{"resultsPerPage":520,"startIndex":0,"totalResults":520,"format":"NVD_CVE","version":"2.0","timestamp":"2026-07-26T13:40:02.134","vulnerabilities":[{"cve":{"id":"CVE-2025-9577","sourceIdentifier":"cna@vuldb.com","published":"2025-08-28T19:15:34.880","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the file /etc/shadow.sample of the component Administrative Interface. The manipulation results in use of default credentials. Attacking locally is a requirement. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit has been released to the public and may be exploited."},{"lang":"es","value":"Se ha descubierto una falla de seguridad en TOTOLINK X2000R hasta la versión 2.0.0. El elemento afectado es una función desconocida del archivo /etc/sha4dow.sample del componente Interfaz Administrativa. La manipulación resulta en el uso de credenciales predeterminadas. Atacar localmente es un requisito. Los ataques de esta naturaleza son altamente complejos. La explotabilidad se describe como difícil. El exploit ha sido publicado y puede ser explotado."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"TOTOLINK","product":"X2000R","modules":["Administrative Interface"],"versions":[{"version":"2.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":1.1,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":2.5,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.0,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.0,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.0,"impactScore":5.9}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:H/Au:S/C:P/I:N/A:N","baseScore":1.0,"accessVector":"LOCAL","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":1.5,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-28T18:41:00.764851Z","id":"CVE-2025-9577","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1392"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:totolink:x2000r_firmware:2.0.0-b20230727.1043.web:*:*:*:*:*:*:*","matchCriteriaId":"79A3F735-30B4-44DF-98B5-5DDB3ABEA61D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:totolink:x2000r:-:*:*:*:*:*:*:*","matchCriteriaId":"299F34FB-4D53-4846-B6F0-4431D61B5154"}]}]}],"references":[{"url":"https://github.com/XXRicardo/iot-cve/blob/main/TOLOLINK/X2000R-Gh-V2.0.0.md","source":"cna@vuldb.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/XXRicardo/iot-cve/blob/main/TOLOLINK/X2000R-Gh-V2.0.0.md#steps-to-reproduce","source":"cna@vuldb.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://vuldb.com/?ctiid.321691","source":"cna@vuldb.com","tags":["Permissions Required","VDB Entry"]},{"url":"https://vuldb.com/?id.321691","source":"cna@vuldb.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://vuldb.com/?submit.636069","source":"cna@vuldb.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://www.totolink.net/","source":"cna@vuldb.com","tags":["Product"]},{"url":"https://github.com/XXRicardo/iot-cve/blob/main/TOLOLINK/X2000R-Gh-V2.0.0.md","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/XXRicardo/iot-cve/blob/main/TOLOLINK/X2000R-Gh-V2.0.0.md#steps-to-reproduce","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2025-15098","sourceIdentifier":"cna@vuldb.com","published":"2025-12-26T03:15:50.460","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was determined in YunaiV yudao-cloud up to 2025.11. This affects the function BpmHttpCallbackTrigger/BpmSyncHttpRequestTrigger of the component Business Process Management. Executing manipulation of the argument url/header/body can lead to server-side request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way."},{"lang":"es","value":"Una vulnerabilidad fue determinada en YunaiV yudao-cloud hasta 2025.11. Esto afecta la función BpmHttpCallbackTrigger/BpmSyncHttpRequestTrigger del componente Gestión de Procesos de Negocio. La ejecución de la manipulación del argumento url/header/body puede llevar a falsificación de petición del lado del servidor. El ataque puede ser realizado de forma remota. El exploit ha sido divulgado públicamente y puede ser utilizado. El proveedor fue contactado tempranamente sobre esta divulgación, pero no respondió de ninguna manera."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"YunaiV","product":"yudao-cloud","modules":["Business Process Management"],"versions":[{"version":"2025.0","status":"affected"},{"version":"2025.1","status":"affected"},{"version":"2025.2","status":"affected"},{"version":"2025.3","status":"affected"},{"version":"2025.4","status":"affected"},{"version":"2025.5","status":"affected"},{"version":"2025.6","status":"affected"},{"version":"2025.7","status":"affected"},{"version":"2025.8","status":"affected"},{"version":"2025.9","status":"affected"},{"version":"2025.10","status":"affected"},{"version":"2025.11","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":3.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-26T19:29:24.006123Z","id":"CVE-2025-15098","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/AnalogyC0de/public_exp/blob/main/archives/yudao-cloud-bpm_SSRF/report.md","source":"cna@vuldb.com"},{"url":"https://github.com/AnalogyC0de/public_exp/blob/main/archives/yudao-cloud-bpm_SSRF/report.md#proof-of-concept","source":"cna@vuldb.com"},{"url":"https://vuldb.com/?ctiid.338429","source":"cna@vuldb.com"},{"url":"https://vuldb.com/?id.338429","source":"cna@vuldb.com"},{"url":"https://vuldb.com/?submit.710170","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2025-15437","sourceIdentifier":"cna@vuldb.com","published":"2026-01-02T09:15:42.453","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variable Handler. Performing a manipulation of the argument REQUEST_URI results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used. Upgrading to version 6.1.26 and 6.3 is able to mitigate this issue. The patch is named 264ac5b2be5b3c673ebd8cb862e673f5d300d9a7. The affected component should be upgraded."},{"lang":"es","value":"Una vulnerabilidad fue encontrada en LigeroSmart hasta 6.1.24. Esto afecta una parte desconocida del componente Environment Variable Handler. Realizar la manipulación del argumento REQUEST_URI resulta en cross site scripting. El ataque puede ser iniciado remotamente. El exploit ha sido hecho público y podría ser usado. Actualizar a la versión 6.1.26 y 6.3 es capaz de mitigar este problema. El parche se llama 264ac5b2be5b3c673ebd8cb862e673f5d300d9a7. El componente afectado debería ser actualizado."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"n/a","product":"LigeroSmart","modules":["Environment Variable Handler"],"versions":[{"version":"6.1.0","status":"affected"},{"version":"6.1.1","status":"affected"},{"version":"6.1.2","status":"affected"},{"version":"6.1.3","status":"affected"},{"version":"6.1.4","status":"affected"},{"version":"6.1.5","status":"affected"},{"version":"6.1.6","status":"affected"},{"version":"6.1.7","status":"affected"},{"version":"6.1.8","status":"affected"},{"version":"6.1.9","status":"affected"},{"version":"6.1.10","status":"affected"},{"version":"6.1.11","status":"affected"},{"version":"6.1.12","status":"affected"},{"version":"6.1.13","status":"affected"},{"version":"6.1.14","status":"affected"},{"version":"6.1.15","status":"affected"},{"version":"6.1.16","status":"affected"},{"version":"6.1.17","status":"affected"},{"version":"6.1.18","status":"affected"},{"version":"6.1.19","status":"affected"},{"version":"6.1.20","status":"affected"},{"version":"6.1.21","status":"affected"},{"version":"6.1.22","status":"affected"},{"version":"6.1.23","status":"affected"},{"version":"6.1.24","status":"affected"},{"version":"6.1.26","status":"unaffected"},{"version":"6.3","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.0,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-06T20:15:05.351675Z","id":"CVE-2025-15437","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"},{"lang":"en","value":"CWE-94"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ligerosmart:ligerosmart:*:*:*:*:*:*:*:*","versionEndIncluding":"6.1.24","matchCriteriaId":"B77D3C25-59EA-487F-A514-AB4279A163BC"}]}]}],"references":[{"url":"https://github.com/LigeroSmart/ligerosmart/","source":"cna@vuldb.com","tags":["Product"]},{"url":"https://github.com/LigeroSmart/ligerosmart/commit/264ac5b2be5b3c673ebd8cb862e673f5d300d9a7","source":"cna@vuldb.com","tags":["Patch"]},{"url":"https://github.com/LigeroSmart/ligerosmart/issues/278","source":"cna@vuldb.com","tags":["Issue Tracking"]},{"url":"https://github.com/LigeroSmart/ligerosmart/issues/278#issuecomment-3675129508","source":"cna@vuldb.com","tags":["Exploit","Issue Tracking"]},{"url":"https://github.com/LigeroSmart/ligerosmart/releases/tag/6.1.26","source":"cna@vuldb.com","tags":["Release Notes"]},{"url":"https://vuldb.com/?ctiid.339364","source":"cna@vuldb.com","tags":["Permissions Required","VDB Entry"]},{"url":"https://vuldb.com/?id.339364","source":"cna@vuldb.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://vuldb.com/?submit.729021","source":"cna@vuldb.com","tags":["Third Party Advisory","VDB Entry"]}]}},{"cve":{"id":"CVE-2025-62842","sourceIdentifier":"security@qnapsecurity.com.tw","published":"2026-01-02T16:17:00.710","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read or modify files or directories.\n\nWe have already fixed the vulnerability in the following version:\nHBS 3 Hybrid Backup Sync 26.2.0.938 and later"},{"lang":"es","value":"Se ha informado de una vulnerabilidad de control externo de nombre o ruta de archivo que afecta a HBS 3 Hybrid Backup Sync. Si un atacante obtiene acceso a la red local, puede entonces explotar la vulnerabilidad para leer o modificar archivos o directorios.\n\nYa hemos corregido la vulnerabilidad en la siguiente versión:\nHBS 3 Hybrid Backup Sync 26.2.0.938 y posteriores"}],"affected":[{"source":"security@qnapsecurity.com.tw","affectedData":[{"vendor":"QNAP Systems Inc.","product":"HBS 3 Hybrid Backup Sync","defaultStatus":"unaffected","versions":[{"version":"26.1.x","lessThan":"26.2.0.938","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@qnapsecurity.com.tw","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.0,"baseSeverity":"HIGH","attackVector":"PHYSICAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-05T20:31:31.402444Z","id":"CVE-2025-62842","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@qnapsecurity.com.tw","type":"Secondary","description":[{"lang":"en","value":"CWE-73"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:qnap:hybrid_backup_sync:*:*:*:*:*:*:*:*","versionEndExcluding":"26.2.0.938","matchCriteriaId":"EBAF4E08-08BE-4F0C-ABA3-B0F73AB66E76"}]}]}],"references":[{"url":"https://www.qnap.com/en/security-advisory/qsa-25-46","source":"security@qnapsecurity.com.tw","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2024-14030","sourceIdentifier":"9b29abf9-4ab0-4765-b253-1875cd9b441e","published":"2026-03-31T12:16:26.153","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Sereal::Decoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library.\n\nSereal::Decoder embeds a version of the Zstandard (zstd) library that is vulnerable to CVE-2019-11922.  This is a race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used."},{"lang":"es","value":"Las versiones de Sereal::Decoder de 4.000 a 4.009_002 para Perl son vulnerables a una falla de sobrescritura de búfer en la biblioteca Zstandard.\n\nSereal::Decoder incrusta una versión de la biblioteca Zstandard (zstd) que es vulnerable a CVE-2019-11922. Se trata de una condición de carrera en las funciones de compresión de una sola pasada de Zstandard anteriores a la versión 1.3.8 que podría permitir a un atacante escribir bytes fuera de los límites si se utilizara un búfer de salida más pequeño que el tamaño recomendado."}],"affected":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","affectedData":[{"vendor":"YVES","product":"Sereal::Decoder","defaultStatus":"unaffected","collectionURL":"https://cpan.org/modules","packageName":"Sereal-Decoder","repo":"https://github.com/Sereal/Sereal","versions":[{"version":"4.000","lessThanOrEqual":"4.009_002","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T14:18:18.323057Z","id":"CVE-2024-14030","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:yves:sereal\\:\\:decoder:*:*:*:*:*:perl:*:*","versionStartIncluding":"4.000","versionEndExcluding":"4.010","matchCriteriaId":"2A8D88D7-1129-4874-BDC7-5627BAB3CB74"}]}]}],"references":[{"url":"https://github.com/advisories/GHSA-w77f-wv46-4vcx","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","tags":["Not Applicable"]},{"url":"https://metacpan.org/release/YVES/Sereal-Decoder-4.010/changes","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","tags":["Release Notes"]},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-11922","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","tags":["Not Applicable"]}]}},{"cve":{"id":"CVE-2024-14031","sourceIdentifier":"9b29abf9-4ab0-4765-b253-1875cd9b441e","published":"2026-03-31T12:16:26.310","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Sereal::Encoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library.\n\nSereal::Encoder embeds a version of the Zstandard (zstd) library that is vulnerable to CVE-2019-11922.  This is a race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used."},{"lang":"es","value":"Las versiones de Sereal::Encoder de 4.000 a 4.009_002 para Perl son vulnerables a una falla de sobrescritura de búfer en la biblioteca Zstandard.\n\nSereal::Encoder incrusta una versión de la biblioteca Zstandard (zstd) que es vulnerable a CVE-2019-11922. Se trata de una condición de carrera en las funciones de compresión de una sola pasada de Zstandard anteriores a la versión 1.3.8 que podría permitir a un atacante escribir bytes fuera de los límites si se utilizara un búfer de salida más pequeño que el tamaño recomendado."}],"affected":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","affectedData":[{"vendor":"YVES","product":"Sereal::Encoder","defaultStatus":"unaffected","collectionURL":"https://cpan.org/modules","packageName":"Sereal-Encoder","repo":"https://github.com/Sereal/Sereal","versions":[{"version":"4.000","lessThanOrEqual":"4.009_002","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T14:19:21.141997Z","id":"CVE-2024-14031","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:yves:sereal\\:\\:encoder:*:*:*:*:*:perl:*:*","versionStartIncluding":"4.000","versionEndExcluding":"4.010","matchCriteriaId":"FFD60C5E-CBFB-4CA6-B28F-B3E80D5F7F13"}]}]}],"references":[{"url":"https://github.com/advisories/GHSA-w77f-wv46-4vcx","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","tags":["Not Applicable"]},{"url":"https://metacpan.org/release/YVES/Sereal-Encoder-4.010/changes","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","tags":["Release Notes"]},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-11922","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","tags":["Not Applicable"]}]}},{"cve":{"id":"CVE-2025-14213","sourceIdentifier":"2505284f-8ffb-486c-bf60-e19c1097a90b","published":"2026-03-31T12:16:26.813","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attacker with access to the Socket web interface (UI) to execute arbitrary operating system commands as the root user on the Socket’s internal system."},{"lang":"es","value":"Las versiones de Socket de Cato Networks anteriores a la 25 contienen una vulnerabilidad de inyección de comandos que permite a un atacante autenticado con acceso a la interfaz web (UI) del Socket ejecutar comandos arbitrarios del sistema operativo como usuario root en el sistema interno del Socket."}],"affected":[{"source":"2505284f-8ffb-486c-bf60-e19c1097a90b","affectedData":[{"vendor":"Cato Networks","product":"Socket","defaultStatus":"unaffected","platforms":["Linux"],"versions":[{"version":"24 and below","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"2505284f-8ffb-486c-bf60-e19c1097a90b","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T13:21:50.775743Z","id":"CVE-2025-14213","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"2505284f-8ffb-486c-bf60-e19c1097a90b","type":"Secondary","description":[{"lang":"en","value":"CWE-20"},{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://support.catonetworks.com/hc/en-us/articles/33184937283357-CVE-2025-14213-Socket-WebUI-OS-Command-Injection","source":"2505284f-8ffb-486c-bf60-e19c1097a90b"}]}},{"cve":{"id":"CVE-2026-0396","sourceIdentifier":"security@open-xchange.com","published":"2026-03-31T12:16:27.190","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI."},{"lang":"es","value":"Un atacante podría ser capaz de inyectar contenido HTML en el panel de control web interno enviando consultas DNS manipuladas a una instancia de DNSdist donde se han habilitado reglas dinámicas basadas en dominio ya sea a través de DynBlockRulesGroup:setSuffixMatchRule o DynBlockRulesGroup:setSuffixMatchRuleFFI."}],"affected":[{"source":"security@open-xchange.com","affectedData":[{"vendor":"PowerDNS","product":"DNSdist","defaultStatus":"unaffected","collectionURL":"https://repo.powerdns.com/","packageName":"dnsdist","modules":["Web Dashboard"],"programFiles":["html/local.js"],"repo":"https://github.com/PowerDNS/pdns","versions":[{"version":"1.9.0","lessThan":"1.9.12","versionType":"semver","status":"affected"},{"version":"2.0.0","lessThan":"2.0.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@open-xchange.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T13:21:05.454104Z","id":"CVE-2026-0396","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-80"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*","versionStartIncluding":"1.9.0","versionEndExcluding":"1.9.12","matchCriteriaId":"628B3B94-81DE-496E-B36A-B79A3DFFE1F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0.0","versionEndExcluding":"2.0.3","matchCriteriaId":"9AC850DD-FDD8-4C48-B861-4BBAF423FF57"}]}]}],"references":[{"url":"https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-02.html","source":"security@open-xchange.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-0397","sourceIdentifier":"security@open-xchange.com","published":"2026-03-31T12:16:27.340","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malicious website and extract information about the running configuration from the dashboard. The root cause of the issue is a misconfiguration of the Cross-Origin Resource Sharing (CORS) policy."},{"lang":"es","value":"Cuando el servidor web interno está habilitado (por defecto está deshabilitado), un atacante podría engañar a un administrador que ha iniciado sesión en el panel de control para que visite un sitio web malicioso y extraiga información sobre la configuración en ejecución del panel de control. La causa raíz del problema es una configuración incorrecta de la política de Intercambio de Recursos de Origen Cruzado (CORS)."}],"affected":[{"source":"security@open-xchange.com","affectedData":[{"vendor":"PowerDNS","product":"DNSdist","defaultStatus":"unaffected","collectionURL":"https://repo.powerdns.com/","packageName":"dnsdist","modules":["Internal Web Server"],"programFiles":["dnsdist-web.cc"],"repo":"https://github.com/PowerDNS/pdns","versions":[{"version":"1.9.0","lessThan":"1.9.12","versionType":"semver","status":"affected"},{"version":"2.0.0","lessThan":"2.0.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@open-xchange.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T13:19:54.934769Z","id":"CVE-2026-0397","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-942"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*","versionStartIncluding":"1.9.0","versionEndExcluding":"1.9.12","matchCriteriaId":"628B3B94-81DE-496E-B36A-B79A3DFFE1F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0.0","versionEndExcluding":"2.0.3","matchCriteriaId":"9AC850DD-FDD8-4C48-B861-4BBAF423FF57"}]}]}],"references":[{"url":"https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-02.html","source":"security@open-xchange.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-24028","sourceIdentifier":"security@open-xchange.com","published":"2026-03-31T12:16:27.487","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a denial of service, or access unrelated memory, leading to potential information disclosure."},{"lang":"es","value":"Un atacante podría desencadenar una lectura fuera de límites al enviar un paquete de respuesta DNS manipulado, cuando código Lua personalizado utiliza newDNSPacketOverlay para analizar paquetes DNS. La lectura fuera de límites podría desencadenar un fallo, lo que llevaría a una denegación de servicio, o acceder a memoria no relacionada, lo que llevaría a una posible revelación de información."}],"affected":[{"source":"security@open-xchange.com","affectedData":[{"vendor":"PowerDNS","product":"DNSdist","defaultStatus":"unaffected","collectionURL":"https://repo.powerdns.com/","packageName":"dnsdist","modules":["Lua DNS parser"],"programFiles":["dnsparser.hh"],"repo":"https://github.com/PowerDNS/pdns","versions":[{"version":"1.9.0","lessThan":"1.9.12","versionType":"semver","status":"affected"},{"version":"2.0.0","lessThan":"2.0.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@open-xchange.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T13:18:03.818786Z","id":"CVE-2026-24028","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-126"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*","versionStartIncluding":"1.9.0","versionEndExcluding":"1.9.12","matchCriteriaId":"628B3B94-81DE-496E-B36A-B79A3DFFE1F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0.0","versionEndExcluding":"2.0.3","matchCriteriaId":"9AC850DD-FDD8-4C48-B861-4BBAF423FF57"}]}]}],"references":[{"url":"https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-02.html","source":"security@open-xchange.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-24029","sourceIdentifier":"security@open-xchange.com","published":"2026-03-31T12:16:27.633","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries regardless of the configured ACL."},{"lang":"es","value":"Cuando la opción early_acl_drop (earlyACLDrop en Lua) está deshabilitada (el valor predeterminado es habilitada) en un frontend de DNS sobre HTTPS que utiliza el proveedor nghttp2, la comprobación de ACL se omite, permitiendo que todos los clientes envíen consultas DoH independientemente de la ACL configurada."}],"affected":[{"source":"security@open-xchange.com","affectedData":[{"vendor":"PowerDNS","product":"DNSdist","defaultStatus":"unaffected","collectionURL":"https://repo.powerdns.com/","packageName":"dnsdist","modules":["Incoming DNS over HTTPS"],"programFiles":["dnsdist-nghttp2-in.cc"],"repo":"https://github.com/PowerDNS/pdns","versions":[{"version":"1.9.0","lessThan":"1.9.12","versionType":"semver","status":"affected"},{"version":"2.0.0","lessThan":"2.0.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@open-xchange.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T13:15:34.638851Z","id":"CVE-2026-24029","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*","versionStartIncluding":"1.9.0","versionEndExcluding":"1.9.12","matchCriteriaId":"628B3B94-81DE-496E-B36A-B79A3DFFE1F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0.0","versionEndExcluding":"2.0.3","matchCriteriaId":"9AC850DD-FDD8-4C48-B861-4BBAF423FF57"}]}]}],"references":[{"url":"https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-02.html","source":"security@open-xchange.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-24030","sourceIdentifier":"security@open-xchange.com","published":"2026-03-31T12:16:27.770","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HTTP/3 payloads, resulting in a denial of service. In setups with a large quantity of memory available this usually results in an exception and the QUIC connection is properly closed, but in some cases the system might enter an out-of-memory state instead and terminate the process."},{"lang":"es","value":"Un atacante podría engañar a DNSdist para que asigne demasiada memoria mientras procesa cargas útiles de DNS sobre QUIC o DNS sobre HTTP/3, lo que resultaría en una denegación de servicio. En configuraciones con una gran cantidad de memoria disponible, esto generalmente resulta en una excepción y la conexión QUIC se cierra correctamente, pero en algunos casos el sistema podría entrar en un estado de falta de memoria en su lugar y terminar el proceso."}],"affected":[{"source":"security@open-xchange.com","affectedData":[{"vendor":"PowerDNS","product":"DNSdist","defaultStatus":"unaffected","collectionURL":"https://repo.powerdns.com/","packageName":"dnsdist","modules":["Incoming DNS over QUIC","Incoming DNS over HTTP/3"],"programFiles":["doq.cc","doh3.cc"],"repo":"https://github.com/PowerDNS/pdns","versions":[{"version":"1.9.0","lessThan":"1.9.12","versionType":"semver","status":"affected"},{"version":"2.0.0","lessThan":"2.0.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@open-xchange.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T13:14:53.937284Z","id":"CVE-2026-24030","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-789"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*","versionStartIncluding":"1.9.0","versionEndExcluding":"1.9.12","matchCriteriaId":"628B3B94-81DE-496E-B36A-B79A3DFFE1F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0.0","versionEndExcluding":"2.0.3","matchCriteriaId":"9AC850DD-FDD8-4C48-B861-4BBAF423FF57"}]}]}],"references":[{"url":"https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-02.html","source":"security@open-xchange.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27853","sourceIdentifier":"security@open-xchange.com","published":"2026-03-31T12:16:27.917","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQuestion:changeName or DNSResponse:changeName methods in custom Lua code. In some cases the rewritten packet might become larger than the initial response and even exceed 65535 bytes, potentially leading to a crash resulting in denial of service."},{"lang":"es","value":"Un atacante podría desencadenar una escritura fuera de límites enviando respuestas DNS manipuladas a un DNSdist utilizando los métodos DNSQuestion:changeName o DNSResponse:changeName en código Lua personalizado. En algunos casos, el paquete reescrito podría volverse más grande que la respuesta inicial e incluso exceder los 65535 bytes, lo que podría provocar un fallo que resultaría en denegación de servicio."}],"affected":[{"source":"security@open-xchange.com","affectedData":[{"vendor":"PowerDNS","product":"DNSdist","defaultStatus":"unaffected","collectionURL":"https://repo.powerdns.com/","packageName":"dnsdist","modules":["DNS packet writer"],"programFiles":["dnswriter.cc"],"repo":"https://github.com/PowerDNS/pdns","versions":[{"version":"1.9.0","lessThan":"1.9.12","versionType":"semver","status":"affected"},{"version":"2.0.0","lessThan":"2.0.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@open-xchange.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T13:14:03.664956Z","id":"CVE-2026-27853","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-787"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*","versionStartIncluding":"1.9.0","versionEndExcluding":"1.9.12","matchCriteriaId":"628B3B94-81DE-496E-B36A-B79A3DFFE1F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0.0","versionEndExcluding":"2.0.3","matchCriteriaId":"9AC850DD-FDD8-4C48-B861-4BBAF423FF57"}]}]}],"references":[{"url":"https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-02.html","source":"security@open-xchange.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27854","sourceIdentifier":"security@open-xchange.com","published":"2026-03-31T12:16:28.053","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:getEDNSOptions method in custom Lua code. In some cases DNSQuestion:getEDNSOptions might refer to a version of the DNS packet that has been modified, thus triggering a use-after-free and potentially a crash resulting in denial of service."},{"lang":"es","value":"Un atacante podría desencadenar un uso después de liberación enviando consultas DNS manipuladas a un DNSdist utilizando el método DNSQuestion:getEDNSOptions en código Lua personalizado. En algunos casos, DNSQuestion:getEDNSOptions podría referirse a una versión del paquete DNS que ha sido modificada, desencadenando así un uso después de liberación y potencialmente un fallo que resultaría en denegación de servicio."}],"affected":[{"source":"security@open-xchange.com","affectedData":[{"vendor":"PowerDNS","product":"DNSdist","defaultStatus":"unaffected","collectionURL":"https://repo.powerdns.com/","packageName":"dnsdist","modules":["EDNS options cache"],"programFiles":["dnsdist.hh"],"repo":"https://github.com/PowerDNS/pdns","versions":[{"version":"1.9.0","lessThan":"1.9.12","versionType":"semver","status":"affected"},{"version":"2.0.0","lessThan":"2.0.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@open-xchange.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.2,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T13:12:37.483504Z","id":"CVE-2026-27854","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-416"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*","versionStartIncluding":"1.9.0","versionEndExcluding":"1.9.12","matchCriteriaId":"628B3B94-81DE-496E-B36A-B79A3DFFE1F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0.0","versionEndExcluding":"2.0.3","matchCriteriaId":"9AC850DD-FDD8-4C48-B861-4BBAF423FF57"}]}]}],"references":[{"url":"https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-02.html","source":"security@open-xchange.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-32916","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-03-31T12:16:28.197","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. Remote unauthenticated requests to plugin-owned routes can invoke runtime.subagent methods to perform privileged gateway actions including session deletion and agent execution."},{"lang":"es","value":"Las versiones de OpenClaw 2026.3.7 anteriores a la 2026.3.11 contienen una vulnerabilidad de omisión de autorización donde las rutas de subagente de plugin ejecutan métodos de pasarela a través de un cliente operador sintético con amplios alcances administrativos. Las solicitudes remotas no autenticadas a rutas propiedad del plugin pueden invocar métodos de runtime.subagent para realizar acciones de pasarela privilegiadas, incluyendo la eliminación de sesión y la ejecución de agente."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"OpenClaw","product":"OpenClaw","defaultStatus":"unaffected","packageURL":"pkg:npm/openclaw","versions":[{"version":"2026.3.7","lessThan":"2026.3.11","versionType":"semver","status":"affected"},{"version":"2026.3.11","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.2,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","baseScore":9.4,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":5.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T15:34:04.240250Z","id":"CVE-2026-32916","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-266"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*","versionStartIncluding":"2026.3.7","versionEndExcluding":"2026.3.11","matchCriteriaId":"0106B0C9-F4C3-4B34-B42E-A03C84DDB446"}]}]}],"references":[{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-xw77-45gv-p728","source":"disclosure@vulncheck.com","tags":["Vendor Advisory"]},{"url":"https://www.vulncheck.com/advisories/openclaw-authorization-bypass-in-plugin-subagent-routes-via-synthetic-admin-scopes","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-32917","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-03-31T12:16:28.487","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. The vulnerability exists because unsanitized remote attachment paths containing shell metacharacters are passed directly to the SCP remote operand without validation, enabling command execution when remote attachment staging is enabled."},{"lang":"es","value":"OpenClaw anterior a 2026.3.13 contiene una vulnerabilidad de inyección de comandos remota en el flujo de preparación de adjuntos de iMessage que permite a los atacantes ejecutar comandos arbitrarios en hosts remotos configurados. La vulnerabilidad existe porque las rutas de adjuntos remotos no saneadas que contienen metacaracteres de shell se pasan directamente al operando remoto de SCP sin validación, lo que permite la ejecución de comandos cuando la preparación de adjuntos remotos está habilitada."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"OpenClaw","product":"OpenClaw","defaultStatus":"unaffected","packageURL":"pkg:npm/openclaw","versions":[{"version":"0","lessThan":"2026.3.13","versionType":"semver","status":"affected"},{"version":"2026.3.13","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.2,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T13:31:35.762105Z","id":"CVE-2026-32917","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*","versionEndExcluding":"2026.3.13","matchCriteriaId":"70DEDAA7-16AC-4833-ADD0-540DD4A0B1CB"}]}]}],"references":[{"url":"https://github.com/openclaw/openclaw/commit/a54bf71b4c0cbe554a84340b773df37ee8e959de","source":"disclosure@vulncheck.com","tags":["Patch"]},{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-g2f6-pwvx-r275","source":"disclosure@vulncheck.com","tags":["Vendor Advisory"]},{"url":"https://www.vulncheck.com/advisories/openclaw-remote-command-injection-via-unsanitized-imessage-attachment-paths-in-scp","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-32920","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-03-31T12:16:28.727","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution. Attackers can execute malicious code by including crafted workspace plugins in cloned repositories that execute when users run OpenClaw from the directory."},{"lang":"es","value":"OpenClaw anterior a 2026.3.12 descubre y carga automáticamente complementos de .OpenClaw/extensions/ sin verificación explícita de confianza, lo que permite la ejecución de código arbitrario. Los atacantes pueden ejecutar código malicioso al incluir complementos de espacio de trabajo manipulados en repositorios clonados que se ejecutan cuando los usuarios ejecutan OpenClaw desde el directorio."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"OpenClaw","product":"OpenClaw","defaultStatus":"unaffected","packageURL":"pkg:npm/openclaw","versions":[{"version":"0","lessThan":"2026.3.12","versionType":"semver","status":"affected"},{"version":"2026.3.12","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-02T15:03:17.540359Z","id":"CVE-2026-32920","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-829"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*","versionEndExcluding":"2026.3.12","matchCriteriaId":"B90EC1D8-4E2B-46AF-8E66-B689693A16CE"}]}]}],"references":[{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-99qw-6mr3-36qr","source":"disclosure@vulncheck.com","tags":["Vendor Advisory"]},{"url":"https://www.vulncheck.com/advisories/openclaw-arbitrary-code-execution-via-auto-discovery-of-workspace-plugins","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-32921","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-03-31T12:16:28.920","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not bound across approval and execution phases. Attackers can obtain approval for script execution, modify the approved script file before execution, and execute different content while maintaining the same approved command shape."},{"lang":"es","value":"OpenClaw anterior a 2026.3.8 contiene una vulnerabilidad de omisión de aprobación en system.run donde los operandos de script mutables no están vinculados entre las fases de aprobación y ejecución. Los atacantes pueden obtener aprobación para la ejecución de scripts, modificar el archivo de script aprobado antes de la ejecución y ejecutar contenido diferente mientras mantienen la misma forma de comando aprobada."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"OpenClaw","product":"OpenClaw","defaultStatus":"unaffected","packageURL":"pkg:npm/openclaw","versions":[{"version":"0","lessThan":"2026.3.8","versionType":"semver","status":"affected"},{"version":"2026.3.8","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":3.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":3.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T12:25:07.327088Z","id":"CVE-2026-32921","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-367"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*","versionEndExcluding":"2026.3.8","matchCriteriaId":"0A2A36CE-E6EC-4C9C-85F4-06C408B57A72"}]}]}],"references":[{"url":"https://github.com/openclaw/openclaw/commit/c76d29208bf6a7f058d2cf582519d28069e42240","source":"disclosure@vulncheck.com","tags":["Patch"]},{"url":"https://github.com/openclaw/openclaw/commit/cf3a479bd1204f62eef7dd82b4aa328749ae6c91","source":"disclosure@vulncheck.com","tags":["Patch"]},{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-8g75-q649-6pv6","source":"disclosure@vulncheck.com","tags":["Vendor Advisory"]},{"url":"https://www.vulncheck.com/advisories/openclaw-script-content-modification-via-mutable-operand-binding-in-system-run","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-32970","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-03-31T12:16:29.113","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and gateway.auth.password SecretRefs are treated as unset, allowing fallback to remote credentials in local mode. Attackers can exploit misconfigured local auth references to cause CLI and helper paths to select incorrect credential sources, potentially bypassing intended local authentication boundaries."},{"lang":"es","value":"OpenClaw anterior a 2026.3.11 contiene una vulnerabilidad de respaldo de credenciales donde los SecretRefs locales no disponibles gateway.auth.token y gateway.auth.password se tratan como no establecidos, permitiendo el respaldo a credenciales remotas en modo local. Los atacantes pueden explotar referencias de autenticación local mal configuradas para hacer que las rutas de CLI y de ayuda seleccionen fuentes de credenciales incorrectas, potencialmente eludiendo los límites de autenticación local previstos."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"OpenClaw","product":"OpenClaw","defaultStatus":"unaffected","packageURL":"pkg:npm/openclaw","versions":[{"version":"0","lessThan":"2026.3.11","versionType":"semver","status":"affected"},{"version":"2026.3.11","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.0,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":2.5,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.0,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.3,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T13:57:45.374597Z","id":"CVE-2026-32970","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-636"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*","versionEndExcluding":"2026.3.11","matchCriteriaId":"4B01F0B5-B0CB-462E-A546-2BA2CACD83D5"}]}]}],"references":[{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-qvr7-g57c-mrc7","source":"disclosure@vulncheck.com","tags":["Vendor Advisory"]},{"url":"https://www.vulncheck.com/advisories/openclaw-credential-fallback-logic-bypass-via-unavailable-local-auth-secretrefs","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-32971","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-03-31T12:16:29.280","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays extracted shell payloads instead of the executed argv. Attackers can place wrapper binaries and induce wrapper-shaped commands to execute local code after operators approve misleading command text."},{"lang":"es","value":"OpenClaw anterior a 2026.3.11 contiene una vulnerabilidad de integridad de aprobación en las aprobaciones de system.run del host de nodo que muestra cargas útiles de shell extraídas en lugar del argv ejecutado. Los atacantes pueden colocar binarios envoltorio e inducir comandos con forma de envoltorio para ejecutar código local después de que los operadores aprueben texto de comando engañoso."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"OpenClaw","product":"OpenClaw","defaultStatus":"unaffected","packageURL":"pkg:npm/openclaw","versions":[{"version":"0","lessThan":"2026.3.11","versionType":"semver","status":"affected"},{"version":"2026.3.11","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"ACTIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T00:00:00+00:00","id":"CVE-2026-32971","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-451"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*","versionEndExcluding":"2026.3.11","matchCriteriaId":"4B01F0B5-B0CB-462E-A546-2BA2CACD83D5"}]}]}],"references":[{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-rw39-5899-8mxp","source":"disclosure@vulncheck.com","tags":["Vendor Advisory"]},{"url":"https://www.vulncheck.com/advisories/openclaw-node-host-approval-ui-mismatch-allows-execution-of-unintended-commands","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-32976","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-03-31T12:16:29.470","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration despite configWrites restrictions. Attackers with authorized access on one account can execute channel commands like /config set channels.<provider>.accounts.<id> to modify configuration on target accounts with configWrites: false."},{"lang":"es","value":"OpenClaw anterior a 2026.3.11 contiene una vulnerabilidad de omisión de autorización que permite que los comandos de canal muten la configuración protegida de cuentas hermanas a pesar de las restricciones de configWrites. Atacantes con acceso autorizado en una cuenta pueden ejecutar comandos de canal como /config set channels.<provider>.accounts.<id> para modificar la configuración en cuentas objetivo con configWrites: false."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"OpenClaw","product":"OpenClaw","defaultStatus":"unaffected","packageURL":"pkg:npm/openclaw","versions":[{"version":"0","lessThan":"2026.3.11","versionType":"semver","status":"affected"},{"version":"2026.3.11","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T15:38:30.474161Z","id":"CVE-2026-32976","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*","versionEndExcluding":"2026.3.11","matchCriteriaId":"4B01F0B5-B0CB-462E-A546-2BA2CACD83D5"}]}]}],"references":[{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-8jhh-jcqg-mj5p","source":"disclosure@vulncheck.com","tags":["Vendor Advisory"]},{"url":"https://www.vulncheck.com/advisories/openclaw-account-scoped-configwrites-policy-bypass-via-channel-commands","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-32977","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-03-31T12:16:29.660","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container path during the final move operation. An attacker can exploit a time-of-check-time-of-use race condition by modifying parent paths inside the sandbox to redirect committed files outside the validated writable path within the container mount namespace."},{"lang":"es","value":"OpenClaw anterior a 2026.3.11 contiene una vulnerabilidad de omisión de límite de sandbox en el paso de confirmación writeFile de fs-bridge que utiliza una ruta de contenedor no anclada durante la operación de movimiento final. Un atacante puede explotar una condición de carrera de tiempo de verificación-tiempo de uso modificando rutas padre dentro del sandbox para redirigir archivos confirmados fuera de la ruta de escritura validada dentro del espacio de nombres de montaje del contenedor."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"OpenClaw","product":"OpenClaw","defaultStatus":"unaffected","packageURL":"pkg:npm/openclaw","versions":[{"version":"0","lessThan":"2026.3.11","versionType":"semver","status":"affected"},{"version":"2026.3.11","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.0,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T13:28:14.952240Z","id":"CVE-2026-32977","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-367"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*","versionEndExcluding":"2026.3.11","matchCriteriaId":"4B01F0B5-B0CB-462E-A546-2BA2CACD83D5"}]}]}],"references":[{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-xvx8-77m6-gwg6","source":"disclosure@vulncheck.com","tags":["Vendor Advisory"]},{"url":"https://www.vulncheck.com/advisories/openclaw-sandbox-boundary-bypass-via-unanchored-writefile-commit-path","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-32982","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-03-31T12:16:29.850","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages. When media downloads fail, the original Telegram file URLs containing bot tokens are embedded in MediaFetchError strings and leaked to logs and error surfaces."},{"lang":"es","value":"OpenClaw anterior a 2026.3.13 contiene una vulnerabilidad de revelación de información en la función fetchRemoteMedia que expone los tokens de bot de Telegram en los mensajes de error. Cuando las descargas de medios fallan, las URL de archivo originales de Telegram que contienen tokens de bot se incrustan en cadenas MediaFetchError y se filtran a los registros y a las superficies de error."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"OpenClaw","product":"OpenClaw","defaultStatus":"unaffected","packageURL":"pkg:npm/openclaw","versions":[{"version":"0","lessThan":"2026.3.13","versionType":"semver","status":"affected"},{"version":"2026.3.13","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-02T15:05:55.594582Z","id":"CVE-2026-32982","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*","versionEndExcluding":"2026.3.13","matchCriteriaId":"70DEDAA7-16AC-4833-ADD0-540DD4A0B1CB"}]}]}],"references":[{"url":"https://github.com/openclaw/openclaw/commit/7a53eb7ea8295b08be137e231c9a98c1a79b5cd5","source":"disclosure@vulncheck.com","tags":["Patch"]},{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-xwcj-hwhf-h378","source":"disclosure@vulncheck.com","tags":["Vendor Advisory"]},{"url":"https://www.vulncheck.com/advisories/openclaw-telegram-bot-token-exposure-in-media-fetch-error-logs","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-32988","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-03-31T12:16:30.047","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and population are not pinned to a verified parent directory. Attackers can exploit a race condition in parent-path alias changes to write attacker-controlled bytes outside the intended validated path before the final guarded replace step executes."},{"lang":"es","value":"OpenClaw anterior a 2026.3.11 contiene una vulnerabilidad de omisión de límite de sandbox en las escrituras por etapas de fs-bridge donde la creación y población de archivos temporales no están ancladas a un directorio padre verificado. Los atacantes pueden explotar una condición de carrera en los cambios de alias de ruta padre para escribir bytes controlados por el atacante fuera de la ruta validada prevista antes de que se ejecute el paso final de reemplazo protegido."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"OpenClaw","product":"OpenClaw","defaultStatus":"unaffected","packageURL":"pkg:npm/openclaw","versions":[{"version":"0","lessThan":"2026.3.11","versionType":"semver","status":"affected"},{"version":"2026.3.11","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.1,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T12:17:15.349744Z","id":"CVE-2026-32988","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-367"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*","versionEndExcluding":"2026.3.11","matchCriteriaId":"4B01F0B5-B0CB-462E-A546-2BA2CACD83D5"}]}]}],"references":[{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-mj4p-rc52-m843","source":"disclosure@vulncheck.com","tags":["Vendor Advisory"]},{"url":"https://www.vulncheck.com/advisories/openclaw-sandbox-boundary-bypass-via-unvalidated-temporary-file-creation","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-3139","sourceIdentifier":"security@wordfence.com","published":"2026-03-31T12:16:31.037","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.15.5 via the wppb_save_avatar_value() function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to reassign ownership of arbitrary posts and attachments by changing 'post_author'."},{"lang":"es","value":"El plugin User Profile Builder - Beautiful User Registration Forms, User Profiles & User Role Editor para WordPress es vulnerable a Referencia Directa a Objeto Insegura en versiones hasta e incluyendo la 3.15.5 a través de la función wppb_save_avatar_value() debido a la falta de validación en una clave controlada por el usuario. Esto hace posible que atacantes autenticados, con acceso de nivel suscriptor y superior, reasignen la propiedad de publicaciones y archivos adjuntos arbitrarios cambiando 'post_author'."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"cozmoslabs","product":"User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.15.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T15:39:36.557641Z","id":"CVE-2026-3139","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/changeset/3481772/profile-builder","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/760f7736-db49-4210-a2f3-3abb506106d7?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-3191","sourceIdentifier":"security@wordfence.com","published":"2026-03-31T12:16:31.200","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.12. This is due to missing or incorrect nonce validation on the 'minify_html_menu_options' function. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link."},{"lang":"es","value":"El plugin Minify HTML para WordPress es vulnerable a la falsificación de petición en sitios cruzados en todas las versiones hasta la 2.1.12, inclusive. Esto se debe a la validación de nonce ausente o incorrecta en la función 'minify_html_menu_options'. Esto hace posible que atacantes no autenticados actualicen la configuración del plugin a través de una petición falsificada, siempre que puedan engañar a un administrador del sitio para que realice una acción como hacer clic en un enlace."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"teckel","product":"Minify HTML","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.1.12","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-02T15:06:40.524972Z","id":"CVE-2026-3191","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/minify-html-markup/tags/2.1.12/minify-html.php#L139","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3486011/minify-html-markup","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/fe14b92b-1784-4083-9b9f-23d7f69a3215?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-30310","sourceIdentifier":"cve@mitre.org","published":"2026-03-31T14:16:11.390","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"In its design for automatic terminal command execution, Sixth offers two options: Execute safe commands and Execute all commands. The description for the former states that commands determined by the model to be safe will be automatically executed, whereas if the model judges a command to be potentially destructive, it still requires user approval. However, this design is highly susceptible to prompt injection attacks. An attacker can employ a generic template to wrap any malicious command and mislead the model into misclassifying it as a 'safe' command, thereby bypassing the user approval requirement and resulting in arbitrary command execution."},{"lang":"es","value":"En su diseño para la ejecución automática de comandos de terminal, Sixth ofrece dos opciones: Ejecutar comandos seguros y Ejecutar todos los comandos. La descripción de la primera establece que los comandos determinados por el modelo como seguros se ejecutarán automáticamente, mientras que si el modelo juzga un comando como potencialmente destructivo, aún requiere la aprobación del usuario. Sin embargo, este diseño es altamente susceptible a ataques de inyección de prompts. Un atacante puede emplear una plantilla genérica para envolver cualquier comando malicioso y engañar al modelo para que lo clasifique erróneamente como un comando 'seguro', eludiendo así el requisito de aprobación del usuario y resultando en la ejecución arbitraria de comandos."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-01T18:39:07.654899Z","id":"CVE-2026-30310","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]}],"references":[{"url":"https://github.com/Secsys-FDU/LLM-Tool-Calling-CVEs/issues/12","source":"cve@mitre.org"},{"url":"https://trysixth.com/","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-3308","sourceIdentifier":"cret@cert.org","published":"2026-03-31T14:16:12.560","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version 1.27.0 allows an attacker to maliciously craft a PDF that can trigger an integer overflow within the 'pdf_load_image_imp' function. This allows a heap out-of-bounds write that could be exploited for arbitrary code execution."},{"lang":"es","value":"Una vulnerabilidad de desbordamiento de entero en 'pdf-image.c' en la versión 1.27.0 de MuPDF de Artifex permite a un atacante crear maliciosamente un PDF que puede desencadenar un desbordamiento de entero dentro de la función 'pdf_load_image_imp'. Esto permite una escritura fuera de límites en el heap que podría ser explotada para la ejecución de código arbitrario."}],"affected":[{"source":"cret@cert.org","affectedData":[{"vendor":"Artifex Software Inc. *PyMuPDF*","product":"MuPDF","versions":[{"version":"0","lessThanOrEqual":"1.27.0","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-01T14:47:30.846054Z","id":"CVE-2026-3308","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-190"}]}],"references":[{"url":"https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=a26f0142e7d390d4a82c6e5ae0e312e07cc4ec85","source":"cret@cert.org"},{"url":"https://github.com/ArtifexSoftware/mupdf","source":"cret@cert.org"},{"url":"https://github.com/ArtifexSoftware/mupdf/commit/a26f0142e7d390d4a82c6e5ae0e312e07cc4ec85","source":"cret@cert.org"},{"url":"https://lists.debian.org/debian-lts-announce/2026/04/msg00020.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.kb.cert.org/vuls/id/951662","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-20915","sourceIdentifier":"security@checkmk.com","published":"2026-03-31T15:16:11.527","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create pending changes to inject malicious JavaScript into the Pending Changes sidebar, which will execute in the browsers of other users viewing the sidebar."},{"lang":"es","value":"El cross-site scripting (XSS) almacenado en Checkmk versión 2.5.0 (beta) anterior a 2.5.0b2 permite a usuarios autenticados con permiso para crear cambios pendientes inyectar JavaScript malicioso en la barra lateral de Cambios Pendientes, que se ejecutará en los navegadores de otros usuarios que vean la barra lateral."}],"affected":[{"source":"security@checkmk.com","affectedData":[{"vendor":"Checkmk GmbH","product":"Checkmk","defaultStatus":"unaffected","versions":[{"version":"2.5.0b1","lessThan":"2.5.0b2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security@checkmk.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T17:15:45.902831Z","id":"CVE-2026-20915","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@checkmk.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:checkmk:checkmk:2.5.0:b1:*:*:*:*:*:*","matchCriteriaId":"F8943BB3-1487-494C-B4EB-89EB0B18B6A2"}]}]}],"references":[{"url":"https://checkmk.com/werk/19526","source":"security@checkmk.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-29870","sourceIdentifier":"cve@mitre.org","published":"2026-03-31T15:16:12.733","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file writes via the checkpoint_dir parameter in OfflineACE.run. The save_to_file method in ace/skillbook.py fails to normalize or validate filesystem paths, allowing traversal sequences to escape the intended checkpoint directory. This vulnerability allows attackers to overwrite arbitrary files accessible to the application process, potentially leading to application corruption, privilege escalation, or code execution depending on the deployment context."},{"lang":"es","value":"Una vulnerabilidad de salto de directorio en el proyecto agentic-context-engine versiones hasta la 0.7.1 permite escrituras de archivos arbitrarias a través del parámetro checkpoint_dir en OfflineACE.run. El método save_to_file en ace/skillbook.py no normaliza ni valida las rutas del sistema de archivos, permitiendo que las secuencias de salto escapen del directorio de punto de control previsto. Esta vulnerabilidad permite a los atacantes sobrescribir archivos arbitrarios accesibles al proceso de la aplicación, lo que podría llevar a la corrupción de la aplicación, escalada de privilegios, o ejecución de código dependiendo del contexto de despliegue."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","baseScore":7.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":4.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T15:06:38.268919Z","id":"CVE-2026-29870","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://github.com/lilmingwa13/security-research/blob/main/CVE-2026-29870.md","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-30309","sourceIdentifier":"cve@mitre.org","published":"2026-03-31T15:16:12.863","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"InfCode's terminal auto-execution module contains a critical command filtering vulnerability that renders its blacklist security mechanism completely ineffective. The predefined blocklist fails to cover native high-risk commands in Windows PowerShell (such as powershell), and the matching algorithm lacks dynamic semantic parsing unable to recognize string concatenation, variable assignment, or double-quote interpolation in Shell syntax. Malicious commands can bypass interception through simple syntax obfuscation. An attacker can construct a file containing malicious instructions for remote code injection. When a user imports and views such a file in the IDE, the Agent executes dangerous PowerShell commands outside the blacklist without user confirmation, resulting in arbitrary command execution or sensitive data leakage."},{"lang":"es","value":"El módulo de auto-ejecución de terminal de InfCode contiene una crítica vulnerabilidad de filtrado de comandos que hace que su mecanismo de seguridad de lista negra sea completamente ineficaz. La lista de bloqueo predefinida no cubre comandos nativos de alto riesgo en Windows PowerShell (como powershell), y el algoritmo de coincidencia carece de análisis semántico dinámico incapaz de reconocer la concatenación de cadenas, la asignación de variables o la interpolación de comillas dobles en la sintaxis de Shell. Los comandos maliciosos pueden eludir la intercepción mediante una simple ofuscación de sintaxis. Un atacante puede construir un archivo que contenga instrucciones maliciosas para la inyección remota de código. Cuando un usuario importa y visualiza dicho archivo en el IDE, el Agente ejecuta comandos peligrosos de PowerShell fuera de la lista negra sin confirmación del usuario, lo que resulta en la ejecución arbitraria de comandos o la fuga de datos sensibles."