9c/0x110 fs/btrfs/ulist.c:114\n    extent_changeset_prealloc fs/btrfs/extent_io.h:217 [inline]\n    __set_extent_bit+0x16b/0x1a70 fs/btrfs/extent-io-tree.c:1086\n    set_record_extent_bits+0x50/0x90 fs/btrfs/extent-io-tree.c:1821\n    qgroup_reserve_data+0x274/0x7d0 fs/btrfs/qgroup.c:4312\n    btrfs_qgroup_reserve_data+0x2e/0xb0 fs/btrfs/qgroup.c:4355\n    btrfs_do_encoded_write+0x92e/0x1040 fs/btrfs/inode.c:9746\n    btrfs_encoded_write fs/btrfs/file.c:1482 [inline]\n    btrfs_do_write_iter+0x280/0x610 fs/btrfs/file.c:1507\n    btrfs_ioctl_encoded_write+0x3d6/0x490 fs/btrfs/ioctl.c:4738\n    btrfs_ioctl+0x6f9/0xc90 fs/btrfs/ioctl.c:-1\n    vfs_ioctl fs/ioctl.c:51 [inline]\n    __do_sys_ioctl fs/ioctl.c:906 [inline]\n    __se_sys_ioctl+0xf9/0x170 fs/ioctl.c:892\n    do_syscall_x64 arch/x86/entry/common.c:47 [inline]\n    do_syscall_64+0xbe/0x1a0 arch/x86/entry/common.c:78\n    entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFix this by freeing an extent changeset before returning from\nbtrfs_do_encoded_write()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/btrfs/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22","lessThan":"0f0da96ccb1b9f35f4d3d4540dcaab0969d9d6b0","versionType":"git","status":"affected"},{"version":"7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22","lessThan":"e2c7e88815edd5ecfb88e7660ab9fd42bda6bc47","versionType":"git","status":"affected"},{"version":"7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22","lessThan":"20c0eeb4313f9f89d47b80b672b5846f9827cb31","versionType":"git","status":"affected"},{"version":"7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22","lessThan":"24a8f2c29aebb753ccb962fbb25bae18d7978f6e","versionType":"git","status":"affected"},{"version":"7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22","lessThan":"60b50ceba6243802f8d2c0a9a7c2d549a93b1d64","versionType":"git","status":"affected"},{"version":"7c0c7269f7b508ba6e4b063a9314d6bd1fb6db22","lessThan":"d2a4e4e626b2f4670b69b430c357f03f53eb6632","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/btrfs/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0f0da96ccb1b9f35f4d3d4540dcaab0969d9d6b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/20c0eeb4313f9f89d47b80b672b5846f9827cb31","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/24a8f2c29aebb753ccb962fbb25bae18d7978f6e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/60b50ceba6243802f8d2c0a9a7c2d549a93b1d64","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2a4e4e626b2f4670b69b430c357f03f53eb6632","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2c7e88815edd5ecfb88e7660ab9fd42bda6bc47","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74723","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:47.323","lastModified":"2026-08-25T06:18:58.147","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: lzo: reject inline extents without valid headers\n\n[BUG]\nFor a crafted btrfs image, the following KASAN can be triggered when\nreading an inline lzo compressed file extent:\n\n  BUG: KASAN: slab-out-of-bounds in lzo_decompress+0x57d/0x700\n  Read of size 4 at addr ffff888006f2e644 by task btrfs_lzo_inlin/77\n\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0x5b/0x70\n   print_report+0xd1/0x610\n   kasan_report+0xe0/0x110\n   __asan_report_load_n_noabort+0x13/0x20\n   lzo_decompress+0x57d/0x700\n   btrfs_decompress+0x140/0x1c0\n   uncompress_inline+0x147/0x1b0\n   btrfs_get_extent+0xb23/0x10a0\n   btrfs_do_readpage.constprop.0+0x538/0x1ac0\n   btrfs_readahead+0x32f/0x5f0\n   read_pages+0x16f/0x850\n   page_cache_ra_unbounded+0x296/0x490\n   do_page_cache_ra+0xd9/0x130\n   page_cache_sync_ra+0x3ee/0x6f0\n   filemap_get_pages+0x306/0x15c0\n   filemap_read+0x329/0xd00\n   btrfs_file_read_iter+0x1f8/0x2b0\n   vfs_read+0x4ef/0x720\n   ksys_read+0xf8/0x1d0\n   __x64_sys_read+0x71/0xb0\n   x64_sys_call+0x1ab0/0x1b70\n   do_syscall_64+0x61/0x470\n   entry_SYSCALL_64_after_hwframe+0x4b/0x53\n   </TASK>\n\n[CAUSE]\nFor an inline lzo compressed file extent, there should always be one lzo\nheader, recording the total length of the compressed data, followed by\none segment header, recording the compressed lzo payload.\n\nBut if a crafted inline lzo compressed file extent contains only an lzo\nheader, without the segment header or payload, lzo_decompress() will\nstill try to read the segment header, causing a read beyond the item\nboundary.\n\nFurthermore if the inline lzo compressed file extent is the first item\nof the leaf, it will be at the extent buffer boundary. The above\nout-of-boundary read will go beyond the extent buffer boundary,\ntriggering the above KASAN report.\n\n[FIX]\nValidate the total length of the inlined lzo compressed file extent, to\nmake sure there is at least one LZO header and one segment header, and a\nnon-zero payload.\n\n[ Rework the commit message to remove slop ]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/btrfs/lzo.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a6fa6fae40ec336c7df6155255ae64ebef43a8bc","lessThan":"fc50b475ad27f50b4dcc98fc4c44e8802bc1b248","versionType":"git","status":"affected"},{"version":"a6fa6fae40ec336c7df6155255ae64ebef43a8bc","lessThan":"0fa78ef637deb5dbe341582f88553a4bce496de0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/btrfs/lzo.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.38","status":"affected"},{"version":"0","lessThan":"2.6.38","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/0fa78ef637deb5dbe341582f88553a4bce496de0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc50b475ad27f50b4dcc98fc4c44e8802bc1b248","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74724","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:47.450","lastModified":"2026-08-25T06:18:58.390","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: avoid out-of-bounds write in ip_vs_nat_icmp\n\nSashiko warns that local attacker can modify the packet\nwhile it is processed by IPVS. Some places read the\nIP ihl field multiple times which can cause out-of-bounds\naccess. One such place is ip_vs_nat_icmp where we\ncan write after the validated area.\n\nFix it by providing ciph argument just like it is done for\nIPv6 and use ciph->len as offset to the embedded transport\nheader.\n\nModify some IPv4 header checks by reading the ihl field\nonly once."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/ip_vs.h","net/netfilter/ipvs/ip_vs_core.c","net/netfilter/ipvs/ip_vs_xmit.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3b8f79af0e98f27b932b0b416e9c52b692d31ff9","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3c779b258c9c3c3567af68d4f45c2f751f35bd0e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"be65fa324640c7a95e30b146159a2be5cc73f22e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a69a4b3fff5814d079beff9a1e9d369994b2ed47","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"243d0187ec4c3837b9b0004f18d1068e46115760","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"646922a0379496154e8c8faca4f8e2fd9100cacc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/ip_vs.h","net/netfilter/ipvs/ip_vs_core.c","net/netfilter/ipvs/ip_vs_xmit.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/243d0187ec4c3837b9b0004f18d1068e46115760","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3b8f79af0e98f27b932b0b416e9c52b692d31ff9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3c779b258c9c3c3567af68d4f45c2f751f35bd0e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/646922a0379496154e8c8faca4f8e2fd9100cacc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a69a4b3fff5814d079beff9a1e9d369994b2ed47","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be65fa324640c7a95e30b146159a2be5cc73f22e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74725","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:47.567","lastModified":"2026-08-25T06:18:58.687","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nenic: fix tx_hang_reset use-after-free on device removal\n\nenic_remove() cancels the reset and change_mtu_work items but does not\ncancel tx_hang_reset. A TX timeout that fires while the device is being\nremoved can schedule enic_tx_hang_reset() so that it runs after\nfree_netdev(), resulting in a use-after-free.\n\ncancel_work_sync() alone is not sufficient here: the still-live watchdog\nand notify paths can re-schedule these work items in the window between\nthe cancel and unregister_netdev(). Use disable_work_sync(), which\ncancels the work and blocks any subsequent schedule_work() from\nrequeuing it, and apply it to the reset and change_mtu_work items as\nwell so the same requeue race is closed for all teardown work."