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-31T15:13:25.258792Z","id":"CVE-2026-30309","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:tokfinity:infcode:*:*:*:*:*:*:*:*","versionEndIncluding":"1.3.1","matchCriteriaId":"E3D12CD1-2D4A-40B2-B18B-A5CCB61891E4"}]}]}],"references":[{"url":"https://github.com/Secsys-FDU/LLM-Tool-Calling-CVEs/issues/11","source":"cve@mitre.org","tags":["Issue Tracking","Third Party Advisory"]},{"url":"https://www.tokfinity.com/infcode","source":"cve@mitre.org","tags":["Product"]}]}},{"cve":{"id":"CVE-2026-30311","sourceIdentifier":"cve@mitre.org","published":"2026-03-31T15:16:12.987","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operations, it fails to account for standard Shell command substitution Ridvay Code (specifically$(...)and backticks ...). An attacker can construct a command such as git log --grep=\"$(malicious_command)\", forcing Syntx to misidentify it as a safe git operation and automatically approve it. The underlying Shell prioritizes the execution of the malicious code injected within the arguments, resulting in Remote Code Execution without any user interaction."},{"lang":"es","value":"El módulo de autoaprobación de comandos de Ridvay Code contiene una crítica vulnerabilidad de inyección de comandos del sistema operativo que hace que su mecanismo de seguridad de lista blanca sea completamente ineficaz. El sistema se basa en expresiones regulares frágiles para analizar las estructuras de comandos; aunque intenta interceptar operaciones peligrosas, no tiene en cuenta la sustitución de comandos estándar de Shell (específicamente $(...) y las comillas invertidas ...). Un atacante puede construir un comando como git log --grep='$(malicious_command)', forzando a Syntx a identificarlo erróneamente como una operación git segura y aprobarlo automáticamente. El Shell subyacente prioriza la ejecución del código malicioso inyectado dentro de los argumentos, lo que resulta en ejecución remota de código sin ninguna interacción del usuario."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-01T18:38:14.416509Z","id":"CVE-2026-30311","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ridvay:auto-approval_module:*:*:*:*:*:*:*:*","versionEndIncluding":"0.1.1","matchCriteriaId":"37024489-48B5-4B6F-8818-6EB0CEFF5A06"}]}]}],"references":[{"url":"https://github.com/Secsys-FDU/LLM-Tool-Calling-CVEs/issues/8","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://ridvay.com/","source":"cve@mitre.org","tags":["Product"]}]}},{"cve":{"id":"CVE-2026-30312","sourceIdentifier":"cve@mitre.org","published":"2026-03-31T15:16:13.110","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on string-based parsing to validate commands; while it intercepts dangerous operators such as ;, &&, ||, |, and command substitution patterns, it fails to account for raw newline characters embedded within the input. An attacker can construct a payload by embedding a literal newline between a whitelisted command and malicious code (e.g., git log malicious_command), forcing DSAI-Cline to misidentify it as a safe operation and automatically approve it. The underlying PowerShell interpreter treats the newline as a command separator, executing both commands sequentially, resulting in Remote Code Execution without any user interaction."},{"lang":"es","value":"El módulo de autoaprobación de comandos de DSAI-Cline contiene una crítica vulnerabilidad de inyección de comandos del sistema operativo que hace que su mecanismo de seguridad de lista blanca sea completamente ineficaz. El sistema se basa en el análisis de cadenas para validar comandos; si bien intercepta operadores peligrosos como ;, &&, ||, | y patrones de sustitución de comandos, no tiene en cuenta los caracteres de nueva línea sin procesar incrustados en la entrada. Un atacante puede construir una carga útil incrustando una nueva línea literal entre un comando de lista blanca y código malicioso (por ejemplo, git log malicious_command), lo que obliga a DSAI-Cline a identificarlo erróneamente como una operación segura y aprobarlo automáticamente. El intérprete de PowerShell subyacente trata la nueva línea como un separador de comandos, ejecutando ambos comandos secuencialmente, lo que resulta en ejecución remota de código sin ninguna interacción del usuario."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-01T18:37:22.603503Z","id":"CVE-2026-30312","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://github.com/Secsys-FDU/LLM-Tool-Calling-CVEs/issues/9","source":"cve@mitre.org"},{"url":"https://github.com/necboy/cline-DSAI","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-30314","sourceIdentifier":"cve@mitre.org","published":"2026-03-31T15:16:13.233","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operations, it fails to account for standard Shell command substitution Ridvay Code (specifically$(...)and backticks ...). An attacker can construct a command such as git log --grep=\"$(malicious_command)\", forcing Syntx to misidentify it as a safe git operation and automatically approve it. The underlying Shell prioritizes the execution of the malicious code injected within the arguments, resulting in Remote Code Execution without any user interaction."},{"lang":"es","value":"El módulo de autoaprobación de comandos de Ridvay Code contiene una vulnerabilidad crítica de inyección de comandos del sistema operativo (OS) que hace que su mecanismo de seguridad de lista blanca sea completamente ineficaz. El sistema se basa en expresiones regulares frágiles para analizar las estructuras de comandos; si bien intenta interceptar operaciones peligrosas, no tiene en cuenta la sustitución de comandos estándar de Shell de Ridvay Code (específicamente $(...) y las comillas invertidas ...). Un atacante puede construir un comando como git log --grep=\"$(malicious_command)\", forzando a Syntx a identificarlo erróneamente como una operación git segura y a aprobarlo automáticamente. El Shell subyacente prioriza la ejecución del código malicioso inyectado dentro de los argumentos, lo que resulta en ejecución remota de código sin ninguna interacción del usuario."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-01T18:32:31.594478Z","id":"CVE-2026-30314","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ridvay:auto-approval_module:*:*:*:*:*:*:*:*","versionEndIncluding":"0.1.1","matchCriteriaId":"37024489-48B5-4B6F-8818-6EB0CEFF5A06"}]}]}],"references":[{"url":"https://github.com/Secsys-FDU/LLM-Tool-Calling-CVEs/issues/8","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://ridvay.com/","source":"cve@mitre.org","tags":["Product"]}]}},{"cve":{"id":"CVE-2026-1343","sourceIdentifier":"psirt@us.ibm.com","published":"2026-04-08T01:16:40.503","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows an attacker to contact internal authentication endpoints which are protected by the Reverse Proxy."},{"lang":"es","value":"IBM Verify Identity Access Contenedor 11.0 hasta 11.0.2 y IBM Security Verify Access Contenedor 10.0 hasta 10.0.9.1 y IBM Verify Identity Access 11.0 hasta 11.0.2 y IBM Security Verify Access 10.0 hasta 10.0.9.1 permite a un atacante contactar puntos finales de autenticación internos que están protegidos por el Proxy Inverso."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Verify Identity Access Container","cpes":["cpe:2.3:a:ibm:verify_identity_access_container:11.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:verify_identity_access_container:11.0.2:*:*:*:*:*:*:*"],"versions":[{"version":"11.0","lessThanOrEqual":"11.0.2","versionType":"semver","status":"affected"}]},{"vendor":"IBM","product":"Security Verify Access Container","cpes":["cpe:2.3:a:ibm:security_verify_access_container:10.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:security_verify_access_container:10.0.9.1:*:*:*:*:*:*:*"],"versions":[{"version":"10.0","lessThanOrEqual":"10.0.9.1","versionType":"semver","status":"affected"}]},{"vendor":"IBM","product":"Verify Identity Access","cpes":["cpe:2.3:a:ibm:verify_identity_access:11.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:verify_identity_access:11.0.2:*:*:*:*:*:*:*"],"versions":[{"version":"11.0","lessThanOrEqual":"11.0.2","versionType":"semver","status":"affected"}]},{"vendor":"IBM","product":"Security Verify Access","cpes":["cpe:2.3:a:ibm:security_verify_access:10.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:security_verify_access:10.0.9.1:*:*:*:*:*:*:*"],"versions":[{"version":"10.0","lessThanOrEqual":"10.0.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T15:44:04.946640Z","id":"CVE-2026-1343","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.0.9.1","matchCriteriaId":"C71B5C3B-4B1F-4330-9260-26B349CAE490"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:security_verify_access_container:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0.0.0","versionEndIncluding":"10.0.9.1","matchCriteriaId":"674B3E72-09DE-48D4-9F07-43152474E8CD"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:verify_identity_access:*:*:*:*:*:*:*:*","versionStartIncluding":"11.0.0.0","versionEndIncluding":"11.0.2.0","matchCriteriaId":"980521A4-FDCB-4EC4-9871-6CD57DEC14E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:verify_identity_access_container:*:*:*:*:*:*:*:*","versionStartIncluding":"11.0.0.0","versionEndIncluding":"11.0.2.0","matchCriteriaId":"3FDCBF44-E483-4248-A39E-CB9226FF4BC9"}]}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7268253","source":"psirt@us.ibm.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-1346","sourceIdentifier":"psirt@us.ibm.com","published":"2026-04-08T01:16:40.750","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to escalate their privileges to root due to execution with unnecessary privileges than required."},{"lang":"es","value":"IBM Verify Identity Access Contenedor 11.0 hasta 11.0.2 y IBM Security Verify Access Contenedor 10.0 hasta 10.0.9.1 y IBM Verify Identity Access 11.0 hasta 11.0.2 y IBM Security Verify Access 10.0 hasta 10.0.9.1 podrían permitir a un usuario autenticado localmente escalar sus privilegios a root debido a la ejecución con privilegios innecesarios de los requeridos."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Verify Identity Access Container","cpes":["cpe:2.3:a:ibm:verify_identity_access_container:11.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:verify_identity_access_container:11.0.2:*:*:*:*:*:*:*"],"versions":[{"version":"11.0","lessThanOrEqual":"11.0.2","versionType":"semver","status":"affected"}]},{"vendor":"IBM","product":"Security Verify Access Container","cpes":["cpe:2.3:a:ibm:security_verify_access_container:10.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:security_verify_access_container:10.0.9.1:*:*:*:*:*:*:*"],"versions":[{"version":"10.0","lessThanOrEqual":"10.0.9.1","versionType":"semver","status":"affected"}]},{"vendor":"IBM","product":"Verify Identity Access","cpes":["cpe:2.3:a:ibm:verify_identity_access:11.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:verify_identity_access:11.0.2:*:*:*:*:*:*:*"],"versions":[{"version":"11.0","lessThanOrEqual":"11.0.2","versionType":"semver","status":"affected"}]},{"vendor":"IBM","product":"Security Verify Access","cpes":["cpe:2.3:a:ibm:security_verify_access:10.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:security_verify_access:10.0.9.1:*:*:*:*:*:*:*"],"versions":[{"version":"10.0","lessThanOrEqual":"10.0.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T00:00:00+00:00","id":"CVE-2026-1346","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-250"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0.0","versionEndIncluding":"10.0.9.1","matchCriteriaId":"C71B5C3B-4B1F-4330-9260-26B349CAE490"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:security_verify_access_container:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0.0.0","versionEndIncluding":"10.0.9.1","matchCriteriaId":"674B3E72-09DE-48D4-9F07-43152474E8CD"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:verify_identity_access:*:*:*:*:*:*:*:*","versionStartIncluding":"11.0.0.0","versionEndIncluding":"11.0.2.0","matchCriteriaId":"980521A4-FDCB-4EC4-9871-6CD57DEC14E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:verify_identity_access_container:*:*:*:*:*:*:*:*","versionStartIncluding":"11.0.0.0","versionEndIncluding":"11.0.2.0","matchCriteriaId":"3FDCBF44-E483-4248-A39E-CB9226FF4BC9"}]}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7268253","source":"psirt@us.ibm.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-14732","sourceIdentifier":"security@wordfence.com","published":"2026-04-08T02:16:02.667","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget parameters in all versions up to, and including, 3.35.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."},{"lang":"es","value":"El plugin Elementor Website Builder - More Than Just a Page Builder para WordPress es vulnerable a cross-site scripting almacenado a través de varios parámetros de widget en todas las versiones hasta la 3.35.5, inclusive, debido a una sanitización de entrada y un escape de salida insuficientes. Esto permite a atacantes autenticados, con acceso de nivel Colaborador y superior, inyectar scripts web arbitrarios en páginas que se ejecutarán cada vez que un usuario acceda a una página inyectada."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"elemntor","product":"Elementor Website Builder – more than just a page builder","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.35.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T15:57:13.519645Z","id":"CVE-2025-14732","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-87"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/elementor/trunk/modules/wp-rest/classes/elementor-post-meta.php#L67","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=/elementor/tags/3.35.5&new_path=/elementor/tags/3.35.6","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/20232d70-72b2-47b7-ac7e-ad07892864ef?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-27140","sourceIdentifier":"security@golang.org","published":"2026-04-08T02:16:02.887","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass."},{"lang":"es","value":"Nombres de archivo SWIG que contienen 'cgo' y cargas útiles bien elaboradas podrían conducir a contrabando de código y ejecución de código arbitrario en tiempo de compilación debido a la omisión de la capa de confianza."}],"affected":[{"source":"security@golang.org","affectedData":[{"vendor":"Go toolchain","product":"cmd/go","defaultStatus":"unaffected","collectionURL":"https://pkg.go.dev","packageName":"cmd/go","versions":[{"version":"0","lessThan":"1.25.9","versionType":"semver","status":"affected"},{"version":"1.26.0-0","lessThan":"1.26.2","versionType":"semver","status":"affected"}]}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","affectedData":[{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang","cpes":["cpe:/o:redhat:enterprise_linux:10.1"],"versions":[{"version":"0:1.25.9-3.el10_1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:1.25.9-1.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"go-toolset:rhel8","cpes":["cpe:/a:redhat:enterprise_linux:8"],"versions":[{"version":"8100020260422204008.a3795dee","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"go-toolset:rhel8","cpes":["cpe:/a:redhat:rhel_aus:8.4"],"versions":[{"version":"8040020260505161557.5081a262","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"go-toolset:rhel8","cpes":["cpe:/a:redhat:rhel_eus_long_life:8.4"],"versions":[{"version":"8040020260505161557.5081a262","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"go-toolset:rhel8","cpes":["cpe:/a:redhat:rhel_aus:8.6"],"versions":[{"version":"8060020260505152018.97d7f71f","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.6 Telecommunications Update Service","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"go-toolset:rhel8","cpes":["cpe:/a:redhat:rhel_tus:8.6"],"versions":[{"version":"8060020260505152018.97d7f71f","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"go-toolset:rhel8","cpes":["cpe:/a:redhat:rhel_e4s:8.6"],"versions":[{"version":"8060020260505152018.97d7f71f","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.8 Telecommunications Update Service","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"go-toolset:rhel8","cpes":["cpe:/a:redhat:rhel_tus:8.8"],"versions":[{"version":"8080020260506150958.6b4b45d8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"go-toolset:rhel8","cpes":["cpe:/a:redhat:rhel_e4s:8.8"],"versions":[{"version":"8080020260506150958.6b4b45d8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"0:1.25.9-1.el9_7","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang","cpes":["cpe:/a:redhat:rhel_e4s:9.0"],"versions":[{"version":"0:1.17.13-12.el9_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang","cpes":["cpe:/a:redhat:rhel_e4s:9.2"],"versions":[{"version":"0:1.19.13-25.el9_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.4 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang","cpes":["cpe:/a:redhat:rhel_eus:9.4"],"versions":[{"version":"0:1.21.13-16.el9_4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"0:1.25.9-1.el9_6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.17","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-docker-builder-rhel9","cpes":["cpe:/a:redhat:openshift:4.17::el9"],"versions":[{"version":"1782184924","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.18","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-docker-builder-rhel9","cpes":["cpe:/a:redhat:openshift:4.18::el9"],"versions":[{"version":"1780978272","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/aws-karpenter-provider-aws-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041462","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/aws-kms-encryption-provider-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040098","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/azure-kms-encryption-provider-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041224","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/azure-service-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043978","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/cloud-network-config-controller-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040126","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/container-networking-plugins-microshift-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040410","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/egress-router-cni-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043779","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/frr-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041886","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/insights-runtime-exporter-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043827","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/insights-runtime-extractor-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044940","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/kube-metrics-server-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044576","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/kubevirt-csi-driver-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044702","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/network-tools-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780465170","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/oc-mirror-plugin-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043484","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/openshift-route-controller-manager-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780042119","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/openstack-resource-controller-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041614","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-agent-installer-api-server-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1779779751","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-agent-installer-csr-approver-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044383","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-agent-installer-node-agent-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780462567","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-agent-installer-orchestrator-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044334","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-agent-installer-utils-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044523","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-apiserver-network-proxy-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043476","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-aws-cloud-controller-manager-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040386","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-aws-cluster-api-controllers-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040551","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-aws-ebs-csi-driver-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040374","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-aws-ebs-csi-driver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040173","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-aws-pod-identity-webhook-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040106","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-azure-cloud-controller-manager-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040431","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-azure-cloud-node-manager-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040250","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-azure-cluster-api-controllers-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040455","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-azure-disk-csi-driver-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040569","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-azure-disk-csi-driver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040125","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-azure-file-csi-driver-operator-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040115","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-azure-file-csi-driver-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041802","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-azure-workload-identity-webhook-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040474","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-baremetal-cluster-api-controllers-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041847","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-baremetal-installer-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780462866","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-baremetal-machine-controllers-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043216","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-baremetal-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041137","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-baremetal-runtimecfg-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041696","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cli-artifacts-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780456268","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cli-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780454976","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cloud-credential-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044088","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-api-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043838","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-authentication-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043267","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-autoscaler-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043688","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-autoscaler-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780042895","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-baremetal-operator-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780042508","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-bootstrap-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043788","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-capi-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780077151","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-cloud-controller-manager-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043389","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-config-api-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043841","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-config-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040140","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-control-plane-machine-set-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044360","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043742","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-dns-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044651","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-etcd-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043209","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-image-registry-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044985","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-ingress-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043338","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-kube-apiserver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040877","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-kube-cluster-api-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043417","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-kube-controller-manager-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043063","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-kube-scheduler-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044416","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-kube-storage-version-migrator-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041673","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-machine-approver-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780077014","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-monitoring-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043304","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-network-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040117","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-node-tuning-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040462","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-olm-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043588","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-openshift-apiserver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040365","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-openshift-controller-manager-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044673","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-policy-controller-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780042236","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-samples-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040315","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-storage-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044883","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-version-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043164","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-configmap-reloader-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780042603","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-console-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780365421","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-console-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043143","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-container-networking-plugins-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043821","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-coredns-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780042237","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-csi-driver-manila-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041901","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-csi-driver-manila-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041003","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-csi-driver-nfs-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041501","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-csi-external-attacher-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044427","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-csi-external-provisioner-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041753","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-csi-external-resizer-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040144","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-csi-external-snapshotter-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041782","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-csi-livenessprobe-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040459","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-csi-node-driver-registrar-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041860","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-csi-snapshot-controller-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044670","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-docker-builder-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780462456","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-docker-registry-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043300","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-etcd-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780060002","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-gcp-cloud-controller-manager-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041279","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-gcp-cluster-api-controllers-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041069","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-gcp-pd-csi-driver-operator-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780042252","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-gcp-pd-csi-driver-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041162","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-gcp-workload-identity-federation-webhook-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040104","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-hyperkube-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780060168","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-hypershift-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044706","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-ibmcloud-cluster-api-controllers-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041921","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-ibm-cloud-controller-manager-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040998","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-ibmcloud-machine-controllers-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040920","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-ibm-vpc-block-csi-driver-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040850","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-ibm-vpc-block-csi-driver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040338","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-image-customization-controller-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040138","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-insights-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044358","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-installer-artifacts-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780046879","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-installer-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780059431","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-ironic-machine-os-downloader-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780365576","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-kube-proxy-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040812","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-kube-rbac-proxy-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041732","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-kube-state-metrics-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044865","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-kube-storage-version-migrator-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041147","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-kubevirt-cloud-controller-manager-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041460","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-libvirt-machine-controllers-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780462410","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-machine-api-provider-aws-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040278","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-machine-api-provider-azure-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040161","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-machine-api-provider-gcp-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040359","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-machine-api-provider-openstack-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040470","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-machine-api-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780045070","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-machine-config-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780384569","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-monitoring-plugin-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780503846","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-multus-admission-controller-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040131","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-multus-cni-microshift-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041461","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-multus-cni-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040876","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-multus-networkpolicy-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043841","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-multus-route-override-cni-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040139","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-multus-whereabouts-ipam-cni-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043162","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-must-gather-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780456062","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-network-interface-bond-cni-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040160","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-network-metrics-daemon-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043151","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-nutanix-cloud-controller-manager-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040143","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-nutanix-machine-controllers-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040249","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-oauth-apiserver-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043773","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-oauth-proxy-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041035","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-oauth-server-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041508","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-olm-catalogd-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041774","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-olm-operator-controller-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780045015","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-openshift-apiserver-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044994","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-openshift-controller-manager-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041206","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-openshift-state-metrics-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044407","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-openstack-cinder-csi-driver-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040576","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-openstack-cinder-csi-driver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044692","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-openstack-cloud-controller-manager-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044330","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-openstack-cluster-api-controllers-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780045024","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-operator-framework-tools-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780365324","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-operator-lifecycle-manager-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780365279","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-operator-marketplace-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780042274","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-operator-registry-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780365284","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-ovn-kubernetes-microshift-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780046352","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-ovn-kubernetes-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780056937","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-pod-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040715","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-powervs-block-csi-driver-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041386","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-powervs-block-csi-driver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040612","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-powervs-cloud-controller-manager-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780293328","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-powervs-machine-controllers-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041754","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-prometheus-alertmanager-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040283","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-prometheus-config-reloader-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041841","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-prometheus-node-exporter-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043953","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-prometheus-operator-admission-webhook-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043165","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-prometheus-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780503869","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-prometheus-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040471","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-prom-label-proxy-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044248","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-service-ca-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780041841","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-telemeter-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780043624","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-tests-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780466471","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-thanos-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780320077","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-tools-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780462550","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-vmware-vsphere-csi-driver-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040430","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-vmware-vsphere-csi-driver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040095","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-vsphere-cloud-controller-manager-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040502","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-vsphere-cluster-api-controllers-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040511","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-vsphere-csi-driver-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040430","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-vsphere-csi-driver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040095","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-vsphere-csi-driver-syncer-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040119","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-vsphere-problem-detector-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780040106","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ovirt-csi-driver-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044606","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ovirt-csi-driver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1780044910","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-docker-builder-rhel9","cpes":["cpe:/a:redhat:service_mesh:2"]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 2","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-golang-builder-container","cpes":["cpe:/a:redhat:service_mesh:2"]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-service-mesh/istio-cni-rhel8","cpes":["cpe:/a:redhat:service_mesh:2"]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-service-mesh/istio-rhel8-operator","cpes":["cpe:/a:redhat:service_mesh:2"]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-service-mesh/pilot-rhel8","cpes":["cpe:/a:redhat:service_mesh:2"]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-service-mesh/proxyv2-rhel9","cpes":["cpe:/a:redhat:service_mesh:2"]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-service-mesh/ratelimit-rhel8","cpes":["cpe:/a:redhat:service_mesh:2"]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 3","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-docker-builder-rhel9","cpes":["cpe:/a:redhat:service_mesh:3"]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 3","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-golang-builder-container","cpes":["cpe:/a:redhat:service_mesh:3"]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 3","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-service-mesh/istio-cni-rhel9","cpes":["cpe:/a:redhat:service_mesh:3"]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 3","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-service-mesh/istio-pilot-rhel9","cpes":["cpe:/a:redhat:service_mesh:3"]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 3","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-service-mesh/istio-proxyv2-rhel9","cpes":["cpe:/a:redhat:service_mesh:3"]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 3","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-service-mesh/istio-rhel9-operator","cpes":["cpe:/a:redhat:service_mesh:3"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang1.25","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang1.26","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-golang-builder-container","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Virtualization 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-docker-builder-rhel9","cpes":["cpe:/a:redhat:container_native_virtualization:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Virtualization 4","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-golang-builder-container","cpes":["cpe:/a:redhat:container_native_virtualization:4"]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","baseScore":9.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T03:55:58.901718Z","id":"CVE-2026-27140","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","description":[{"lang":"en","value":"CWE-641"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*","versionEndExcluding":"1.25.9","matchCriteriaId":"C6C9C072-9817-402D-877F-F83584B07017"},{"vulnerable":true,"criteria":"cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*","versionStartIncluding":"1.26.0","versionEndExcluding":"1.26.2","matchCriteriaId":"39FE9BAF-55E9-43AA-B14E-239E7EF1D65D"}]}]}],"references":[{"url":"https://go.dev/cl/763768","source":"security@golang.org","tags":["Release Notes"]},{"url":"https://go.dev/issue/78335","source":"security@golang.org","tags":["Issue Tracking"]},{"url":"https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","source":"security@golang.org","tags":["Mailing List","Release Notes"]},{"url":"https://pkg.go.dev/vuln/GO-2026-4871","source":"security@golang.org","tags":["Vendor Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:10217","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:10219","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:10704","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16021","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16024","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16494","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16497","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16498","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16694","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16697","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16698","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:23246","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:25182","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:34099","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-27140","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2456341","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27140.json","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}]}},{"cve":{"id":"CVE-2026-27143","sourceIdentifier":"security@golang.org","published":"2026-04-08T02:16:03.017","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption."},{"lang":"es","value":"La aritmética sobre variables de inducción en bucles no se comprobó correctamente para subdesbordamiento o desbordamiento. Como resultado, el compilador permitiría que ocurriera una indexación inválida en tiempo de ejecución, lo que podría llevar a corrupción de memoria."}],"affected":[{"source":"security@golang.org","affectedData":[{"vendor":"Go toolchain","product":"cmd/compile","defaultStatus":"unaffected","collectionURL":"https://pkg.go.dev","packageName":"cmd/compile","versions":[{"version":"0","lessThan":"1.25.9","versionType":"semver","status":"affected"},{"version":"1.26.0-0","lessThan":"1.26.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-13T17:50:24.131708Z","id":"CVE-2026-27143","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*","versionEndExcluding":"1.25.9","matchCriteriaId":"C6C9C072-9817-402D-877F-F83584B07017"},{"vulnerable":true,"criteria":"cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*","versionStartIncluding":"1.26.0","versionEndExcluding":"1.26.2","matchCriteriaId":"39FE9BAF-55E9-43AA-B14E-239E7EF1D65D"}]}]}],"references":[{"url":"https://go.dev/cl/763765","source":"security@golang.org","tags":["Patch"]},{"url":"https://go.dev/issue/78333","source":"security@golang.org","tags":["Issue Tracking"]},{"url":"https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","source":"security@golang.org","tags":["Mailing List","Release Notes"]},{"url":"https://pkg.go.dev/vuln/GO-2026-4868","source":"security@golang.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27144","sourceIdentifier":"security@golang.org","published":"2026-04-08T02:16:03.130","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented the compiler from making the correct determination about non-overlapping moves, potentially leading to memory corruption at runtime."},{"lang":"es","value":"El compilador está diseñado para desenvolver los punteros que son los operandos de un movimiento de memoria; una conversión de interfaz no operativa impidió que el compilador hiciera la determinación correcta sobre los movimientos no superpuestos, lo que podría llevar a corrupción de memoria en tiempo de ejecución."}],"affected":[{"source":"security@golang.org","affectedData":[{"vendor":"Go toolchain","product":"cmd/compile","defaultStatus":"unaffected","collectionURL":"https://pkg.go.dev","packageName":"cmd/compile","versions":[{"version":"0","lessThan":"1.25.9","versionType":"semver","status":"affected"},{"version":"1.26.0-0","lessThan":"1.26.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.2},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-13T17:49:47.300247Z","id":"CVE-2026-27144","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-843"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*","versionEndExcluding":"1.25.9","matchCriteriaId":"C6C9C072-9817-402D-877F-F83584B07017"},{"vulnerable":true,"criteria":"cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*","versionStartIncluding":"1.26.0","versionEndExcluding":"1.26.2","matchCriteriaId":"39FE9BAF-55E9-43AA-B14E-239E7EF1D65D"}]}]}],"references":[{"url":"https://go.dev/cl/763764","source":"security@golang.org","tags":["Patch"]},{"url":"https://go.dev/issue/78371","source":"security@golang.org","tags":["Issue Tracking"]},{"url":"https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","source":"security@golang.org","tags":["Mailing List","Release Notes"]},{"url":"https://pkg.go.dev/vuln/GO-2026-4867","source":"security@golang.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-32280","sourceIdentifier":"security@golang.org","published":"2026-04-08T02:16:03.247","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls."},{"lang":"es","value":"Durante la construcción de la cadena, la cantidad de trabajo que se realiza no se limita correctamente cuando un gran número de certificados intermedios se pasan en VerifyOptions.Intermediates, lo que puede llevar a una denegación de servicio. Esto afecta tanto a los usuarios directos de crypto/x509 como a los usuarios de crypto/tls."}],"affected":[{"source":"security@golang.org","affectedData":[{"vendor":"Go standard library","product":"crypto/x509","defaultStatus":"unaffected","collectionURL":"https://pkg.go.dev","packageName":"crypto/x509","programRoutines":[{"name":"Certificate.buildChains"},{"name":"Certificate.Verify"}],"versions":[{"version":"0","lessThan":"1.25.9","versionType":"semver","status":"affected"},{"version":"1.26.0-0","lessThan":"1.26.2","versionType":"semver","status":"affected"}]}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","affectedData":[{"vendor":"Red Hat","product":"Cryostat 4 on RHEL 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"cryostat/cryostat-storage-rhel9","cpes":["cpe:/a:redhat:cryostat:4::el9"],"versions":[{"version":"4.1.1-7","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"HawtIO HawtIO 4.4.0","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"hawtio","cpes":["cpe:/a:redhat:apache_camel_hawtio:4.4::el9"],"versions":[{"version":"operator-container","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.5 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"automation-gateway-proxy","cpes":["cpe:/a:redhat:ansible_automation_platform:2.5::el8"],"versions":[{"version":"0:2.5.10-6.el8ap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.5 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"receptor","cpes":["cpe:/a:redhat:ansible_automation_platform:2.5::el8"],"versions":[{"version":"0:1.6.5-1.el8ap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.5 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"automation-gateway-proxy","cpes":["cpe:/a:redhat:ansible_automation_platform:2.5::el9"],"versions":[{"version":"0:2.6.14-3.el9ap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.5 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"receptor","cpes":["cpe:/a:redhat:ansible_automation_platform:2.5::el9"],"versions":[{"version":"0:1.6.5-1.el9ap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.6 for RHEL 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"receptor","cpes":["cpe:/a:redhat:ansible_automation_platform:2.6::el10"],"versions":[{"version":"0:1.6.5-1.el10ap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.6 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"automation-gateway-proxy","cpes":["cpe:/a:redhat:ansible_automation_platform:2.6::el9"],"versions":[{"version":"0:2.6.14-3.el9ap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.6 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"receptor","cpes":["cpe:/a:redhat:ansible_automation_platform:2.6::el9"],"versions":[{"version":"0:1.6.5-1.el9ap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"golang","cpes":["cpe:/o:redhat:enterprise_linux:10.1"],"versions":[{"version":"0:1.25.9-3.el10_1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"git-lfs","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:3.7.1-4.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"opentelemetry-collector","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:0.144.0-2.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"golang-github-openprinting-ipp-usb","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:0.9.27-7.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhc","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"1:0.3.8-5.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"go-fdo-client","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:1.0.0-4.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"go-fdo-server","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:1.0.1-2.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"delve","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:1.26.1-2.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"podman","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"7:5.8.2-3.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"yggdrasil","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:0.4.9-5.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"skopeo","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"2:1.22.2-2.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"buildah","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"2:1.43.1-2.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:1.25.9-1.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gvisor-tap-vsock","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"6:0.8.5-2.el10_0.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"grafana-pcp","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:5.2.2-6.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"grafana","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:10.2.6-24.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"yggdrasil","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:0.4.7-4.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang-github-openprinting-ipp-usb","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:0.9.27-3.el10_0.4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhc-worker-playbook","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:0.2.3-5.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"git-lfs","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:3.6.1-2.el10_0.4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"opentelemetry-collector","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:0.144.0-2.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"osbuild-composer","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:134.1-7.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"buildah","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"2:1.39.9-1.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"podman","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"6:5.4.0-15.el10_0.2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"skopeo","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"2:1.18.1-3.el10_0.2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhc","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"1:0.3.2-4.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"delve","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:1.25.2-4.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7 Extended Lifecycle Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"host-metering","cpes":["cpe:/o:redhat:rhel_els:7"],"versions":[{"version":"0:1.4.0-7.el7_9","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"go-toolset:rhel8","cpes":["cpe:/a:redhat:enterprise_linux:8"],"versions":[{"version":"8100020260422204008.a3795dee","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"grafana","cpes":["cpe:/a:redhat:enterprise_linux:8"],"versions":[{"version":"0:9.2.10-30.el8_10","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"grafana-pcp","cpes":["cpe:/a:redhat:enterprise_linux:8"],"versions":[{"version":"0:5.1.1-14.el8_10","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhc","cpes":["cpe:/a:redhat:enterprise_linux:8"],"versions":[{"version":"1:0.2.5-7.el8_10","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"git-lfs","cpes":["cpe:/a:redhat:enterprise_linux:8"],"versions":[{"version":"0:3.4.1-10.el8_10","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"container-tools:rhel8","cpes":["cpe:/a:redhat:enterprise_linux:8"],"versions":[{"version":"8100020260520103055.afee755d","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"container-tools:rhel8","cpes":["cpe:/a:redhat:rhel_aus:8.6"],"versions":[{"version":"8060020260515174849.ad008a3a","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.6 Telecommunications Update Service","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"container-tools:rhel8","cpes":["cpe:/a:redhat:rhel_tus:8.6"],"versions":[{"version":"8060020260515174849.ad008a3a","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"container-tools:rhel8","cpes":["cpe:/a:redhat:rhel_e4s:8.6"],"versions":[{"version":"8060020260515174849.ad008a3a","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"golang","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"0:1.25.9-1.el9_7","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"git-lfs","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"0:3.6.1-8.el9_7.1","lessThan":"*","versionType":"rpm","status":"unaffected"},{"version":"0:3.7.1-4.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"opentelemetry-collector","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"0:0.144.0-2.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhc","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"1:0.2.7-7.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"podman","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"6:5.8.2-3.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"skopeo","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"2:1.22.2-6.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"buildah","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"2:1.43.1-2.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"runc","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"4:1.4.2-2.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"containernetworking-plugins","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"1:1.9.0-3.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.4 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"opentelemetry-collector","cpes":["cpe:/a:redhat:rhel_eus:9.4"],"versions":[{"version":"0:0.144.0-2.el9_4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"buildah","cpes":["cpe:/a:redhat:rhel_e4s:9.4"],"versions":[{"version":"2:1.33.15-1.el9_4.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"podman","cpes":["cpe:/a:redhat:rhel_e4s:9.4"],"versions":[{"version":"4:4.9.4-20.el9_4.3","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"skopeo","cpes":["cpe:/a:redhat:rhel_e4s:9.4"],"versions":[{"version":"2:1.14.6-1.el9_4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"0:1.25.9-1.el9_6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"podman","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"5:5.4.0-20.el9_6.3","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"opentelemetry-collector","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"0:0.144.0-2.el9_6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"git-lfs","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"0:3.6.1-2.el9_6.4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"grafana-pcp","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"0:5.1.1-14.el9_6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"grafana","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"0:10.2.6-21.el9_6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"buildah","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"2:1.39.9-1.el9_6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"containernetworking-plugins","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"1:1.6.2-3.el9_6.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"skopeo","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"2:1.18.1-5.el9_6.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"osbuild-composer","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"0:132.2-7.el9_6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhc","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"1:0.2.7-1.el9_6.4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gvisor-tap-vsock","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"6:0.8.5-2.el9_6.2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.14","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"containernetworking-plugins","cpes":["cpe:/a:redhat:openshift:4.14::el8"],"versions":[{"version":"1:1.4.0-6.rhaos4.14.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.14","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"podman","cpes":["cpe:/a:redhat:openshift:4.14::el8"],"versions":[{"version":"3:4.4.1-25.rhaos4.14.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.14","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"skopeo","cpes":["cpe:/a:redhat:openshift:4.14::el8"],"versions":[{"version":"2:1.11.3-7.rhaos4.14.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.15","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"containernetworking-plugins","cpes":["cpe:/a:redhat:openshift:4.15::el8"],"versions":[{"version":"1:1.4.0-6.rhaos4.15.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.15","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"skopeo","cpes":["cpe:/a:redhat:openshift:4.15::el8"],"versions":[{"version":"2:1.11.3-8.rhaos4.15.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.17","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"containernetworking-plugins","cpes":["cpe:/a:redhat:openshift:4.17::el8"],"versions":[{"version":"1:1.4.0-9.rhaos4.17.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.17","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ose-aws-ecr-image-credential-provider","cpes":["cpe:/a:redhat:openshift:4.17::el8"],"versions":[{"version":"0:4.17.0-202606022046.p2.g144bace.assembly.stream.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.17","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ose-azure-acr-image-credential-provider","cpes":["cpe:/a:redhat:openshift:4.17::el8"],"versions":[{"version":"0:4.17.0-202606171749.p2.g5bcfbfd.assembly.stream.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.17","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ose-gcp-gcr-image-credential-provider","cpes":["cpe:/a:redhat:openshift:4.17::el8"],"versions":[{"version":"0:4.17.0-202606022046.p2.g8ce997d.assembly.stream.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.17","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"podman","cpes":["cpe:/a:redhat:openshift:4.17::el8"],"versions":[{"version":"5:5.2.2-19.rhaos4.17.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.17","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"runc","cpes":["cpe:/a:redhat:openshift:4.17::el8"],"versions":[{"version":"4:1.2.9-5.rhaos4.17.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.17","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"skopeo","cpes":["cpe:/a:redhat:openshift:4.17::el8"],"versions":[{"version":"2:1.16.1-6.rhaos4.17.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.18","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"containernetworking-plugins","cpes":["cpe:/a:redhat:openshift:4.18::el8"],"versions":[{"version":"1:1.4.0-9.rhaos4.18.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.18","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"podman","cpes":["cpe:/a:redhat:openshift:4.18::el8"],"versions":[{"version":"5:5.2.2-12.rhaos4.18.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.18","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"runc","cpes":["cpe:/a:redhat:openshift:4.18::el8"],"versions":[{"version":"4:1.2.9-6.rhaos4.18.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.18","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"skopeo","cpes":["cpe:/a:redhat:openshift:4.18::el8"],"versions":[{"version":"2:1.16.1-5.rhaos4.18.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.18","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ose-aws-ecr-image-credential-provider","cpes":["cpe:/a:redhat:openshift:4.18::el8"],"versions":[{"version":"0:4.18.0-202606021914.p2.gc395190.assembly.stream.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.18","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ose-azure-acr-image-credential-provider","cpes":["cpe:/a:redhat:openshift:4.18::el8"],"versions":[{"version":"0:4.18.0-202606021914.p2.g9c24d76.assembly.stream.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.18","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ose-gcp-gcr-image-credential-provider","cpes":["cpe:/a:redhat:openshift:4.18::el8"],"versions":[{"version":"0:4.18.0-202606021914.p2.g6ea2356.assembly.stream.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"runc","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"4:1.2.5-6.rhaos4.19.el9","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"skopeo","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"2:1.18.1-6.rhaos4.19.el9","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 17.1 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"etcd","cpes":["cpe:/a:redhat:openstack:17.1::el9"],"versions":[{"version":"0:3.4.26-9.5.el9ost","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenStack Services on OpenShift 18.0","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"golang-github-openstack-k8s-operators-os-diff","cpes":["cpe:/a:redhat:openstack:18.0::el9"],"versions":[{"version":"0:0.1.1-18.0.20260602234716.a95ae05.el9ost","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.16 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"yggdrasil-worker-forwarder","cpes":["cpe:/a:redhat:satellite:6.16::el8"],"versions":[{"version":"0:0.0.3-5.el8sat","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.16 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"yggdrasil-worker-forwarder","cpes":["cpe:/a:redhat:satellite:6.16::el9"],"versions":[{"version":"0:0.0.3-5.el9sat","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.19 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"yggdrasil-worker-forwarder","cpes":["cpe:/a:redhat:satellite:6.19::el9"],"versions":[{"version":"0:0.0.3-5.el9sat","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"RHEM 1.0 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"flightctl","cpes":["cpe:/a:redhat:edge_manager:1.0::el9"],"versions":[{"version":"0:1.0.3-1.el9em","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"RHEM 1.1 for RHEL 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"flightctl","cpes":["cpe:/a:redhat:edge_manager:1.1::el10"],"versions":[{"version":"0:1.1.3-1.el10em","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"RHEM 1.1 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"flightctl","cpes":["cpe:/a:redhat:edge_manager:1.1:el9"],"versions":[{"version":"0:1.1.3-1.el9em","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Compliance Operator 1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"compliance/openshift-compliance-operator-bundle","cpes":["cpe:/a:redhat:openshift_compliance_operator:1::el9"],"versions":[{"version":"1781605005","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Custom Metric Autoscaler 2.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9","cpes":["cpe:/a:redhat:openshift_custom_metrics_autoscaler:2.19::el9"],"versions":[{"version":"1780101239","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Logging for Red Hat OpenShift 6.0","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-logging/eventrouter-rhel9","cpes":["cpe:/a:redhat:logging:6.0::el9"],"versions":[{"version":"1781192891","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Logging Subsystem for Red Hat OpenShift 6.4","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-logging/eventrouter-rhel9","cpes":["cpe:/a:redhat:logging:6.4::el9"],"versions":[{"version":"1780051640","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"mirror registry for Red Hat OpenShift 2.0","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift/mirror-registry-rhel8","cpes":["cpe:/a:redhat:mirror_registry:2.0::el8"],"versions":[{"version":"1782177012","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/assisted-service-9-rhel9","cpes":["cpe:/a:redhat:multicluster_engine:2.10::el9"],"versions":[{"version":"1780106633","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.11.0","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/assisted-service-9-rhel9","cpes":["cpe:/a:redhat:multicluster_engine:2.11::el9"],"versions":[{"version":"1779991600","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.17","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/assisted-service-9-rhel9","cpes":["cpe:/a:redhat:multicluster_engine:2.17::el9"],"versions":[{"version":"1780297056","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.6","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/assisted-service-8-rhel8","cpes":["cpe:/a:redhat:multicluster_engine:2.6::el8"],"versions":[{"version":"1782203678","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.6","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/assisted-service-9-rhel9","cpes":["cpe:/a:redhat:multicluster_engine:2.6::el9"],"versions":[{"version":"1782207490","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.8","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/assisted-service-8-rhel8","cpes":["cpe:/a:redhat:multicluster_engine:2.8::el8"],"versions":[{"version":"1779910504","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.8","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/assisted-service-9-rhel9","cpes":["cpe:/a:redhat:multicluster_engine:2.8::el9"],"versions":[{"version":"1779910129","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Multicluster Global Hub 1.4.5","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-globalhub/multicluster-globalhub-agent-rhel9","cpes":["cpe:/a:redhat:multicluster_globalhub:1.4::el9"],"versions":[{"version":"1779838819","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Multicluster Global Hub 1.5.6","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-globalhub/multicluster-globalhub-agent-rhel9","cpes":["cpe:/a:redhat:multicluster_globalhub:1.5::el9"],"versions":[{"version":"1779828691","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Multicluster Global Hub 1.6.2","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-globalhub/multicluster-globalhub-agent-rhel9","cpes":["cpe:/a:redhat:multicluster_globalhub:1.6::el9"],"versions":[{"version":"1780320809","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Network Observability (NETOBSERV) 1.11.2","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"network-observability/network-observability-cli-rhel9","cpes":["cpe:/a:redhat:network_observ_optr:1.11::el9"],"versions":[{"version":"1778508501","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"OpenShift API for Data Protection 1.4","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"oadp/oadp-velero-rhel9","cpes":["cpe:/a:redhat:openshift_api_data_protection:1.4::el9"],"versions":[{"version":"1779809598","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"OpenShift API for Data Protection 1.5","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"oadp/oadp-velero-rhel9","cpes":["cpe:/a:redhat:openshift_api_data_protection:1.5::el9"],"versions":[{"version":"1779808027","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.14","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhacm2/subctl-rhel9","cpes":["cpe:/a:redhat:acm:2.14::el9"],"versions":[{"version":"1780238563","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Security 4.9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"advanced-cluster-security/rhacs-main-rhel8","cpes":["cpe:/a:redhat:advanced_cluster_security:4.9::el8"],"versions":[{"version":"1777986630","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Security 4.9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"advanced-cluster-security/rhacs-rhel8-operator","cpes":["cpe:/a:redhat:advanced_cluster_security:4.9::el8"],"versions":[{"version":"1777986630","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Security 4.9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"advanced-cluster-security/rhacs-roxctl-rhel8","cpes":["cpe:/a:redhat:advanced_cluster_security:4.9::el8"],"versions":[{"version":"1777986630","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Security 4.9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"advanced-cluster-security/rhacs-scanner-v4-rhel8","cpes":["cpe:/a:redhat:advanced_cluster_security:4.9::el8"],"versions":[{"version":"1777986630","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Security 4.9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"advanced-cluster-security/rhacs-scanner-rhel8","cpes":["cpe:/a:redhat:advanced_cluster_security:4.9::el8"],"versions":[{"version":"1782891812","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Security 4.9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"advanced-cluster-security/rhacs-scanner-slim-rhel8","cpes":["cpe:/a:redhat:advanced_cluster_security:4.9::el8"],"versions":[{"version":"1782891812","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Security for Kubernetes 4.10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"advanced-cluster-security/rhacs-main-rhel8","cpes":["cpe:/a:redhat:advanced_cluster_security:4.10::el8"],"versions":[{"version":"1777976489","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Security for Kubernetes 4.10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"advanced-cluster-security/rhacs-rhel8-operator","cpes":["cpe:/a:redhat:advanced_cluster_security:4.10::el8"],"versions":[{"version":"1777976489","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Security for Kubernetes 4.10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"advanced-cluster-security/rhacs-roxctl-rhel8","cpes":["cpe:/a:redhat:advanced_cluster_security:4.10::el8"],"versions":[{"version":"1777976489","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Security for Kubernetes 4.10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"advanced-cluster-security/rhacs-scanner-v4-rhel8","cpes":["cpe:/a:redhat:advanced_cluster_security:4.10::el8"],"versions":[{"version":"1777976489","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Security for Kubernetes 4.10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"advanced-cluster-security/rhacs-scanner-rhel8","cpes":["cpe:/a:redhat:advanced_cluster_security:4.10::el8"],"versions":[{"version":"1778755463","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Security for Kubernetes 4.10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"advanced-cluster-security/rhacs-scanner-slim-rhel8","cpes":["cpe:/a:redhat:advanced_cluster_security:4.10::el8"],"versions":[{"version":"1778755463","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.6","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"ansible-automation-platform-26/receptor-rhel9","cpes":["cpe:/a:redhat:ansible_automation_platform:2.6::el9"],"versions":[{"version":"1777391542","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Developer Hub 1.8","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhdh/rhdh-rhel9-operator","cpes":["cpe:/a:redhat:rhdh:1.8::el9"],"versions":[{"version":"1779841292","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Developer Hub 1.9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhdh/rhdh-rhel9-operator","cpes":["cpe:/a:redhat:rhdh:1.9::el9"],"versions":[{"version":"1777902709","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Edge Manager 1.0","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhem/flightctl-ui-rhel9","cpes":["cpe:/a:redhat:edge_manager:1.0::el9"],"versions":[{"version":"1783502438","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Edge Manager 1.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhem/flightctl-ui-rhel10","cpes":["cpe:/a:redhat:edge_manager:1.1::el10"],"versions":[{"version":"1784194574","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Edge Manager 1.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhem/flightctl-ui-rhel9","cpes":["cpe:/a:redhat:edge_manager:1.1::el9"],"versions":[{"version":"1784127736","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Lightspeed (formerly Insights) for Runtimes 1.0","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator","cpes":["cpe:/a:redhat:lightspeed_for_runtimes:1.0::el9"],"versions":[{"version":"1.0.3-1779996197","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Migration Toolkit 1.8","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhmtc/openshift-migration-registry-rhel8","cpes":["cpe:/a:redhat:rhmt:1.8::el8"],"versions":[{"version":"1783914276","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI 2.25","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhoai/odh-rhel9-operator","cpes":["cpe:/a:redhat:openshift_ai:2.25::el9"],"versions":[{"version":"1780513840","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Builds 1.7.4","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-builds/openshift-builds-waiters-rhel9","cpes":["cpe:/a:redhat:openshift_builds:1.7::el9"],"versions":[{"version":"1780374228","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Dev Spaces 3.28","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"devspaces/udi-rhel9","cpes":["cpe:/a:redhat:openshift_devspaces:3.28::el9"],"versions":[{"version":"1779829736","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.9.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/opentelemetry-collector-rhel9","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.9::el9"],"versions":[{"version":"1778056267","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.9.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/opentelemetry-rhel9-operator","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.9::el9"],"versions":[{"version":"1778056233","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.9.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/opentelemetry-target-allocator-rhel9","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.9::el9"],"versions":[{"version":"1778056245","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.9.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/tempo-rhel9","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.9::el9"],"versions":[{"version":"1776435680","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 2.6","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/istio-cni-rhel8","cpes":["cpe:/a:redhat:service_mesh:2.6::el8"],"versions":[{"version":"1777374598","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 2.6","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/istio-rhel8-operator","cpes":["cpe:/a:redhat:service_mesh:2.6::el8"],"versions":[{"version":"1777320087","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 2.6","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/pilot-rhel8","cpes":["cpe:/a:redhat:service_mesh:2.6::el8"],"versions":[{"version":"1777319850","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 2.6","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/ratelimit-rhel8","cpes":["cpe:/a:redhat:service_mesh:2.6::el8"],"versions":[{"version":"1777319773","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 2.6","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/kiali-rhel8","cpes":["cpe:/a:redhat:service_mesh:2.6::el8"],"versions":[{"version":"1778191378","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 3.0","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/istio-cni-rhel9","cpes":["cpe:/a:redhat:service_mesh:3.0::el9"],"versions":[{"version":"1777883393","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 3.0","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/istio-pilot-rhel9","cpes":["cpe:/a:redhat:service_mesh:3.0::el9"],"versions":[{"version":"1777883471","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 3.0","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/istio-rhel9-operator","cpes":["cpe:/a:redhat:service_mesh:3.0::el9"],"versions":[{"version":"1778149127","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 3.0","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/kiali-rhel9","cpes":["cpe:/a:redhat:service_mesh:3.0::el9"],"versions":[{"version":"1778164208","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 3.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/istio-cni-rhel9","cpes":["cpe:/a:redhat:service_mesh:3.1::el9"],"versions":[{"version":"1777884045","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 3.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/istio-pilot-rhel9","cpes":["cpe:/a:redhat:service_mesh:3.1::el9"],"versions":[{"version":"1777884022","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 3.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/istio-rhel9-operator","cpes":["cpe:/a:redhat:service_mesh:3.1::el9"],"versions":[{"version":"1778149657","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 3.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/kiali-rhel9","cpes":["cpe:/a:redhat:service_mesh:3.1::el9"],"versions":[{"version":"1778164042","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 3.2","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/istio-cni-rhel9","cpes":["cpe:/a:redhat:service_mesh:3.2::el9"],"versions":[{"version":"1778007597","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 3.2","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/istio-pilot-rhel9","cpes":["cpe:/a:redhat:service_mesh:3.2::el9"],"versions":[{"version":"1778007366","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 3.2","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/istio-rhel9-operator","cpes":["cpe:/a:redhat:service_mesh:3.2::el9"],"versions":[{"version":"1778150474","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 3.2","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/kiali-rhel9","cpes":["cpe:/a:redhat:service_mesh:3.2::el9"],"versions":[{"version":"1778163909","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 3.3","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/istio-cni-rhel9","cpes":["cpe:/a:redhat:service_mesh:3.3::el9"],"versions":[{"version":"1778007548","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 3.3","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/istio-pilot-rhel9","cpes":["cpe:/a:redhat:service_mesh:3.3::el9"],"versions":[{"version":"1778007569","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 3.3","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/istio-rhel9-operator","cpes":["cpe:/a:redhat:service_mesh:3.3::el9"],"versions":[{"version":"1778151060","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Service Mesh 3.3","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-service-mesh/kiali-rhel9","cpes":["cpe:/a:redhat:service_mesh:3.3::el9"],"versions":[{"version":"1778163986","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenStack Services on OpenShift 18.0","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhoso-operators/sg-core-rhel9","cpes":["cpe:/a:redhat:openstack:18.0::el9"],"versions":[{"version":"1782140297","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.10::el8"],"versions":[{"version":"1779822261","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.14","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.14::el8"],"versions":[{"version":"1779689392","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.15","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.15::el8"],"versions":[{"version":"1780891395","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.16","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel9","cpes":["cpe:/a:redhat:quay:3.16::el9"],"versions":[{"version":"1779204086","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.17","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel9","cpes":["cpe:/a:redhat:quay:3.17::el9"],"versions":[{"version":"1779922205","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.9::el8"],"versions":[{"version":"1779811473","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Trusted Artifact Signer 1.3","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhtas/client-server-rhel9","cpes":["cpe:/a:redhat:trusted_artifact_signer:1.3::el9"],"versions":[{"version":"1780399582","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Web Terminal 1.11","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"web-terminal/web-terminal-exec-rhel9","cpes":["cpe:/a:redhat:webterminal:1.11::el9"],"versions":[{"version":"1780423339","lessThan":"*","versionType":"rpm","status":"unaffected"},{"version":"1784296203","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Web Terminal 1.12","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"web-terminal/web-terminal-exec-rhel9","cpes":["cpe:/a:redhat:webterminal:1.12::el9"],"versions":[{"version":"1780425077","lessThan":"*","versionType":"rpm","status":"unaffected"},{"version":"1784247610","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Web Terminal 1.13","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"web-terminal/web-terminal-exec-rhel9","cpes":["cpe:/a:redhat:webterminal:1.13::el9"],"versions":[{"version":"1780425080","lessThan":"*","versionType":"rpm","status":"unaffected"},{"version":"1784296127","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Web Terminal 1.14","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"web-terminal/web-terminal-exec-rhel9","cpes":["cpe:/a:redhat:webterminal:1.14::el9"],"versions":[{"version":"1780424928","lessThan":"*","versionType":"rpm","status":"unaffected"},{"version":"1784296114","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Web Terminal 1.15","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"web-terminal/web-terminal-exec-rhel9","cpes":["cpe:/a:redhat:webterminal:1.15::el9"],"versions":[{"version":"1780424829","lessThan":"*","versionType":"rpm","status":"unaffected"},{"version":"1784296033","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Service Telemetry Framework 1.5","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"stf/sg-core-rhel9","cpes":["cpe:/a:redhat:stf:1.5::el9"],"versions":[{"version":"1777452570","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Assisted Installer for Red Hat OpenShift Container Platform 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhai/assisted-installer-rhel9","cpes":["cpe:/a:redhat:assisted_installer:2"]},{"vendor":"Red Hat","product":"cert-manager Operator for Red Hat OpenShift","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"cert-manager/jetstack-cert-manager-rhel9","cpes":["cpe:/a:redhat:cert_manager:1"]},{"vendor":"Red Hat","product":"Confidential Compute Attestation","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"build-of-trustee/trustee-rhel9-operator","cpes":["cpe:/a:redhat:confidential_compute_attestation:1"]},{"vendor":"Red Hat","product":"Confidential Compute Attestation","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-sandboxed-containers/osc-monitor-rhel9","cpes":["cpe:/a:redhat:confidential_compute_attestation:1"]},{"vendor":"Red Hat","product":"Deployment Validation Operator","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"dvo/deployment-validation-rhel8-operator","cpes":["cpe:/a:redhat:deployment_validator_operator"]},{"vendor":"Red Hat","product":"ExternalDNS Operator","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"edo/external-dns-rhel8","cpes":["cpe:/a:redhat:ext_dns_optr:1"]},{"vendor":"Red Hat","product":"ExternalDNS Operator","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"edo/external-dns-rhel9","cpes":["cpe:/a:redhat:ext_dns_optr:1"]},{"vendor":"Red Hat","product":"External Secrets Operator for Red Hat OpenShift","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"external-secrets-operator/external-secrets-rhel9","cpes":["cpe:/a:redhat:external_secrets_operator:1"]},{"vendor":"Red Hat","product":"Fence Agents Remediation Operator","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"workload-availability/fence-agents-remediation-rhel8-operator","cpes":["cpe:/a:redhat:workload_availability_far:0"]},{"vendor":"Red Hat","product":"File Integrity Operator","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"compliance/openshift-compliance-operator-bundle","cpes":["cpe:/a:redhat:openshift_file_integrity_operator:1"]},{"vendor":"Red Hat","product":"Gatekeeper 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gatekeeper/gatekeeper-rhel9-operator","cpes":["cpe:/a:redhat:gatekeeper:3"]},{"vendor":"Red Hat","product":"Logging Subsystem for Red Hat OpenShift","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-logging/eventrouter-rhel9","cpes":["cpe:/a:redhat:logging:5"]},{"vendor":"Red Hat","product":"Logging Subsystem for Red Hat OpenShift","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-logging/logging-loki-rhel9","cpes":["cpe:/a:redhat:logging:5"]},{"vendor":"Red Hat","product":"Logical Volume Manager Storage","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"lvms4/lvms-rhel9-operator","cpes":["cpe:/a:redhat:lvms:4"]},{"vendor":"Red Hat","product":"Logical Volume Manager Storage","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"lvms4/topolvm-rhel8","cpes":["cpe:/a:redhat:lvms:4"]},{"vendor":"Red Hat","product":"Logical Volume Manager Storage","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"lvms4/topolvm-rhel9","cpes":["cpe:/a:redhat:lvms:4"]},{"vendor":"Red Hat","product":"Machine Deletion Remediation Operator","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"workload-availability/machine-deletion-remediation-rhel8-operator","cpes":["cpe:/a:redhat:workload_availability_mdr:0"]},{"vendor":"Red Hat","product":"Migration Toolkit for Applications 8","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"mta/mta-cli-rhel9","cpes":["cpe:/a:redhat:migration_toolkit_applications:8"]},{"vendor":"Red Hat","product":"mirror registry for Red Hat OpenShift","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift/mirror-registry-rhel8","cpes":["cpe:/a:redhat:mirror_registry:1"]},{"vendor":"Red Hat","product":"Multicluster Engine for Kubernetes","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"multicluster-engine/discovery-rhel9","cpes":["cpe:/a:redhat:multicluster_engine"]},{"vendor":"Red Hat","product":"Node HealthCheck Operator","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"workload-availability/node-healthcheck-rhel8-operator","cpes":["cpe:/a:redhat:workload_availability_nhc:0"]},{"vendor":"Red Hat","product":"OpenShift Developer Tools and Services","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"helm","cpes":["cpe:/a:redhat:ocp_tools"]},{"vendor":"Red Hat","product":"OpenShift Developer Tools and Services","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ocp-tools-4/jenkins-agent-base-rhel9","cpes":["cpe:/a:redhat:ocp_tools"]},{"vendor":"Red Hat","product":"OpenShift Developer Tools and Services","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ocp-tools-4/jenkins-rhel8","cpes":["cpe:/a:redhat:ocp_tools"]},{"vendor":"Red Hat","product":"OpenShift Lightspeed","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-lightspeed/lightspeed-rhel9-operator","cpes":["cpe:/a:redhat:openshift_lightspeed"]},{"vendor":"Red Hat","product":"OpenShift Pipelines","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-pipelines-client","cpes":["cpe:/a:redhat:openshift_pipelines:1"]},{"vendor":"Red Hat","product":"OpenShift Serverless","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kn-workflow-plugin","cpes":["cpe:/a:redhat:serverless:1"]},{"vendor":"Red Hat","product":"OpenShift Serverless","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-serverless-1/kn-plugin-event-sender-rhel9","cpes":["cpe:/a:redhat:serverless:1"]},{"vendor":"Red Hat","product":"OpenShift Serverless","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-serverless-clients","cpes":["cpe:/a:redhat:serverless:1"]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-service-mesh/openshift-golang-builder","cpes":["cpe:/a:redhat:service_mesh:2"]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-service-mesh/proxyv2-rhel9","cpes":["cpe:/a:redhat:service_mesh:2"]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 3","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-service-mesh/istio-proxyv2-rhel9","cpes":["cpe:/a:redhat:service_mesh:3"]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 3","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-service-mesh/openshift-golang-builder","cpes":["cpe:/a:redhat:service_mesh:3"]},{"vendor":"Red Hat","product":"Power monitoring for Red Hat OpenShift","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-power-monitoring/kepler-rhel9","cpes":["cpe:/a:redhat:openshift_power_monitoring"]},{"vendor":"Red Hat","product":"Red Hat 3scale API Management Platform 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"3scale-amp2/3scale-rhel7-operator","cpes":["cpe:/a:redhat:red_hat_3scale_amp:2"]},{"vendor":"Red Hat","product":"Red Hat 3scale API Management Platform 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"3scale-amp2/3scale-rhel9-operator","cpes":["cpe:/a:redhat:red_hat_3scale_amp:2"]},{"vendor":"Red Hat","product":"Red Hat 3scale API Management Platform 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"3scale-amp26/3scale-operator","cpes":["cpe:/a:redhat:red_hat_3scale_amp:2"]},{"vendor":"Red Hat","product":"Red Hat 3scale API Management Platform 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"3scale-amp26/operator","cpes":["cpe:/a:redhat:red_hat_3scale_amp:2"]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"multicluster-engine/assisted-service-9-rhel9","cpes":["cpe:/a:redhat:acm:2"]},{"vendor":"Red Hat","product":"Red Hat AI Inference Server","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhaiis/vllm-cpu-rhel9","cpes":["cpe:/a:redhat:ai_inference_server:3"]},{"vendor":"Red Hat","product":"Red Hat AI Inference Server","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhaiis/vllm-neuron-rhel9","cpes":["cpe:/a:redhat:ai_inference_server:3"]},{"vendor":"Red Hat","product":"Red Hat AI Inference Server","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhaiis/vllm-tpu-rhel9","cpes":["cpe:/a:redhat:ai_inference_server:3"]},{"vendor":"Red Hat","product":"Red Hat AI Inference Server","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhaii/vllm-neuron-rhel9","cpes":["cpe:/a:redhat:ai_inference_server:3"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-automation-platform/platform-operator-bundle","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"automation-gateway-proxy-openssl30","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"automation-gateway-proxy-openssl32","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python3.11-galaxy-ng","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python3.11-grpcio","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python3.12-galaxy-ng","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python3.12-grpcio","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python3x-grpcio","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python-grpcio","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Certification Program for Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redhat-certification-preflight","cpes":["cpe:/a:redhat:certifications:9"]},{"vendor":"Red Hat","product":"Red Hat Connectivity Link 1","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhcl-1/coredns-rhel9","cpes":["cpe:/a:redhat:connectivity_link:1"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"butane","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"conmon","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"grafana","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"grafana-pcp","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gvisor-tap-vsock","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ignition","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"image-builder","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"osbuild-composer","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhc-worker-playbook","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhel10/bootc-image-builder","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"toolbox","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"trustee","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"trustee-guest-components","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhc","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhc-worker-script","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"osbuild-composer","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"weldr-client","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"butane","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"conmon","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"grafana","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"grafana-pcp","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gvisor-tap-vsock","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ignition","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"image-builder","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"osbuild-composer","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhel9/bootc-image-builder","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"toolbox","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"trustee-guest-components","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"weldr-client","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux AI (RHEL AI) 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang","cpes":["cpe:/a:redhat:enterprise_linux_ai:3"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux AI (RHEL AI) 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhelai3/bootc-aws-cuda-rhel9","cpes":["cpe:/a:redhat:enterprise_linux_ai:3"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux AI (RHEL AI) 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhelai3/bootc-azure-cuda-rhel9","cpes":["cpe:/a:redhat:enterprise_linux_ai:3"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux AI (RHEL AI) 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhelai3/bootc-azure-rocm-rhel9","cpes":["cpe:/a:redhat:enterprise_linux_ai:3"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux AI (RHEL AI) 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhelai3/bootc-cuda-rhel9","cpes":["cpe:/a:redhat:enterprise_linux_ai:3"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux AI (RHEL AI) 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhelai3/bootc-gaudi-rhel9","cpes":["cpe:/a:redhat:enterprise_linux_ai:3"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux AI (RHEL AI) 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhelai3/bootc-gcp-cuda-rhel9","cpes":["cpe:/a:redhat:enterprise_linux_ai:3"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux AI (RHEL AI) 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhelai3/bootc-rocm-rhel9","cpes":["cpe:/a:redhat:enterprise_linux_ai:3"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang1.25","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang1.26","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-ai-gateway-payload-processing-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-cli-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-data-science-pipelines-argo-argoexec-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-data-science-pipelines-operator-controller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-eval-hub-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-feast-operator-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-kf-notebook-controller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-kserve-agent-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-kserve-controller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-kserve-llmisvc-controller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-kserve-router-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-kube-auth-proxy-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-kuberay-operator-controller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-llama-stack-k8s-operator-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-llm-d-batch-gateway-apiserver-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-llm-d-batch-gateway-gc-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-llm-d-batch-gateway-processor-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-llm-d-inference-scheduler-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-llm-d-routing-sidecar-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-maas-api-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-maas-controller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-mlflow-operator-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-ml-pipelines-api-server-v2-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-ml-pipelines-driver-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-ml-pipelines-launcher-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-mod-arch-automl-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-mod-arch-autorag-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-mod-arch-eval-hub-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-mod-arch-gen-ai-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-mod-arch-maas-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-mod-arch-mlflow-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-mod-arch-model-registry-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-model-controller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-model-registry-operator-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-model-registry-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-model-serving-api-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-must-gather-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-notebook-controller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-rhaii-cluster-validator-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-rhel8-operator","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-spark-operator-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-ta-lmes-driver-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-th06-cpu-torch291-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-th06-cuda130-torch291-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-trainer-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-training-operator-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-trustyai-service-operator-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-workload-variant-autoscaler-controller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/rhai-cli-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Cluster Manager CLI","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ocm-cli-clients/ocm-cli-rhel9","cpes":["cpe:/a:redhat:openshift_cluster_manager_cli:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"butane","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"conmon","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"conmon-rs","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"cri-o","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"cri-tools","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang-github-prometheus-promu","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ignition","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kata-containers","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"microshift","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/frr-rhel9","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/openshift-golang-builder","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-ansible-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-ansible-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-sdn-rhel8","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-clients","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-kuryr","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat Openshift Data Foundation 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"odf4/cephcsi-rhel9","cpes":["cpe:/a:redhat:openshift_data_foundation:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Dev Workspaces Operator","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"devworkspace/devworkspace-rhel9-operator","cpes":["cpe:/a:redhat:devworkspace"]},{"vendor":"Red Hat","product":"Red Hat OpenShift for Windows Containers","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4-wincw/windows-machine-config-rhel9-operator","cpes":["cpe:/a:redhat:windows_machine_config"]},{"vendor":"Red Hat","product":"Red Hat OpenShift GitOps","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-gitops-1/dex-rhel8","cpes":["cpe:/a:redhat:openshift_gitops:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift on AWS","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rosa","cpes":["cpe:/a:redhat:openshift_service_on_aws:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Virtualization 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"cnv4/openshift-golang-builder","cpes":["cpe:/a:redhat:container_native_virtualization:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Virtualization 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"container-native-virtualization/virt-api","cpes":["cpe:/a:redhat:container_native_virtualization:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Virtualization 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"container-native-virtualization/virt-api-rhel9","cpes":["cpe:/a:redhat:container_native_virtualization:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Virtualization 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kubevirt","cpes":["cpe:/a:redhat:container_native_virtualization:4"]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 16.2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"etcd","cpes":["cpe:/a:redhat:openstack:16.2"]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 16.2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang-github-infrawatch-apputils","cpes":["cpe:/a:redhat:openstack:16.2"]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 16.2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhosp-rhel8/osp-director-agent","cpes":["cpe:/a:redhat:openstack:16.2"]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 17.1","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"collectd-libpod-stats","cpes":["cpe:/a:redhat:openstack:17.1"]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 17.1","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang-github-infrawatch-apputils","cpes":["cpe:/a:redhat:openstack:17.1"]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 17.1","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhosp-rhel9/osp-director-agent","cpes":["cpe:/a:redhat:openstack:17.1"]},{"vendor":"Red Hat","product":"Red Hat Quay 3","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"quay/quay-builder-rhel8","cpes":["cpe:/a:redhat:quay:3"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"satellite:el8/yggdrasil-worker-forwarder","cpes":["cpe:/a:redhat:satellite:6"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"satellite/iop-vmaas-rhel9","cpes":["cpe:/a:redhat:satellite:6"]},{"vendor":"Red Hat","product":"Red Hat Service Interconnect 1","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"skupper-cli","cpes":["cpe:/a:redhat:service_interconnect:1"]},{"vendor":"Red Hat","product":"Red Hat Service Interconnect 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"skupper-cli","cpes":["cpe:/a:redhat:service_interconnect:2"]},{"vendor":"Red Hat","product":"Security Profiles Operator","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"compliance/openshift-selinuxd-rhel8","cpes":["cpe:/a:redhat:openshift_security_profiles_operator:1"]},{"vendor":"Red Hat","product":"streams for Apache Kafka 3","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang-github-danielqsj-kafka_exporter","cpes":["cpe:/a:redhat:amq_streams:3"]},{"vendor":"Red Hat","product":"Zero Trust Workload Identity Manager","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"zero-trust-workload-identity-manager/spiffe-csi-driver-rhel9","cpes":["cpe:/a:redhat:zero_trust_workload_identity_manager:1"]},{"vendor":"Red Hat","product":"Zero Trust Workload Identity Manager - Tech Preview","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9","cpes":["cpe:/a:redhat:zero_trust_workload_identity_manager:0"]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T17:46:14.569488Z","id":"CVE-2026-32280","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*","versionEndExcluding":"1.25.9","matchCriteriaId":"C6C9C072-9817-402D-877F-F83584B07017"},{"vulnerable":true,"criteria":"cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*","versionStartIncluding":"1.26.0","versionEndExcluding":"1.26.2","matchCriteriaId":"39FE9BAF-55E9-43AA-B14E-239E7EF1D65D"}]}]}],"references":[{"url":"https://go.dev/cl/758320","source":"security@golang.org","tags":["Patch"]},{"url":"https://go.dev/issue/78282","source":"security@golang.org","tags":["Issue Tracking"]},{"url":"https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","source":"security@golang.org","tags":["Mailing List","Release Notes"]},{"url":"https://pkg.go.dev/vuln/GO-2026-4947","source":"security@golang.org","tags":["Vendor Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:10217","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:10219","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:10704","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:11507","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:11514","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:11688","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:13545","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:13791","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:13826","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:13829","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:14020","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:14162","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:14200","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:14391","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:15980","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16021","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16024","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16101","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16476","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16477","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16505","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16508","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16532","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16534","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16535","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16537","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16542","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16874","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16875","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:17084","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:17287","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:18027","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:18032","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19133","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19135","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19144","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19350","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19353","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19375","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19450","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19550","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19634","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19714","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19715","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19719","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19720","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19721","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19722","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19750","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19839","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:20556","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:20569","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:20570","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:20571","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:20607","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:20608","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:20609","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:20889","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:21017","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:21338","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:21655","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:21769","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:21772","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22130","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22141","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22258","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22260","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22268","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22309","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22347","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22415","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22422","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22465","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22485","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22709","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22713","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22840","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22862","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22958","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22959","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22960","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22961","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22962","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:23102","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:23103","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:23244","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:23345","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:23361","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24337","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24359","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24470","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24478","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24716","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24761","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24762","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24853","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24977","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:25089","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:25127","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:25180","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:26447","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:26568","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:26571","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:26585","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:26636","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:27076","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:28038","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:28047","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:28074","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:28196","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:28198","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:28441","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:28886","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:28961","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:29035","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:29195","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:29455","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:29702","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:29703","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:29854","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:33722","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:34097","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:34192","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:34196","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:34197","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:34365","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36319","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36651","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36796","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:39810","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:39894","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:40118","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:40945","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:41019","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:41928","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:42043","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:42047","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:42049","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:42050","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:42051","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:9385","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-32280","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2456339","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}]}},{"cve":{"id":"CVE-2026-32281","sourceIdentifier":"security@golang.org","published":"2026-04-08T02:16:03.350","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool."},{"lang":"es","value":"Validar cadenas de certificados que usan políticas es inesperadamente ineficiente cuando los certificados en la cadena contienen un número muy grande de mapeos de políticas, lo que podría causar denegación de servicio. Esto solo afecta la validación de cadenas de certificados que de otro modo serían de confianza, emitidas por una CA raíz en el CertPool VerifyOptions.Roots, o en el pool de certificados del sistema."}],"affected":[{"source":"security@golang.org","affectedData":[{"vendor":"Go standard library","product":"crypto/x509","defaultStatus":"unaffected","collectionURL":"https://pkg.go.dev","packageName":"crypto/x509","programRoutines":[{"name":"policiesValid"},{"name":"Certificate.Verify"}],"versions":[{"version":"0","lessThan":"1.25.9","versionType":"semver","status":"affected"},{"version":"1.26.0-0","lessThan":"1.26.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-13T17:52:37.734298Z","id":"CVE-2026-32281","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-295"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*","versionEndExcluding":"1.25.9","matchCriteriaId":"C6C9C072-9817-402D-877F-F83584B07017"},{"vulnerable":true,"criteria":"cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*","versionStartIncluding":"1.26.0","versionEndExcluding":"1.26.2","matchCriteriaId":"39FE9BAF-55E9-43AA-B14E-239E7EF1D65D"}]}]}],"references":[{"url":"https://go.dev/cl/758061","source":"security@golang.org","tags":["Patch"]},{"url":"https://go.dev/issue/78281","source":"security@golang.org","tags":["Issue Tracking"]},{"url":"https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","source":"security@golang.org","tags":["Issue Tracking","Release Notes"]},{"url":"https://pkg.go.dev/vuln/GO-2026-4946","source":"security@golang.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-32282","sourceIdentifier":"security@golang.org","published":"2026-04-08T02:16:03.467","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation."},{"lang":"es","value":"En Linux, si el objetivo de Root.Chmod es reemplazado por un enlace simbólico mientras la operación chmod está en curso, Chmod puede operar sobre el objetivo del enlace simbólico, incluso cuando el objetivo se encuentra fuera de la raíz. La llamada al sistema fchmodat de Linux ignora silenciosamente la bandera AT_SYMLINK_NOFOLLOW, que Root.Chmod utiliza para evitar el recorrido de enlaces simbólicos. Root.Chmod verifica su objetivo antes de actuar y devuelve un error si el objetivo es un enlace simbólico que se encuentra fuera de la raíz, por lo que el impacto está limitado a los casos en que el objetivo es reemplazado por un enlace simbólico entre la verificación y la operación."}],"affected":[{"source":"security@golang.org","affectedData":[{"vendor":"Go standard library","product":"internal/syscall/unix","defaultStatus":"unaffected","collectionURL":"https://pkg.go.dev","packageName":"internal/syscall/unix","platforms":["linux"],"programRoutines":[{"name":"Fchmodat"}],"versions":[{"version":"0","lessThan":"1.25.9","versionType":"semver","status":"affected"},{"version":"1.26.0-0","lessThan":"1.26.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.5,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.5,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-13T17:47:42.666766Z","id":"CVE-2026-32282","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-59"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*","versionEndExcluding":"1.25.9","matchCriteriaId":"C6C9C072-9817-402D-877F-F83584B07017"},{"vulnerable":true,"criteria":"cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*","versionStartIncluding":"1.26.0","versionEndExcluding":"1.26.2","matchCriteriaId":"39FE9BAF-55E9-43AA-B14E-239E7EF1D65D"}]}]}],"references":[{"url":"https://go.dev/cl/763761","source":"security@golang.org","tags":["Patch"]},{"url":"https://go.dev/issue/78293","source":"security@golang.org","tags":["Issue Tracking"]},{"url":"https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","source":"security@golang.org","tags":["Mailing List","Release Notes"]},{"url":"https://pkg.go.dev/vuln/GO-2026-4864","source":"security@golang.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-32283","sourceIdentifier":"security@golang.org","published":"2026-04-08T02:16:03.580","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3."},{"lang":"es","value":"Si una de las partes de la conexión TLS envía múltiples mensajes de actualización de clave después del handshake en un único registro, la conexión puede entrar en un interbloqueo, causando un consumo descontrolado de recursos. Esto puede llevar a una denegación de servicio. Esto solo afecta a TLS 1.3."}],"affected":[{"source":"security@golang.org","affectedData":[{"vendor":"Go standard library","product":"crypto/tls","defaultStatus":"unaffected","collectionURL":"https://pkg.go.dev","packageName":"crypto/tls","programRoutines":[{"name":"Conn.handleKeyUpdate"},{"name":"clientHandshakeStateTLS13.establishHandshakeKeys"},{"name":"clientHandshakeStateTLS13.readServerFinished"},{"name":"serverHandshakeStateTLS13.sendServerParameters"},{"name":"serverHandshakeStateTLS13.readClientFinished"},{"name":"Conn.Handshake"},{"name":"Conn.HandshakeContext"},{"name":"Conn.Read"},{"name":"Conn.Write"},{"name":"Dial"},{"name":"DialWithDialer"},{"name":"Dialer.Dial"},{"name":"Dialer.DialContext"},{"name":"QUICConn.HandleData"},{"name":"QUICConn.Start"}],"versions":[{"version":"0","lessThan":"1.25.9","versionType":"semver","status":"affected"},{"version":"1.26.0-0","lessThan":"1.26.2","versionType":"semver","status":"affected"}]}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","affectedData":[{"vendor":"Red Hat","product":"Cryostat 4 on RHEL 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"cryostat/cryostat-storage-rhel9","cpes":["cpe:/a:redhat:cryostat:4::el9"],"versions":[{"version":"4.1.1-7","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.5 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"automation-gateway-proxy","cpes":["cpe:/a:redhat:ansible_automation_platform:2.5::el8"],"versions":[{"version":"0:2.5.10-6.el8ap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.5 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"receptor","cpes":["cpe:/a:redhat:ansible_automation_platform:2.5::el8"],"versions":[{"version":"0:1.6.5-1.el8ap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.5 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"automation-gateway-proxy","cpes":["cpe:/a:redhat:ansible_automation_platform:2.5::el9"],"versions":[{"version":"0:2.6.14-3.el9ap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.5 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"receptor","cpes":["cpe:/a:redhat:ansible_automation_platform:2.5::el9"],"versions":[{"version":"0:1.6.5-1.el9ap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.6 for RHEL 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"receptor","cpes":["cpe:/a:redhat:ansible_automation_platform:2.6::el10"],"versions":[{"version":"0:1.6.5-1.el10ap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.6 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"automation-gateway-proxy","cpes":["cpe:/a:redhat:ansible_automation_platform:2.6::el9"],"versions":[{"version":"0:2.6.14-3.el9ap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.6 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"receptor","cpes":["cpe:/a:redhat:ansible_automation_platform:2.6::el9"],"versions":[{"version":"0:1.6.5-1.el9ap","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"golang","cpes":["cpe:/o:redhat:enterprise_linux:10.1"],"versions":[{"version":"0:1.25.9-3.el10_1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"grafana","cpes":["cpe:/o:redhat:enterprise_linux:10.1","cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:10.2.6-25.el10_1","lessThan":"*","versionType":"rpm","status":"unaffected"},{"version":"0:10.2.6-26.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhc-worker-playbook","cpes":["cpe:/o:redhat:enterprise_linux:10.1","cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:0.2.3-5.el10_1","lessThan":"*","versionType":"rpm","status":"unaffected"},{"version":"0:0.2.7-3.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"grafana-pcp","cpes":["cpe:/o:redhat:enterprise_linux:10.1","cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:5.3.0-4.el10_1","lessThan":"*","versionType":"rpm","status":"unaffected"},{"version":"0:5.3.0-5.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"yggdrasil","cpes":["cpe:/o:redhat:enterprise_linux:10.1","cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:0.4.8-5.el10_1","lessThan":"*","versionType":"rpm","status":"unaffected"},{"version":"0:0.4.9-4.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"git-lfs","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:3.7.1-4.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"opentelemetry-collector","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:0.144.0-2.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"go-fdo-server","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:1.0.1-1.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"go-fdo-client","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:1.0.0-3.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"golang-github-openprinting-ipp-usb","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:0.9.27-7.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhc","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"1:0.3.8-4.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"osbuild-composer","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:165.1-2.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"image-builder","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:52.1-1.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"delve","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:1.26.1-2.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"podman","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"7:5.8.2-3.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"skopeo","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"2:1.22.2-2.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"buildah","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"2:1.43.1-2.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:1.25.9-1.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gvisor-tap-vsock","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"6:0.8.5-2.el10_0.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"grafana-pcp","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:5.2.2-6.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"grafana","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:10.2.6-24.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"yggdrasil","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:0.4.7-4.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang-github-openprinting-ipp-usb","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:0.9.27-3.el10_0.4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhc-worker-playbook","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:0.2.3-5.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"git-lfs","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:3.6.1-2.el10_0.4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"opentelemetry-collector","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:0.144.0-2.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"osbuild-composer","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:134.1-7.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"buildah","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"2:1.39.9-1.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"podman","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"6:5.4.0-15.el10_0.2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"skopeo","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"2:1.18.1-3.el10_0.2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhc","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"1:0.3.2-4.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"delve","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:1.25.2-4.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7 Extended Lifecycle Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"host-metering","cpes":["cpe:/o:redhat:rhel_els:7"],"versions":[{"version":"0:1.4.0-7.el7_9","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"go-toolset:rhel8","cpes":["cpe:/a:redhat:enterprise_linux:8"],"versions":[{"version":"8100020260422204008.a3795dee","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"grafana","cpes":["cpe:/a:redhat:enterprise_linux:8"],"versions":[{"version":"0:9.2.10-30.el8_10","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"grafana-pcp","cpes":["cpe:/a:redhat:enterprise_linux:8"],"versions":[{"version":"0:5.1.1-14.el8_10","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhc","cpes":["cpe:/a:redhat:enterprise_linux:8"],"versions":[{"version":"1:0.2.5-7.el8_10","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"git-lfs","cpes":["cpe:/a:redhat:enterprise_linux:8"],"versions":[{"version":"0:3.4.1-10.el8_10","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"container-tools:rhel8","cpes":["cpe:/a:redhat:enterprise_linux:8"],"versions":[{"version":"8100020260520103055.afee755d","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"container-tools:rhel8","cpes":["cpe:/a:redhat:rhel_aus:8.6"],"versions":[{"version":"8060020260515174849.ad008a3a","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.6 Telecommunications Update Service","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"container-tools:rhel8","cpes":["cpe:/a:redhat:rhel_tus:8.6"],"versions":[{"version":"8060020260515174849.ad008a3a","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"container-tools:rhel8","cpes":["cpe:/a:redhat:rhel_e4s:8.6"],"versions":[{"version":"8060020260515174849.ad008a3a","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"golang","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"0:1.25.9-1.el9_7","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"grafana-pcp","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"0:5.1.1-14.el9_7","lessThan":"*","versionType":"rpm","status":"unaffected"},{"version":"0:5.1.1-15.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"grafana","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"0:10.2.6-21.el9_7","lessThan":"*","versionType":"rpm","status":"unaffected"},{"version":"0:10.2.6-22.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"git-lfs","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"0:3.6.1-8.el9_7.1","lessThan":"*","versionType":"rpm","status":"unaffected"},{"version":"0:3.7.1-4.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"opentelemetry-collector","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"0:0.144.0-2.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhc","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"1:0.2.7-6.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"osbuild-composer","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"0:165.1-2.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"image-builder","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"0:52.1-1.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"podman","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"6:5.8.2-3.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"skopeo","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"2:1.22.2-6.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"buildah","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"2:1.43.1-2.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"containernetworking-plugins","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"1:1.9.0-3.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"buildah","cpes":["cpe:/a:redhat:rhel_e4s:9.0"],"versions":[{"version":"1:1.26.11-1.el9_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.4 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"opentelemetry-collector","cpes":["cpe:/a:redhat:rhel_eus:9.4"],"versions":[{"version":"0:0.144.0-2.el9_4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"buildah","cpes":["cpe:/a:redhat:rhel_e4s:9.4"],"versions":[{"version":"2:1.33.15-1.el9_4.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"podman","cpes":["cpe:/a:redhat:rhel_e4s:9.4"],"versions":[{"version":"4:4.9.4-20.el9_4.3","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"skopeo","cpes":["cpe:/a:redhat:rhel_e4s:9.4"],"versions":[{"version":"2:1.14.6-1.el9_4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"0:1.25.9-1.el9_6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"podman","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"5:5.4.0-20.el9_6.3","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"opentelemetry-collector","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"0:0.144.0-2.el9_6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"git-lfs","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"0:3.6.1-2.el9_6.4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"grafana-pcp","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"0:5.1.1-14.el9_6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"grafana","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"0:10.2.6-21.el9_6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"buildah","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"2:1.39.9-1.el9_6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"containernetworking-plugins","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"1:1.6.2-3.el9_6.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"skopeo","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"2:1.18.1-5.el9_6.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"osbuild-composer","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"0:132.2-7.el9_6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhc","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"1:0.2.7-1.el9_6.4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gvisor-tap-vsock","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"6:0.8.5-2.el9_6.2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 17.1 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"etcd","cpes":["cpe:/a:redhat:openstack:17.1::el9"],"versions":[{"version":"0:3.4.26-9.5.el9ost","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenStack Services on OpenShift 18.0","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang-github-openstack-k8s-operators-os-diff","cpes":["cpe:/a:redhat:openstack:18.0::el9"],"versions":[{"version":"0:0.1.1-18.0.20260602234716.a95ae05.el9ost","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.16 for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"yggdrasil-worker-forwarder","cpes":["cpe:/a:redhat:satellite:6.16::el8"],"versions":[{"version":"0:0.0.3-5.el8sat","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.16 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"yggdrasil-worker-forwarder","cpes":["cpe:/a:redhat:satellite:6.16::el9"],"versions":[{"version":"0:0.0.3-5.el9sat","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Satellite 6.19 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"yggdrasil-worker-forwarder","cpes":["cpe:/a:redhat:satellite:6.19::el9"],"versions":[{"version":"0:0.0.3-5.el9sat","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"RHEM 1.0 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"flightctl","cpes":["cpe:/a:redhat:edge_manager:1.0::el9"],"versions":[{"version":"0:1.0.3-1.el9em","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"RHEM 1.1 for RHEL 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"flightctl","cpes":["cpe:/a:redhat:edge_manager:1.1::el10"],"versions":[{"version":"0:1.1.3-1.el10em","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"RHEM 1.1 for RHEL 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"flightctl","cpes":["cpe:/a:redhat:edge_manager:1.1:el9"],"versions":[{"version":"0:1.1.3-1.el9em","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Compliance Operator 1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"compliance/openshift-compliance-operator-bundle","cpes":["cpe:/a:redhat:openshift_compliance_operator:1::el9"],"versions":[{"version":"1781605005","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Custom Metric Autoscaler 2.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9","cpes":["cpe:/a:redhat:openshift_custom_metrics_autoscaler:2.19::el9"],"versions":[{"version":"1780101239","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Multicluster Global Hub 1.3.4","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-globalhub/multicluster-globalhub-agent-rhel9","cpes":["cpe:/a:redhat:multicluster_globalhub:1.3::el9"],"versions":[{"version":"1779210675","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Multicluster Global Hub 1.4.5","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-globalhub/multicluster-globalhub-agent-rhel9","cpes":["cpe:/a:redhat:multicluster_globalhub:1.4::el9"],"versions":[{"version":"1779838819","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Multicluster Global Hub 1.5.6","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-globalhub/multicluster-globalhub-agent-rhel9","cpes":["cpe:/a:redhat:multicluster_globalhub:1.5::el9"],"versions":[{"version":"1779828691","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Multicluster Global Hub 1.6.2","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-globalhub/multicluster-globalhub-agent-rhel9","cpes":["cpe:/a:redhat:multicluster_globalhub:1.6::el9"],"versions":[{"version":"1780320809","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang1-26-main","cpes":["cpe:/a:redhat:hummingbird:1"],"versions":[{"version":"1.26.2-1.hum1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang1-25-main","cpes":["cpe:/a:redhat:hummingbird:1"],"versions":[{"version":"1.25.9-1.hum1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Lightspeed (formerly Insights) for Runtimes 1.0","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator","cpes":["cpe:/a:redhat:lightspeed_for_runtimes:1.0::el9"],"versions":[{"version":"1.0.3-1779996197","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Migration Toolkit 1.8","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhmtc/openshift-migration-registry-rhel8","cpes":["cpe:/a:redhat:rhmt:1.8::el8"],"versions":[{"version":"1783914276","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI 2.25","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhoai/odh-kueue-controller-rhel9","cpes":["cpe:/a:redhat:openshift_ai:2.25::el9"],"versions":[{"version":"1783544461","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.9.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/opentelemetry-collector-rhel9","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.9::el9"],"versions":[{"version":"1778056267","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.9.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/opentelemetry-rhel9-operator","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.9::el9"],"versions":[{"version":"1778056233","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.9.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"rhosdt/opentelemetry-target-allocator-rhel9","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.9::el9"],"versions":[{"version":"1778056245","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Assisted Installer for Red Hat OpenShift Container Platform 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhai/assisted-installer-rhel9","cpes":["cpe:/a:redhat:assisted_installer:2"]},{"vendor":"Red Hat","product":"Builds for Red Hat OpenShift","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-builds/openshift-builds-waiters-rhel9","cpes":["cpe:/a:redhat:openshift_builds:1"]},{"vendor":"Red Hat","product":"cert-manager Operator for Red Hat OpenShift","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"cert-manager/jetstack-cert-manager-rhel9","cpes":["cpe:/a:redhat:cert_manager:1"]},{"vendor":"Red Hat","product":"Confidential Compute Attestation","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"build-of-trustee/trustee-rhel9-operator","cpes":["cpe:/a:redhat:confidential_compute_attestation:1"]},{"vendor":"Red Hat","product":"Confidential Compute Attestation","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-sandboxed-containers/osc-monitor-rhel9","cpes":["cpe:/a:redhat:confidential_compute_attestation:1"]},{"vendor":"Red Hat","product":"Deployment Validation Operator","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"dvo/deployment-validation-rhel8-operator","cpes":["cpe:/a:redhat:deployment_validator_operator"]},{"vendor":"Red Hat","product":"ExternalDNS Operator","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"edo/external-dns-rhel8","cpes":["cpe:/a:redhat:ext_dns_optr:1"]},{"vendor":"Red Hat","product":"ExternalDNS Operator","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"edo/external-dns-rhel9","cpes":["cpe:/a:redhat:ext_dns_optr:1"]},{"vendor":"Red Hat","product":"External Secrets Operator for Red Hat OpenShift","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"external-secrets-operator/external-secrets-rhel9","cpes":["cpe:/a:redhat:external_secrets_operator:1"]},{"vendor":"Red Hat","product":"Fence Agents Remediation Operator","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"workload-availability/fence-agents-remediation-rhel8-operator","cpes":["cpe:/a:redhat:workload_availability_far:0"]},{"vendor":"Red Hat","product":"File Integrity Operator","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"compliance/openshift-compliance-operator-bundle","cpes":["cpe:/a:redhat:openshift_file_integrity_operator:1"]},{"vendor":"Red Hat","product":"Gatekeeper 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gatekeeper/gatekeeper-rhel9-operator","cpes":["cpe:/a:redhat:gatekeeper:3"]},{"vendor":"Red Hat","product":"Logging Subsystem for Red Hat OpenShift","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-logging/eventrouter-rhel9","cpes":["cpe:/a:redhat:logging:5","cpe:/a:redhat:logging:6"]},{"vendor":"Red Hat","product":"Logging Subsystem for Red Hat OpenShift","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-logging/logging-loki-rhel9","cpes":["cpe:/a:redhat:logging:5"]},{"vendor":"Red Hat","product":"Logical Volume Manager Storage","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"lvms4/lvms-rhel9-operator","cpes":["cpe:/a:redhat:lvms:4"]},{"vendor":"Red Hat","product":"Logical Volume Manager Storage","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"lvms4/topolvm-rhel8","cpes":["cpe:/a:redhat:lvms:4"]},{"vendor":"Red Hat","product":"Logical Volume Manager Storage","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"lvms4/topolvm-rhel9","cpes":["cpe:/a:redhat:lvms:4"]},{"vendor":"Red Hat","product":"Machine Deletion Remediation Operator","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"workload-availability/machine-deletion-remediation-rhel8-operator","cpes":["cpe:/a:redhat:workload_availability_mdr:0"]},{"vendor":"Red Hat","product":"Migration Toolkit for Applications 8","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"mta/mta-cli-rhel9","cpes":["cpe:/a:redhat:migration_toolkit_applications:8"]},{"vendor":"Red Hat","product":"mirror registry for Red Hat OpenShift","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift/mirror-registry-rhel8","cpes":["cpe:/a:redhat:mirror_registry:1"]},{"vendor":"Red Hat","product":"mirror registry for Red Hat OpenShift 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift/mirror-registry-rhel8","cpes":["cpe:/a:redhat:mirror_registry:2"]},{"vendor":"Red Hat","product":"Multicluster Engine for Kubernetes","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"multicluster-engine/assisted-service-9-rhel9","cpes":["cpe:/a:redhat:multicluster_engine"]},{"vendor":"Red Hat","product":"Multicluster Engine for Kubernetes","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"multicluster-engine/discovery-rhel9","cpes":["cpe:/a:redhat:multicluster_engine"]},{"vendor":"Red Hat","product":"Network Observability Operator","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"network-observability/network-observability-cli-rhel9","cpes":["cpe:/a:redhat:network_observ_optr:1"]},{"vendor":"Red Hat","product":"Node HealthCheck Operator","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"workload-availability/node-healthcheck-rhel8-operator","cpes":["cpe:/a:redhat:workload_availability_nhc:0"]},{"vendor":"Red Hat","product":"OpenShift API for Data Protection","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"oadp/oadp-velero-rhel9","cpes":["cpe:/a:redhat:openshift_api_data_protection:1"]},{"vendor":"Red Hat","product":"OpenShift Developer Tools and Services","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"helm","cpes":["cpe:/a:redhat:ocp_tools"]},{"vendor":"Red Hat","product":"OpenShift Developer Tools and Services","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ocp-tools-4/jenkins-agent-base-rhel9","cpes":["cpe:/a:redhat:ocp_tools"]},{"vendor":"Red Hat","product":"OpenShift Developer Tools and Services","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ocp-tools-4/jenkins-rhel8","cpes":["cpe:/a:redhat:ocp_tools"]},{"vendor":"Red Hat","product":"OpenShift Developer Tools and Services","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ocp-tools-4/jenkins-rhel9","cpes":["cpe:/a:redhat:ocp_tools"]},{"vendor":"Red Hat","product":"OpenShift Developer Tools and Services","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-jenkins","cpes":["cpe:/a:redhat:ocp_tools"]},{"vendor":"Red Hat","product":"OpenShift Lightspeed","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-lightspeed/lightspeed-rhel9-operator","cpes":["cpe:/a:redhat:openshift_lightspeed"]},{"vendor":"Red Hat","product":"OpenShift Pipelines","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-pipelines-client","cpes":["cpe:/a:redhat:openshift_pipelines:1"]},{"vendor":"Red Hat","product":"OpenShift Serverless","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kn-workflow-plugin","cpes":["cpe:/a:redhat:serverless:1"]},{"vendor":"Red Hat","product":"OpenShift Serverless","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-serverless-1/kn-plugin-event-sender-rhel9","cpes":["cpe:/a:redhat:serverless:1"]},{"vendor":"Red Hat","product":"OpenShift Serverless","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-serverless-clients","cpes":["cpe:/a:redhat:serverless:1"]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-golang-builder-container","cpes":["cpe:/a:redhat:service_mesh:2"]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-service-mesh/kiali-rhel8","cpes":["cpe:/a:redhat:service_mesh:2"]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-golang-builder-container","cpes":["cpe:/a:redhat:service_mesh:3"]},{"vendor":"Red Hat","product":"OpenShift Service Mesh 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-service-mesh/kiali-rhel9","cpes":["cpe:/a:redhat:service_mesh:3"]},{"vendor":"Red Hat","product":"Power monitoring for Red Hat OpenShift","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-power-monitoring/kepler-rhel9","cpes":["cpe:/a:redhat:openshift_power_monitoring"]},{"vendor":"Red Hat","product":"Red Hat 3scale API Management Platform 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"3scale-amp2/3scale-rhel7-operator","cpes":["cpe:/a:redhat:red_hat_3scale_amp:2"]},{"vendor":"Red Hat","product":"Red Hat 3scale API Management Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"3scale-amp2/3scale-rhel9-operator","cpes":["cpe:/a:redhat:red_hat_3scale_amp:2"]},{"vendor":"Red Hat","product":"Red Hat 3scale API Management Platform 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"3scale-amp26/3scale-operator","cpes":["cpe:/a:redhat:red_hat_3scale_amp:2"]},{"vendor":"Red Hat","product":"Red Hat 3scale API Management Platform 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"3scale-amp26/operator","cpes":["cpe:/a:redhat:red_hat_3scale_amp:2"]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhacm2/subctl-rhel9","cpes":["cpe:/a:redhat:acm:2"]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Security 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"advanced-cluster-security/rhacs-main-rhel8","cpes":["cpe:/a:redhat:advanced_cluster_security:4"]},{"vendor":"Red Hat","product":"Red Hat AI Inference Server","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhaiis/vllm-cpu-rhel9","cpes":["cpe:/a:redhat:ai_inference_server:3"]},{"vendor":"Red Hat","product":"Red Hat AI Inference Server","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhaiis/vllm-neuron-rhel9","cpes":["cpe:/a:redhat:ai_inference_server:3"]},{"vendor":"Red Hat","product":"Red Hat AI Inference Server","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhaiis/vllm-tpu-rhel9","cpes":["cpe:/a:redhat:ai_inference_server:3"]},{"vendor":"Red Hat","product":"Red Hat AI Inference Server","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhaii/vllm-neuron-rhel9","cpes":["cpe:/a:redhat:ai_inference_server:3"]},{"vendor":"Red Hat","product":"Red Hat AMQ Broker 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"amq7/amq-broker-rhel9-operator","cpes":["cpe:/a:redhat:amq_broker:7"]},{"vendor":"Red Hat","product":"Red Hat AMQ Broker 7","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang-github-danielqsj-kafka_exporter","cpes":["cpe:/a:redhat:amq_broker:7"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-automation-platform-26/receptor-rhel9","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-automation-platform/platform-operator-bundle","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"automation-gateway-proxy-openssl30","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"automation-gateway-proxy-openssl32","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python3.11-galaxy-ng","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python3.11-grpcio","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python3.12-galaxy-ng","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python3.12-grpcio","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python3x-grpcio","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python-grpcio","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat build of Apache Camel - HawtIO 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"hawtio-operator-container","cpes":["cpe:/a:redhat:apache_camel_hawtio:4"]},{"vendor":"Red Hat","product":"Red Hat build of Apicurio Registry 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"apicurio/apicurio-registry-rhel8-operator","cpes":["cpe:/a:redhat:service_registry:2"]},{"vendor":"Red Hat","product":"Red Hat build of Apicurio Registry 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"apicurio/apicurio-registry-rhel9-operator","cpes":["cpe:/a:redhat:service_registry:2"]},{"vendor":"Red Hat","product":"Red Hat Certification Program for Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redhat-certification-preflight","cpes":["cpe:/a:redhat:certifications:9"]},{"vendor":"Red Hat","product":"Red Hat Connectivity Link 1","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhcl-1/coredns-rhel9","cpes":["cpe:/a:redhat:connectivity_link:1"]},{"vendor":"Red Hat","product":"Red Hat Developer Hub","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhdh/rhdh-rhel9-operator","cpes":["cpe:/a:redhat:rhdh:1"]},{"vendor":"Red Hat","product":"Red Hat Edge Manager 1","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhem/flightctl-ui-rhel9","cpes":["cpe:/a:redhat:edge_manager:1"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"butane","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"conmon","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gvisor-tap-vsock","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ignition","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhel10/bootc-image-builder","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"toolbox","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"trustee","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"trustee-guest-components","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhc","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhc-worker-script","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"osbuild-composer","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"weldr-client","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"butane","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"conmon","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gvisor-tap-vsock","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ignition","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhel9/bootc-image-builder","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"runc","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"toolbox","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"trustee-guest-components","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"weldr-client","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux AI (RHEL AI) 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang","cpes":["cpe:/a:redhat:enterprise_linux_ai:3"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux AI (RHEL AI) 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhelai3/bootc-aws-cuda-rhel9","cpes":["cpe:/a:redhat:enterprise_linux_ai:3"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux AI (RHEL AI) 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhelai3/bootc-azure-cuda-rhel9","cpes":["cpe:/a:redhat:enterprise_linux_ai:3"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux AI (RHEL AI) 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhelai3/bootc-azure-rocm-rhel9","cpes":["cpe:/a:redhat:enterprise_linux_ai:3"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux AI (RHEL AI) 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhelai3/bootc-cuda-rhel9","cpes":["cpe:/a:redhat:enterprise_linux_ai:3"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux AI (RHEL AI) 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhelai3/bootc-gaudi-rhel9","cpes":["cpe:/a:redhat:enterprise_linux_ai:3"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux AI (RHEL AI) 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhelai3/bootc-gcp-cuda-rhel9","cpes":["cpe:/a:redhat:enterprise_linux_ai:3"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux AI (RHEL AI) 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhelai3/bootc-rocm-rhel9","cpes":["cpe:/a:redhat:enterprise_linux_ai:3"]},{"vendor":"Red Hat","product":"Red Hat JBoss Web Server 6","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"jboss-webserver/jws-rhel9-operator","cpes":["cpe:/a:redhat:jboss_enterprise_web_server:6"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhai/base-image-neuron-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-ai-gateway-payload-processing-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-cli-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-codeflare-operator-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-dashboard-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-data-science-pipelines-argo-argoexec-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-data-science-pipelines-operator-controller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-eval-hub-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-feast-operator-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-kf-notebook-controller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-kserve-agent-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-kserve-controller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-kserve-llmisvc-controller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-kserve-router-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-kube-auth-proxy-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-kuberay-operator-controller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-llama-stack-core-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-llama-stack-k8s-operator-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-llm-d-batch-gateway-apiserver-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-llm-d-batch-gateway-gc-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-llm-d-batch-gateway-processor-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-llm-d-inference-scheduler-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-llm-d-routing-sidecar-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-maas-api-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-maas-controller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-mlflow-operator-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-ml-pipelines-api-server-v2-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-ml-pipelines-driver-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-ml-pipelines-launcher-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-ml-pipelines-runtime-generic-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-mm-rest-proxy-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-mod-arch-automl-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-mod-arch-autorag-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-mod-arch-eval-hub-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-mod-arch-gen-ai-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-mod-arch-maas-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-mod-arch-mlflow-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-mod-arch-model-registry-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-model-controller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-modelmesh-runtime-adapter-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-modelmesh-serving-controller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-model-registry-job-async-upload-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-model-registry-operator-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-model-registry-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-model-serving-api-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-must-gather-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-notebook-controller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-rhaii-cluster-validator-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-rhel9-operator","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-spark-operator-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-ta-lmes-driver-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-ta-lmes-job-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-th06-cpu-torch210-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-th06-cpu-torch291-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-th06-cuda130-torch210-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-th06-cuda130-torch291-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-th06-rocm64-torch291-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-trainer-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-training-operator-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-trustyai-service-operator-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-workload-variant-autoscaler-controller-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/rhai-cli-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Cluster Manager CLI","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ocm-cli-clients/ocm-cli-rhel9","cpes":["cpe:/a:redhat:openshift_cluster_manager_cli:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"butane","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"conmon","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"conmon-rs","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"containernetworking-plugins","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"cri-o","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"cri-tools","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang-github-prometheus-promu","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ignition","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kata-containers","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"microshift","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/frr-rhel9","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-ansible-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-ansible-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-sdn-rhel8","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-sdn-rhel9","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-clients","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-golang-builder-container","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-kuryr","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ose-aws-ecr-image-credential-provider","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ose-azure-acr-image-credential-provider","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ose-gcp-gcr-image-credential-provider","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"podman","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"runc","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"skopeo","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat Openshift Data Foundation 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"odf4/cephcsi-rhel9","cpes":["cpe:/a:redhat:openshift_data_foundation:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Dev Spaces","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"devspaces/udi-rhel9","cpes":["cpe:/a:redhat:openshift_devspaces:3"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Dev Workspaces Operator","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"devworkspace/devworkspace-rhel9-operator","cpes":["cpe:/a:redhat:devworkspace"]},{"vendor":"Red Hat","product":"Red Hat OpenShift for Windows Containers","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4-wincw/windows-machine-config-rhel9-operator","cpes":["cpe:/a:redhat:windows_machine_config"]},{"vendor":"Red Hat","product":"Red Hat OpenShift GitOps","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-gitops-1/dex-rhel8","cpes":["cpe:/a:redhat:openshift_gitops:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift on AWS","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rosa","cpes":["cpe:/a:redhat:openshift_service_on_aws:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Virtualization 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"container-native-virtualization/virt-api","cpes":["cpe:/a:redhat:container_native_virtualization:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Virtualization 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"container-native-virtualization/virt-api-rhel9","cpes":["cpe:/a:redhat:container_native_virtualization:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Virtualization 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"kubevirt","cpes":["cpe:/a:redhat:container_native_virtualization:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Virtualization 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-golang-builder-container","cpes":["cpe:/a:redhat:container_native_virtualization:4"]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 16.2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"etcd","cpes":["cpe:/a:redhat:openstack:16.2"]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 16.2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang-github-infrawatch-apputils","cpes":["cpe:/a:redhat:openstack:16.2"]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 16.2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhosp-rhel8/osp-director-agent","cpes":["cpe:/a:redhat:openstack:16.2"]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 17.1","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"collectd-libpod-stats","cpes":["cpe:/a:redhat:openstack:17.1"]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 17.1","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang-github-infrawatch-apputils","cpes":["cpe:/a:redhat:openstack:17.1"]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 17.1","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhosp-rhel9/osp-director-agent","cpes":["cpe:/a:redhat:openstack:17.1"]},{"vendor":"Red Hat","product":"Red Hat OpenStack Platform 18.0","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoso-operators/sg-core-rhel9","cpes":["cpe:/a:redhat:openstack:18.0"]},{"vendor":"Red Hat","product":"Red Hat Quay 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3"]},{"vendor":"Red Hat","product":"Red Hat Quay 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"quay/quay-rhel9","cpes":["cpe:/a:redhat:quay:3"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"satellite:el8/yggdrasil-worker-forwarder","cpes":["cpe:/a:redhat:satellite:6"]},{"vendor":"Red Hat","product":"Red Hat Satellite 6","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"satellite/iop-vmaas-rhel9","cpes":["cpe:/a:redhat:satellite:6"]},{"vendor":"Red Hat","product":"Red Hat Service Interconnect 1","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"skupper-cli","cpes":["cpe:/a:redhat:service_interconnect:1"]},{"vendor":"Red Hat","product":"Red Hat Service Interconnect 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"skupper-cli","cpes":["cpe:/a:redhat:service_interconnect:2"]},{"vendor":"Red Hat","product":"Red Hat Trusted Artifact Signer","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhtas/ec-rhel9","cpes":["cpe:/a:redhat:trusted_artifact_signer:1"]},{"vendor":"Red Hat","product":"Red Hat Web Terminal","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"web-terminal/web-terminal-exec-rhel9","cpes":["cpe:/a:redhat:webterminal:1"]},{"vendor":"Red Hat","product":"Security Profiles Operator","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"compliance/openshift-selinuxd-rhel8","cpes":["cpe:/a:redhat:openshift_security_profiles_operator:1"]},{"vendor":"Red Hat","product":"Service Telemetry Framework 1.5","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"stf/sg-core-rhel9","cpes":["cpe:/a:redhat:stf:1.5"]},{"vendor":"Red Hat","product":"streams for Apache Kafka 3","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"golang-github-danielqsj-kafka_exporter","cpes":["cpe:/a:redhat:amq_streams:3"]},{"vendor":"Red Hat","product":"Zero Trust Workload Identity Manager","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"zero-trust-workload-identity-manager/spiffe-csi-driver-rhel9","cpes":["cpe:/a:redhat:zero_trust_workload_identity_manager:1"]},{"vendor":"Red Hat","product":"Zero Trust Workload Identity Manager - Tech Preview","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9","cpes":["cpe:/a:redhat:zero_trust_workload_identity_manager:0"]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-13T17:51:46.207289Z","id":"CVE-2026-32283","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","description":[{"lang":"en","value":"CWE-764"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*","versionEndExcluding":"1.25.9","matchCriteriaId":"C6C9C072-9817-402D-877F-F83584B07017"},{"vulnerable":true,"criteria":"cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*","versionStartIncluding":"1.26.0","versionEndExcluding":"1.26.2","matchCriteriaId":"39FE9BAF-55E9-43AA-B14E-239E7EF1D65D"}]}]}],"references":[{"url":"https://go.dev/cl/763767","source":"security@golang.org","tags":["Patch"]},{"url":"https://go.dev/issue/78334","source":"security@golang.org","tags":["Issue Tracking"]},{"url":"https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","source":"security@golang.org","tags":["Mailing List","Release Notes"]},{"url":"https://pkg.go.dev/vuln/GO-2026-4870","source":"security@golang.org","tags":["Vendor Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:10217","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:10219","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:10704","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:11507","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:11514","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:11704","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:11711","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:11712","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:11863","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:11881","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:14162","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:14200","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:14391","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:15980","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16021","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16024","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16101","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16102","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:16875","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:17075","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:17084","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:17287","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:18027","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:18032","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19126","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19132","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19133","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19134","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19135","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19136","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19137","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19139","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19144","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19156","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19350","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19351","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19352","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19353","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19369","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19450","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19550","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19634","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19714","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19715","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19719","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19720","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19721","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19722","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19750","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19839","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:20556","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:20569","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:20570","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:20571","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:20607","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:20608","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:20609","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:21769","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22347","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22423","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22450","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22485","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22709","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22713","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22714","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22937","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:23102","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:23103","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:23228","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:23345","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24337","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24470","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24761","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24762","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:26447","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:26571","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:26636","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:27076","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:28038","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:28047","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:28074","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:29035","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:29195","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:29455","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:29703","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:33722","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:34192","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:34196","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:34197","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:34365","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36796","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:39810","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:41019","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:41928","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:42644","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:7291","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:7385","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-32283","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2456338","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}]}},{"cve":{"id":"CVE-2026-32288","sourceIdentifier":"security@golang.org","published":"2026-04-08T02:16:03.707","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the \"old GNU sparse map\" format."