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/cisco/enic/enic_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"937317c7c1097aa878a5000e3aab616eb5c590c0","lessThan":"8619865f34fb3b130b567855382a5c4aadd522b9","versionType":"git","status":"affected"},{"version":"937317c7c1097aa878a5000e3aab616eb5c590c0","lessThan":"e506e704b74748ffd0e1c92a7453ca2a959f832b","versionType":"git","status":"affected"},{"version":"937317c7c1097aa878a5000e3aab616eb5c590c0","lessThan":"4f3464fc6c1f26afc504fd525c574f2bc14c9d42","versionType":"git","status":"affected"},{"version":"937317c7c1097aa878a5000e3aab616eb5c590c0","lessThan":"ec680ea4ba1bca92a767fb7e7869758bfdd886e3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/cisco/enic/enic_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.4","status":"affected"},{"version":"0","lessThan":"4.4","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/4f3464fc6c1f26afc504fd525c574f2bc14c9d42","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8619865f34fb3b130b567855382a5c4aadd522b9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e506e704b74748ffd0e1c92a7453ca2a959f832b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ec680ea4ba1bca92a767fb7e7869758bfdd886e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74726","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:47.673","lastModified":"2026-08-25T06:18:58.980","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor\n\nbond_alb_monitor() reads primary_is_promisc under RCU, then drops RCU and\ntakes RTNL via rtnl_trylock() before undoing the promiscuity it set on the\nactive slave. In that window the active slave can change under RTNL\n(RTM_DELLINK -> __bond_release_one() -> bond_alb_handle_active_change()),\nwhich already drops the promiscuity and clears primary_is_promisc. The\nmonitor still acts on the stale decision: if the slave was removed with no\nfailover, curr_active_slave is now NULL and the deref faults; if it failed\nover, the stale dev_set_promiscuity(-1) underflows the new slave's\npromiscuity counter and pins it in IFF_PROMISC.\n\n  Oops: general protection fault, probably for non-canonical address ...\n  KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n  Workqueue: b42 bond_alb_monitor\n  RIP: 0010:bond_alb_monitor (drivers/net/bonding/bond_alb.c:1600)\n   process_one_work (kernel/workqueue.c:3322)\n   worker_thread (kernel/workqueue.c:3486)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n  Kernel panic - not syncing: Fatal exception\n\nRe-check primary_is_promisc (and curr_active_slave) after taking RTNL so\nthe monitor only undoes an increment it still owns. The other bonding\nmonitors already re-read state under RTNL in their commit phase\n(bond_miimon_commit/bond_ab_arp_commit); bond_alb_monitor() was the only\none acting on the pre-trylock decision."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/bonding/bond_alb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d0e81b7e2246a41d068ecaf15aac9de570816d63","lessThan":"f7668762bf5fd6db9397de5c0514407489d9d815","versionType":"git","status":"affected"},{"version":"d0e81b7e2246a41d068ecaf15aac9de570816d63","lessThan":"09add8d5cfa9c46828f51eaad162c36e86366b71","versionType":"git","status":"affected"},{"version":"d0e81b7e2246a41d068ecaf15aac9de570816d63","lessThan":"b82f51681a7a88c7d3c865e817a3340d42b5fa2a","versionType":"git","status":"affected"},{"version":"d0e81b7e2246a41d068ecaf15aac9de570816d63","lessThan":"dd148539fb4741d01c06b7d2c8bd84b01920756c","versionType":"git","status":"affected"},{"version":"d0e81b7e2246a41d068ecaf15aac9de570816d63","lessThan":"dccec0227ed8d9e36936d66e256b957dc2858468","versionType":"git","status":"affected"},{"version":"d0e81b7e2246a41d068ecaf15aac9de570816d63","lessThan":"2faf75a8a06504071b4c0aea7e45a9cc49a4e187","versionType":"git","status":"affected"},{"version":"d0e81b7e2246a41d068ecaf15aac9de570816d63","lessThan":"257c4a3a34d8f51efb00f35375a0c6ce3c8f6ce2","versionType":"git","status":"affected"},{"version":"d0e81b7e2246a41d068ecaf15aac9de570816d63","lessThan":"683c6ba6e58e6ed1037831ea97dd58d9c0e76b8d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/bonding/bond_alb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.24","status":"affected"},{"version":"0","lessThan":"2.6.24","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.5}]},"references":[{"url":"https://git.kernel.org/stable/c/09add8d5cfa9c46828f51eaad162c36e86366b71","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/257c4a3a34d8f51efb00f35375a0c6ce3c8f6ce2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2faf75a8a06504071b4c0aea7e45a9cc49a4e187","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/683c6ba6e58e6ed1037831ea97dd58d9c0e76b8d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b82f51681a7a88c7d3c865e817a3340d42b5fa2a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dccec0227ed8d9e36936d66e256b957dc2858468","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd148539fb4741d01c06b7d2c8bd84b01920756c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7668762bf5fd6db9397de5c0514407489d9d815","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74727","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:47.813","lastModified":"2026-08-25T06:18:59.263","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\novpn: skip rehash for peers already removed from by_id\n\novpn_nl_peer_set_doit() resolves the target peer via\novpn_peer_get_by_id() before taking ovpn->lock. In the window between\nthe lookup (which only takes a refcount) and the subsequent\nspin_lock_bh(&ovpn->lock), a concurrent OVPN_CMD_PEER_DEL, keepalive\nexpiry, or socket teardown can take ovpn->lock first, run\novpn_peer_remove() to unhash the peer from all four tables (by_id,\nby_vpn_addr4/6, by_transp_addr) and release the lock. set_doit then\nacquires ovpn->lock and calls ovpn_peer_hash_vpn_ip(), which\nre-inserts the now-removed peer back into the rehashing tables.\n\nThe same race affects the float path: ovpn_peer_endpoints_update()\nholds only a refcount and acquires ovpn->lock very late (after async\nAEAD decrypt and a netlink notification), then rehashes the peer\nin the by_transp_addr table.\n\nThe resurrected peer becomes reachable again from the RX lookup\n(ovpn_peer_get_by_transp_addr) and the TX VPN-IP lookup, even though\nuserspace believes it is gone. Once the data-path refcount drops the\npeer is freed via call_rcu while the hash entries embedded in it\nremain linked, opening a UAF window.\n\nBail out of the rehash when hash_entry_id is unhashed, mirroring\nthe sentinel already used by ovpn_peer_remove() to detect the\nalready-removed state. The check is safe under ovpn->lock, which\nserializes every mutation of hash_entry_id, and is a no-op for the\nadd path because ovpn_peer_add_mp() inserts hash_entry_id before\ncalling ovpn_peer_hash_vpn_ip()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ovpn/peer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1d36a36f6d5347360ef9681a05f6166683bafd1d","lessThan":"d20c181088984b6eaa8d7fe7cb5ab3510988df59","versionType":"git","status":"affected"},{"version":"1d36a36f6d5347360ef9681a05f6166683bafd1d","lessThan":"66745480298775f188b2f5ad266643e85a90f73b","versionType":"git","status":"affected"},{"version":"1d36a36f6d5347360ef9681a05f6166683bafd1d","lessThan":"33ec10567fe14456063daf549fdf1a4f53448e4c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ovpn/peer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/33ec10567fe14456063daf549fdf1a4f53448e4c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/66745480298775f188b2f5ad266643e85a90f73b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d20c181088984b6eaa8d7fe7cb5ab3510988df59","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74728","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:47.930","lastModified":"2026-08-22T16:16:47.930","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: handle NULL b_addr in xfs_buf_free\n\nWhen xfs_buf_alloc_backing_mem() fails, xfs_buf_free() is called with\nbp->b_addr still NULL.  The code falls through to the folio_put path\nwhich calls virt_to_folio(NULL), dereferencing an invalid address and\ncausing a kernel crash.\n\n Call Trace:\n  xfs_buf_free+0x25f/0x510\n  xfs_buf_alloc+0xc98/0x19b0\n  xfs_buf_find_insert+0x55/0x14d0\n  xfs_buf_get_map+0x122b/0x17c0\n  xfbtree_init_leaf_block+0x11c/0x4a0\n  xfbtree_init+0x1bb/0x460\n  xrep_rmap_setup_scan+0x100/0x1f0\n  xrep_rmapbt+0x41/0xc0\n\nFix this by skipping folio_put() when bp->b_addr is NULL."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/xfs/xfs_buf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5076a6040ca1613e616d84aecfaac5f932db84e0","lessThan":"ccf6738adcafa5ddbddc4e71b45d8a51b86643c7","versionType":"git","status":"affected"},{"version":"5076a6040ca1613e616d84aecfaac5f932db84e0","lessThan":"3aa0c1d23ee1b9d9b340fb2f4736536e1408d706","versionType":"git","status":"affected"},{"version":"5076a6040ca1613e616d84aecfaac5f932db84e0","lessThan":"d852729c5f4f830fbe7413df032e29459b3daf83","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/xfs/xfs_buf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3aa0c1d23ee1b9d9b340fb2f4736536e1408d706","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ccf6738adcafa5ddbddc4e71b45d8a51b86643c7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d852729c5f4f830fbe7413df032e29459b3daf83","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74729","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:48.033","lastModified":"2026-08-22T16:16:48.033","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read\n\nput_fifo_with_discard() acts as both producer and consumer on the kfifo:\nit calls kfifo_skip() (advances out) and kfifo_put() (advances in) from\nthe IRQ handler without synchronizing with snoop_file_read(), which also\nconsumes via kfifo_to_user(). On SMP systems this concurrent access can\nleave (in - out) larger than the ring buffer, so __kfifo_to_user()'s clamp\nto (in - out) is ineffective and kfifo_copy_to_user() can attempt a\ncopy_to_user() past the kmalloc-2k backing store:\n\n  usercopy: Kernel memory exposure attempt detected from SLUB object\n  'kmalloc-2k' (offset 0, size 2049)!