},{"lang":"es","value":"tar.Reader puede asignar una cantidad ilimitada de memoria al leer un archivo creado maliciosamente que contiene un gran número de regiones dispersas codificadas en el formato 'old GNU sparse map'."}],"affected":[{"source":"security@golang.org","affectedData":[{"vendor":"Go standard library","product":"archive/tar","defaultStatus":"unaffected","collectionURL":"https://pkg.go.dev","packageName":"archive/tar","programRoutines":[{"name":"Reader.readOldGNUSparseMap"},{"name":"readGNUSparseMap1x0"},{"name":"Reader.Next"}],"versions":[{"version":"0","lessThan":"1.25.9","versionType":"semver","status":"affected"},{"version":"1.26.0-0","lessThan":"1.26.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-13T17:51:05.649111Z","id":"CVE-2026-32288","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*","versionEndExcluding":"1.25.9","matchCriteriaId":"C6C9C072-9817-402D-877F-F83584B07017"},{"vulnerable":true,"criteria":"cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*","versionStartIncluding":"1.26.0","versionEndExcluding":"1.26.2","matchCriteriaId":"39FE9BAF-55E9-43AA-B14E-239E7EF1D65D"}]}]}],"references":[{"url":"https://go.dev/cl/763766","source":"security@golang.org","tags":["Patch"]},{"url":"https://go.dev/issue/78301","source":"security@golang.org","tags":["Issue Tracking"]},{"url":"https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","source":"security@golang.org","tags":["Mailing List","Release Notes"]},{"url":"https://pkg.go.dev/vuln/GO-2026-4869","source":"security@golang.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-32289","sourceIdentifier":"security@golang.org","published":"2026-04-08T02:16:03.820","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities."},{"lang":"es","value":"El contexto no se seguía correctamente a través de las ramas de la plantilla para los literales de plantilla de JS, lo que llevó a un escape posiblemente incorrecto del contenido cuando se usaban las ramas. Además, las acciones de la plantilla dentro de los literales de plantilla de JS no seguían correctamente la profundidad de las llaves, lo que llevó a que se aplicara un escape incorrecto. Estos problemas podrían causar que las acciones dentro de los literales de plantilla de JS fueran escapadas incorrecta o indebidamente, lo que llevó a vulnerabilidades de XSS."}],"affected":[{"source":"security@golang.org","affectedData":[{"vendor":"Go standard library","product":"html/template","defaultStatus":"unaffected","collectionURL":"https://pkg.go.dev","packageName":"html/template","programRoutines":[{"name":"context.String"},{"name":"context.mangle"},{"name":"escaper.escapeBranch"},{"name":"Error.Error"},{"name":"HTMLEscaper"},{"name":"JSEscape"},{"name":"JSEscapeString"},{"name":"JSEscaper"},{"name":"ParseFS"},{"name":"ParseFiles"},{"name":"ParseGlob"},{"name":"Template.AddParseTree"},{"name":"Template.Clone"},{"name":"Template.DefinedTemplates"},{"name":"Template.Execute"},{"name":"Template.ExecuteTemplate"},{"name":"Template.Funcs"},{"name":"Template.Parse"},{"name":"Template.ParseFS"},{"name":"Template.ParseFiles"},{"name":"Template.ParseGlob"},{"name":"URLQueryEscaper"}],"versions":[{"version":"0","lessThan":"1.25.9","versionType":"semver","status":"affected"},{"version":"1.26.0-0","lessThan":"1.26.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-13T17:48:22.714020Z","id":"CVE-2026-32289","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*","versionEndExcluding":"1.25.9","matchCriteriaId":"C6C9C072-9817-402D-877F-F83584B07017"},{"vulnerable":true,"criteria":"cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*","versionStartIncluding":"1.26.0","versionEndExcluding":"1.26.2","matchCriteriaId":"39FE9BAF-55E9-43AA-B14E-239E7EF1D65D"}]}]}],"references":[{"url":"https://go.dev/cl/763762","source":"security@golang.org","tags":["Patch"]},{"url":"https://go.dev/issue/78331","source":"security@golang.org","tags":["Issue Tracking"]},{"url":"https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","source":"security@golang.org","tags":["Mailing List","Release Notes"]},{"url":"https://pkg.go.dev/vuln/GO-2026-4865","source":"security@golang.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-3296","sourceIdentifier":"security@wordfence.com","published":"2026-04-08T02:16:04.067","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php file calling PHP's native unserialize() on stored entry meta values without passing the allowed_classes parameter. This makes it possible for unauthenticated attackers to inject a serialized PHP object payload through any public Everest Forms form field. The payload survives sanitize_text_field() sanitization (serialization control characters are not stripped) and is stored in the wp_evf_entrymeta database table. When an administrator views entries or views an individual entry, the unsafe unserialize() call processes the stored data without class restrictions."},{"lang":"es","value":"El plugin Everest Forms para WordPress es vulnerable a la inyección de objetos PHP en todas las versiones hasta la 3.4.3, inclusive, a través de la deserialización de entrada no confiable de los metadatos de entrada de formulario. Esto se debe a que el archivo html-admin-page-entries-view.php llama a la función nativa unserialize() de PHP en los valores meta de entrada almacenados sin pasar el parámetro allowed_classes. Esto hace posible que atacantes no autenticados inyecten una carga útil de objeto PHP serializado a través de cualquier campo de formulario público de Everest Forms. La carga útil sobrevive a la sanitización de sanitize_text_field() (los caracteres de control de serialización no se eliminan) y se almacena en la tabla de la base de datos wp_evf_entrymeta. Cuando un administrador ve las entradas o ve una entrada individual, la llamada insegura a unserialize() procesa los datos almacenados sin restricciones de clase."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"wpeverest","product":"Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.4.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T14:21:41.571035Z","id":"CVE-2026-3296","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-502"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/everest-forms/tags/3.4.3/includes/admin/views/html-admin-page-entries-view.php#L133","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/everest-forms/tags/3.4.3/includes/evf-core-functions.php#L5594","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/everest-forms/trunk/includes/admin/views/html-admin-page-entries-view.php#L133","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3489938/everest-forms/tags/3.4.4/readme.txt?old=3464753&old_path=everest-forms%2Ftags%2F3.4.3%2Freadme.txt","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=/everest-forms/tags/3.4.3&new_path=/everest-forms/tags/3.4.4","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2693ae37-790d-4b18-a9ec-054c8c27b8bc?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-1163","sourceIdentifier":"security@huntr.dev","published":"2026-04-08T03:16:07.500","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails to invalidate active sessions after a password reset, allowing an attacker to continue using an old session token. This issue arises due to the absence of logic to reject requests after a period of inactivity and the excessively long default session duration of 31 days. The vulnerability enables an attacker to maintain persistent access to a compromised account, even after the victim resets their password."},{"lang":"es","value":"Existe una vulnerabilidad de expiración de sesión insuficiente en la última versión de parisneo/lollms. La aplicación no invalida las sesiones activas después de un restablecimiento de contraseña, permitiendo a un atacante continuar usando un token de sesión antiguo. Este problema surge debido a la ausencia de lógica para rechazar solicitudes después de un período de inactividad y la duración de sesión predeterminada excesivamente larga de 31 días. La vulnerabilidad permite a un atacante mantener acceso persistente a una cuenta comprometida, incluso después de que la víctima restablezca su contraseña."}],"affected":[{"source":"security@huntr.dev","affectedData":[{"vendor":"parisneo","product":"parisneo/lollms","versions":[{"version":"unspecified","lessThanOrEqual":"latest","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"security@huntr.dev","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L","baseScore":4.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":0.7,"impactScore":3.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T15:58:28.539428Z","id":"CVE-2026-1163","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@huntr.dev","type":"Secondary","description":[{"lang":"en","value":"CWE-613"}]}],"references":[{"url":"https://huntr.com/bounties/abe2d1c4-c21c-4608-8a8e-274565246a8b","source":"security@huntr.dev"}]}},{"cve":{"id":"CVE-2026-2988","sourceIdentifier":"security@wordfence.com","published":"2026-04-08T04:17:00.897","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podcast' shortcodes in versions up to, and including, 11.15.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."},{"lang":"es","value":"El plugin Blubrry PowerPress para WordPress es vulnerable a cross-site scripting almacenado a través de los shortcodes 'powerpress' y 'podcast' en versiones hasta la 11.15.15, inclusive, debido a una sanitización de entrada y un escape de salida insuficientes. Esto permite a atacantes autenticados, con acceso de nivel de colaborador y superior, inyectar scripts web arbitrarios en páginas que se ejecutarán cada vez que un usuario acceda a una página inyectada."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"blubrry","product":"PowerPress Podcasting plugin by Blubrry","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"11.15.15","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T14:47:25.742606Z","id":"CVE-2026-2988","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/changeset/3473781/powerpress","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/de25459d-9e19-4e3e-982f-0b34fa89dc30?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-4379","sourceIdentifier":"security@wordfence.com","published":"2026-04-08T04:17:09.967","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The LightPress Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `group` attribute in the `[gallery]` shortcode in all versions up to, and including, 2.3.4. This is due to the plugin modifying gallery shortcode output to include the `group` attribute value without proper escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."},{"lang":"es","value":"El plugin LightPress Lightbox para WordPress es vulnerable a cross-site scripting almacenado a través del atributo 'group' en el shortcode '[gallery]' en todas las versiones hasta la 2.3.4, inclusive. Esto se debe a que el plugin modifica la salida del shortcode de galería para incluir el valor del atributo 'group' sin el escape adecuado. Esto permite a atacantes autenticados, con acceso de nivel Colaborador y superior, inyectar scripts web arbitrarios en páginas que se ejecutarán cada vez que un usuario acceda a una página inyectada."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"firelightwp","product":"LightPress Lightbox","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.3.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-13T15:06:26.859366Z","id":"CVE-2026-4379","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/wp-jquery-lightbox/tags/2.3.4/lightboxes/wp-jquery-lightbox/class-wp-jquery-lightbox.php#L376","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-jquery-lightbox/tags/2.3.4/lightboxes/wp-jquery-lightbox/class-wp-jquery-lightbox.php#L395","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=/wp-jquery-lightbox/tags/2.3.4&new_path=/wp-jquery-lightbox/tags/2.3.5","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2bed4818-70c5-40b7-8d8d-f43f3baa0f3d?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-3239","sourceIdentifier":"security@wordfence.com","published":"2026-04-08T05:16:05.567","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonial_view shortcode in all versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."},{"lang":"es","value":"El plugin Strong Testimonials para WordPress es vulnerable a cross-site scripting almacenado a través del shortcode 'testimonial_view' del plugin en todas las versiones hasta la 3.2.21, inclusive, debido a una sanitización de entrada y escape de salida insuficientes en los atributos proporcionados por el usuario. Esto hace posible que atacantes autenticados, con acceso de nivel de colaborador y superior, inyecten scripts web arbitrarios en páginas que se ejecutarán cada vez que un usuario acceda a una página inyectada."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"wpchill","product":"Strong Testimonials","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.2.21","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T15:06:55.230866Z","id":"CVE-2026-3239","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/changeset/3470120/strong-testimonials","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/88d769cd-bea8-42e4-80a8-a77c0699b50c?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-4341","sourceIdentifier":"security@wordfence.com","published":"2026-04-08T05:16:06.840","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'follow_us_text' setting of the Mount widget in all versions up to, and including, 4.1.10. This is due to insufficient input sanitization and output escaping. Specifically, the `render_social_link()` function in `modules/mount/widgets/mount.php` outputs the `follow_us_text` Elementor widget setting using `echo` without any escaping function. The setting value is stored in `_elementor_data` post meta via `update_post_meta`. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."},{"lang":"es","value":"El plugin Prime Slider - Addons for Elementor para WordPress es vulnerable a cross-site scripting almacenado a través de la configuración 'follow_us_text' del widget Mount en todas las versiones hasta la 4.1.10, inclusive. Esto se debe a una sanitización de entrada insuficiente y a un escape de salida deficiente. Específicamente, la función 'render_social_link()' en 'modules/mount/widgets/mount.php' genera la configuración del widget de Elementor 'follow_us_text' usando 'echo' sin ninguna función de escape. El valor de la configuración se almacena en la meta de publicación '_elementor_data' a través de 'update_post_meta'. Esto hace posible que atacantes autenticados, con acceso de nivel de Autor y superior, inyecten scripts web arbitrarios en páginas que se ejecutarán cada vez que un usuario acceda a una página inyectada."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"bdthemes","product":"Prime Slider – Addons for Elementor","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"4.1.10","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T15:56:04.299674Z","id":"CVE-2026-4341","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/bdthemes-prime-slider-lite/tags/4.1.9/modules/mount/widgets/mount.php#L1027","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/bdthemes-prime-slider-lite/tags/4.1.9/modules/mount/widgets/mount.php#L230","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/bdthemes-prime-slider-lite/trunk/modules/mount/widgets/mount.php#L1027","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/bdthemes-prime-slider-lite/trunk/modules/mount/widgets/mount.php#L230","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3493676%40bdthemes-prime-slider-lite&new=3493676%40bdthemes-prime-slider-lite&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4a2ef416-4354-4e09-b9be-e36c1f655110?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-4785","sourceIdentifier":"security@wordfence.com","published":"2026-04-08T05:16:06.997","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_caption' parameter in the [latepoint_resources] shortcode in versions up to and including 5.3.0. This is due to insufficient output escaping when the 'items' parameter is set to 'bundles'. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."},{"lang":"es","value":"El plugin LatePoint - Calendar Booking Plugin for Appointments and Events para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del parámetro 'button_caption' en el shortcode [latepoint_resources] en versiones hasta la 5.3.0 inclusive. Esto se debe a un escape de salida insuficiente cuando el parámetro 'items' está configurado como 'bundles'. Esto hace posible que atacantes autenticados, con acceso de nivel de colaborador y superior, inyecten scripts web arbitrarios en páginas que se ejecutarán cada vez que un usuario acceda a una página inyectada."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"latepoint","product":"LatePoint – Calendar Booking Plugin for Appointments and Events","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"5.3.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T14:13:09.433553Z","id":"CVE-2026-4785","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/latepoint/tags/5.2.10/lib/helpers/shortcodes_helper.php#L272","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/latepoint/tags/5.2.10/lib/helpers/shortcodes_helper.php#L40","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/latepoint/trunk/lib/helpers/shortcodes_helper.php#L272","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/latepoint/trunk/lib/helpers/shortcodes_helper.php#L40","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3491516/latepoint","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/55c5c094-69c0-4e2a-be0c-fab6f1039309?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-24913","sourceIdentifier":"vultures@jpcert.or.jp","published":"2026-04-08T06:16:27.073","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user who can log in to the product."},{"lang":"es","value":"Existe una vulnerabilidad de inyección SQL en MATCHA INVOICE 2.6.6 y anteriores. Si esta vulnerabilidad es explotada, la información almacenada en la base de datos puede ser obtenida o alterada por un usuario que puede iniciar sesión en el producto."}],"affected":[{"source":"vultures@jpcert.or.jp","affectedData":[{"vendor":"ICZ Corporation","product":"MATCHA INVOICE","versions":[{"version":"2.6.6 and earlier","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"vultures@jpcert.or.jp","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV30":[{"source":"vultures@jpcert.or.jp","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T15:06:21.413556Z","id":"CVE-2026-24913","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"vultures@jpcert.or.jp","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:icz:matcha_invoice:*:*:*:*:*:*:*:*","versionEndIncluding":"2.6.6","matchCriteriaId":"4BF23003-709B-4C38-BD44-946DDD4D511C"}]}]}],"references":[{"url":"https://jvn.jp/en/jp/JVN33581068/","source":"vultures@jpcert.or.jp","tags":["Third Party Advisory"]},{"url":"https://oss.icz.co.jp/news/?p=1386","source":"vultures@jpcert.or.jp","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27787","sourceIdentifier":"vultures@jpcert.or.jp","published":"2026-04-08T06:16:28.480","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product."},{"lang":"es","value":"Vulnerabilidad de cross-site scripting existe en MATCHA SNS 1.3.9 y anteriores. Si esta vulnerabilidad es explotada, un script arbitrario puede ser ejecutado en el navegador web del usuario que accedió al sitio web utilizando el producto."}],"affected":[{"source":"vultures@jpcert.or.jp","affectedData":[{"vendor":"ICZ Corporation","product":"MATCHA SNS","versions":[{"version":"1.3.9 and earlier","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"vultures@jpcert.or.jp","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV30":[{"source":"vultures@jpcert.or.jp","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T13:55:00.130119Z","id":"CVE-2026-27787","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"vultures@jpcert.or.jp","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:icz:matcha_sns:*:*:*:*:*:*:*:*","versionEndIncluding":"1.3.9","matchCriteriaId":"3644E0FD-FAB6-4D37-B37A-FA17DBB9B755"}]}]}],"references":[{"url":"https://jvn.jp/en/jp/JVN33581068/","source":"vultures@jpcert.or.jp","tags":["Third Party Advisory"]},{"url":"https://oss.icz.co.jp/news/?p=1388","source":"vultures@jpcert.or.jp","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-1794","sourceIdentifier":"security@wordfence.com","published":"2026-04-08T07:16:19.643","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded SVG files in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."},{"lang":"es","value":"El plugin AM LottiePlayer para WordPress es vulnerable a cross-site scripting almacenado a través de archivos SVG subidos en todas las versiones hasta la 3.6.0, inclusive, debido a una sanitización de entrada y un escape de salida insuficientes. Esto permite a atacantes autenticados, con acceso de nivel de Autor y superior, inyectar scripts web arbitrarios en páginas que se ejecutarán cada vez que un usuario acceda a una página inyectada."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"johanaarstein","product":"AM LottiePlayer","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.6.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T14:47:23.763614Z","id":"CVE-2025-1794","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/am-lottieplayer/tags/3.5.0/includes/upload-thumbnail.php","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ef2f1ad1-1e2e-4b56-b16c-d87956b142ad?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-2838","sourceIdentifier":"security@wordfence.com","published":"2026-04-08T07:16:20.707","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Whole Enquiry Cart for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘woowhole_success_msg’ parameter in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled."},{"lang":"es","value":"El plugin Whole Enquiry Cart for WooCommerce para WordPress es vulnerable a cross-site scripting almacenado a través del parámetro 'woowhole_success_msg' en todas las versiones hasta la 1.2.1, inclusive, debido a una sanitización de entrada y un escape de salida insuficientes. Esto permite que atacantes autenticados, con acceso de nivel de administrador, inyecten scripts web arbitrarios en páginas que se ejecutarán cada vez que un usuario acceda a una página inyectada. Esto solo afecta a instalaciones multisitio y a las instalaciones donde se ha deshabilitado unfiltered_html."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"idealwebdesignlk","product":"Whole Enquiry Cart for WooCommerce","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-13T15:07:21.336584Z","id":"CVE-2026-2838","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/whole-cart-enquiry/trunk/admin.php#L53","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ddc14a98-1df8-480b-bae3-5ec057b498af?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-3142","sourceIdentifier":"security@wordfence.com","published":"2026-04-08T07:16:20.870","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Pinterest Site Verification plugin using Meta Tag plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_var' parameter in versions up to, and including, 1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."},{"lang":"es","value":"El plugin Pinterest Site Verification que utiliza el plugin Meta Tag para WordPress es vulnerable a cross-site scripting almacenado a través del parámetro 'post_var' en versiones hasta la 1.8, inclusive, debido a una sanitización de entrada insuficiente y un escape de salida deficiente. Esto permite a atacantes autenticados, con acceso de nivel de suscriptor y superior, inyectar scripts web arbitrarios en páginas que se ejecutarán cada vez que un usuario acceda a una página inyectada."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"uniquecodergmailcom","product":"Pinterest Site Verification plugin using Meta Tag","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T13:54:30.533499Z","id":"CVE-2026-3142","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/pinterest-site-verification/tags/1.8/PinterestMetaTagSiteVerification.php#L132","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pinterest-site-verification/tags/1.8/PinterestMetaTagSiteVerification.php#L160","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pinterest-site-verification/tags/1.8/PinterestMetaTagSiteVerification.php#L172","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pinterest-site-verification/tags/1.8/PinterestMetaTagSiteVerification.php#L180","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pinterest-site-verification/tags/1.8/PinterestMetaTagSiteVerification.php#L214","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pinterest-site-verification/tags/1.8/PinterestMetaTagSiteVerification.php#L92","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pinterest-site-verification/trunk/PinterestMetaTagSiteVerification.php#L160","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7ccb7534-b588-4bdd-9627-0e38c0ee5e8a?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-4654","sourceIdentifier":"security@wordfence.com","published":"2026-04-08T08:16:24.237","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.3.7. This is due to the wpas_get_ticket_replies_ajax() function failing to verify whether the authenticated user has permission to view the specific ticket being requested. This makes it possible for authenticated attackers, with subscriber-level access and above, to access sensitive information from all support tickets in the system by manipulating the ticket_id parameter."},{"lang":"es","value":"El plugin Awesome Support - WordPress HelpDesk & Support Plugin para WordPress es vulnerable a Referencia Directa Insegura a Objeto en versiones hasta la 6.3.7, inclusive. Esto se debe a que la función wpas_get_ticket_replies_ajax() no verifica si el usuario autenticado tiene permiso para ver el ticket específico solicitado. Esto permite a atacantes autenticados, con acceso de nivel de suscriptor y superior, acceder a información sensible de todos los tickets de soporte en el sistema manipulando el parámetro ticket_id."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"awesomesupport","product":"Awesome Support – WordPress HelpDesk & Support Plugin","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"6.3.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T18:50:01.418065Z","id":"CVE-2026-4654","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/awesome-support/tags/6.3.7/includes/functions-post.php#L1823","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/awesome-support/tags/6.3.7/includes/functions-post.php#L1851","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/awesome-support/trunk/includes/functions-post.php#L1823","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/awesome-support/trunk/includes/functions-post.php#L1851","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3497662%40awesome-support&new=3497662%40awesome-support&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9f9015fa-b3f0-4312-8acd-02b715e26f33?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-4655","sourceIdentifier":"security@wordfence.com","published":"2026-04-08T08:16:24.407","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG Image Widget in versions up to and including 8.4.2. This is due to insufficient input sanitization and output escaping on SVG content fetched from remote URLs in the render_svg() function. The function fetches SVG content using wp_safe_remote_get() and then directly echoes it to the page without any sanitization, only applying a preg_replace() to add attributes to the SVG tag which does not remove malicious event handlers. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary JavaScript in SVG files that will execute whenever a user accesses a page containing the malicious widget."},{"lang":"es","value":"El plugin Element Pack Addons para Elementor para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del widget de imagen SVG en versiones hasta la 8.4.2 inclusive. Esto se debe a una sanitización de entrada y un escape de salida insuficientes en el contenido SVG obtenido de URLs remotas en la función render_svg(). La función obtiene contenido SVG utilizando wp_safe_remote_get() y luego lo imprime directamente en la página sin ninguna sanitización, solo aplicando un preg_replace() para añadir atributos a la etiqueta SVG, lo que no elimina los manejadores de eventos maliciosos. Esto hace posible que atacantes autenticados, con acceso de nivel Colaborador y superior, inyecten JavaScript arbitrario en archivos SVG que se ejecutará cada vez que un usuario acceda a una página que contenga el widget malicioso."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"bdthemes","product":"Element Pack – Widgets, Templates & Addons for Elementor","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"8.4.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T14:47:21.778238Z","id":"CVE-2026-4655","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/tags/8.4.2/modules/svg-image/widgets/svg-image.php#L1028","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/tags/8.4.2/modules/svg-image/widgets/svg-image.php#L1063-L1129","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/tags/8.4.2/modules/svg-image/widgets/svg-image.php#L989-L1033","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/trunk/modules/svg-image/widgets/svg-image.php#L1028","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/trunk/modules/svg-image/widgets/svg-image.php#L1063-L1129","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/trunk/modules/svg-image/widgets/svg-image.php#L989-L1033","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3494214%40bdthemes-element-pack-lite&new=3494214%40bdthemes-element-pack-lite&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0838f085-8ff7-4c6a-bd5b-af99f666377b?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-1396","sourceIdentifier":"security@wordfence.com","published":"2026-04-08T09:16:20.167","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Magic Conversation For Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'magic-conversation' shortcode in all versions up to, and including, 3.0.97 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."},{"lang":"es","value":"El plugin Magic Conversation For Gravity Forms para WordPress es vulnerable a cross-site scripting almacenado a través del shortcode 'magic-conversation' en todas las versiones hasta la 3.0.97, inclusive, debido a una sanitización de entrada y un escape de salida insuficientes en los atributos proporcionados por el usuario. Esto permite a atacantes autenticados, con acceso de nivel de colaborador y superior, inyectar scripts web arbitrarios en páginas que se ejecutarán cada vez que un usuario acceda a una página inyectada."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"magicplugins","product":"Magic Conversation For Gravity Forms","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.0.97","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-13T15:07:39.225383Z","id":"CVE-2026-1396","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/magic-conversation-for-gravity-forms/tags/3.0.96/main.php#L1627","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/magic-conversation-for-gravity-forms/trunk/main.php#L1627","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3482359/magic-conversation-for-gravity-forms/trunk/main.php","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bc425c4a-cb4e-4f50-b85b-8c4c7778c073?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-25776","sourceIdentifier":"vultures@jpcert.or.jp","published":"2026-04-08T09:16:20.360","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script."},{"lang":"es","value":"Movable Type proporcionado por Six Apart Ltd. contiene una vulnerabilidad de inyección de código que puede permitir a un atacante ejecutar scripts Perl arbitrarios."}],"affected":[{"source":"vultures@jpcert.or.jp","affectedData":[{"vendor":"Six Apart Ltd.","product":"Movable Type","versions":[{"version":"9.1.0 and earlier","status":"affected"}]},{"vendor":"Six Apart Ltd.","product":"Movable Type","versions":[{"version":"9.0.6 and earlier","status":"affected"}]},{"vendor":"Six Apart Ltd.","product":"Movable Type","versions":[{"version":"8.8.2 and earlier","status":"affected"}]},{"vendor":"Six Apart Ltd.","product":"Movable Type","versions":[{"version":"8.0.9 and earlier","status":"affected"}]},{"vendor":"Six Apart Ltd.","product":"Movable Type Advanced","versions":[{"version":"9.1.0 and earlier","status":"affected"}]},{"vendor":"Six Apart Ltd.","product":"Movable Type Advanced","versions":[{"version":"9.0.6 and earlier","status":"affected"}]},{"vendor":"Six Apart Ltd.","product":"Movable Type Advanced","versions":[{"version":"8.8.2 and earlier","status":"affected"}]},{"vendor":"Six Apart Ltd.","product":"Movable Type Advanced","versions":[{"version":"8.0.9 and earlier","status":"affected"}]},{"vendor":"Six Apart Ltd.","product":"Movable Type Premium","versions":[{"version":"9.1.0 and earlier","status":"affected"}]},{"vendor":"Six Apart Ltd.","product":"Movable Type Premium","versions":[{"version":"9.0.6 and earlier","status":"affected"}]},{"vendor":"Six Apart Ltd.","product":"Movable Type Premium Advanced Edition","versions":[{"version":"9.1.0 and earlier","status":"affected"}]},{"vendor":"Six Apart Ltd.","product":"Movable Type Premium Advanced Edition","versions":[{"version":"9.0.6 and earlier","status":"affected"}]},{"vendor":"Six Apart Ltd.","product":"Movable Type Premium","versions":[{"version":"2.14 and earlier","status":"affected"}]},{"vendor":"Six Apart Ltd.","product":"Movable Type Premium Advanced Edition","versions":[{"version":"2.14 and earlier","status":"affected"}]},{"vendor":"Six Apart Ltd.","product":"Movable Type Premium (MT8-based)","versions":[{"version":"2.14 and earlier","status":"affected"}]},{"vendor":"Six Apart Ltd.","product":"Movable Type","versions":[{"version":"5.1 to 5.18","status":"affected"}]},{"vendor":"Six Apart Ltd.","product":"Movable Type","versions":[{"version":"5.2","status":"affected"},{"version":"5.2.1 to 5.2.13","status":"affected"}]},{"vendor":"Six Apart Ltd.","product":"Movable Type","versions":[{"version":"6.0","status":"affected"},{"version":"6.0.1 to 6.8.8","status":"affected"}]},{"vendor":"Six Apart Ltd.","product":"Movable Type","versions":[{"version":"7 r.4207 to r.5510","status":"affected"}]},{"vendor":"Six Apart Ltd.","product":"Movable Type","versions":[{"version":"8.4.0 to 8.4.4","status":"affected"}]},{"vendor":"Six Apart Ltd.","product":"Movable Type","versions":[{"version":"1.0 to 1.68","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"vultures@jpcert.or.jp","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV30":[{"source":"vultures@jpcert.or.jp","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T13:21:57.431441Z","id":"CVE-2026-25776","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"vultures@jpcert.or.jp","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movable_type:*:*:*:*:premium_advanced:*:*:*","versionEndIncluding":"2.14","matchCriteriaId":"09DB1CCF-6A57-4A3F-AA0F-857A73E71792"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movable_type:9.0.5:*:*:*:premium_advanced:*:*:*","matchCriteriaId":"7212698E-C32C-418D-9674-5A92AF165D58"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movable_type:9.0.6:*:*:*:premium_advanced:*:*:*","matchCriteriaId":"19071E2C-D05C-4DD5-85A5-278F99AF152B"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movable_type:9.1.0:*:*:*:premium_advanced:*:*:*","matchCriteriaId":"99E9FBCF-3C7A-4383-AEEA-523F091914B1"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:*","versionStartIncluding":"8.0.2","versionEndExcluding":"8.0.10","matchCriteriaId":"E9932FC9-6FE6-4D49-B14A-88655FCC3F09"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:*","versionStartIncluding":"8.8.0","versionEndExcluding":"8.8.3","matchCriteriaId":"8D1EDB69-C876-44CD-872E-B516269013FF"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movable_type:*:*:*:*:advanced:*:*:*","versionStartIncluding":"9.0.1","versionEndExcluding":"9.0.7","matchCriteriaId":"1E752A5F-BD39-4024-9791-D1D816F13599"},{"vulnerable":true,"criteria":"cpe:2.3:a:sixapart:movable_type:9.1.0:*:*:*:advanced:*:*:*","matchCriteriaId":"69BA6472-F15D-4B42-A264-04B9C52FAF11"}]}]}],"references":[{"url":"https://jvn.jp/en/jp/JVN66473735/","source":"vultures@jpcert.or.jp","tags":["Third Party Advisory"]},{"url":"https://movabletype.org/news/2026/04/mt-907-released.html","source":"vultures@jpcert.or.jp","tags":["Vendor Advisory"]},{"url":"https://www.sixapart.jp/movabletype/news/2026/04/08-1100.html","source":"vultures@jpcert.or.jp","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-2509","sourceIdentifier":"security@wordfence.com","published":"2026-04-08T14:16:27.693","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget's Custom Attributes field in all versions up to, and including, 2.0.8. This is due to an incomplete event handler blocklist in the 'pagelayer_xss_content' XSS filtering function, which blocks common, but not all, event handlers. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."},{"lang":"es","value":"El plugin Page Builder: Pagelayer para WordPress es vulnerable a Stored Cross-Site Scripting a través del campo de Atributos Personalizados del widget de Botón en todas las versiones hasta la versión, e incluyendo, 2.0.8. Esto se debe a una lista negra de gestores de eventos incompleta en la función de filtrado de XSS 'pagelayer_xss_content', que bloquea gestores de eventos comunes, pero no todos. Esto hace posible que atacantes autenticados, con acceso de nivel de Colaborador y superior, inyecten scripts web arbitrarios en páginas que se ejecutarán cada vez que un usuario acceda a una página inyectada."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"softaculous","product":"Page Builder: Pagelayer – Drag and Drop website builder","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.0.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T14:47:17.692642Z","id":"CVE-2026-2509","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/pagelayer/trunk/main/functions.php#L1293","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pagelayer/trunk/main/shortcode_functions.php#L689","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3479046/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/915c119d-2bae-4ea6-babb-7e8e99054cd0?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-31411","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-04-08T14:16:27.977","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: atm: fix crash due to unvalidated vcc pointer in sigd_send()\n\nReproducer available at [1].\n\nThe ATM send path (sendmsg -> vcc_sendmsg -> sigd_send) reads the vcc\npointer from msg->vcc and uses it directly without any validation. This\npointer comes from userspace via sendmsg() and can be arbitrarily forged:\n\n    int fd = socket(AF_ATMSVC, SOCK_DGRAM, 0);\n    ioctl(fd, ATMSIGD_CTRL);  // become ATM signaling daemon\n    struct msghdr msg = { .msg_iov = &iov, ... };\n    *(unsigned long *)(buf + 4) = 0xdeadbeef;  // fake vcc pointer\n    sendmsg(fd, &msg, 0);  // kernel dereferences 0xdeadbeef\n\nIn normal operation, the kernel sends the vcc pointer to the signaling\ndaemon via sigd_enq() when processing operations like connect(), bind(),\nor listen(). The daemon is expected to return the same pointer when\nresponding. However, a malicious daemon can send arbitrary pointer values.\n\nFix this by introducing find_get_vcc() which validates the pointer by\nsearching through vcc_hash (similar to how sigd_close() iterates over\nall VCCs), and acquires a reference via sock_hold() if found.\n\nSince struct atm_vcc embeds struct sock as its first member, they share\nthe same lifetime. Therefore using sock_hold/sock_put is sufficient to\nkeep the vcc alive while it is being used.\n\nNote that there may be a race with sigd_close() which could mark the vcc\nwith various flags (e.g., ATM_VF_RELEASED) after find_get_vcc() returns.\nHowever, sock_hold() guarantees the memory remains valid, so this race\nonly affects the logical state, not memory safety.\n\n[1]: https://gist.github.com/mrpre/1ba5949c45529c511152e2f4c755b0f3"},{"lang":"es","value":"En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nnet: atm: corrige un fallo debido a un puntero vcc no validado en sigd_send()\n\nReproductor disponible en [1].\n\nLa ruta de envío de ATM (sendmsg   ->   vcc_sendmsg   ->   sigd_send) lee el puntero vcc de msg  ->  vcc y lo usa directamente sin ninguna validación. Este puntero proviene del espacio de usuario a través de sendmsg() y puede ser forjado arbitrariamente:\n\n    int fd = socket(AF_ATMSVC, SOCK_DGRAM, 0);\n    ioctl(fd, ATMSIGD_CTRL);  // se convierte en demonio de señalización ATM\n    struct msghdr msg = { .msg_iov = &iov, ... };\n    *(unsigned long *)(buf + 4) = 0xdeadbeef;  // puntero vcc falso\n    sendmsg(fd, &msg, 0);  // el kernel desreferencia 0xdeadbeef\n\nEn operación normal, el kernel envía el puntero vcc al demonio de señalización a través de sigd_enq() al procesar operaciones como connect(), bind() o listen(). Se espera que el demonio devuelva el mismo puntero al responder. Sin embargo, un demonio malicioso puede enviar valores de puntero arbitrarios.\n\nEsto se soluciona introduciendo find_get_vcc() que valida el puntero buscando en vcc_hash (similar a cómo sigd_close() itera sobre todos los VCC), y adquiere una referencia a través de sock_hold() si se encuentra.\n\nDado que struct atm_vcc incrusta struct sock como su primer miembro, comparten la misma vida útil. Por lo tanto, usar sock_hold/sock_put es suficiente para mantener el vcc activo mientras se está utilizando.\n\nTenga en cuenta que puede haber una condición de carrera con sigd_close() que podría marcar el vcc con varias banderas (por ejemplo, ATM_VF_RELEASED) después de que find_get_vcc() retorne. Sin embargo, sock_hold() garantiza que la memoria permanece válida, por lo que esta condición de carrera solo afecta el estado lógico, no la seguridad de la memoria.\n\n[1]: https://gist.github.com/mrpre/1ba5949c45529c511152e2f4c755b0f3"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/atm/signaling.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c96549d07dfdd51aadf0722cfb40711574424840","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1c8bda3df028d5e54134077dcd09f46ca8cfceb5","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3e1a8b00095246a9a2b46b57f6d471c6d3c00ed2","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e3f80666c2739296c3b69a127300455c43aa1067","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"21c303fec138c002f90ed33bce60e807d53072bb","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"69d3f9ee5489e6e8b66defcfa226e91d82393297","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"440c9a5fc477a8ee259d8bf669531250b8398651","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ae88a5d2f29b69819dc7b04086734439d074a643","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/atm/signaling.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.252","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.202","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.165","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.128","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.75","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.14","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"6.19.4","lessThanOrEqual":"6.19.*","versionType":"semver","status":"unaffected"},{"version":"7.0","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]},{"source":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","affectedData":[{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","defaultStatus":"unknown","versions":[{"version":"V3.1.6","lessThan":"*","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","defaultStatus":"unknown","versions":[{"version":"V3.1.5","lessThan":"*","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","defaultStatus":"unknown","versions":[{"version":"V3.1.6","lessThan":"*","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","defaultStatus":"unknown","versions":[{"version":"V3.1.5","lessThan":"*","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","defaultStatus":"unknown","versions":[{"version":"V3.1.6","lessThan":"*","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","defaultStatus":"unknown","versions":[{"version":"V3.1.5","lessThan":"*","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","defaultStatus":"unknown","versions":[{"version":"V3.1.6","lessThan":"*","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","defaultStatus":"unknown","versions":[{"version":"V3.1.5","lessThan":"*","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SIPLUS S7-1500 CPU 1518-4 PN/DP MFP","defaultStatus":"unknown","versions":[{"version":"V3.1.6","lessThan":"*","versionType":"custom","status":"affected"}]},{"vendor":"Siemens","product":"SIPLUS S7-1500 CPU 1518-4 PN/DP MFP","defaultStatus":"unknown","versions":[{"version":"V3.1.5","lessThan":"*","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-476"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.12.1","versionEndExcluding":"5.10.252","matchCriteriaId":"68B6D2AD-7565-4394-B77B-A1EEBCDF590F"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11","versionEndExcluding":"5.15.202","matchCriteriaId":"4002FC2B-1456-4666-B240-0EBF590C4671"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16","versionEndExcluding":"6.1.165","matchCriteriaId":"797C7F46-D0BE-4FB8-A502-C5EF8E6B6654"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"6.6.128","matchCriteriaId":"851E9353-6C09-4CC9-877E-E09DB164A3C2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"6.12.75","matchCriteriaId":"BCE16369-98ED-41CF-8995-DFDC10B288D2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"6.18.14","matchCriteriaId":"BF463CB7-1F58-4607-B847-77ED23E4B9B7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.19","versionEndExcluding":"6.19.4","matchCriteriaId":"672A3E79-EC03-479D-8503-361DFBDC8092"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*","matchCriteriaId":"4F76C298-81DC-43E4-8FC9-DC005A2116EF"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*","matchCriteriaId":"0AB349B2-3F78-4197-882B-90ADB3BF645A"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*","matchCriteriaId":"6AC88830-A9BC-4607-B572-A4B502FC9FD0"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*","matchCriteriaId":"476CB3A5-D022-4F13-AAEF-CB6A5785516A"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*","matchCriteriaId":"F253B622-8837-4245-BCE5-A7BF8FC76A16"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*","matchCriteriaId":"4AE85AD8-4641-4E7C-A2F4-305E2CD9EE64"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*","matchCriteriaId":"F666C8D8-6538-46D4-B318-87610DE64C34"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*","matchCriteriaId":"02259FDA-961B-47BC-AE7F-93D7EC6E90C2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*","matchCriteriaId":"58A9FEFF-C040-420D-8F0A-BFDAAA1DF258"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*","matchCriteriaId":"1D2315C0-D46F-4F85-9754-F9E5E11374A6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*","matchCriteriaId":"512EE3A8-A590-4501-9A94-5D4B268D6138"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/1c8bda3df028d5e54134077dcd09f46ca8cfceb5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"]},{"url":"https://git.kernel.org/stable/c/21c303fec138c002f90ed33bce60e807d53072bb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"]},{"url":"https://git.kernel.org/stable/c/3e1a8b00095246a9a2b46b57f6d471c6d3c00ed2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"]},{"url":"https://git.kernel.org/stable/c/440c9a5fc477a8ee259d8bf669531250b8398651","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"]},{"url":"https://git.kernel.org/stable/c/69d3f9ee5489e6e8b66defcfa226e91d82393297","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"]},{"url":"https://git.kernel.org/stable/c/ae88a5d2f29b69819dc7b04086734439d074a643","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"]},{"url":"https://git.kernel.org/stable/c/c96549d07dfdd51aadf0722cfb40711574424840","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"]},{"url":"https://git.kernel.org/stable/c/e3f80666c2739296c3b69a127300455c43aa1067","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"]},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-019113.html","source":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-082556.html","source":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"}]}},{"cve":{"id":"CVE-2026-31040","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T16:16:22.977","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command execution."},{"lang":"es","value":"Se identificó una vulnerabilidad en stata-mcp anterior a la v1.13.0 donde la validación insuficiente del contenido de archivos do de Stata proporcionados por el usuario puede llevar a la ejecución de comandos."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T18:23:38.978894Z","id":"CVE-2026-31040","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:statamcp:stata-mcp:*:*:*:*:*:*:*:*","versionEndExcluding":"1.13.0","matchCriteriaId":"CD23CBFB-6391-4291-9380-AE45481E555A"}]}]}],"references":[{"url":"https://github.com/SepineTam/stata-mcp/commit/52413ce","source":"cve@mitre.org","tags":["Patch"]},{"url":"https://github.com/SepineTam/stata-mcp/issues/20","source":"cve@mitre.org","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://github.com/SepineTam/stata-mcp/pull/21","source":"cve@mitre.org","tags":["Issue Tracking"]},{"url":"https://github.com/SepineTam/stata-mcp/releases/tag/v1.13.0","source":"cve@mitre.org","tags":["Release Notes"]},{"url":"https://github.com/SepineTam/stata-mcp/issues/20","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2023-46945","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T17:17:01.010","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request"},{"lang":"es","value":"QD 20230821 es vulnerable a falsificación de petición del lado del servidor (SSRF) mediante una petición manipulada"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T20:47:01.299386Z","id":"CVE-2023-46945","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:qd-today:qd:*:*:*:*:*:*:*:*","versionStartIncluding":"20220208","versionEndIncluding":"20230821","matchCriteriaId":"FD7FAE1E-5E6B-40B3-B648-DF32C05DC03D"}]}]}],"references":[{"url":"https://gist.github.com/kurokoleung/5b36b2013a54adadcce79967d3e4f056","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://qd-today.github.io/qd/","source":"cve@mitre.org","tags":["Product"]}]}},{"cve":{"id":"CVE-2025-14243","sourceIdentifier":"secalert@redhat.com","published":"2026-04-08T17:20:25.247","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account creation."},{"lang":"es","value":"Se encontró una falla en el OpenShift Mirror Registry. Esta vulnerabilidad permite a un atacante remoto no autenticado enumerar nombres de usuario y direcciones de correo electrónico válidos a través de diferentes mensajes de error durante fallas de autenticación y creación de cuentas."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"mirror registry for Red Hat OpenShift","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift/mirror-registry-rhel8","cpes":["cpe:/a:redhat:mirror_registry:1"]},{"vendor":"Red Hat","product":"mirror registry for Red Hat OpenShift 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift/mirror-registry-rhel8","cpes":["cpe:/a:redhat:mirror_registry:2"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T19:14:34.911976Z","id":"CVE-2025-14243","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-209"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:-:*:*:*:*:*:*:*","matchCriteriaId":"63757310-FC5B-44E6-9211-36269827BC56"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:2.0:*:*:*:*:*:*:*","matchCriteriaId":"281E6AA4-1E08-488F-BA7A-F0BE7CF42A5B"}]}]}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2025-14243","source":"secalert@redhat.com","tags":["Vendor Advisory"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2419829","source":"secalert@redhat.com","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-57175","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T17:20:46.730","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Siklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b devices have a static root password."},{"lang":"es","value":"Los dispositivos Siklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b tienen una contraseña raíz estática."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"Siklu","product":"EtherHaul 8010","defaultStatus":"unaffected","versions":[{"version":"siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.5,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T14:28:28.508293Z","id":"CVE-2025-57175","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@mitre.org","type":"Secondary","description":[{"lang":"en","value":"CWE-259"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ceragon:etherhaul-8010fx_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"8DC76E10-4980-413A-BF93-9CFE2758A12B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ceragon:etherhaul-8010fx:-:*:*:*:*:*:*:*","matchCriteriaId":"FDAA9028-E0B7-4A38-9B83-F7C07B97D317"}]}]}],"references":[{"url":"https://semaja2.net/2025/04/30/siklu-eh-firmware-decryption/","source":"cve@mitre.org","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-2377","sourceIdentifier":"secalert@redhat.com","published":"2026-04-08T17:21:16.237","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to specify an arbitrary callback URL. A backend process then makes server-side HTTP requests to this provided URL. This vulnerability, known as Server-Side Request Forgery (SSRF), could allow an attacker to send requests from the application's internal network, potentially leading to the disclosure of sensitive information."},{"lang":"es","value":"Se encontró una falla en mirror-registry. Usuarios autenticados pueden explotar la función de exportación de registros al proporcionar una dirección web (URL) especialmente diseñada. Esto permite al backend de la aplicación realizar peticiones arbitrarias a recursos de red internos, una vulnerabilidad conocida como Falsificación de Petición del Lado del Servidor (SSRF). Esto podría conducir a acceso no autorizado a información sensible o a otros sistemas internos."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"Red Hat Quay 3.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.10::el8"],"versions":[{"version":"1779822261","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.12","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.12::el8"],"versions":[{"version":"1779811412","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.14","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.14::el8"],"versions":[{"version":"1779689392","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.15","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.15::el8"],"versions":[{"version":"1780891395","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.16","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel9","cpes":["cpe:/a:redhat:quay:3.16::el9"],"versions":[{"version":"1779204086","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.9::el8"],"versions":[{"version":"1779811473","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"mirror registry for Red Hat OpenShift","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift/mirror-registry-rhel8","cpes":["cpe:/a:redhat:mirror_registry:1"]},{"vendor":"Red Hat","product":"mirror registry for Red Hat OpenShift 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift/mirror-registry-rhel8","cpes":["cpe:/a:redhat:mirror_registry:2"]}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","affectedData":[{"vendor":"Red Hat","product":"Red Hat Quay 3.