\n  kernel BUG at mm/usercopy.c!\n  Call trace:\n   usercopy_abort\n   __check_heap_object\n   __check_object_size\n   kfifo_copy_to_user\n   __kfifo_to_user\n   snoop_file_read\n   vfs_read\n\nSerialize kfifo access with a per-channel spinlock shared between the\nIRQ handler (producer) and the file reader (consumer).  Annotate @fifo\nwith __guarded_by(&lock) and opt the driver into context analysis so the\ncompiler enforces that all fifo access holds the lock."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/soc/aspeed/Makefile","drivers/soc/aspeed/aspeed-lpc-snoop.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3772e5da445420543b25825ac2b5971f3743f6e8","lessThan":"131ab677b03349a5ae48da8722ec7075b37ec66e","versionType":"git","status":"affected"},{"version":"3772e5da445420543b25825ac2b5971f3743f6e8","lessThan":"1acef6d85bfd98bd9dfe1f08bffa397a4dda8a6f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/soc/aspeed/Makefile","drivers/soc/aspeed/aspeed-lpc-snoop.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.19","status":"affected"},{"version":"0","lessThan":"4.19","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/131ab677b03349a5ae48da8722ec7075b37ec66e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1acef6d85bfd98bd9dfe1f08bffa397a4dda8a6f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74730","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:48.137","lastModified":"2026-08-25T06:18:59.463","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: Pin the 'struct nfs_server' during a FREE_STATEID call\n\nDan Aloni reports that he was able to hit a use-after-free bug if a\nFREE_STATEID operation gets delayed for whatever reason. Fix this by\nbumping the refcount of the 'struct nfs_server' object for the duration\nof the FREE_STATEID so it doesn't get cleaned up from underneath us\nwhile operations are still in flight."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/nfs/nfs4proc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009","lessThan":"ed2f92ce2fc48463c41e0e540b9a3454889e8af8","versionType":"git","status":"affected"},{"version":"7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009","lessThan":"d858ab09e787106432d4d9830bad9dfedf02f890","versionType":"git","status":"affected"},{"version":"7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009","lessThan":"af62f1af182d33a0de38308c012841885d8ab92e","versionType":"git","status":"affected"},{"version":"7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009","lessThan":"caee6a68ffaa5016dfc01cd0b3dc1896a32e3abd","versionType":"git","status":"affected"},{"version":"7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009","lessThan":"ed1161ab6239761958b38d5667225634fc2be894","versionType":"git","status":"affected"},{"version":"7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009","lessThan":"d71dfffa512e71b166a889484e4c3b148a9a3af2","versionType":"git","status":"affected"},{"version":"7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009","lessThan":"80ed3d762628b36c9e4b22fac7c65b72ef3b13dd","versionType":"git","status":"affected"},{"version":"7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009","lessThan":"cf616096a0f3a2b60f7d68b6b39674a6867ded9c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/nfs/nfs4proc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.10","status":"affected"},{"version":"0","lessThan":"3.10","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.152","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/80ed3d762628b36c9e4b22fac7c65b72ef3b13dd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af62f1af182d33a0de38308c012841885d8ab92e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/caee6a68ffaa5016dfc01cd0b3dc1896a32e3abd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf616096a0f3a2b60f7d68b6b39674a6867ded9c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d71dfffa512e71b166a889484e4c3b148a9a3af2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d858ab09e787106432d4d9830bad9dfedf02f890","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed1161ab6239761958b38d5667225634fc2be894","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed2f92ce2fc48463c41e0e540b9a3454889e8af8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74731","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:48.257","lastModified":"2026-08-25T06:18:59.753","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Skip sub-disable teardown for never-linked sub-schedulers\n\nA sub-scheduler enable can fail before scx_link_sched() links the sched into\nthe hierarchy, e.g. when the parent is already being disabled, and cleanup\nstill runs the full scx_sub_disable().