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.10::el8"],"versions":[{"version":"1779822261","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.12","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.12::el8"],"versions":[{"version":"1779811412","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.14","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.14::el8"],"versions":[{"version":"1779689392","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.15","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.15::el8"],"versions":[{"version":"1780891395","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.16","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel9","cpes":["cpe:/a:redhat:quay:3.16::el9"],"versions":[{"version":"1779204086","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.9::el8"],"versions":[{"version":"1779811473","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"mirror registry for Red Hat OpenShift","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift/mirror-registry-rhel8","cpes":["cpe:/a:redhat:mirror_registry:1"]},{"vendor":"Red Hat","product":"mirror registry for Red Hat OpenShift 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift/mirror-registry-rhel8","cpes":["cpe:/a:redhat:mirror_registry:2"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T18:42:52.638708Z","id":"CVE-2026-2377","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:-:*:*:*:*:*:*:*","matchCriteriaId":"63757310-FC5B-44E6-9211-36269827BC56"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:2.0:*:*:*:*:*:*:*","matchCriteriaId":"281E6AA4-1E08-488F-BA7A-F0BE7CF42A5B"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:*","matchCriteriaId":"B1987BDA-0113-4603-B9BE-76647EB043F2"}]}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:19375","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:21017","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:22629","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:22840","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:23361","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:24853","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-2377","source":"secalert@redhat.com","tags":["Vendor Advisory"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2439201","source":"secalert@redhat.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:19375","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:21017","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22629","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22840","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:23361","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24853","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-2377","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Vendor Advisory"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2439201","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2377.json","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}]}},{"cve":{"id":"CVE-2026-30075","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T17:21:18.503","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"OpenAirInterface Version 2.2.0 has a Buffer Overflow vulnerability in processing UplinkNASTransport containing Authentication Response containing a NAS PDU with oversize response (For example 100 byte). The response is decoded by AMF and passed to the AUSF component for verification. AUSF crashes on receiving this oversize response. This can prohibit users from further registration and verification and can cause Denial of Services (DoS)."},{"lang":"es","value":"OpenAirInterface Versión 2.2.0 tiene una vulnerabilidad de desbordamiento de búfer al procesar UplinkNASTransport que contiene una Respuesta de Autenticación que contiene una PDU NAS con una respuesta de tamaño excesivo (por ejemplo, 100 bytes). La respuesta es decodificada por el AMF y pasada al componente AUSF para su verificación. AUSF falla al recibir esta respuesta de tamaño excesivo. Esto puede impedir que los usuarios se registren y verifiquen posteriormente y puede causar Denegación de Servicios (DoS)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T20:48:12.559806Z","id":"CVE-2026-30075","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openairinterface:oai-cn5g-amf:2.2.0:*:*:*:*:*:*:*","matchCriteriaId":"1BB4900E-B5A7-40ED-8DA6-4E372D5036D9"}]}]}],"references":[{"url":"https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-ausf/-/issues/6","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-ausf/-/issues?show=eyJpaWQiOiI2IiwiZnVsbF9wYXRoIjoib2FpL2NuNWcvb2FpLWNuNWctYXVzZiIsImlkIjo1NDE5fQ%3D%3D","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-ausf/-/issues?show=eyJpaWQiOiI2IiwiZnVsbF9wYXRoIjoib2FpL2NuNWcvb2FpLWNuNWctYXVzZiIsImlkIjo1NDE5fQ%3D%3D","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-30080","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T17:21:18.623","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"OpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection. Configuration has supported integrity NIA1 and NIA2. But if an UE sends initial registration request with only security capability IA0, OpenAirInterface accepts and proceeds. This downgrade security context can lead to the possibility of replay attack."},{"lang":"es","value":"OpenAirInterface v2.2.0 acepta el Modo de Seguridad Completo sin ninguna protección de integridad. La configuración ha soportado integridad NIA1 y NIA2. Pero si un UE envía una solicitud de registro inicial con solo la capacidad de seguridad IA0, OpenAirInterface acepta y procede. Este contexto de seguridad degradado puede llevar a la posibilidad de un ataque de repetición."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T20:44:07.722198Z","id":"CVE-2026-30080","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-294"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openairinterface:oai-cn5g-amf:2.2.0:*:*:*:*:*:*:*","matchCriteriaId":"1BB4900E-B5A7-40ED-8DA6-4E372D5036D9"}]}]}],"references":[{"url":"https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf/-/issues/78","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-amf/-/issues/78","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Issue Tracking","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-31017","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T17:21:18.737","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF. When generating PDFs from user-controlled HTML content, the application allows the inclusion of HTML elements such as <iframe> that reference external resources. The PDF rendering engine automatically fetches these resources on the server side. An attacker can abuse this behavior to force the server to make arbitrary HTTP requests to internal services, including cloud metadata endpoints, potentially leading to sensitive information disclosure."},{"lang":"es","value":"Una vulnerabilidad de falsificación de petición del lado del servidor (SSRF) existe en la funcionalidad de Formato de Impresión de ERPNext v16.0.1 y Frappe Framework v16.1.1, donde el HTML proporcionado por el usuario no se sanea suficientemente antes de ser renderizado a PDF. Al generar PDFs a partir de contenido HTML controlado por el usuario, la aplicación permite la inclusión de elementos HTML como <iframe> que referencian recursos externos. El motor de renderizado de PDF recupera automáticamente estos recursos en el lado del servidor. Un atacante puede abusar de este comportamiento para forzar al servidor a realizar peticiones HTTP arbitrarias a servicios internos, incluyendo puntos finales de metadatos en la nube, lo que podría llevar a la revelación de información sensible."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T20:49:37.726087Z","id":"CVE-2026-31017","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:frappe:erpnext:16.0.1:*:*:*:*:*:*:*","matchCriteriaId":"3B49FE4D-85A8-44E2-9BF2-E60B7FFBAC81"},{"vulnerable":true,"criteria":"cpe:2.3:a:frappe:frappe:16.1.1:*:*:*:*:*:*:*","matchCriteriaId":"461D4C6F-5E45-43CA-A47F-D5DDDD083786"}]}]}],"references":[{"url":"https://github.com/PhDg1410/CVE/tree/main/CVE-2026-31017","source":"cve@mitre.org","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-4498","sourceIdentifier":"security@elastic.co","published":"2026-04-08T17:21:24.300","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elasticsearch RBAC scope via Privilege Abuse (CAPEC-122). This requires an authenticated Kibana user with Fleet sub-feature privileges (such as agents, agent policies, and settings management)."},{"lang":"es","value":"La Ejecución con Privilegios Innecesarios (CWE-250) en los manejadores de rutas de depuración del plugin Fleet de Kibana puede llevar a la lectura de datos de índices más allá de su alcance directo de RBAC de Elasticsearch a través de Abuso de Privilegios (CAPEC-122). Esto requiere un usuario autenticado de Kibana con privilegios de subcaracterísticas de Fleet (como agentes, políticas de agentes y gestión de configuraciones)."}],"affected":[{"source":"security@elastic.co","affectedData":[{"vendor":"Elastic","product":"Kibana","defaultStatus":"unaffected","versions":[{"version":"8.0.0","lessThanOrEqual":"8.19.13","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@elastic.co","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T14:27:31.273591Z","id":"CVE-2026-4498","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@elastic.co","type":"Secondary","description":[{"lang":"en","value":"CWE-250"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"8.19.14","matchCriteriaId":"CF93FCD4-2955-45FD-B96D-925121A156F7"},{"vulnerable":true,"criteria":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"9.2.8","matchCriteriaId":"301F60F3-1479-432C-875A-76797F9A16D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","versionStartIncluding":"9.3.0","versionEndExcluding":"9.3.3","matchCriteriaId":"5EE7B9F3-E587-498B-822D-785CB848F767"}]}]}],"references":[{"url":"https://discuss.elastic.co/t/kibana-8-19-14-9-2-8-9-3-3-security-update-esa-2026-21/385811","source":"security@elastic.co","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-45057","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T18:24:45.597","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input."},{"lang":"es","value":"D-Link DI-8300 v16.07.26A1 se descubrió que contenía un desbordamiento de búfer a través del parámetro ip en la función ip_position_asp. Esta vulnerabilidad permite a los atacantes causar una denegación de servicio (DoS) a través de una entrada manipulada."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T20:50:34.234405Z","id":"CVE-2025-45057","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8300_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"703A6A50-00DA-482E-925C-01463CE0CF64"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8300:-:*:*:*:*:*:*:*","matchCriteriaId":"037DA05B-D471-42A3-B7EE-E341C716D7CB"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://www.dlink.com.cn/techsupport/ProductInfo.aspx?m=DI-8300","source":"cve@mitre.org","tags":["Product"]},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-45058","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T18:24:45.723","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the fx parameter in the jingx_asp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input."},{"lang":"es","value":"D-Link DI-8300 v16.07.26A1 se descubrió que contenía un desbordamiento de búfer a través del parámetro fx en la función jingx_asp. Esta vulnerabilidad permite a los atacantes causar una denegación de servicio (DoS) a través de una entrada manipulada."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T20:51:28.738422Z","id":"CVE-2025-45058","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8300_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"703A6A50-00DA-482E-925C-01463CE0CF64"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8300:-:*:*:*:*:*:*:*","matchCriteriaId":"037DA05B-D471-42A3-B7EE-E341C716D7CB"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://www.dlink.com.cn/techsupport/ProductInfo.aspx?m=DI-8300","source":"cve@mitre.org","tags":["Product"]},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-45059","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T18:24:45.840","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input."},{"lang":"es","value":"D-Link DI-8300 v16.07.26A1 se descubrió que contenía un desbordamiento de búfer a través del parámetro fn en la función tgfile_htm. Esta vulnerabilidad permite a los atacantes causar una Denegación de Servicio (DoS) a través de una entrada manipulada."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T13:07:49.372423Z","id":"CVE-2025-45059","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8300_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"703A6A50-00DA-482E-925C-01463CE0CF64"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8300:-:*:*:*:*:*:*:*","matchCriteriaId":"037DA05B-D471-42A3-B7EE-E341C716D7CB"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://www.dlink.com.cn/techsupport/ProductInfo.aspx?m=DI-8300","source":"cve@mitre.org","tags":["Product"]},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-52221","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T18:24:51.257","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameters."},{"lang":"es","value":"Tenda AC6 15.03.05.16_multi es vulnerable a desbordamiento de búfer en la función formSetCfm a través de los parámetros funcname, funcpara1 y funcpara2."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T13:08:39.678948Z","id":"CVE-2025-52221","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tenda:ac6_firmware:15.03.05.16_multi:*:*:*:*:*:*:*","matchCriteriaId":"D0E5BB82-F2E3-4BB9-AE3C-267D3462CA96"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tenda:ac6:1.0:*:*:*:*:*:*:*","matchCriteriaId":"B622BF6D-85E6-475A-B7FB-11BA1A641191"}]}]}],"references":[{"url":"https://github.com/faqiadegege/IoTVuln/blob/main/tendaAc6_formSetCfm_funcname_overflow/detail.md","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2025-52222","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T18:24:51.373","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-8400 v16.07.26A1, DI-8004w v16.07.26A1, DI-8100 v16.07.26A1, and DI-8100G v17.12.20A1 were discovered to contain a buffer overflow via the rd_en, rd_auth, rd_acct, http_hadmin, http_hadminpwd, rd_key, and rd_ip parameters in the radius_asp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request."},{"lang":"es","value":"D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-8400 v16.07.26A1, DI-8004w v16.07.26A1, DI-8100 v16.07.26A1, y DI-8100G v17.12.20A1 fueron descubiertos por contener un desbordamiento de búfer a través de los parámetros rd_en, rd_auth, rd_acct, http_hadmin, http_hadminpwd, rd_key y rd_ip en la función radius_asp. Esta vulnerabilidad permite a los atacantes causar una denegación de servicio (DoS) a través de una solicitud manipulada."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T13:10:26.470216Z","id":"CVE-2025-52222","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8100_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"4FA39417-3894-4D6D-A899-000F56AA482B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8100:-:*:*:*:*:*:*:*","matchCriteriaId":"8D417784-56F2-40AF-8FE8-C00E6F332131"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8100g_firmware:17.12.20a1:*:*:*:*:*:*:*","matchCriteriaId":"A134EE00-C43F-41CC-9F7C-B94EA94E2113"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8100g:-:*:*:*:*:*:*:*","matchCriteriaId":"DAA6037E-C080-4254-BDEC-1B5DFC64B937"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8004w_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"E568896E-FDFE-4D97-B82E-5E983AE8AF45"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8004w:-:*:*:*:*:*:*:*","matchCriteriaId":"FE1CEDFF-4310-444D-85F9-B93B77D0C73B"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003g_firmware:17.12.21a1:*:*:*:*:*:*:*","matchCriteriaId":"7FCE463D-0777-46D0-A102-81EB20622BA8"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003g:-:*:*:*:*:*:*:*","matchCriteriaId":"47C603E1-32FB-4335-B368-1E95529B3106"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8500_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"47EBB0E8-37EF-4D2B-ADB3-1BDEC33829A3"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8500:-:*:*:*:*:*:*:*","matchCriteriaId":"157BC421-0A70-4F55-840A-683A27F1BD5B"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8200g_firmware:17.12.20a1:*:*:*:*:*:*:*","matchCriteriaId":"759CBE57-D426-4F76-BE51-BBB1276538A5"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8200g:-:*:*:*:*:*:*:*","matchCriteriaId":"D8F711B9-4D2E-4FE3-B1DB-68E3F15BCC26"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8200_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"694649F4-AF9D-456F-AC3E-3848B677013E"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8200:a1:*:*:*:*:*:*:*","matchCriteriaId":"95B5091D-76F9-49EC-8D21-A96549078BFB"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8400_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"7293D6F3-30C0-4805-A662-ADAC551BAB7A"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8400:a1:*:*:*:*:*:*:*","matchCriteriaId":"75CE4566-1587-4A8E-8D4E-8693149670DF"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-32589","sourceIdentifier":"secalert@redhat.com","published":"2026-04-08T18:25:59.790","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have access to. This could allow the attacker to read, modify, or cancel another user's in-progress image upload."},{"lang":"es","value":"Se encontró una falla en el proceso de carga de imágenes de contenedores de Red Hat Quay. Un usuario autenticado con acceso de push a cualquier repositorio en el registro puede interferir con las cargas de imágenes en curso de otros usuarios, incluyendo aquellas en repositorios a los que no tienen acceso. Esto podría permitir al atacante leer, modificar o cancelar la carga de imagen en curso de otro usuario."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"mirror registry for Red Hat OpenShift 2.0","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift/mirror-registry-rhel8","cpes":["cpe:/a:redhat:mirror_registry:2.0::el8"],"versions":[{"version":"1782177012","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.10::el8"],"versions":[{"version":"1779822261","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.12","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.12::el8"],"versions":[{"version":"1779811412","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.14","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.14::el8"],"versions":[{"version":"1779689392","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.15","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.15::el8"],"versions":[{"version":"1780891395","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.16","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel9","cpes":["cpe:/a:redhat:quay:3.16::el9"],"versions":[{"version":"1779204086","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.17","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel9","cpes":["cpe:/a:redhat:quay:3.17::el9"],"versions":[{"version":"1779922205","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.9::el8"],"versions":[{"version":"1779811473","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"mirror registry for Red Hat OpenShift","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift/mirror-registry-rhel8","cpes":["cpe:/a:redhat:mirror_registry:1"]}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","affectedData":[{"vendor":"Red Hat","product":"mirror registry for Red Hat OpenShift 2.0","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift/mirror-registry-rhel8","cpes":["cpe:/a:redhat:mirror_registry:2.0::el8"],"versions":[{"version":"1782177012","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.10::el8"],"versions":[{"version":"1779822261","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.12","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.12::el8"],"versions":[{"version":"1779811412","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.14","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.14::el8"],"versions":[{"version":"1779689392","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.15","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.15::el8"],"versions":[{"version":"1780891395","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.16","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel9","cpes":["cpe:/a:redhat:quay:3.16::el9"],"versions":[{"version":"1779204086","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.17","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel9","cpes":["cpe:/a:redhat:quay:3.17::el9"],"versions":[{"version":"1779922205","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.9::el8"],"versions":[{"version":"1779811473","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"mirror registry for Red Hat OpenShift","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift/mirror-registry-rhel8","cpes":["cpe:/a:redhat:mirror_registry:1"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.1,"impactScore":3.7},{"source":"nvd@nist.gov","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":3.4},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.1,"impactScore":3.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T18:01:21.450628Z","id":"CVE-2026-32589","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:-:*:*:*:*:*:*:*","matchCriteriaId":"63757310-FC5B-44E6-9211-36269827BC56"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:2.0:*:*:*:*:*:*:*","matchCriteriaId":"281E6AA4-1E08-488F-BA7A-F0BE7CF42A5B"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:*","matchCriteriaId":"B1987BDA-0113-4603-B9BE-76647EB043F2"}]}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:19375","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:21017","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:22465","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:22629","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:22840","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:23361","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:24853","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:28441","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-32589","source":"secalert@redhat.com","tags":["Vendor Advisory"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2446963","source":"secalert@redhat.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:19375","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:21017","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22465","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22629","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22840","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:23361","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24853","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:28441","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-32589","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Vendor Advisory"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2446963","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32589.json","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}]}},{"cve":{"id":"CVE-2026-32590","sourceIdentifier":"secalert@redhat.com","published":"2026-04-08T18:25:59.947","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server."},{"lang":"es","value":"Se encontró una vulnerabilidad en el manejo de Red Hat Quay de las cargas reanudables de capas de imágenes de contenedor. El proceso de carga almacena datos intermedios en la base de datos utilizando un formato que, si se manipula, podría permitir a un atacante ejecutar código arbitrario en el servidor Quay."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"mirror registry for Red Hat OpenShift 2.0","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift/mirror-registry-rhel8","cpes":["cpe:/a:redhat:mirror_registry:2.0::el8"],"versions":[{"version":"1782177012","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.10::el8"],"versions":[{"version":"1779822261","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.12","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.12::el8"],"versions":[{"version":"1779811412","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.14","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.14::el8"],"versions":[{"version":"1779689392","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.15","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.15::el8"],"versions":[{"version":"1780891395","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.16","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel9","cpes":["cpe:/a:redhat:quay:3.16::el9"],"versions":[{"version":"1779204086","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.17","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel9","cpes":["cpe:/a:redhat:quay:3.17::el9"],"versions":[{"version":"1779922205","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.17","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel9","cpes":["cpe:/a:redhat:quay:3.17::el9"],"versions":[{"version":"1780604033","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.9::el8"],"versions":[{"version":"1779811473","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"mirror registry for Red Hat OpenShift","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift/mirror-registry-rhel8","cpes":["cpe:/a:redhat:mirror_registry:1"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T19:14:47.764287Z","id":"CVE-2026-32590","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-502"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:-:*:*:*:*:*:*:*","matchCriteriaId":"63757310-FC5B-44E6-9211-36269827BC56"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:2.0:*:*:*:*:*:*:*","matchCriteriaId":"281E6AA4-1E08-488F-BA7A-F0BE7CF42A5B"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:*","matchCriteriaId":"B1987BDA-0113-4603-B9BE-76647EB043F2"}]}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:19375","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:21017","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:22465","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:22629","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:22840","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:23361","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:24833","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:24853","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:28441","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-32590","source":"secalert@redhat.com","tags":["Vendor Advisory"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2446964","source":"secalert@redhat.com","tags":["Issue Tracking","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-32591","sourceIdentifier":"secalert@redhat.com","published":"2026-04-08T18:26:00.107","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verifying that it points to a legitimate external service. An attacker with organization administrator privileges could supply a crafted hostname to force the Quay server to make requests to internal network services, cloud infrastructure endpoints, or other resources that should not be accessible from the Quay application."},{"lang":"es","value":"Se encontró un fallo en la característica de configuración de caché de proxy de Red Hat Quay. Cuando un administrador de organización configura un registro ascendente para el almacenamiento en caché de proxy, Quay realiza una conexión de red al nombre de host del registro especificado sin verificar que apunte a un servicio externo legítimo. Un atacante con privilegios de administrador de organización podría proporcionar un nombre de host manipulado para forzar al servidor Quay a realizar solicitudes a servicios de red internos, puntos finales de infraestructura en la nube u otros recursos que no deberían ser accesibles desde la aplicación Quay."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"Red Hat Quay 3.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.10::el8"],"versions":[{"version":"1783750447","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.12","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.12::el8"],"versions":[{"version":"1783751865","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.12","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.12::el8"],"versions":[{"version":"1784353904","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.15","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.15::el8"],"versions":[{"version":"1784351966","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.16","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel9","cpes":["cpe:/a:redhat:quay:3.16::el9"],"versions":[{"version":"1783955846","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.17","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel9","cpes":["cpe:/a:redhat:quay:3.17::el9"],"versions":[{"version":"1780604033","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.9::el8"],"versions":[{"version":"1784125838","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"mirror registry for Red Hat OpenShift","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift/mirror-registry-rhel8","cpes":["cpe:/a:redhat:mirror_registry:1"]},{"vendor":"Red Hat","product":"mirror registry for Red Hat OpenShift 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift/mirror-registry-rhel8","cpes":["cpe:/a:redhat:mirror_registry:2"]}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","affectedData":[{"vendor":"Red Hat","product":"Red Hat Quay 3.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.10::el8"],"versions":[{"version":"1783750447","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.12","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.12::el8"],"versions":[{"version":"1783751865","lessThan":"*","versionType":"rpm","status":"unaffected"},{"version":"1784353904","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.15","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.15::el8"],"versions":[{"version":"1784351966","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.16","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel9","cpes":["cpe:/a:redhat:quay:3.16::el9"],"versions":[{"version":"1783955846","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.17","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel9","cpes":["cpe:/a:redhat:quay:3.17::el9"],"versions":[{"version":"1780604033","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Quay 3.9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"quay/quay-rhel8","cpes":["cpe:/a:redhat:quay:3.9::el8"],"versions":[{"version":"1784125838","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"mirror registry for Red Hat OpenShift","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift/mirror-registry-rhel8","cpes":["cpe:/a:redhat:mirror_registry:1"]},{"vendor":"Red Hat","product":"mirror registry for Red Hat OpenShift 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift/mirror-registry-rhel8","cpes":["cpe:/a:redhat:mirror_registry:2"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N","baseScore":5.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":0.9,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":4.2},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N","baseScore":5.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":0.9,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T20:34:13.210994Z","id":"CVE-2026-32591","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:-:*:*:*:*:*:*:*","matchCriteriaId":"63757310-FC5B-44E6-9211-36269827BC56"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:mirror_registry_for_red_hat_openshift:2.0:*:*:*:*:*:*:*","matchCriteriaId":"281E6AA4-1E08-488F-BA7A-F0BE7CF42A5B"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:*","matchCriteriaId":"B1987BDA-0113-4603-B9BE-76647EB043F2"}]}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:24833","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:40262","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:41031","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:41066","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:42146","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:42796","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:43052","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-32591","source":"secalert@redhat.com","tags":["Vendor Advisory"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2446965","source":"secalert@redhat.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:24833","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:40262","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:41031","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:41066","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:42146","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:42796","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:43052","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-32591","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Vendor Advisory"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2446965","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32591.json","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}]}},{"cve":{"id":"CVE-2025-30650","sourceIdentifier":"sirt@juniper.net","published":"2026-04-08T19:24:00.440","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root.\n\nThis issue affects systems running Junos OS using Linux-based line cards. Affected line cards include:\n  *  MPC7, MPC8, MPC9, MPC10, MPC11\n  *  LC2101, LC2103\n  *  LC480, LC4800, LC9600\n  *  MX304 (built-in FPC)\n  *  MX-SPC3\n  *  SRX5K-SPC3\n  *  EX9200-40XS\n\n\n  *  FPC3-PTX-U2, FPC3-PTX-U3\n  *  FPC3-SFF-PTX\n  *  LC1101, LC1102, LC1104, LC1105\n\n\n\n\n\nThis issue affects Junos OS: \n\n\n\n  *  all versions before 22.4R3-S8, \n  *  from 23.2 before 23.2R2-S6, \n  *  from 23.4 before 23.4R2-S6, \n  *  from 24.2 before 24.2R2-S3, \n  *  from 24.4 before 24.4R2,\n  *  from 25.2 before 25.2R2."},{"lang":"es","value":"Una vulnerabilidad de autenticación faltante para función crítica en el procesamiento de comandos de Juniper Networks Junos OS permite a un atacante local privilegiado obtener acceso a las tarjetas de línea que ejecutan Junos OS Evolved como root.\n\nEste problema afecta a los sistemas que ejecutan Junos OS que utilizan tarjetas de línea basadas en Linux. Las tarjetas de línea afectadas incluyen:\n  * MPC7, MPC8, MPC9, MPC10, MPC11\n  * LC2101, LC2103\n  * LC480, LC4800, LC9600\n  * MX304 (FPC integrado)\n  * MX-SPC3\n  * SRX5K-SPC3\n  * EX9200-40XS\n  * FPC3-PTX-U2, FPC3-PTX-U3\n  * FPC3-SFF-PTX\n  * LC1101, LC1102, LC1104, LC1105\n\nEste problema afecta a Junos OS:\n  * todas las versiones anteriores a 22.4R3-S8,\n  * desde 23.2 antes de 23.2R2-S6,\n  * desde 23.4 antes de 23.4R2-S6,\n  * desde 24.2 antes de 24.2R2-S3,\n  * desde 24.4 antes de 24.4R2,\n  * desde 25.2 antes de 25.2R2."}],"affected":[{"source":"sirt@juniper.net","affectedData":[{"vendor":"Juniper Networks","product":"Junos OS","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"22.4R3-S8","versionType":"semver","status":"affected"},{"version":"23.2","lessThan":"23.2R2-S6","versionType":"semver","status":"affected"},{"version":"23.4","lessThan":"23.4R2-S6","versionType":"semver","status":"affected"},{"version":"24.2","lessThan":"24.2R2-S3","versionType":"semver","status":"affected"},{"version":"24.4","lessThan":"24.4R2","versionType":"semver","status":"affected"},{"version":"25.2","lessThan":"25.2R2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"sirt@juniper.net","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:A/V:C/RE:M/U:Amber","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NO","Recovery":"AUTOMATIC","valueDensity":"CONCENTRATED","vulnerabilityResponseEffort":"MODERATE","providerUrgency":"AMBER"}}],"cvssMetricV31":[{"source":"sirt@juniper.net","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T20:06:27.813930Z","id":"CVE-2025-30650","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"sirt@juniper.net","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://github.com/orangecertcc/security-research/security/advisories/GHSA-fwhc-gh5m-v8fq","source":"sirt@juniper.net"},{"url":"https://kb.juniper.net/JSA107863","source":"sirt@juniper.net"}]}},{"cve":{"id":"CVE-2025-50644","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:15.103","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of user input in the qj.asp endpoint."},{"lang":"es","value":"Una vulnerabilidad de desbordamiento de búfer existe en D-Link DI-8003 16.07.26A1 debido a la validación incorrecta de la entrada del usuario en el endpoint qj.asp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T13:11:33.740410Z","id":"CVE-2025-50644","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10505","source":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50645","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:15.227","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability has been discovered in D-Link DI-8003 16.07.26A1, which can lead to a buffer overflow when the s parameter in the pppoe_list_opt.asp endpoint is manipulated. By sending a crafted request with an excessively large value for the s parameter, an attacker can trigger a buffer overflow condition."},{"lang":"es","value":"Una vulnerabilidad ha sido descubierta en D-Link DI-8003 16.07.26A1, lo que puede conducir a un desbordamiento de búfer cuando se manipula el parámetro s en el endpoint pppoe_list_opt.asp. Al enviar una solicitud manipulada con un valor excesivamente grande para el parámetro s, un atacante puede desencadenar una condición de desbordamiento de búfer."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T13:12:28.894430Z","id":"CVE-2025-50645","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10505","source":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50646","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:15.347","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to insufficient input validation on the name parameter in the /qos_type_asp.asp endpoint."},{"lang":"es","value":"Una vulnerabilidad de desbordamiento de búfer existe en D-Link DI-8003 16.07.26A1 debido a una validación de entrada insuficiente en el parámetro name en el endpoint /qos_type_asp.asp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T13:13:00.436142Z","id":"CVE-2025-50646","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10505","source":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50647","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:15.460","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1, specifically in the handling of the wans parameter in the qos.asp endpoint."},{"lang":"es","value":"Existe una vulnerabilidad de desbordamiento de búfer en D-Link DI-8003 16.07.26A1, específicamente en el manejo del parámetro wans en el endpoint qos.asp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T13:14:08.908789Z","id":"CVE-2025-50647","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10505","source":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50648","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:15.570","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate input validation in the /tggl.asp endpoint."},{"lang":"es","value":"Existe una vulnerabilidad de desbordamiento de búfer en D-Link DI-8003 16.07.26A1 debido a una validación de entrada inadecuada en el endpoint /tggl.asp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T15:37:51.497169Z","id":"CVE-2025-50648","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10505","source":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50649","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:15.687","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper input validation in the vlan_name parameter in the /shut_set.asp endpoint."},{"lang":"es","value":"Existe una vulnerabilidad de desbordamiento de búfer en D-Link DI-8003 16.07.26A1 debido a una validación de entrada incorrecta en el parámetro vlan_name en el endpoint /shut_set.asp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T15:37:58.342026Z","id":"CVE-2025-50649","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10505","source":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50650","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:15.800","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate validation of input size in the routes_static parameter in the /router.asp endpoint."},{"lang":"es","value":"Existe una vulnerabilidad de desbordamiento de búfer en D-Link DI-8003 16.07.26A1 debido a una validación inadecuada del tamaño de entrada en el parámetro routes_static en el endpoint /router.asp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T15:38:03.826245Z","id":"CVE-2025-50650","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10505","source":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50652","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:15.917","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue in D-Link DI-8003 16.07.26A1 related to improper handling of the id parameter in the /saveparm_usb.asp endpoint."},{"lang":"es","value":"Un problema en D-Link DI-8003 16.07.26A1 relacionado con el manejo inadecuado del parámetro id en el endpoint /saveparm_usb.asp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T15:38:09.068647Z","id":"CVE-2025-50652","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10505","source":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50653","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:16.040","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name and mem parameters in the /time_group.asp endpoint."},{"lang":"es","value":"Existe una vulnerabilidad de desbordamiento de búfer en D-Link DI-8003 16.07.26A1 debido a un manejo inadecuado de los parámetros name y mem en el endpoint /time_group.asp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T15:38:13.799518Z","id":"CVE-2025-50653","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10505","source":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50654","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:16.147","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of the id parameter in the /thd_member.asp endpoint."},{"lang":"es","value":"Existe una vulnerabilidad de desbordamiento de búfer en D-Link DI-8003 16.07.26A1 debido a una validación incorrecta del parámetro id en el endpoint /thd_member.asp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T15:38:19.637596Z","id":"CVE-2025-50654","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10505","source":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50655","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:16.257","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /thd_group.asp endpoint."},{"lang":"es","value":"Existe una vulnerabilidad de desbordamiento de búfer en D-Link DI-8003 16.07.26A1 debido a un manejo inadecuado del parámetro name en el endpoint /thd_group.asp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T17:40:42.417508Z","id":"CVE-2025-50655","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10505","source":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50657","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:16.363","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the pid parameter in the /trace.asp endpoint."},{"lang":"es","value":"Existe una vulnerabilidad de desbordamiento de búfer en D-Link DI-8003 16.07.26A1 debido a un manejo inadecuado del parámetro pid en el endpoint /trace.asp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T17:41:43.916094Z","id":"CVE-2025-50657","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10505","source":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50659","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:16.470","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the custom_error parameter in the /user.asp endpoint."},{"lang":"es","value":"Existe una vulnerabilidad de desbordamiento de búfer en D-Link DI-8003 16.07.26A1 debido a un manejo inadecuado del parámetro custom_error en el endpoint /user.asp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T17:42:34.295701Z","id":"CVE-2025-50659","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10505","source":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50660","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:16.583","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_member.asp endpoint."},{"lang":"es","value":"Una vulnerabilidad de desbordamiento de búfer existe en D-Link DI-8003 16.07.26A1 debido a un manejo inadecuado del parámetro name en el endpoint /url_member.asp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T17:43:25.992470Z","id":"CVE-2025-50660","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10505","source":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50661","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:16.693","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /url_rule.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request with parameters name, en, ips, u, time, act, rpri, and log."},{"lang":"es","value":"Una vulnerabilidad de desbordamiento de búfer existe en D-Link DI-8003 16.07.26A1 debido a un manejo inadecuado de múltiples parámetros en el endpoint /url_rule.asp. Un atacante puede explotar esta vulnerabilidad enviando una solicitud HTTP GET manipulada con los parámetros name, en, ips, u, time, act, rpri y log."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T17:47:47.863227Z","id":"CVE-2025-50661","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10505","source":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50662","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:16.807","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_group.asp endpoint."},{"lang":"es","value":"Una vulnerabilidad de desbordamiento de búfer existe en D-Link DI-8003 16.07.26A1 debido a un manejo inadecuado del parámetro name en el endpoint /url_group.asp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T17:52:08.262439Z","id":"CVE-2025-50662","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10505","source":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50663","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:16.920","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /usb_paswd.asp endpoint."},{"lang":"es","value":"Una vulnerabilidad de desbordamiento de búfer existe en D-Link DI-8003 16.07.26A1 debido a un manejo inadecuado del parámetro 'name' en el endpoint /usb_paswd.asp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T17:55:52.830126Z","id":"CVE-2025-50663","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10505","source":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50664","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:17.033","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /user_group.asp endpoint. The attacker can exploit this vulnerability by sending a crafted HTTP GET request with parameters name, mem, pri, and attr."},{"lang":"es","value":"Una vulnerabilidad de desbordamiento de búfer existe en D-Link DI-8003 16.07.26A1 debido a un manejo inadecuado de parámetros en el endpoint /user_group.asp. El atacante puede explotar esta vulnerabilidad enviando una solicitud HTTP GET manipulada con los parámetros name, mem, pri y attr."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T17:57:52.321354Z","id":"CVE-2025-50664","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10505","source":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50665","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:17.140","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of input parameters in the /web_keyword.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request via the name, en, time, mem_gb2312, and mem_utf8 parameters."},{"lang":"es","value":"Una vulnerabilidad de desbordamiento de búfer existe en D-Link DI-8003 16.07.26A1 debido a un manejo inadecuado de los parámetros de entrada en el endpoint /web_keyword.asp. Un atacante puede explotar esta vulnerabilidad enviando una solicitud HTTP GET manipulada a través de los parámetros name, en, time, mem_gb2312 y mem_utf8."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T15:38:24.301582Z","id":"CVE-2025-50665","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10505","source":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50666","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:17.250","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /web_post.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in parameters such as name, en, user_id, log, and time."},{"lang":"es","value":"Una vulnerabilidad de desbordamiento de búfer existe en D-Link DI-8003 16.07.26A1 debido al manejo inadecuado de múltiples parámetros en el endpoint /web_post.asp. Un atacante puede explotar esta vulnerabilidad enviando una solicitud HTTP GET manipulada en parámetros como name, en, user_id, log y time."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T15:38:29.287209Z","id":"CVE-2025-50666","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10505","source":"cve@mitre.org"},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50667","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:17.360","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the iface parameter in the /wan_line_detection.asp endpoint."},{"lang":"es","value":"Una vulnerabilidad de desbordamiento de búfer existe en D-Link DI-8003 16.07.26A1 debido a un manejo inadecuado del parámetro iface en el endpoint /wan_line_detection.asp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T15:38:33.691041Z","id":"CVE-2025-50667","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50668","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:17.473","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the s parameter in the /web_list_opt.asp endpoint."},{"lang":"es","value":"Una vulnerabilidad de desbordamiento de búfer existe en D-Link DI-8003 16.07.26A1 debido a un manejo inadecuado del parámetro s en el endpoint /web_list_opt.asp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T15:38:39.177867Z","id":"CVE-2025-50668","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50669","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:17.580","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 and DI-8003G 19.12.10A1 due to improper handling of the wan_ping parameter in the /wan_ping.asp endpoint."},{"lang":"es","value":"Una vulnerabilidad de desbordamiento de búfer existe en D-Link DI-8003 16.07.26A1 y DI-8003G 19.12.10A1 debido a un manejo inadecuado del parámetro wan_ping en el endpoint /wan_ping.asp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T15:38:44.026977Z","id":"CVE-2025-50669","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50670","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:17.690","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_bwr.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in the name, qq, and time parameters."},{"lang":"es","value":"Una vulnerabilidad de desbordamiento de búfer existe en D-Link DI-8003 16.07.26A1 debido a un manejo inadecuado de los parámetros en el endpoint /xwgl_bwr.asp. Un atacante puede explotar esta vulnerabilidad enviando una solicitud HTTP GET manipulada en los parámetros name, qq y time."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T15:38:48.304219Z","id":"CVE-2025-50670","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50671","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:17.803","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_ref.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request with excessively long strings in parameters name, en, user_id, shibie_name, time, act, log, and rpri."},{"lang":"es","value":"Una vulnerabilidad de desbordamiento de búfer existe en D-Link DI-8003 16.07.26A1 debido a un manejo inadecuado de parámetros en el endpoint /xwgl_ref.asp. Un atacante puede explotar esta vulnerabilidad enviando una solicitud HTTP GET especialmente diseñada con cadenas excesivamente largas en los parámetros name, en, user_id, shibie_name, time, act, log y rpri."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T17:46:38.240289Z","id":"CVE-2025-50671","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50672","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:17.913","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_dlink.asp endpoint."},{"lang":"es","value":"Una vulnerabilidad de desbordamiento de búfer existe en D-Link DI-8003 16.07.26A1 debido al manejo inadecuado de parámetros en el endpoint /yyxz_dlink.asp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T15:38:53.093545Z","id":"CVE-2025-50672","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-50673","sourceIdentifier":"cve@mitre.org","published":"2026-04-08T19:24:18.040","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport parameter in the /webgl.asp endpoint."},{"lang":"es","value":"Una vulnerabilidad de desbordamiento de búfer existe en D-Link DI-8003 16.07.26A1 debido a un manejo inadecuado del parámetro http_lanport en el endpoint /webgl.asp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-10T15:38:58.456247Z","id":"CVE-2025-50673","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:di-8003_firmware:16.07.26a1:*:*:*:*:*:*:*","matchCriteriaId":"FA25536C-1B96-4611-BF35-A0AD24747929"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:di-8003:-:*:*:*:*:*:*:*","matchCriteriaId":"E6644787-50D7-4190-A2E3-DD54F43AE38C"}]}]}],"references":[{"url":"https://github.com/xiaotea/iot-vulnerability-collection/blob/main/README.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://www.dlink.com/en/security-bulletin/","source":"cve@mitre.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-0811","sourceIdentifier":"security@wordfence.com","published":"2026-04-08T19:24:52.740","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is due to missing or incorrect nonce validation on the 'vsz_cf7_save_setting_callback' function. This makes it possible for unauthenticated attackers to delete form entry via a forged request granted they can trick a site administrator into performing an action such as clicking on a link."},{"lang":"es","value":"El plugin Advanced Contact form 7 DB para WordPress es vulnerable a la falsificación de petición en sitios cruzados en todas las versiones hasta la 2.0.9, inclusive. Esto se debe a la validación de nonce faltante o incorrecta en la función 'vsz_cf7_save_setting_callback'. Esto hace posible que atacantes no autenticados eliminen entradas de formulario a través de una petición falsificada, siempre que puedan engañar a un administrador del sitio para que realice una acción como hacer clic en un enlace."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"vsourz1td","product":"Advanced Contact form 7 DB","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.0.9","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T19:00:58.912791Z","id":"CVE-2026-0811","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/advanced-cf7-db/tags/2.0.9/admin/class-advanced-cf7-db-admin.php#L885","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3497481/advanced-cf7-db","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/88097744-d2f5-4ae5-aa71-0f4a0decd911?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-0814","sourceIdentifier":"security@wordfence.com","published":"2026-04-08T19:24:52.880","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in all versions up to, and including, 2.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export form submissions to excel file."},{"lang":"es","value":"El plugin Advanced Contact form 7 DB para WordPress es vulnerable a acceso no autorizado a datos debido a una comprobación de capacidad faltante en la función 'vsz_cf7_export_to_excel' en todas las versiones hasta la 2.0.9, inclusive. Esto hace posible que atacantes autenticados, con acceso de nivel Suscriptor y superior, exporten envíos de formularios a un archivo de Excel."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"vsourz1td","product":"Advanced Contact form 7 DB","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.0.9","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T18:36:16.706726Z","id":"CVE-2026-0814","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/advanced-cf7-db/tags/2.0.9/admin/class-advanced-cf7-db-admin.php#L1507","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3497481/advanced-cf7-db","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5e3de1a4-a534-475b-9138-2337755b0288?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-20709","sourceIdentifier":"secure@intel.com","published":"2026-04-08T19:25:12.600","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(R) Processor J Series, Intel(R) Celeron(R) Processor N Series may allow an escalation of privilege. Hardware reverse engineer adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via physical access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts."},{"lang":"es","value":"El uso de una clave criptográfica predeterminada en el hardware para algunas series de procesadores Intel(R) Pentium(R) Silver, series de procesadores Intel(R) Celeron(R) J, series de procesadores Intel(R) Celeron(R) N puede permitir una escalada de privilegios. Un adversario de ingeniería inversa de hardware con un usuario privilegiado combinado con un ataque de alta complejidad puede permitir la escalada de privilegios. Este resultado puede ocurrir potencialmente a través de acceso físico cuando los requisitos de ataque están presentes con conocimiento interno especial y no requiere interacción del usuario. La vulnerabilidad potencial puede impactar la confidencialidad (alta), integridad (ninguna) y disponibilidad (ninguna) del sistema vulnerable, lo que resulta en impactos posteriores en la confidencialidad (alta), integridad (alta) y disponibilidad (ninguna) del sistema."}],"affected":[{"source":"secure@intel.com","affectedData":[{"vendor":"n/a","product":"Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(R) Processor J Series, Intel(R) Celeron(R) Processor N Series may allow an escalation of privilege. Hardware reverse engineer adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via physical access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.","defaultStatus":"unaffected","versions":[{"version":"See references","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"secure@intel.