\n\nThat is racy against root disable: drain_descendants() is the only ordering\nbetween a sub's disable-time task walk and root disable's all-task teardown,\nand an unlinked sub is invisible to it. Root's teardown can thus run between\nthe never-linked sub's drain and its walk, exiting every task to no\nscheduler.\n\nThe walk then trips the membership WARN and re-homes the exited tasks onto\nthe dying hierarchy, a use-after-free.\n\nSkip the cgroup ownership reset and the task walk if @sch was never linked,\nindicated by the empty ->sibling as unlinking only happens later in the same\nfunction. The membership WARN remains valid: a linked sub is always waited\non by an ancestor's drain."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/sched/ext/ext.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"337ec00b1d9c676f637651c2cefddb8612b867ee","lessThan":"6428093a4a986c38c9089b5eb32b56d914ef437a","versionType":"git","status":"affected"},{"version":"337ec00b1d9c676f637651c2cefddb8612b867ee","lessThan":"8c13364db9c9a43ed286f3a8d0fb9477b1adc43c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/sched/ext/ext.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/6428093a4a986c38c9089b5eb32b56d914ef437a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8c13364db9c9a43ed286f3a8d0fb9477b1adc43c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74732","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:48.360","lastModified":"2026-08-22T16:16:48.360","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check for tg ops in dce110_set_avmute\n\nSome older DCE timing generators do not implement is_tg_enabled in\ntheir ops table. Calling it unconditionally when waiting for AV mute\nframes causes a NULL pointer dereference on Southern Islands dGPUs\nwhen turning the display off over HDMI.\n\nCheck that tg and the required ops exist before waiting for frames.\n\n(cherry picked from commit 2686a0c0aaa07bec2e24131835cf27b5fd4935a5)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/amd/display/dc/hwss/dce110/dce110_hwseq.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"853c2d31408bd45dcf92d0eb1f06eb439a56cf04","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d089f32d34f821c8f0ef23d5fcd77bd43c1b3b92","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5edbb409b0bc5001195f4b7cfca19122361211a1","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3141e3d61469bba2624a91c5e2407f110b33b29e","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.12.104","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.45","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.9","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/amd/display/dc/hwss/dce110/dce110_hwseq.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12.104","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.45","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3141e3d61469bba2624a91c5e2407f110b33b29e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5edbb409b0bc5001195f4b7cfca19122361211a1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/853c2d31408bd45dcf92d0eb1f06eb439a56cf04","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d089f32d34f821c8f0ef23d5fcd77bd43c1b3b92","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-74733","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-22T16:16:48.463","lastModified":"2026-08-25T06:18:59.963","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock\n\nLocking is disabled in the regmap config as this driver uses its own\nlock. This means that all calls to regmap functions (read or write) must\nhold the i2c_lock. The function pca953x_irq_bus_sync_unlock() did not do\nthis, and it was therefore possible that multiple threads could cause an\nincorrect register to be read/written.\n\nA previous patch partly fixed this, but only protected the write to the\ninterrupt mask register, and not the read from the direction register."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpio/gpio-pca953x.