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:P/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"secure@intel.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N","baseScore":6.6,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.3,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T19:49:48.538705Z","id":"CVE-2026-20709","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secure@intel.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1394"}]}],"references":[{"url":"https://intel.com/content/www/us/en/security-center/advisory/intel-sa-00609.html","source":"secure@intel.com"}]}},{"cve":{"id":"CVE-2026-27806","sourceIdentifier":"security-advisories@github.com","published":"2026-04-08T19:25:13.543","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local user's password via a GUI dialog and interpolates it directly into a Tcl/expect script executed via exec.Command(\"expect\", \"-c\", script). Because the password is inserted into Tcl brace-quoted send {%s}, a password containing } terminates the literal and injects arbitrary Tcl commands. Since Orbit runs as root, this allows a local unprivileged user to escalate to root privileges. This vulnerability is fixed in 4.81.1."},{"lang":"es","value":"Fleet es software de gestión de dispositivos de código abierto. Antes de la versión 4.81.1, el flujo de rotación de claves de cifrado de disco FileVault del agente Orbit recopila la contraseña de un usuario local a través de un diálogo de GUI y la intercala directamente en un script Tcl/expect ejecutado mediante exec.Command(\"expect\", \"-c\", script). Debido a que la contraseña se inserta en el comando Tcl send {%s} entre llaves, una contraseña que contiene } termina el literal e inyecta comandos Tcl arbitrarios. Dado que Orbit se ejecuta como root, esto permite a un usuario local sin privilegios escalar a privilegios de root. Esta vulnerabilidad se corrigió en la versión 4.81.1."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"fleetdm","product":"fleet","versions":[{"version":"< 4.81.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T14:24:06.342149Z","id":"CVE-2026-27806","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:fleetdm:fleet:*:*:*:*:*:*:*:*","versionEndExcluding":"4.81.1","matchCriteriaId":"09CFBED5-C6C2-4CCB-A48C-7E89E878E4F7"}]}]}],"references":[{"url":"https://github.com/fleetdm/fleet/security/advisories/GHSA-rphv-h674-5hp2","source":"security-advisories@github.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-2942","sourceIdentifier":"security@wordfence.com","published":"2026-04-08T19:25:19.820","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible."},{"lang":"es","value":"El plugin ProSolution WP Client para WordPress es vulnerable a cargas de archivos arbitrarios debido a la falta de validación del tipo de archivo en la función 'proSol_fileUploadProcess' en todas las versiones hasta la 1.9.9, inclusive. Esto permite a atacantes no autenticados cargar archivos arbitrarios en el servidor del sitio afectado, lo que puede posibilitar la ejecución remota de código."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"prosolution","product":"ProSolution WP Client","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.9.9","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T19:22:38.794301Z","id":"CVE-2026-2942","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-434"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/prosolution-wp-client/trunk/public/class-prosolwpclient-public.php?rev=3331282#L993","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3484577/prosolution-wp-client","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/3852aef6-42e7-4b71-a1ba-dd41284fd07b?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-30814","sourceIdentifier":"f23511db-6c3e-4e32-a477-6aa17d310630","published":"2026-04-08T19:25:20.140","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially execute arbitrary code via a specially crafted configuration file. Successful exploitation may cause a crash and could allow arbitrary code execution, enabling modification of device state, exposure of sensitive data, or further compromise of device integrity.\n\nThis issue affects AX53 v1.0: before 1.7.1 Build 20260213."},{"lang":"es","value":"Un desbordamiento de búfer basado en pila en el módulo tmpServer de TP-Link Archer AX53 v1.0 permite a un atacante adyacente autenticado activar un fallo de segmentación y potencialmente ejecutar código arbitrario a través de un archivo de configuración especialmente diseñado. La explotación exitosa puede causar un bloqueo y podría permitir la ejecución de código arbitrario, lo que permite la modificación del estado del dispositivo, la exposición de datos sensibles o un mayor compromiso de la integridad del dispositivo.\n\nEste problema afecta a AX53 v1.0: anterior a 1.7.1 Build 20260213."}],"affected":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","affectedData":[{"vendor":"TP-Link Systems Inc.","product":"AX53 v1.0","defaultStatus":"unaffected","modules":["tmpServer"],"versions":[{"version":"0","lessThan":"1.7.1 Build 20260213","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"ADJACENT","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T00:00:00+00:00","id":"CVE-2026-30814","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:archer_ax53_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.7.1","matchCriteriaId":"B096B7BB-7693-4C45-B5F7-8FD6E4969DCE"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:archer_ax53:1.0:*:*:*:*:*:*:*","matchCriteriaId":"5F3EA1D9-EB47-4785-9CF0-F2B51945917D"}]}]}],"references":[{"url":"https://talosintelligence.com/vulnerability_reports/","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Third Party Advisory"]},{"url":"https://www.tp-link.com/en/support/download/archer-ax53/v1/#Firmware","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Product"]},{"url":"https://www.tp-link.com/my/support/download/archer-ax53/v1/#Firmware","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Product"]},{"url":"https://www.tp-link.com/us/support/faq/5055/","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Vendor Advisory"]},{"url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2302","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-30815","sourceIdentifier":"f23511db-6c3e-4e32-a477-6aa17d310630","published":"2026-04-08T19:25:20.320","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An OS command injection vulnerability in the OpenVPN module\nof TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow modification of configuration files, disclosure of sensitive information, or further compromise of device integrity.\n\nThis issue affects AX53 v1.0: before 1.7.1 Build 20260213."},{"lang":"es","value":"Una vulnerabilidad de inyección de comandos del sistema operativo en el módulo OpenVPN de TP-Link Archer AX53 v1.0 permite a un atacante adyacente autenticado ejecutar comandos del sistema cuando se procesa un archivo de configuración especialmente diseñado debido a una validación de entrada insuficiente. La explotación exitosa puede permitir la modificación de archivos de configuración, la divulgación de información sensible o un mayor compromiso de la integridad del dispositivo.\n\nEste problema afecta a AX53 v1.0: anterior a 1.7.1 Build 20260213."}],"affected":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","affectedData":[{"vendor":"TP-Link Systems Inc.","product":"AX53 v1.0","defaultStatus":"unaffected","modules":["openvpn"],"versions":[{"version":"0","lessThan":"1.7.1 Build 20260213","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T00:00:00+00:00","id":"CVE-2026-30815","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:archer_ax53_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.7.1","matchCriteriaId":"B096B7BB-7693-4C45-B5F7-8FD6E4969DCE"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:archer_ax53:1.0:*:*:*:*:*:*:*","matchCriteriaId":"5F3EA1D9-EB47-4785-9CF0-F2B51945917D"}]}]}],"references":[{"url":"https://talosintelligence.com/vulnerability_reports/","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Third Party Advisory"]},{"url":"https://www.tp-link.com/en/support/download/archer-ax53/v1/#Firmware","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Product"]},{"url":"https://www.tp-link.com/my/support/download/archer-ax53/v1/#Firmware","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Product"]},{"url":"https://www.tp-link.com/us/support/faq/5055/","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Vendor Advisory"]},{"url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2303","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2307","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2308","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2309","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-30816","sourceIdentifier":"f23511db-6c3e-4e32-a477-6aa17d310630","published":"2026-04-08T19:25:20.477","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed. \nSuccessful\nexploitation may allow unauthorized access to arbitrary files on the device,\npotentially exposing sensitive information.This issue affects AX53 v1.0: before 1.7.1 Build 20260213."},{"lang":"es","value":"Una vulnerabilidad de control externo de configuración en el módulo OpenVPN de TP-Link AX53 v1.0 permite a un atacante adyacente autenticado leer un archivo arbitrario cuando se procesa un archivo de configuración malicioso. La explotación exitosa puede permitir el acceso no autorizado a archivos arbitrarios en el dispositivo, exponiendo potencialmente información sensible. Este problema afecta a AX53 v1.0: antes de 1.7.1 Build 20260213."}],"affected":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","affectedData":[{"vendor":"TP-Link Systems Inc.","product":"AX53 v1.0","defaultStatus":"unaffected","modules":["openvpn"],"versions":[{"version":"0","lessThan":"1.7.1 Build 20260213","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T19:10:48.309522Z","id":"CVE-2026-30816","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","type":"Secondary","description":[{"lang":"en","value":"CWE-15"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-610"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:archer_ax53_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.7.1","matchCriteriaId":"BBAE4118-799E-4ADB-9088-1CB86B54C09B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:archer_ax53:1.0:*:*:*:*:*:*:*","matchCriteriaId":"5F3EA1D9-EB47-4785-9CF0-F2B51945917D"}]}]}],"references":[{"url":"https://talosintelligence.com/vulnerability_reports/","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Third Party Advisory"]},{"url":"https://www.tp-link.com/en/support/download/archer-ax53/v1/#Firmware","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Product"]},{"url":"https://www.tp-link.com/my/support/download/archer-ax53/v1/#Firmware","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Product"]},{"url":"https://www.tp-link.com/us/support/faq/5055/","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Vendor Advisory"]},{"url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2304","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-30817","sourceIdentifier":"f23511db-6c3e-4e32-a477-6aa17d310630","published":"2026-04-08T19:25:20.627","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed.  Successful exploitation may allow unauthorized access to arbitrary files on the device, potentially exposing sensitive information.This issue affects AX53 v1.0: before 1.7.1 Build 20260213."},{"lang":"es","value":"Una vulnerabilidad de control de configuración externo en el módulo OpenVPN de TP-Link AX53 v1.0 permite a un atacante adyacente autenticado leer archivos arbitrarios cuando se procesa un archivo de configuración malicioso. La explotación exitosa puede permitir el acceso no autorizado a archivos arbitrarios en el dispositivo, exponiendo potencialmente información sensible. Este problema afecta a AX53 v1.0: antes de 1.7.1 Build 20260213."}],"affected":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","affectedData":[{"vendor":"TP-Link Systems Inc.","product":"AX53 v1.0","defaultStatus":"unaffected","modules":["dnsmasq"],"versions":[{"version":"0","lessThan":"1.7.1 Build 20260213","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T19:10:32.982476Z","id":"CVE-2026-30817","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","type":"Secondary","description":[{"lang":"en","value":"CWE-15"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-610"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:archer_ax53_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.7.1","matchCriteriaId":"B096B7BB-7693-4C45-B5F7-8FD6E4969DCE"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:archer_ax53:1.0:*:*:*:*:*:*:*","matchCriteriaId":"5F3EA1D9-EB47-4785-9CF0-F2B51945917D"}]}]}],"references":[{"url":"https://talosintelligence.com/vulnerability_reports/","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Third Party Advisory"]},{"url":"https://www.tp-link.com/en/support/download/archer-ax53/v1/#Firmware","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Product"]},{"url":"https://www.tp-link.com/my/support/download/archer-ax53/v1/#Firmware","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Product"]},{"url":"https://www.tp-link.com/us/support/faq/5055/","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Vendor Advisory"]},{"url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2305","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-30818","sourceIdentifier":"f23511db-6c3e-4e32-a477-6aa17d310630","published":"2026-04-08T19:25:20.770","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrary code when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow the attacker to modify device configuration, access sensitive information, or further compromise system integrity.\n\nThis issue affects AX53 v1.0: before 1.7.1 Build 20260213."},{"lang":"es","value":"Una vulnerabilidad de inyección de comandos del sistema operativo en el módulo dnsmasq de TP-Link Archer AX53 v1.0 permite a un atacante adyacente autenticado ejecutar código arbitrario cuando se procesa un archivo de configuración especialmente diseñado debido a una validación de entrada insuficiente. La explotación exitosa puede permitir al atacante modificar la configuración del dispositivo, acceder a información sensible o comprometer aún más la integridad del sistema.\n\nEste problema afecta a AX53 v1.0: anterior a 1.7.1 Build 20260213."}],"affected":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","affectedData":[{"vendor":"TP-Link Systems Inc.","product":"AX53 v1.0","defaultStatus":"unaffected","modules":["dnsmasq"],"versions":[{"version":"0","lessThan":"1.7.1 Build 20260213","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T00:00:00+00:00","id":"CVE-2026-30818","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:archer_ax53_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.7.1","matchCriteriaId":"B096B7BB-7693-4C45-B5F7-8FD6E4969DCE"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:archer_ax53:1.0:*:*:*:*:*:*:*","matchCriteriaId":"5F3EA1D9-EB47-4785-9CF0-F2B51945917D"}]}]}],"references":[{"url":"https://talosintelligence.com/vulnerability_reports/","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Third Party Advisory"]},{"url":"https://www.tp-link.com/en/support/download/archer-ax53/v1/#Firmware","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Product"]},{"url":"https://www.tp-link.com/my/support/download/archer-ax53/v1/#Firmware","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Product"]},{"url":"https://www.tp-link.com/us/support/faq/5055/","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Vendor Advisory"]},{"url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2306","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-23869","sourceIdentifier":"cve-assign@fb.com","published":"2026-04-08T20:16:23.003","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered by sending specially crafted HTTP requests to Server Function endpoints.The payload of the HTTP request causes excessive CPU usage for up to a minute ending in a thrown error that is catchable."},{"lang":"es","value":"Una vulnerabilidad de denegación de servicio existe en los Componentes de Servidor de React, que afecta a los siguientes paquetes: react-server-dom-parcel, react-server-dom-turbopack y react-server-dom-webpack (versiones 19.0.0 a 19.0.4, 19.1.0 a 19.1.5, y 19.2.0 a 19.2.4). La vulnerabilidad se activa al enviar solicitudes HTTP especialmente diseñadas a los puntos finales de la Función de Servidor. La carga útil de la solicitud HTTP causa un uso excesivo de la CPU durante hasta un minuto, terminando en un error lanzado que es capturable."}],"affected":[{"source":"cve-assign@fb.com","affectedData":[{"vendor":"Meta","product":"react-server-dom-turbopack","defaultStatus":"unaffected","versions":[{"version":"19.0.0","lessThanOrEqual":"19.0.4","versionType":"semver","status":"affected"},{"version":"19.1.0","lessThanOrEqual":"19.1.5","versionType":"semver","status":"affected"},{"version":"19.2.0","lessThanOrEqual":"19.2.4","versionType":"semver","status":"affected"}]},{"vendor":"Meta","product":"react-server-dom-parcel","defaultStatus":"unaffected","versions":[{"version":"19.0.0","lessThanOrEqual":"19.0.4","versionType":"semver","status":"affected"},{"version":"19.1.0","lessThanOrEqual":"19.1.5","versionType":"semver","status":"affected"},{"version":"19.2.0","lessThanOrEqual":"19.2.4","versionType":"semver","status":"affected"}]},{"vendor":"Meta","product":"react-server-dom-webpack","defaultStatus":"unaffected","versions":[{"version":"19.0.0","lessThanOrEqual":"19.0.4","versionType":"semver","status":"affected"},{"version":"19.1.0","lessThanOrEqual":"19.1.5","versionType":"semver","status":"affected"},{"version":"19.2.0","lessThanOrEqual":"19.2.4","versionType":"semver","status":"affected"}]}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","affectedData":[{"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhoai/odh-dashboard-rhel9","cpes":["cpe:/a:redhat:openshift_ai"]}]}],"metrics":{"cvssMetricV31":[{"source":"cve-assign@fb.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-08T19:55:33.314236Z","id":"CVE-2026-23869","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-400"},{"lang":"en","value":"CWE-502"}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://github.com/facebook/react/security/advisories/GHSA-479c-33wc-g2pg","source":"cve-assign@fb.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-23869","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2456663","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23869.json","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}]}},{"cve":{"id":"CVE-2026-40024","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-04-08T22:16:22.430","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker to write files to arbitrary locations outside the intended recovery directory via crafted filenames or directory paths with path traversal sequences in a filesystem image. An attacker can craft a malicious filesystem image with embedded /../ sequences in filenames that, when processed by tsk_recover, writes files outside the output directory, potentially achieving code execution by overwriting shell configuration or cron entries."},{"lang":"es","value":"The Sleuth Kit hasta 4.14.0 contiene una vulnerabilidad de salto de ruta en tsk_recover que permite a un atacante escribir archivos en ubicaciones arbitrarias fuera del directorio de recuperación previsto mediante nombres de archivo o rutas de directorio manipulados con secuencias de salto de ruta en una imagen de sistema de archivos. Un atacante puede crear una imagen de sistema de archivos maliciosa con secuencias /../ incrustadas en los nombres de archivo que, al ser procesada por tsk_recover, escribe archivos fuera del directorio de salida, potencialmente logrando la ejecución de código al sobrescribir la configuración del shell o las entradas de cron."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"sleuthkit","product":"sleuthkit","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"4.14.0","versionType":"custom","status":"affected"},{"version":"a3f96b3bc36a8bb1a00c297f77110d4a6e7dd31b","versionType":"git","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T18:12:19.473427Z","id":"CVE-2026-40024","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sleuthkit:the_sleuth_kit:*:*:*:*:*:*:*:*","versionEndExcluding":"4.15.0","matchCriteriaId":"5A619301-F6A9-4151-9528-0BB27E356214"}]}]}],"references":[{"url":"https://github.com/sleuthkit/sleuthkit/commit/a3f96b3bc36a8bb1a00c297f77110d4a6e7dd31b","source":"disclosure@vulncheck.com","tags":["Patch"]},{"url":"https://mobasi.ai/sentinel","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]},{"url":"https://www.vulncheck.com/advisories/sleuth-kit-tsk-recover-path-traversal","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-40025","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-04-08T22:16:22.603","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where the wrapped_key_parser class follows attacker-controlled length fields without bounds checking, causing heap reads past the allocated buffer. An attacker can craft a malicious APFS disk image that triggers information disclosure or crashes when processed by any Sleuth Kit tool that parses APFS volumes."},{"lang":"es","value":"El Sleuth Kit hasta la versión 4.14.0 contiene una vulnerabilidad de lectura fuera de límites en el analizador de keybag del sistema de archivos APFS, donde la clase wrapped_key_parser sigue campos de longitud controlados por el atacante sin verificación de límites, causando lecturas de heap más allá del búfer asignado. Un atacante puede crear una imagen de disco APFS maliciosa que desencadena la revelación de información o fallos cuando es procesada por cualquier herramienta de Sleuth Kit que analiza volúmenes APFS."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"sleuthkit","product":"sleuthkit","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"4.14.0","versionType":"custom","status":"affected"},{"version":"8b9c9e7d493bd68624f3b1a3963edd45c3ff7611","versionType":"git","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.8,"impactScore":2.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T15:03:14.878617Z","id":"CVE-2026-40025","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-125"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sleuthkit:the_sleuth_kit:*:*:*:*:*:*:*:*","versionEndExcluding":"4.15.0","matchCriteriaId":"5A619301-F6A9-4151-9528-0BB27E356214"}]}]}],"references":[{"url":"https://github.com/sleuthkit/sleuthkit/commit/8b9c9e7d493bd68624f3b1a3963edd45c3ff7611","source":"disclosure@vulncheck.com","tags":["Patch"]},{"url":"https://github.com/sleuthkit/sleuthkit/pull/3444","source":"disclosure@vulncheck.com","tags":["Issue Tracking"]},{"url":"https://mobasi.ai/sentinel","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]},{"url":"https://www.vulncheck.com/advisories/sleuth-kit-apfs-keybag-parser-out-of-bounds-read","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2025-12664","sourceIdentifier":"cve@gitlab.com","published":"2026-04-08T23:16:56.200","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 13.0 y anteriores a la 18.8.9, la 18.9 y anteriores a la 18.9.5, y la 18.10 y anteriores a la 18.10.3 que podría haber permitido a un usuario no autenticado causar denegación de servicio mediante el envío de consultas GraphQL repetidas."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"13.0","lessThan":"18.8.9","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.5","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T13:03:46.881882Z","id":"CVE-2025-12664","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"18.8.9","matchCriteriaId":"48E564F7-CB57-4A79-A921-BA28CF67C623"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"5C4D8A99-6E70-4D55-9ACF-FF2620F070E0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"DBCB346F-0B28-458B-A453-29DA4B0E91FC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"13.0.0","versionEndExcluding":"18.8.9","matchCriteriaId":"69D195DE-D52F-4794-84F8-B88A736360A0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"3BA6A89D-D2C1-45B9-A8E8-64256816D880"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"BB2F3665-2451-4A4D-8538-93F540975F0E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/579376","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3377091","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2025-9484","sourceIdentifier":"cve@gitlab.com","published":"2026-04-08T23:16:57.343","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 16.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user to have access to other users' email addresses via certain GraphQL queries."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afectaba a todas las versiones desde la 16.6 y anteriores a la 18.8.9, la 18.9 y anteriores a la 18.9.5, y la 18.10 y anteriores a la 18.10.3 que bajo ciertas circunstancias podría haber permitido a un usuario autenticado tener acceso a las direcciones de correo electrónico de otros usuarios a través de ciertas consultas GraphQL."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.6","lessThan":"18.8.9","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.5","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T13:03:07.698784Z","id":"CVE-2025-9484","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.6.0","versionEndExcluding":"18.8.9","matchCriteriaId":"935920C5-6C73-43AE-8CA5-80DBA520C1D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"3BA6A89D-D2C1-45B9-A8E8-64256816D880"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"BB2F3665-2451-4A4D-8538-93F540975F0E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/565363","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3303810","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1092","sourceIdentifier":"cve@gitlab.com","published":"2026-04-08T23:16:57.510","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service due to improper input validation of JSON payloads."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afectaba a todas las versiones desde la 12.10 antes de la 18.8.9, la 18.9 antes de la 18.9.5, y la 18.10 antes de la 18.10.3 que podría haber permitido a un usuario no autenticado causar denegación de servicio debido a una validación de entrada incorrecta de las cargas útiles JSON."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"12.10","lessThan":"18.8.9","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.5","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T15:09:43.259973Z","id":"CVE-2026-1092","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"18.8.9","matchCriteriaId":"4E41EACE-A6CA-490D-9592-4964BFBF6B76"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"3BA6A89D-D2C1-45B9-A8E8-64256816D880"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"BB2F3665-2451-4A4D-8538-93F540975F0E"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"12.10.0","versionEndExcluding":"18.8.9","matchCriteriaId":"41952659-B58E-4EB8-976C-AA43350A39F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"5C4D8A99-6E70-4D55-9ACF-FF2620F070E0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"DBCB346F-0B28-458B-A453-29DA4B0E91FC"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/586479","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3487030","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1101","sourceIdentifier":"cve@gitlab.com","published":"2026-04-08T23:16:57.667","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to cause denial of service to the GitLab instance due to improper input validation in GraphQL queries."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afectaba a todas las versiones desde la 18.2 anterior a la 18.8.9, la 18.9 anterior a la 18.9.5 y la 18.10 anterior a la 18.10.3 que podría haber permitido a un usuario autenticado causar una denegación de servicio a la instancia de GitLab debido a una validación de entrada incorrecta en las consultas GraphQL."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.2","lessThan":"18.8.9","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.5","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T15:40:51.074249Z","id":"CVE-2026-1101","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-1284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2","versionEndExcluding":"18.8.9","matchCriteriaId":"DE6B64C1-04D6-4E07-A730-72DD62AB9443"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"3BA6A89D-D2C1-45B9-A8E8-64256816D880"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"BB2F3665-2451-4A4D-8538-93F540975F0E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/586488","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3460228","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1516","sourceIdentifier":"cve@gitlab.com","published":"2026-04-08T23:16:57.920","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Code Quality reports could have allowed an authenticated user to leak IP addresses of users viewing the report via specially crafted content."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afectaba a todas las versiones desde la 18.0.0 anteriores a la 18.8.9, la 18.9 anteriores a la 18.9.5, y la 18.10 anteriores a la 18.10.3 que en los informes de Calidad de Código podría haber permitido a un usuario autenticado filtrar direcciones IP de usuarios que visualizaban el informe a través de contenido especialmente diseñado."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.0.0","lessThan":"18.8.9","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.5","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T15:42:16.466494Z","id":"CVE-2026-1516","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.0.0","versionEndExcluding":"18.8.9","matchCriteriaId":"E44C8A18-7C71-4626-85E4-9753A7039A03"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"3BA6A89D-D2C1-45B9-A8E8-64256816D880"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"BB2F3665-2451-4A4D-8538-93F540975F0E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/587893","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3514461","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-1752","sourceIdentifier":"cve@gitlab.com","published":"2026-04-08T23:16:58.077","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with developer-role permissions to modify protected environment settings due to improper authorization checks in the API."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afecta a todas las versiones desde la 11.3 anterior a la 18.8.9, la 18.9 anterior a la 18.9.5 y la 18.10 anterior a la 18.10.3 que podría haber permitido a un usuario autenticado con permisos de rol de desarrollador modificar la configuración de entornos protegidos debido a comprobaciones de autorización incorrectas en la API."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"11.3","lessThan":"18.8.9","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.5","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T14:58:34.582561Z","id":"CVE-2026-1752","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"11.3.0","versionEndExcluding":"18.8.9","matchCriteriaId":"680D11CA-8B72-40D6-B510-852E4E7C5DE9"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"3BA6A89D-D2C1-45B9-A8E8-64256816D880"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"BB2F3665-2451-4A4D-8538-93F540975F0E"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/588413","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3533545","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-2104","sourceIdentifier":"cve@gitlab.com","published":"2026-04-08T23:16:58.393","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to access confidential issues assigned to other users via CSV export due to insufficient authorization checks."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 18.2 anterior a la 18.8.9, la 18.9 anterior a la 18.9.5 y la 18.10 anterior a la 18.10.3 que podría haber permitido a un usuario autenticado acceder a problemas confidenciales asignados a otros usuarios a través de la exportación CSV debido a comprobaciones de autorización insuficientes."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"18.2","lessThan":"18.8.9","versionType":"semver","status":"affected"},{"version":"18.9","lessThan":"18.9.5","versionType":"semver","status":"affected"},{"version":"18.10","lessThan":"18.10.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T15:43:15.918452Z","id":"CVE-2026-2104","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.8.9","matchCriteriaId":"CFAD5EB0-9700-4C16-AEF0-27599F84541F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"3BA6A89D-D2C1-45B9-A8E8-64256816D880"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"BB2F3665-2451-4A4D-8538-93F540975F0E"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.2.0","versionEndExcluding":"18.8.9","matchCriteriaId":"6E8B1FB2-AA24-4447-8403-F082B4DCA62A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.9.0","versionEndExcluding":"18.9.5","matchCriteriaId":"5C4D8A99-6E70-4D55-9ACF-FF2620F070E0"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"18.10.0","versionEndExcluding":"18.10.3","matchCriteriaId":"DBCB346F-0B28-458B-A453-29DA4B0E91FC"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/work_items/589021","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3541476","source":"cve@gitlab.com","tags":["Permissions Required"]}]}},{"cve":{"id":"CVE-2026-3199","sourceIdentifier":"103e4ec9-0a87-450b-af77-479448ddef11","published":"2026-04-08T23:16:59.160","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control."},{"lang":"es","value":"Una vulnerabilidad en el componente de gestión de tareas de Sonatype Nexus Repository versiones 3.22.1 a 3.90.2 permite a un atacante autenticado con permisos de creación de tareas ejecutar código arbitrario, eludiendo el control de seguridad nexus.scripts.allowCreation."}],"affected":[{"source":"103e4ec9-0a87-450b-af77-479448ddef11","affectedData":[{"vendor":"Sonatype","product":"Nexus Repository","defaultStatus":"unaffected","cpes":["cpe:2.3:a:sonatype:nexus_repository_manager:3.22.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.23.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.24.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.25.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.26.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.26.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.27.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.28.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.28.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.29.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.29.2:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.30.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.30.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.31.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.31.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.32.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.32.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.33.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.33.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.34.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.34.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.35.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.36.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.37.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.37.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.37.2:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.37.3:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.38.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.38.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.39.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.40.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.40.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.41.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.41.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.42.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.43.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.44.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.45.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.45.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.46.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.47.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.47.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.48.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.49.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.50.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.51.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.52.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.53.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.53.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.54.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.54.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.55.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.56.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.57.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.57.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.58.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.58.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.59.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.60.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.61.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.62.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.63.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.64.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.65.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.66.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.67.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.67.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.68.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.68.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.69.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.70.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.70.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.70.2:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.70.3:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.71.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.72.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.73.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.74.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.75.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.75.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.76.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.76.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.77.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.78.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.78.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.79.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.80.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.81.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.82.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.83.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.83.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.83.2:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.84.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.84.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.85.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.86.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.86.2:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.87.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.87.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.88.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.89.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.90.0:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.90.1:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:nexus_repository_manager:3.90.2:*:*:*:*:*:*:*"],"versions":[{"version":"3.22.1","lessThan":"3.91.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"103e4ec9-0a87-450b-af77-479448ddef11","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.4,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T13:17:18.770700Z","id":"CVE-2026-3199","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"103e4ec9-0a87-450b-af77-479448ddef11","type":"Secondary","description":[{"lang":"en","value":"CWE-502"}]}],"references":[{"url":"https://help.sonatype.com/en/sonatype-nexus-repository-3-91-0-release-notes.html","source":"103e4ec9-0a87-450b-af77-479448ddef11"},{"url":"https://support.sonatype.com/hc/en-us/articles/50615414548499","source":"103e4ec9-0a87-450b-af77-479448ddef11"}]}},{"cve":{"id":"CVE-2026-32220","sourceIdentifier":"secure@microsoft.com","published":"2026-04-14T18:17:29.873","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally."},{"lang":"es","value":"Control de acceso inadecuado en el enclave de seguridad basado en virtualización (VBS) de Windows permite a un atacante autorizado eludir una característica de seguridad localmente."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"Microsoft","product":"Windows 11 Version 24H2","platforms":["ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.26100.0","lessThan":"10.0.26100.8246","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 11 Version 25H2","platforms":["ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.26200.0","lessThan":"10.0.26200.8246","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 11 version 26H1","platforms":["ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.28000.0","lessThan":"10.0.28000.1836","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2025","platforms":["x64-based Systems"],"versions":[{"version":"10.0.26100.0","lessThan":"10.0.26100.32690","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2025 (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"10.0.26100.0","lessThan":"10.0.26100.32690","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T10:40:47.932140Z","id":"CVE-2026-32220","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.26100.8246","matchCriteriaId":"94EB36C7-1FF2-4B44-AD91-F3540F09393E"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.26100.8246","matchCriteriaId":"14B23C3F-C8AC-491A-BCA5-EB6982C8F9E9"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.26200.8246","matchCriteriaId":"361B5DAB-8D1F-45D7-A33C-F49EBA56B5F8"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.26200.8246","matchCriteriaId":"ADC6CE99-AB5D-4DD5-82A9-892366C4B2FD"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.28000.1836","matchCriteriaId":"690E74A8-E72C-47B6-96EB-37C48D69A635"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.28000.1836","matchCriteriaId":"13A01FA1-08DC-4E33-9FFC-AB4BCD9634CA"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.26100.32690","matchCriteriaId":"ADF41A14-B9DA-4788-82A8-74DCDCD090E1"}]}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32220","source":"secure@microsoft.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-32221","sourceIdentifier":"secure@microsoft.com","published":"2026-04-14T18:17:30.087","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally."},{"lang":"es","value":"Desbordamiento de búfer basado en montículo en el Componente Gráfico de Microsoft permite a un atacante no autorizado ejecutar código localmente."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"Microsoft","product":"Windows 11 Version 24H2","platforms":["ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.26100.0","lessThan":"10.0.26100.8246","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 11 Version 25H2","platforms":["ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.26200.0","lessThan":"10.0.26200.8246","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 11 version 26H1","platforms":["ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.28000.0","lessThan":"10.0.28000.1836","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2025","platforms":["x64-based Systems"],"versions":[{"version":"10.0.26100.0","lessThan":"10.0.26100.32690","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2025 (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"10.0.26100.0","lessThan":"10.0.26100.32690","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T03:56:38.457373Z","id":"CVE-2026-32221","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-122"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.26100.8246","matchCriteriaId":"94EB36C7-1FF2-4B44-AD91-F3540F09393E"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.26100.8246","matchCriteriaId":"14B23C3F-C8AC-491A-BCA5-EB6982C8F9E9"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.26200.8246","matchCriteriaId":"361B5DAB-8D1F-45D7-A33C-F49EBA56B5F8"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.26200.8246","matchCriteriaId":"ADC6CE99-AB5D-4DD5-82A9-892366C4B2FD"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.28000.1836","matchCriteriaId":"690E74A8-E72C-47B6-96EB-37C48D69A635"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.28000.1836","matchCriteriaId":"13A01FA1-08DC-4E33-9FFC-AB4BCD9634CA"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.26100.32690","matchCriteriaId":"ADF41A14-B9DA-4788-82A8-74DCDCD090E1"}]}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32221","source":"secure@microsoft.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-32222","sourceIdentifier":"secure@microsoft.com","published":"2026-04-14T18:17:30.290","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally."},{"lang":"es","value":"Desreferencia de puntero no confiable en Windows Win32K - ICOMP permite a un atacante autorizado elevar privilegios localmente."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"Microsoft","product":"Windows 11 Version 24H2","platforms":["ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.26100.0","lessThan":"10.0.26100.8246","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 11 Version 25H2","platforms":["ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.26200.0","lessThan":"10.0.26200.8246","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 11 version 26H1","platforms":["ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.28000.0","lessThan":"10.0.28000.1836","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2025","platforms":["x64-based Systems"],"versions":[{"version":"10.0.26100.0","lessThan":"10.0.26100.32690","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2025 (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"10.0.26100.0","lessThan":"10.0.26100.32690","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T03:55:28.439732Z","id":"CVE-2026-32222","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-822"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.26100.8246","matchCriteriaId":"94EB36C7-1FF2-4B44-AD91-F3540F09393E"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.26100.8246","matchCriteriaId":"14B23C3F-C8AC-491A-BCA5-EB6982C8F9E9"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.26200.8246","matchCriteriaId":"361B5DAB-8D1F-45D7-A33C-F49EBA56B5F8"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.26200.8246","matchCriteriaId":"ADC6CE99-AB5D-4DD5-82A9-892366C4B2FD"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.28000.1836","matchCriteriaId":"690E74A8-E72C-47B6-96EB-37C48D69A635"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.28000.1836","matchCriteriaId":"13A01FA1-08DC-4E33-9FFC-AB4BCD9634CA"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.26100.32690","matchCriteriaId":"ADF41A14-B9DA-4788-82A8-74DCDCD090E1"}]}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32222","source":"secure@microsoft.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-32223","sourceIdentifier":"secure@microsoft.com","published":"2026-04-14T18:17:30.490","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack."},{"lang":"es","value":"Desbordamiento de búfer basado en montículo en el controlador de impresión USB de Windows permite a un atacante no autorizado elevar privilegios con un ataque físico."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"Microsoft","product":"Windows 11 Version 24H2","platforms":["ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.26100.0","lessThan":"10.0.26100.8246","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 11 Version 25H2","platforms":["ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.26200.0","lessThan":"10.0.26200.8246","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 11 version 26H1","platforms":["ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.28000.0","lessThan":"10.0.28000.1836","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2025","platforms":["x64-based Systems"],"versions":[{"version":"10.0.26100.0","lessThan":"10.0.26100.32690","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2025 (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"10.0.26100.0","lessThan":"10.0.26100.32690","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-14T19:28:52.114553Z","id":"CVE-2026-32223","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-122"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.26100.8246","matchCriteriaId":"94EB36C7-1FF2-4B44-AD91-F3540F09393E"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.26100.8246","matchCriteriaId":"14B23C3F-C8AC-491A-BCA5-EB6982C8F9E9"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.26200.8246","matchCriteriaId":"361B5DAB-8D1F-45D7-A33C-F49EBA56B5F8"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.26200.8246","matchCriteriaId":"ADC6CE99-AB5D-4DD5-82A9-892366C4B2FD"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.28000.1836","matchCriteriaId":"690E74A8-E72C-47B6-96EB-37C48D69A635"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.28000.1836","matchCriteriaId":"13A01FA1-08DC-4E33-9FFC-AB4BCD9634CA"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.26100.32690","matchCriteriaId":"ADF41A14-B9DA-4788-82A8-74DCDCD090E1"}]}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32223","source":"secure@microsoft.com","tags":["Vendor Advisory"]},{"url":"https://www.vicarius.io/vsociety/posts/cve-2026-32223-detection-script-heap-based-buffer-overflow-in-windows-usb-print-driver","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.vicarius.io/vsociety/posts/cve-2026-32223-mitigation-script-heap-based-buffer-overflow-in-windows-usb-print-driver","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-32224","sourceIdentifier":"secure@microsoft.com","published":"2026-04-14T18:17:30.690","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally."},{"lang":"es","value":"Uso después de liberar en el Servicio de Actualización de Windows Server permite a un atacante autorizado elevar privilegios localmente."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"Microsoft","product":"Windows 11 version 26H1","platforms":["ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.28000.0","lessThan":"10.0.28000.1836","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.0,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.0,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T03:56:15.991608Z","id":"CVE-2026-32224","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-416"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.28000.1836","matchCriteriaId":"690E74A8-E72C-47B6-96EB-37C48D69A635"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.28000.1836","matchCriteriaId":"13A01FA1-08DC-4E33-9FFC-AB4BCD9634CA"}]}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32224","source":"secure@microsoft.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-32225","sourceIdentifier":"secure@microsoft.com","published":"2026-04-14T18:17:30.850","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network."},{"lang":"es","value":"Fallo del mecanismo de protección en Windows Shell permite a un atacante no autorizado eludir una característica de seguridad a través de una red."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"Microsoft","product":"Windows 10 Version 1607","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"10.0.14393.0","lessThan":"10.0.14393.9060","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 10 Version 1809","platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"10.0.17763.0","lessThan":"10.0.17763.8644","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 10 Version 21H2","platforms":["32-bit Systems","ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.19044.0","lessThan":"10.0.19044.7184","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 10 Version 22H2","platforms":["32-bit Systems","ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.19045.0","lessThan":"10.0.19045.7184","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 11 version 22H3","platforms":["ARM64-based Systems"],"versions":[{"version":"10.0.22631.0","lessThan":"10.0.22631.6936","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 11 Version 23H2","platforms":["x64-based Systems"],"versions":[{"version":"10.0.22631.0","lessThan":"10.0.22631.6936","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 11 Version 24H2","platforms":["ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.26100.0","lessThan":"10.0.26100.8246","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 11 Version 25H2","platforms":["ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.26200.0","lessThan":"10.0.26200.8246","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 11 version 26H1","platforms":["ARM64-based Systems","x64-based Systems"],"versions":[{"version":"10.0.28000.0","lessThan":"10.0.28000.1836","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2012","platforms":["x64-based Systems"],"versions":[{"version":"6.2.9200.0","lessThan":"6.2.9200.26026","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2012 (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"6.2.9200.0","lessThan":"6.2.9200.26026","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2012 R2","platforms":["x64-based Systems"],"versions":[{"version":"6.3.9600.0","lessThan":"6.3.9600.23132","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2012 R2 (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"6.3.9600.0","lessThan":"6.3.9600.23132","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2016","platforms":["x64-based Systems"],"versions":[{"version":"10.0.14393.0","lessThan":"10.0.14393.9060","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2016 (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"10.0.14393.0","lessThan":"10.0.14393.9060","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2019","platforms":["x64-based Systems"],"versions":[{"version":"10.0.17763.0","lessThan":"10.0.17763.8644","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2019 (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"10.0.17763.0","lessThan":"10.0.17763.8644","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2022","platforms":["x64-based Systems"],"versions":[{"version":"10.0.20348.0","lessThan":"10.0.20348.5020","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2022, 23H2 Edition (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"10.0.25398.0","lessThan":"10.0.25398.2274","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2025","platforms":["x64-based Systems"],"versions":[{"version":"10.0.26100.0","lessThan":"10.0.26100.32690","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2025 (Server Core installation)","platforms":["x64-based Systems"],"versions":[{"version":"10.0.26100.0","lessThan":"10.0.26100.32690","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-09T00:00:00+00:00","id":"CVE-2026-32225","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-693"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.14393.9060","matchCriteriaId":"158C16A3-547E-4130-8428-8E429C37E573"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.14393.9060","matchCriteriaId":"58E1A340-D49A-4EBB-A750-876922ACD5CA"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.17763.8644","matchCriteriaId":"64248504-2307-45FC-8FF3-7A227CFD8675"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.17763.8644","matchCriteriaId":"9B1465B1-BDE6-4634-8F12-43F71D68A4D6"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.19044.7184","matchCriteriaId":"88A175C4-E033-4FE7-B2BF-8BAE14321BC4"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.19044.7184","matchCriteriaId":"86DBF14A-F486-4FE7-9126-D1D54952FC6C"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.19044.7184","matchCriteriaId":"C375372B-D3D4-4B11-AAD8-69AC344C24BC"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.19045.7184","matchCriteriaId":"8CE2E268-E776-4697-9E43-33ABA4CDBE05"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.19045.7184","matchCriteriaId":"269B8E88-6473-41DD-BA33-D9184B82CA58"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*","versionEndExcluding":"10.0.19045.7184","matchCriteriaId":"FCBB431B-EF21-4454-BDA3-D8F276BE7A64"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.22631.6936","matchCriteriaId":"B33CE091-B873-4C30-BA05-54A8C1839212"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.22631.6936","matchCriteriaId":"E3AF28F3-D486-4B88-9E0E-371241024174"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.26100.8246","matchCriteriaId":"94EB36C7-1FF2-4B44-AD91-F3540F09393E"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.26100.8246","matchCriteriaId":"14B23C3F-C8AC-491A-BCA5-EB6982C8F9E9"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.26200.8246","matchCriteriaId":"361B5DAB-8D1F-45D7-A33C-F49EBA56B5F8"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.26200.8246","matchCriteriaId":"ADC6CE99-AB5D-4DD5-82A9-892366C4B2FD"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*","versionEndExcluding":"10.0.28000.1836","matchCriteriaId":"690E74A8-E72C-47B6-96EB-37C48D69A635"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*","versionEndExcluding":"10.0.28000.1836","matchCriteriaId":"13A01FA1-08DC-4E33-9FFC-AB4BCD9634CA"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*","matchCriteriaId":"A7DF96F8-BA6A-4780-9CA3-F719B3F81074"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*","matchCriteriaId":"DB18C4CE-5917-401E-ACF7-2747084FD36E"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.14393.9060","matchCriteriaId":"982DB0CA-5196-4E42-B2F7-994BE8179715"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.17763.8644","matchCriteriaId":"647CF9B5-8898-469B-9C09-D372A7843187"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.20348.5020","matchCriteriaId":"DC6837B7-5DFD-4AF7-B436-3C6FEF48BA60"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.25398.2274","matchCriteriaId":"55A1F3AB-5299-4495-9A73-FDA23C6FD88D"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.26100.32690","matchCriteriaId":"ADF41A14-B9DA-4788-82A8-74DCDCD090E1"}]}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32225","source":"secure@microsoft.