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bfc6444b57dc7186b6acc964705d7516cbaf3904","lessThan":"e6a2f5f845f50b0c4299bace5111f56d3390a090","versionType":"git","status":"affected"},{"version":"bfc6444b57dc7186b6acc964705d7516cbaf3904","lessThan":"9dc325327babe7f159e84cbe9380a45342da0585","versionType":"git","status":"affected"},{"version":"58a5c93bd1a6e949267400080f07e57ffe05ec34","versionType":"git","status":"affected"},{"version":"e2ecdddca80dd845df42376e4b0197fe97018ba2","versionType":"git","status":"affected"},{"version":"de7cffa53149c7b48bd1bb29b02390c9f05b7f41","versionType":"git","status":"affected"},{"version":"6.1.101","lessThan":"6.2","versionType":"semver","status":"affected"},{"version":"6.6.42","lessThan":"6.7","versionType":"semver","status":"affected"},{"version":"6.9.11","lessThan":"6.10","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpio/gpio-pca953x.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","versionType":"semver","status":"unaffected"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/9dc325327babe7f159e84cbe9380a45342da0585","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e6a2f5f845f50b0c4299bace5111f56d3390a090","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-12999","sourceIdentifier":"vulnerabilities@zephyrproject.org","published":"2026-08-22T21:16:48.747","lastModified":"2026-08-26T16:59:23.267","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"The Infineon Airoc Wi-Fi driver's transmit callback airoc_mgmt_send() in drivers/wifi/infineon/airoc_wifi.c allocates a net_buf from the fixed airoc_pool for every outbound packet. When whd_network_send_ethernet_data() returns a synchronous failure, the underlying WHD library does not take ownership of the buffer, but the pre-fix driver returned -EIO without releasing it. Each failed transmit therefore permanently leaks one buffer from the pool.\n\nairoc_pool is small and fixed (AIROC_WIFI_TX_PACKET_POOL_COUNT + AIROC_WIFI_RX_PACKET_POOL_COUNT, default 20 buffers) and is shared by WHD's whd_host_buffer_get callback for both transmit and receive. Once enough send failures have leaked the pool dry, airoc_wifi_host_buffer_get() returns WHD_BUFFER_ALLOC_FAIL for all subsequent allocations, so both transmit and the WHD-driven receive path fail and Wi-Fi connectivity is lost until the device is rebooted.\n\nThe leak occurs only on the transmit error path. A Wi-Fi-adjacent attacker can influence the conditions that cause synchronous send failures (for example by deauthenticating/disassociating the station while the local stack continues to attempt transmits), and ordinary transient failures over the device's lifetime accumulate toward the same state. Reliable on-demand triggering is of high complexity and the impact is availability-only, but the resulting denial of service is permanent and non-recoverable without a reboot.\n\nThe fix releases the buffer with airoc_wifi_buffer_release() on the failure branch, returning it to the pool. The commit also removes a redundant k_sem_give() in airoc_mgmt_disconnect(); because data->sema_common is a binary semaphore (limit 1) the duplicate give merely saturated at 1 and had no security impact."}],"affected":[{"source":"vulnerabilities@zephyrproject.org","affectedData":[{"vendor":"zephyrproject","product":"zephyr","defaultStatus":"unaffected","collectionURL":"https://github.com/zephyrproject-rtos/zephyr","packageName":"zephyr","programFiles":["drivers/wifi/infineon/airoc_wifi.c"],"versions":[{"version":"3.6.0","lessThan":"4.4.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"vulnerabilities@zephyrproject.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-25T19:07:13.318585Z","id":"CVE-2026-12999","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"vulnerabilities@zephyrproject.org","type":"Secondary","description":[{"lang":"en","value":"CWE-401"}]}],"references":[{"url":"https://github.com/zephyrproject-rtos/zephyr/commit/4e6f624292ed153a762e98c7a297998c8d0b52c4","source":"vulnerabilities@zephyrproject.org"},{"url":"https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-8w97-ghfm-5wjp","source":"vulnerabilities@zephyrproject.org"}]}},{"cve":{"id":"CVE-2026-47895","sourceIdentifier":"cve@mitre.org","published":"2026-08-22T22:16:28.153","lastModified":"2026-08-24T14:16:55.217","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"strongSwan","product":"strongSwan","defaultStatus":"unaffected","versions":[{"version":"4.3.3","lessThan":"6.0.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-24T12:43:42.540667Z","id":"CVE-2026-47895","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@mitre.org","type":"Secondary","description":[{"lang":"en","value":"CWE-415"}]}],"references":[{"url":"https://github.com/strongswan/strongswan/releases/tag/6.0.7","source":"cve@mitre.org"},{"url":"https://www.strongswan.org/download.html","source":"cve@mitre.org"}]}}]}