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-32226","sourceIdentifier":"secure@microsoft.com","published":"2026-04-14T18:17:31.190","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network."},{"lang":"es","value":"Ejecución concurrente utilizando un recurso compartido con sincronización inadecuada ('condición de carrera') en .NET Framework permite a un atacante no autorizado denegar el servicio a través de una red."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"Microsoft","product":"Microsoft .NET Framework 3.5","platforms":["Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"versions":[{"version":"3.5.0","lessThan":"2.0.50727.8982 & 3.0.30729.8976","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft .NET Framework 3.5 AND 4.7.2","platforms":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for ARM64-based Systems","Windows 10 Version 1809 for x64-based Systems"],"versions":[{"version":"4.7.0","lessThan":"2.0.50727.9068 & 3.0.30729.9065 & 4.7.4141.0","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft .NET Framework 3.5 AND 4.8","platforms":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for ARM64-based Systems","Windows 10 Version 1809 for x64-based Systems","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 11 version 21H2 for x64-based Systems","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server, version 20H2 (Server Core Installation)"],"versions":[{"version":"4.8.0","lessThan":"2.0.50727.9068 & 3.0.30729.9065 & 4.8.4801.0","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft .NET Framework 3.5 AND 4.8.1","platforms":["Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 11 Version 22H2 for ARM64-based Systems","Windows 11 Version 22H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems","Windows 11 version 26H1 for x64-based Systems","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2022, 23H2 Edition (Server Core installation)","Windows Server 2025","Windows Server 2025 (Server Core installation)"],"versions":[{"version":"4.8.1","lessThan":"2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2","platforms":["Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"versions":[{"version":"4.7.0","lessThan":"4.8.4801.0","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft .NET Framework 4.7.2","platforms":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for ARM64-based Systems","Windows 10 Version 1809 for x64-based Systems"],"versions":[{"version":"10.0.0.0","lessThan":"2.0.50727.9068 & 3.0.30729.9065 & 4.7.4141.0","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft .NET Framework 4.8","platforms":["Windows 10 Version 1607 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 11 Version 22H2 for x64-based Systems","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"versions":[{"version":"4.8.0","lessThan":"2.0.50727.9181 & 3.0.30729.9165 & 4.8.4801.0","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft .NET Framework 4.8.1","platforms":["Windows Server 2022 (Server Core installation)"],"versions":[{"version":"4.8.0.0","lessThan":"2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-14T19:03:36.736622Z","id":"CVE-2026-32226","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-362"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:3.5:-:*:*:*:*:*:*","matchCriteriaId":"23317443-1968-4791-9F20-AD3B308A83D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:*","matchCriteriaId":"3EF7A75E-EE27-4AA7-8D84-9D696728A4CE"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:arm64:*","matchCriteriaId":"73D24713-D897-408D-893B-77A61982597D"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x64:*","matchCriteriaId":"306B7CE6-8239-4AED-9ED4-4C9F5B349F58"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:3.5:-:*:*:*:*:*:*","matchCriteriaId":"23317443-1968-4791-9F20-AD3B308A83D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:4.8:*:*:*:*:*:*:*","matchCriteriaId":"2D3F18AF-84ED-473B-A8DF-65EB23C475AF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:arm64:*","matchCriteriaId":"73D24713-D897-408D-893B-77A61982597D"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x64:*","matchCriteriaId":"306B7CE6-8239-4AED-9ED4-4C9F5B349F58"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x86:*","matchCriteriaId":"345FCD64-D37B-425B-B64C-8B1640B7E850"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_20h2:-:*:*:*:*:*:x64:*","matchCriteriaId":"23DB22F4-7FFB-4B77-A4BF-EC097938E239"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:4.8:*:*:*:*:*:*:*","matchCriteriaId":"2D3F18AF-84ED-473B-A8DF-65EB23C475AF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:*","matchCriteriaId":"5E491E46-1917-41FE-8F9A-BB0BDDEB42C3"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*","matchCriteriaId":"A7DF96F8-BA6A-4780-9CA3-F719B3F81074"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*","matchCriteriaId":"DB18C4CE-5917-401E-ACF7-2747084FD36E"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:3.5:-:*:*:*:*:*:*","matchCriteriaId":"23317443-1968-4791-9F20-AD3B308A83D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:4.8.1:*:*:*:*:*:*:*","matchCriteriaId":"934D4E46-12C1-41DC-A28C-A2C430E965E4"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_11_26h1:-:*:*:*:*:*:arm64:*","matchCriteriaId":"CBFE0371-0C4D-406A-9EC7-456104271C3E"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_11_26h1:-:*:*:*:*:*:x64:*","matchCriteriaId":"F2B83840-FCE8-445A-AE55-ACEDA6534FA1"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2025:-:*:*:*:*:*:x64:*","matchCriteriaId":"FE97605F-7942-435A-9F5B-D51FA19A41AD"}]}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32226","source":"secure@microsoft.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-33116","sourceIdentifier":"secure@microsoft.com","published":"2026-04-14T18:17:33.903","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network."},{"lang":"es","value":"Bucle con condición de salida inalcanzable ('bucle infinito') en .NET, .NET Framework, Visual Studio permite a un atacante no autorizado denegar el servicio a través de una red."}],"affected":[{"source":"secure@microsoft.com","affectedData":[{"vendor":"Microsoft","product":".NET 10.0","versions":[{"version":"10.0.0","lessThan":"10.0.6","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":".NET 8.0","versions":[{"version":"8.0","lessThan":"8.0.26","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":".NET 8.0","versions":[{"version":"8.0.0","lessThan":"8.0.26","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":".NET 9.0","versions":[{"version":"9.0.0","lessThan":"9.0.15","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft .NET Framework 3.5","platforms":["Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"versions":[{"version":"3.5.0","lessThan":"2.0.50727.8982 & 3.0.30729.8976","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft .NET Framework 3.5 AND 4.7.2","platforms":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for ARM64-based Systems","Windows 10 Version 1809 for x64-based Systems"],"versions":[{"version":"4.7.0","lessThan":"2.0.50727.9068 & 3.0.30729.9065 & 4.7.4141.0","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft .NET Framework 3.5 AND 4.8","platforms":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for ARM64-based Systems","Windows 10 Version 1809 for x64-based Systems","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows Server 2022","Windows Server 2022 (Server Core installation)"],"versions":[{"version":"4.8.0","lessThan":"2.0.50727.9068 & 3.0.30729.9065 & 4.8.4801.0","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft .NET Framework 3.5 AND 4.8.1","platforms":["Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 11 Version 22H2 for ARM64-based Systems","Windows 11 Version 22H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems","Windows 11 Version 26H1 for x64-based Systems","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2022, 23H2 Edition (Server Core installation)","Windows Server 2025","Windows Server 2025 (Server Core installation)"],"versions":[{"version":"4.8.1","lessThan":"2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2","platforms":["Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"versions":[{"version":"4.7.0","lessThan":"4.8.4801.0","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Microsoft .NET Framework 4.8","platforms":["Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"versions":[{"version":"4.8.0","lessThan":"4.8.4801.0","versionType":"custom","status":"affected"}]}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","affectedData":[{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"dotnet10.0","cpes":["cpe:/o:redhat:enterprise_linux:10.1"],"versions":[{"version":"0:10.0.106-1.el10_1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"dotnet8.0","cpes":["cpe:/o:redhat:enterprise_linux:10.1"],"versions":[{"version":"0:8.0.126-1.el10_1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"dotnet9.0","cpes":["cpe:/o:redhat:enterprise_linux:10.1"],"versions":[{"version":"0:9.0.116-1.el10_1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"dotnet9.0","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:9.0.116-1.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"dotnet8.0","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:8.0.126-1.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"dotnet8.0","cpes":["cpe:/a:redhat:enterprise_linux:8"],"versions":[{"version":"0:8.0.126-1.el8_10","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"dotnet10.0","cpes":["cpe:/a:redhat:enterprise_linux:8"],"versions":[{"version":"0:10.0.106-1.el8_10","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"dotnet9.0","cpes":["cpe:/a:redhat:enterprise_linux:8"],"versions":[{"version":"0:9.0.116-1.el8_10","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"dotnet8.0","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"0:8.0.126-1.el9_7","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"dotnet10.0","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"0:10.0.106-1.el9_7","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"dotnet9.0","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"0:9.0.116-1.el9_7","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.4 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"dotnet8.0","cpes":["cpe:/a:redhat:rhel_eus:9.4"],"versions":[{"version":"0:8.0.126-1.el9_4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"dotnet9.0","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"0:9.0.116-1.el9_6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"dotnet8.0","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"0:8.0.126-1.el9_6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"dotnet10-0-main","cpes":["cpe:/a:redhat:hummingbird:1"],"versions":[{"version":"10.0.106-1.hum1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"dotnet8-0-main","cpes":["cpe:/a:redhat:hummingbird:1"],"versions":[{"version":"8.0.126-1.hum1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"dotnet9-0-main","cpes":["cpe:/a:redhat:hummingbird:1"],"versions":[{"version":"9.0.116-1.hum1","lessThan":"*","versionType":"rpm","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-14T19:48:26.946135Z","id":"CVE-2026-33116","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secure@microsoft.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"},{"lang":"en","value":"CWE-400"},{"lang":"en","value":"CWE-835"}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","description":[{"lang":"en","value":"CWE-776"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0.0","versionEndExcluding":"10.0.6","matchCriteriaId":"CD89D801-933E-4D78-9187-D2CA94370FA0"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"},{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"8.0.26","matchCriteriaId":"CB15ABFB-047C-4B69-BD19-68D3EFEDCB78"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"},{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"9.0.15","matchCriteriaId":"EB2D66A6-4F92-4AB0-A8F0-FCE4EC0BED1A"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"},{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:3.5:-:*:*:*:*:*:*","matchCriteriaId":"23317443-1968-4791-9F20-AD3B308A83D1"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*","matchCriteriaId":"A7DF96F8-BA6A-4780-9CA3-F719B3F81074"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*","matchCriteriaId":"DB18C4CE-5917-401E-ACF7-2747084FD36E"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:3.5:-:*:*:*:*:*:*","matchCriteriaId":"23317443-1968-4791-9F20-AD3B308A83D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:*","matchCriteriaId":"3EF7A75E-EE27-4AA7-8D84-9D696728A4CE"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:arm64:*","matchCriteriaId":"73D24713-D897-408D-893B-77A61982597D"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x64:*","matchCriteriaId":"306B7CE6-8239-4AED-9ED4-4C9F5B349F58"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x86:*","matchCriteriaId":"345FCD64-D37B-425B-B64C-8B1640B7E850"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:4.6.2:*:*:*:*:*:*:*","matchCriteriaId":"A16AD2B0-2189-4E8E-B7FC-CE598CA1CB2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:4.7:*:*:*:*:*:*:*","matchCriteriaId":"734112B3-1383-4BE3-8721-C0F84566B764"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:4.7.1:*:*:*:*:*:*:*","matchCriteriaId":"36B0E40A-84EF-4099-A395-75D6B8CDA196"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:*","matchCriteriaId":"3EF7A75E-EE27-4AA7-8D84-9D696728A4CE"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*","matchCriteriaId":"A7DF96F8-BA6A-4780-9CA3-F719B3F81074"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*","matchCriteriaId":"DB18C4CE-5917-401E-ACF7-2747084FD36E"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:3.5:-:*:*:*:*:*:*","matchCriteriaId":"23317443-1968-4791-9F20-AD3B308A83D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:4.8:*:*:*:*:*:*:*","matchCriteriaId":"2D3F18AF-84ED-473B-A8DF-65EB23C475AF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:arm64:*","matchCriteriaId":"73D24713-D897-408D-893B-77A61982597D"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x64:*","matchCriteriaId":"306B7CE6-8239-4AED-9ED4-4C9F5B349F58"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x86:*","matchCriteriaId":"345FCD64-D37B-425B-B64C-8B1640B7E850"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_21h2:-:*:*:*:*:*:arm64:*","matchCriteriaId":"8FC46499-DB6E-48BF-9334-85EE27AFE7AF"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_21h2:-:*:*:*:*:*:x64:*","matchCriteriaId":"83A79DD6-E74E-419F-93F1-323B68502633"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_21h2:-:*:*:*:*:*:x86:*","matchCriteriaId":"61959ACC-B608-4556-92AF-4D94B338907A"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:-:*:*:*:*:*:arm64:*","matchCriteriaId":"A9D54EE6-30AF-411C-A285-A4DCB6C6EC06"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:-:*:*:*:*:*:x64:*","matchCriteriaId":"C230D3BF-7FCE-405C-B62E-B9190C995C3C"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:-:*:*:*:*:*:x86:*","matchCriteriaId":"1FD62DCB-66D1-4CEA-828E-0BD302AC63CA"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*","matchCriteriaId":"821614DD-37DD-44E2-A8A4-FE8D23A33C3C"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:3.5:-:*:*:*:*:*:*","matchCriteriaId":"23317443-1968-4791-9F20-AD3B308A83D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:4.8.1:*:*:*:*:*:*:*","matchCriteriaId":"934D4E46-12C1-41DC-A28C-A2C430E965E4"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_21h2:-:*:*:*:*:*:arm64:*","matchCriteriaId":"8FC46499-DB6E-48BF-9334-85EE27AFE7AF"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_21h2:-:*:*:*:*:*:x64:*","matchCriteriaId":"83A79DD6-E74E-419F-93F1-323B68502633"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_21h2:-:*:*:*:*:*:x86:*","matchCriteriaId":"61959ACC-B608-4556-92AF-4D94B338907A"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:-:*:*:*:*:*:arm64:*","matchCriteriaId":"A9D54EE6-30AF-411C-A285-A4DCB6C6EC06"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:-:*:*:*:*:*:x64:*","matchCriteriaId":"C230D3BF-7FCE-405C-B62E-B9190C995C3C"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_22h2:-:*:*:*:*:*:x86:*","matchCriteriaId":"1FD62DCB-66D1-4CEA-828E-0BD302AC63CA"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_11_22h2:-:*:*:*:*:*:arm64:*","matchCriteriaId":"B2D24C54-F04F-4717-B614-FE67B3ED9DC0"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_11_22h2:-:*:*:*:*:*:x64:*","matchCriteriaId":"D5EC3F68-8F41-4F6B-B2E5-920322A4A321"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_11_23h2:-:*:*:*:*:*:arm64:*","matchCriteriaId":"B0301BA0-81DB-4FC1-9BC3-EB48A56BC608"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_11_23h2:-:*:*:*:*:*:x64:*","matchCriteriaId":"8E3C1327-F331-4448-A253-00EAC7428317"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_11_24h2:-:*:*:*:*:*:arm64:*","matchCriteriaId":"08EE1F3A-A8DE-4867-BB5B-8A8ED867F3CA"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_11_24h2:-:*:*:*:*:*:x64:*","matchCriteriaId":"B1670829-6A8C-4688-B7A5-3DFB878A4861"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_11_25h2:-:*:*:*:*:*:arm64:*","matchCriteriaId":"024EE6EC-6D62-4EAC-B1EF-A5E4EAD439A1"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_11_25h2:-:*:*:*:*:*:x64:*","matchCriteriaId":"25D142AB-B61D-43F3-B7E6-DB9140EFEF75"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_11_26h1:-:*:*:*:*:*:arm64:*","matchCriteriaId":"CBFE0371-0C4D-406A-9EC7-456104271C3E"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_11_26h1:-:*:*:*:*:*:x64:*","matchCriteriaId":"F2B83840-FCE8-445A-AE55-ACEDA6534FA1"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2022:-:*:*:*:*:*:*:*","matchCriteriaId":"821614DD-37DD-44E2-A8A4-FE8D23A33C3C"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2022_23h2:-:*:*:*:*:*:x64:*","matchCriteriaId":"FBF3E8E3-BC4A-4CBA-8859-0AB6393E8A40"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2025:-:*:*:*:*:*:x64:*","matchCriteriaId":"FE97605F-7942-435A-9F5B-D51FA19A41AD"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:4.8:*:*:*:*:*:*:*","matchCriteriaId":"2D3F18AF-84ED-473B-A8DF-65EB23C475AF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:*","matchCriteriaId":"5E491E46-1917-41FE-8F9A-BB0BDDEB42C3"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x86:*","matchCriteriaId":"0A1BC97A-263E-4291-8AEF-02EE4E6031E9"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*","matchCriteriaId":"A7DF96F8-BA6A-4780-9CA3-F719B3F81074"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*","matchCriteriaId":"DB18C4CE-5917-401E-ACF7-2747084FD36E"}]}]}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33116","source":"secure@microsoft.com","tags":["Vendor Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:13280","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:13281","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:13282","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:13283","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:13693","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:8467","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:8468","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:8469","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:8470","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:8471","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:8472","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:8473","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:8474","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:8475","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:9077","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:9080","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:9205","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-33116","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2457741","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33116.json","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}]}},{"cve":{"id":"CVE-2026-27289","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T20:16:34.140","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Photoshop Desktop versions 27.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."},{"lang":"es","value":"Versiones de Photoshop Desktop 27.4 y anteriores están afectadas por una vulnerabilidad de lectura fuera de límites al analizar un archivo manipulado, lo que podría resultar en una lectura más allá del final de una estructura de memoria asignada. Un atacante podría aprovechar esta vulnerabilidad para ejecutar código en el contexto del usuario actual. La explotación de este problema requiere interacción del usuario en el sentido de que una víctima debe abrir un archivo malicioso."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"Photoshop Desktop","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"27.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T03:58:42.437726Z","id":"CVE-2026-27289","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-125"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:photoshop:*:*:*:*:*:*:*:*","versionStartIncluding":"27.0","versionEndExcluding":"27.5","matchCriteriaId":"A030FA03-9A83-4835-98FB-F5542BB4B02A"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/photoshop/apsb26-40.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27311","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T20:16:34.577","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."},{"lang":"es","value":"Las versiones 16.0.2, 15.1.4 y anteriores de Bridge se ven afectadas por una vulnerabilidad de desbordamiento de búfer basado en montículo que podría resultar en ejecución de código arbitrario en el contexto del usuario actual. La explotación de este problema requiere interacción del usuario, ya que la víctima debe abrir un archivo malicioso."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"Bridge","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"15.1.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-14T00:00:00+00:00","id":"CVE-2026-27311","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-122"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:bridge:*:*:*:*:*:*:*:*","versionEndExcluding":"15.1.5","matchCriteriaId":"8B4FBE0D-49AE-47B0-9A02-CF772B606C89"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:bridge:*:*:*:*:*:*:*:*","versionStartIncluding":"16.0","versionEndExcluding":"16.0.3","matchCriteriaId":"AA94FD4C-CD52-43BC-9DD6-C688A783A5F9"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/bridge/apsb26-39.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27312","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T20:16:34.730","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."},{"lang":"es","value":"Las versiones 16.0.2, 15.1.4 y anteriores de Bridge se ven afectadas por una vulnerabilidad de desbordamiento de búfer basado en montículo que podría resultar en ejecución de código arbitrario en el contexto del usuario actual. La explotación de este problema requiere interacción del usuario en el sentido de que la víctima debe abrir un archivo malicioso."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"Bridge","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"15.1.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-14T00:00:00+00:00","id":"CVE-2026-27312","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-122"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:bridge:*:*:*:*:*:*:*:*","versionEndExcluding":"15.1.5","matchCriteriaId":"8B4FBE0D-49AE-47B0-9A02-CF772B606C89"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:bridge:*:*:*:*:*:*:*:*","versionStartIncluding":"16.0","versionEndExcluding":"16.0.3","matchCriteriaId":"AA94FD4C-CD52-43BC-9DD6-C688A783A5F9"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/bridge/apsb26-39.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27313","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T20:16:34.883","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."},{"lang":"es","value":"Las versiones 16.0.2, 15.1.4 y anteriores de Bridge están afectadas por una vulnerabilidad de desbordamiento de búfer basado en montículo que podría resultar en la ejecución de código arbitrario en el contexto del usuario actual. La explotación de este problema requiere interacción del usuario, en el sentido de que la víctima debe abrir un archivo malicioso."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"Bridge","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"15.1.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T03:58:51.017959Z","id":"CVE-2026-27313","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-122"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:bridge:*:*:*:*:*:*:*:*","versionEndExcluding":"15.1.5","matchCriteriaId":"8B4FBE0D-49AE-47B0-9A02-CF772B606C89"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:bridge:*:*:*:*:*:*:*:*","versionStartIncluding":"16.0","versionEndExcluding":"16.0.3","matchCriteriaId":"AA94FD4C-CD52-43BC-9DD6-C688A783A5F9"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/bridge/apsb26-39.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-24893","sourceIdentifier":"security-advisories@github.com","published":"2026-04-14T21:16:24.987","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a command injection vulnerability that allows an authenticated user with permission to add or modify hosts to execute arbitrary OS commands on the monitoring backend. The vulnerability arises because user-controlled host attributes (specifically the host address) are expanded into monitoring command templates without validation, escaping, or quoting. These templates are later executed by the monitoring engine (Nagios/Icinga) via a shell, resulting in remote code execution. Version 5.5.2 patches the issue."},{"lang":"es","value":"openITCOCKPIT es una herramienta de monitorización de código abierto diseñada para diferentes motores de monitorización. openITCOCKPIT Community Edition anterior a la versión 5.5.2 contiene una vulnerabilidad de inyección de comandos que permite a un usuario autenticado con permiso para añadir o modificar hosts ejecutar comandos arbitrarios del sistema operativo en el backend de monitorización. La vulnerabilidad surge porque los atributos de host controlados por el usuario (específicamente la dirección del host) se expanden en plantillas de comandos de monitorización sin validación, escape o entrecomillado. Estas plantillas son posteriormente ejecutadas por el motor de monitorización (Nagios/Icinga) a través de un shell, lo que resulta en ejecución remota de código. La versión 5.5.2 corrige el problema."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"openITCOCKPIT","product":"openITCOCKPIT","versions":[{"version":"< 5.5.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T13:40:22.140339Z","id":"CVE-2026-24893","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"},{"lang":"en","value":"CWE-78"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:it-novum:openitcockpit:*:*:*:*:*:*:*:*","versionEndExcluding":"5.5.2","matchCriteriaId":"59D6662E-E1EB-49A8-8B31-A15DBA895263"}]}]}],"references":[{"url":"https://github.com/openITCOCKPIT/openITCOCKPIT/releases/tag/openITCOCKPIT-5.5.2","source":"security-advisories@github.com","tags":["Product","Release Notes"]},{"url":"https://github.com/openITCOCKPIT/openITCOCKPIT/security/advisories/GHSA-789q-pw85-j2q2","source":"security-advisories@github.com","tags":["Mitigation","Vendor Advisory"]},{"url":"https://openitcockpit.io/blog/posts/2026/2026-04-14-openitcockpit-agent-3.6.0-and-5.5.2","source":"security-advisories@github.com","tags":["Press/Media Coverage","Release Notes"]}]}},{"cve":{"id":"CVE-2026-25125","sourceIdentifier":"security-advisories@github.com","published":"2026-04-14T21:16:25.163","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings parser. Because PHP's parse_ini_string() function supports ${} syntax for environment variable interpolation, attackers with Editor access could inject patterns such as ${APP_KEY} or ${DB_PASSWORD} into CMS page settings fields, causing sensitive environment variables to be resolved, stored in the template, and returned to the attacker when the page was reopened. This could enable exfiltration of credentials and secrets (database passwords, AWS keys, application keys), potentially leading to further attacks such as database access or cookie forgery. The vulnerability is only relevant when cms.safe_mode is enabled, as direct PHP injection is already possible otherwise. This issue has been fixed in versions 3.7.14 and 4.1.10. If users are unable to immediately upgrade, they can workaround this issue by restricting Editor tool access to fully trusted administrators only, and ensuring database and cloud service credentials are not accessible from the web server's network."},{"lang":"es","value":"October es un Sistema de Gestión de Contenidos (CMS) y plataforma web. Las versiones anteriores a la 3.7.14 y 4.1.10 contienen una vulnerabilidad de revelación de información del lado del servidor en el analizador de configuraciones INI. Debido a que la función parse_ini_string() de PHP soporta la sintaxis ${} para la interpolación de variables de entorno, los atacantes con acceso de Editor podrían inyectar patrones como ${APP_KEY} o ${DB_PASSWORD} en los campos de configuración de las páginas del CMS, haciendo que las variables de entorno sensibles se resolvieran, se almacenaran en la plantilla y se devolvieran al atacante cuando la página se volvía a abrir. Esto podría permitir la exfiltración de credenciales y secretos (contraseñas de base de datos, claves de AWS, claves de aplicación), lo que podría conducir a ataques adicionales como el acceso a la base de datos o la falsificación de cookies. La vulnerabilidad solo es relevante cuando cms.safe_mode está habilitado, ya que la inyección directa de PHP ya es posible de otra manera. Este problema ha sido solucionado en las versiones 3.7.14 y 4.1.10. Si los usuarios no pueden actualizar de inmediato, pueden solucionar este problema restringiendo el acceso a la herramienta de Editor solo a administradores de plena confianza y asegurándose de que las credenciales de la base de datos y los servicios en la nube no sean accesibles desde la red del servidor web."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"octobercms","product":"october","versions":[{"version":"< 3.7.14","status":"affected"},{"version":">= 4.0.0, < 4.1.10","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T14:24:59.493377Z","id":"CVE-2026-25125","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"},{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*","versionEndExcluding":"3.7.14","matchCriteriaId":"A4B09756-5CEC-4A63-A91F-58E99350B445"},{"vulnerable":true,"criteria":"cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0.0","versionEndExcluding":"4.1.10","matchCriteriaId":"2727354A-C459-499A-BE8A-3E397FC293F9"}]}]}],"references":[{"url":"https://github.com/octobercms/october/security/advisories/GHSA-g6v3-wv4j-x9hg","source":"security-advisories@github.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-25133","sourceIdentifier":"security-advisories@github.com","published":"2026-04-14T21:16:25.330","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the SVG sanitization logic. The regex pattern used to strip event handler attributes (such as onclick or onload) could be bypassed using a crafted payload that exploits how the pattern matches attribute boundaries, allowing malicious SVG files to be uploaded through the Media Manager with embedded JavaScript. Exploitation could lead to privilege escalation if a superuser views or embeds the malicious SVG, and requires authenticated backend access with media upload permissions. The SVG must be viewed or embedded in a page for the payload to trigger. This issue has been fixed in versions 3.7.14 and 4.1.10."},{"lang":"es","value":"October es un Sistema de Gestión de Contenidos (CMS) y plataforma web. Las versiones anteriores a la 3.7.14 y 4.1.10 contienen una vulnerabilidad de cross-site scripting (XSS) almacenada en la lógica de saneamiento de SVG. El patrón de expresiones regulares utilizado para eliminar atributos de gestor de eventos (como onclick o onload) podría ser eludido utilizando una carga útil diseñada que explota cómo el patrón coincide con los límites de los atributos, permitiendo que archivos SVG maliciosos sean cargados a través del Gestor de Medios con JavaScript incrustado. La explotación podría conducir a una escalada de privilegios si un superusuario visualiza o incrusta el SVG malicioso, y requiere acceso autenticado al backend con permisos de carga de medios. El SVG debe ser visualizado o incrustado en una página para que la carga útil se active. Este problema ha sido solucionado en las versiones 3.7.14 y 4.1.10."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"octobercms","product":"october","versions":[{"version":"< 3.7.14","status":"affected"},{"version":">= 4.0.0, < 4.1.10","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"PASSIVE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-16T13:47:21.893252Z","id":"CVE-2026-25133","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*","versionEndIncluding":"3.7.13","matchCriteriaId":"A07FA7C9-BC27-4953-93C7-AB142B989CC2"},{"vulnerable":true,"criteria":"cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0.0","versionEndIncluding":"4.1.9","matchCriteriaId":"9C5346C3-F4C0-4DD0-AAAC-A12A7EB93C8F"}]}]}],"references":[{"url":"https://github.com/octobercms/october/security/advisories/GHSA-gcqv-f29m-67gr","source":"security-advisories@github.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27287","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T21:16:25.497","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."},{"lang":"es","value":"Versiones de InCopy 20.5.2, 21.2 y anteriores se ven afectadas por una vulnerabilidad de lectura fuera de límites al analizar un archivo manipulado, lo que podría resultar en una lectura más allá del final de una estructura de memoria asignada. Un atacante podría aprovechar esta vulnerabilidad para ejecutar código en el contexto del usuario actual. La explotación de este problema requiere interacción del usuario en el sentido de que una víctima debe abrir un archivo malicioso."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"InCopy","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"21.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T03:58:38.546802Z","id":"CVE-2026-27287","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-125"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:incopy:*:*:*:*:*:*:*:*","versionEndExcluding":"20.5.3","matchCriteriaId":"4E9AFDF0-6924-4DC2-8CDF-214C302F411A"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:incopy:*:*:*:*:*:*:*:*","versionStartIncluding":"21.0","versionEndExcluding":"21.3","matchCriteriaId":"8CA72C62-5102-46F5-AF3B-C715E5C3E0DF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/incopy/apsb26-33.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-15565","sourceIdentifier":"security@wordfence.com","published":"2026-04-14T22:16:27.727","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on the redirect function in all versions up to, and including, 8.3.0. This makes it possible for unauthenticated attackers to mark pending WooCommerce orders as paid/completed."},{"lang":"es","value":"El plugin Nexi XPay para WordPress es vulnerable a la modificación no autorizada de datos debido a la falta de comprobaciones de autorización en la función de redirección en todas las versiones hasta la 8.3.0, inclusive. Esto permite que atacantes no autenticados marquen pedidos pendientes de WooCommerce como pagados/completados."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"cartasi","product":"Nexi XPay","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"8.3.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T13:33:02.118762Z","id":"CVE-2025-15565","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/cartasi-x-pay/tags/8.2.0/src/classes/Nexi/WC_Gateway_XPay_Process_Completion.php#L268","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f420151b-c783-49b1-b0e9-e936a904278a?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-27282","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T22:16:29.257","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction."},{"lang":"es","value":"Las versiones de ColdFusion 2023.18, 2025.6 y anteriores están afectadas por una vulnerabilidad de validación de entrada incorrecta que podría resultar en una elusión de característica de seguridad. Un atacante podría aprovechar esta vulnerabilidad para eludir medidas de seguridad y obtener acceso no autorizado. La explotación de este problema requiere interacción del usuario."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"ColdFusion","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"2025.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T17:42:26.913808Z","id":"CVE-2026-27282","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:*","matchCriteriaId":"B02A37FE-5D31-4892-A3E6-156A8FE62D28"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:*","matchCriteriaId":"0AA3D302-CFEE-4DFD-AB92-F53C87721BFF"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update10:*:*:*:*:*:*","matchCriteriaId":"645D1B5F-2DAB-4AB8-A465-AC37FF494F95"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update11:*:*:*:*:*:*","matchCriteriaId":"ED6D8996-0770-4C9F-BEA5-87EA479D40A5"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update12:*:*:*:*:*:*","matchCriteriaId":"4836086E-3D4A-4A07-A372-382D385CB490"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update13:*:*:*:*:*:*","matchCriteriaId":"CBC19168-4184-4B59-B9C8-E98844124EED"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update14:*:*:*:*:*:*","matchCriteriaId":"A60DCD92-9A5B-411C-9554-642C91D77FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update15:*:*:*:*:*:*","matchCriteriaId":"58CC65EF-60A3-4DFA-AA51-E5013F116CEA"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update16:*:*:*:*:*:*","matchCriteriaId":"2E3EBFB1-4488-4924-A2E2-B7E422D68345"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update17:*:*:*:*:*:*","matchCriteriaId":"A683F9B2-A0DC-4AA0-BE97-9E74FA200AB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update18:*:*:*:*:*:*","matchCriteriaId":"8689F35F-9A81-45D2-B782-DBA12306BA45"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update2:*:*:*:*:*:*","matchCriteriaId":"EB88D4FE-5496-4639-BAF2-9F29F24ABF29"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update3:*:*:*:*:*:*","matchCriteriaId":"43E0ED98-2C1F-40B8-AF60-FEB1D85619C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update4:*:*:*:*:*:*","matchCriteriaId":"76204873-C6E0-4202-8A03-0773270F1802"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update5:*:*:*:*:*:*","matchCriteriaId":"C1A22BE9-0D47-4BA8-8BDB-9B12D7A0F7C7"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update6:*:*:*:*:*:*","matchCriteriaId":"E3A83642-BF14-4C37-BD94-FA76AABE8ADC"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update7:*:*:*:*:*:*","matchCriteriaId":"A892E1DC-F2C8-4F53-8580-A2D1BEED5A25"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update8:*:*:*:*:*:*","matchCriteriaId":"DB97ADBA-C1A9-4EE0-9509-68CB12358AE5"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update9:*:*:*:*:*:*","matchCriteriaId":"E17C38F0-9B0F-4433-9CBD-6E3D63EA9BDC"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:-:*:*:*:*:*:*","matchCriteriaId":"30779417-D4E5-4A01-BE0E-1CE1D134292A"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update1:*:*:*:*:*:*","matchCriteriaId":"80D7FC6A-F264-4CB1-A18D-B091EBA47882"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update2:*:*:*:*:*:*","matchCriteriaId":"E3DA0D20-93BA-4C76-A400-159853CD7277"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update3:*:*:*:*:*:*","matchCriteriaId":"5BAB6F21-61F1-43AB-88BA-553CD9AD6C0E"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update4:*:*:*:*:*:*","matchCriteriaId":"C85288B9-5D63-49EA-828A-8DB3BB2367F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update5:*:*:*:*:*:*","matchCriteriaId":"3882A011-5A01-48E7-B5E7-5A837B1CE245"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update6:*:*:*:*:*:*","matchCriteriaId":"AACCE621-3380-4144-BA1B-AA26FE96B902"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/coldfusion/apsb26-38.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27304","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T22:16:29.417","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction."},{"lang":"es","value":"Las versiones de ColdFusion 2023.18, 2025.6 y anteriores están afectadas por una vulnerabilidad de validación de entrada incorrecta que podría resultar en ejecución de código arbitrario en el contexto del usuario actual. La explotación de este problema no requiere interacción del usuario."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"ColdFusion","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"2025.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T03:58:52.310208Z","id":"CVE-2026-27304","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:*","matchCriteriaId":"B02A37FE-5D31-4892-A3E6-156A8FE62D28"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:*","matchCriteriaId":"0AA3D302-CFEE-4DFD-AB92-F53C87721BFF"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update10:*:*:*:*:*:*","matchCriteriaId":"645D1B5F-2DAB-4AB8-A465-AC37FF494F95"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update11:*:*:*:*:*:*","matchCriteriaId":"ED6D8996-0770-4C9F-BEA5-87EA479D40A5"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update12:*:*:*:*:*:*","matchCriteriaId":"4836086E-3D4A-4A07-A372-382D385CB490"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update13:*:*:*:*:*:*","matchCriteriaId":"CBC19168-4184-4B59-B9C8-E98844124EED"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update14:*:*:*:*:*:*","matchCriteriaId":"A60DCD92-9A5B-411C-9554-642C91D77FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update15:*:*:*:*:*:*","matchCriteriaId":"58CC65EF-60A3-4DFA-AA51-E5013F116CEA"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update16:*:*:*:*:*:*","matchCriteriaId":"2E3EBFB1-4488-4924-A2E2-B7E422D68345"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update17:*:*:*:*:*:*","matchCriteriaId":"A683F9B2-A0DC-4AA0-BE97-9E74FA200AB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update18:*:*:*:*:*:*","matchCriteriaId":"8689F35F-9A81-45D2-B782-DBA12306BA45"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update2:*:*:*:*:*:*","matchCriteriaId":"EB88D4FE-5496-4639-BAF2-9F29F24ABF29"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update3:*:*:*:*:*:*","matchCriteriaId":"43E0ED98-2C1F-40B8-AF60-FEB1D85619C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update4:*:*:*:*:*:*","matchCriteriaId":"76204873-C6E0-4202-8A03-0773270F1802"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update5:*:*:*:*:*:*","matchCriteriaId":"C1A22BE9-0D47-4BA8-8BDB-9B12D7A0F7C7"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update6:*:*:*:*:*:*","matchCriteriaId":"E3A83642-BF14-4C37-BD94-FA76AABE8ADC"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update7:*:*:*:*:*:*","matchCriteriaId":"A892E1DC-F2C8-4F53-8580-A2D1BEED5A25"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update8:*:*:*:*:*:*","matchCriteriaId":"DB97ADBA-C1A9-4EE0-9509-68CB12358AE5"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update9:*:*:*:*:*:*","matchCriteriaId":"E17C38F0-9B0F-4433-9CBD-6E3D63EA9BDC"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:-:*:*:*:*:*:*","matchCriteriaId":"30779417-D4E5-4A01-BE0E-1CE1D134292A"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update1:*:*:*:*:*:*","matchCriteriaId":"80D7FC6A-F264-4CB1-A18D-B091EBA47882"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update2:*:*:*:*:*:*","matchCriteriaId":"E3DA0D20-93BA-4C76-A400-159853CD7277"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update3:*:*:*:*:*:*","matchCriteriaId":"5BAB6F21-61F1-43AB-88BA-553CD9AD6C0E"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update4:*:*:*:*:*:*","matchCriteriaId":"C85288B9-5D63-49EA-828A-8DB3BB2367F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update5:*:*:*:*:*:*","matchCriteriaId":"3882A011-5A01-48E7-B5E7-5A837B1CE245"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update6:*:*:*:*:*:*","matchCriteriaId":"AACCE621-3380-4144-BA1B-AA26FE96B902"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/coldfusion/apsb26-38.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27305","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T22:16:29.573","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction."},{"lang":"es","value":"Las versiones 2023.18, 2025.6 y anteriores de ColdFusion están afectadas por una vulnerabilidad de limitación inadecuada de un nombre de ruta a un directorio restringido ('salto de ruta') que podría conducir a la lectura arbitraria del sistema de archivos. Un atacante podría explotar esta vulnerabilidad para acceder a archivos y directorios sensibles fuera del ámbito de acceso previsto. La explotación de este problema no requiere interacción del usuario."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"ColdFusion","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"2025.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-16T13:09:44.090428Z","id":"CVE-2026-27305","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:*","matchCriteriaId":"B02A37FE-5D31-4892-A3E6-156A8FE62D28"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:*","matchCriteriaId":"0AA3D302-CFEE-4DFD-AB92-F53C87721BFF"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update10:*:*:*:*:*:*","matchCriteriaId":"645D1B5F-2DAB-4AB8-A465-AC37FF494F95"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update11:*:*:*:*:*:*","matchCriteriaId":"ED6D8996-0770-4C9F-BEA5-87EA479D40A5"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update12:*:*:*:*:*:*","matchCriteriaId":"4836086E-3D4A-4A07-A372-382D385CB490"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update13:*:*:*:*:*:*","matchCriteriaId":"CBC19168-4184-4B59-B9C8-E98844124EED"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update14:*:*:*:*:*:*","matchCriteriaId":"A60DCD92-9A5B-411C-9554-642C91D77FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update15:*:*:*:*:*:*","matchCriteriaId":"58CC65EF-60A3-4DFA-AA51-E5013F116CEA"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update16:*:*:*:*:*:*","matchCriteriaId":"2E3EBFB1-4488-4924-A2E2-B7E422D68345"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update17:*:*:*:*:*:*","matchCriteriaId":"A683F9B2-A0DC-4AA0-BE97-9E74FA200AB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update18:*:*:*:*:*:*","matchCriteriaId":"8689F35F-9A81-45D2-B782-DBA12306BA45"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update2:*:*:*:*:*:*","matchCriteriaId":"EB88D4FE-5496-4639-BAF2-9F29F24ABF29"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update3:*:*:*:*:*:*","matchCriteriaId":"43E0ED98-2C1F-40B8-AF60-FEB1D85619C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update4:*:*:*:*:*:*","matchCriteriaId":"76204873-C6E0-4202-8A03-0773270F1802"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update5:*:*:*:*:*:*","matchCriteriaId":"C1A22BE9-0D47-4BA8-8BDB-9B12D7A0F7C7"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update6:*:*:*:*:*:*","matchCriteriaId":"E3A83642-BF14-4C37-BD94-FA76AABE8ADC"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update7:*:*:*:*:*:*","matchCriteriaId":"A892E1DC-F2C8-4F53-8580-A2D1BEED5A25"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update8:*:*:*:*:*:*","matchCriteriaId":"DB97ADBA-C1A9-4EE0-9509-68CB12358AE5"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update9:*:*:*:*:*:*","matchCriteriaId":"E17C38F0-9B0F-4433-9CBD-6E3D63EA9BDC"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:-:*:*:*:*:*:*","matchCriteriaId":"30779417-D4E5-4A01-BE0E-1CE1D134292A"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update1:*:*:*:*:*:*","matchCriteriaId":"80D7FC6A-F264-4CB1-A18D-B091EBA47882"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update2:*:*:*:*:*:*","matchCriteriaId":"E3DA0D20-93BA-4C76-A400-159853CD7277"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update3:*:*:*:*:*:*","matchCriteriaId":"5BAB6F21-61F1-43AB-88BA-553CD9AD6C0E"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update4:*:*:*:*:*:*","matchCriteriaId":"C85288B9-5D63-49EA-828A-8DB3BB2367F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update5:*:*:*:*:*:*","matchCriteriaId":"3882A011-5A01-48E7-B5E7-5A837B1CE245"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update6:*:*:*:*:*:*","matchCriteriaId":"AACCE621-3380-4144-BA1B-AA26FE96B902"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/coldfusion/apsb26-38.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27306","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T22:16:29.730","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Attacker requires elevated privileges. Exploitation of this issue requires user interaction in that a victim must open a malicious file."},{"lang":"es","value":"Las versiones de ColdFusion 2023.18, 2025.6 y anteriores están afectadas por una vulnerabilidad de validación de entrada incorrecta que podría resultar en ejecución de código arbitrario en el contexto del usuario actual. El atacante requiere privilegios elevados. La explotación de este problema requiere interacción del usuario en el sentido de que una víctima debe abrir un archivo malicioso."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"ColdFusion","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"2025.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.7,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T03:58:53.413381Z","id":"CVE-2026-27306","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:*","matchCriteriaId":"B02A37FE-5D31-4892-A3E6-156A8FE62D28"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:*","matchCriteriaId":"0AA3D302-CFEE-4DFD-AB92-F53C87721BFF"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update10:*:*:*:*:*:*","matchCriteriaId":"645D1B5F-2DAB-4AB8-A465-AC37FF494F95"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update11:*:*:*:*:*:*","matchCriteriaId":"ED6D8996-0770-4C9F-BEA5-87EA479D40A5"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update12:*:*:*:*:*:*","matchCriteriaId":"4836086E-3D4A-4A07-A372-382D385CB490"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update13:*:*:*:*:*:*","matchCriteriaId":"CBC19168-4184-4B59-B9C8-E98844124EED"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update14:*:*:*:*:*:*","matchCriteriaId":"A60DCD92-9A5B-411C-9554-642C91D77FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update15:*:*:*:*:*:*","matchCriteriaId":"58CC65EF-60A3-4DFA-AA51-E5013F116CEA"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update16:*:*:*:*:*:*","matchCriteriaId":"2E3EBFB1-4488-4924-A2E2-B7E422D68345"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update17:*:*:*:*:*:*","matchCriteriaId":"A683F9B2-A0DC-4AA0-BE97-9E74FA200AB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update18:*:*:*:*:*:*","matchCriteriaId":"8689F35F-9A81-45D2-B782-DBA12306BA45"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update2:*:*:*:*:*:*","matchCriteriaId":"EB88D4FE-5496-4639-BAF2-9F29F24ABF29"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update3:*:*:*:*:*:*","matchCriteriaId":"43E0ED98-2C1F-40B8-AF60-FEB1D85619C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update4:*:*:*:*:*:*","matchCriteriaId":"76204873-C6E0-4202-8A03-0773270F1802"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update5:*:*:*:*:*:*","matchCriteriaId":"C1A22BE9-0D47-4BA8-8BDB-9B12D7A0F7C7"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update6:*:*:*:*:*:*","matchCriteriaId":"E3A83642-BF14-4C37-BD94-FA76AABE8ADC"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update7:*:*:*:*:*:*","matchCriteriaId":"A892E1DC-F2C8-4F53-8580-A2D1BEED5A25"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update8:*:*:*:*:*:*","matchCriteriaId":"DB97ADBA-C1A9-4EE0-9509-68CB12358AE5"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update9:*:*:*:*:*:*","matchCriteriaId":"E17C38F0-9B0F-4433-9CBD-6E3D63EA9BDC"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:-:*:*:*:*:*:*","matchCriteriaId":"30779417-D4E5-4A01-BE0E-1CE1D134292A"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update1:*:*:*:*:*:*","matchCriteriaId":"80D7FC6A-F264-4CB1-A18D-B091EBA47882"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update2:*:*:*:*:*:*","matchCriteriaId":"E3DA0D20-93BA-4C76-A400-159853CD7277"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update3:*:*:*:*:*:*","matchCriteriaId":"5BAB6F21-61F1-43AB-88BA-553CD9AD6C0E"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update4:*:*:*:*:*:*","matchCriteriaId":"C85288B9-5D63-49EA-828A-8DB3BB2367F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update5:*:*:*:*:*:*","matchCriteriaId":"3882A011-5A01-48E7-B5E7-5A837B1CE245"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update6:*:*:*:*:*:*","matchCriteriaId":"AACCE621-3380-4144-BA1B-AA26FE96B902"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/coldfusion/apsb26-38.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27307","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T22:16:29.890","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust system resources, reducing application speed. Exploitation of this issue does not require user interaction."},{"lang":"es","value":"Las versiones 2023.18, 2025.6 y anteriores de ColdFusion están afectadas por una vulnerabilidad de Consumo de Recursos No Controlado que podría conducir a una denegación de servicio de la aplicación. Un atacante con altos privilegios podría explotar esta vulnerabilidad y agotar los recursos del sistema, reduciendo la velocidad de la aplicación. La explotación de este problema no requiere interacción del usuario."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"ColdFusion","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"2025.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L","baseScore":2.4,"baseSeverity":"LOW","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":0.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T17:32:55.630208Z","id":"CVE-2026-27307","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:*","matchCriteriaId":"B02A37FE-5D31-4892-A3E6-156A8FE62D28"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:*","matchCriteriaId":"0AA3D302-CFEE-4DFD-AB92-F53C87721BFF"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update10:*:*:*:*:*:*","matchCriteriaId":"645D1B5F-2DAB-4AB8-A465-AC37FF494F95"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update11:*:*:*:*:*:*","matchCriteriaId":"ED6D8996-0770-4C9F-BEA5-87EA479D40A5"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update12:*:*:*:*:*:*","matchCriteriaId":"4836086E-3D4A-4A07-A372-382D385CB490"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update13:*:*:*:*:*:*","matchCriteriaId":"CBC19168-4184-4B59-B9C8-E98844124EED"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update14:*:*:*:*:*:*","matchCriteriaId":"A60DCD92-9A5B-411C-9554-642C91D77FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update15:*:*:*:*:*:*","matchCriteriaId":"58CC65EF-60A3-4DFA-AA51-E5013F116CEA"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update16:*:*:*:*:*:*","matchCriteriaId":"2E3EBFB1-4488-4924-A2E2-B7E422D68345"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update17:*:*:*:*:*:*","matchCriteriaId":"A683F9B2-A0DC-4AA0-BE97-9E74FA200AB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update18:*:*:*:*:*:*","matchCriteriaId":"8689F35F-9A81-45D2-B782-DBA12306BA45"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update2:*:*:*:*:*:*","matchCriteriaId":"EB88D4FE-5496-4639-BAF2-9F29F24ABF29"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update3:*:*:*:*:*:*","matchCriteriaId":"43E0ED98-2C1F-40B8-AF60-FEB1D85619C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update4:*:*:*:*:*:*","matchCriteriaId":"76204873-C6E0-4202-8A03-0773270F1802"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update5:*:*:*:*:*:*","matchCriteriaId":"C1A22BE9-0D47-4BA8-8BDB-9B12D7A0F7C7"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update6:*:*:*:*:*:*","matchCriteriaId":"E3A83642-BF14-4C37-BD94-FA76AABE8ADC"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update7:*:*:*:*:*:*","matchCriteriaId":"A892E1DC-F2C8-4F53-8580-A2D1BEED5A25"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update8:*:*:*:*:*:*","matchCriteriaId":"DB97ADBA-C1A9-4EE0-9509-68CB12358AE5"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update9:*:*:*:*:*:*","matchCriteriaId":"E17C38F0-9B0F-4433-9CBD-6E3D63EA9BDC"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:-:*:*:*:*:*:*","matchCriteriaId":"30779417-D4E5-4A01-BE0E-1CE1D134292A"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update1:*:*:*:*:*:*","matchCriteriaId":"80D7FC6A-F264-4CB1-A18D-B091EBA47882"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update2:*:*:*:*:*:*","matchCriteriaId":"E3DA0D20-93BA-4C76-A400-159853CD7277"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update3:*:*:*:*:*:*","matchCriteriaId":"5BAB6F21-61F1-43AB-88BA-553CD9AD6C0E"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update4:*:*:*:*:*:*","matchCriteriaId":"C85288B9-5D63-49EA-828A-8DB3BB2367F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update5:*:*:*:*:*:*","matchCriteriaId":"3882A011-5A01-48E7-B5E7-5A837B1CE245"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update6:*:*:*:*:*:*","matchCriteriaId":"AACCE621-3380-4144-BA1B-AA26FE96B902"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/coldfusion/apsb26-38.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27308","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T22:16:30.050","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust system resources, reducing application speed. Exploitation of this issue does not require user interaction."},{"lang":"es","value":"Las versiones 2023.18, 2025.6 y anteriores de ColdFusion están afectadas por una vulnerabilidad de Consumo de Recursos No Controlado que podría conducir a una denegación de servicio de la aplicación. Un atacante con altos privilegios podría explotar esta vulnerabilidad y agotar los recursos del sistema, reduciendo la velocidad de la aplicación. La explotación de este problema no requiere interacción del usuario."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"ColdFusion","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"2025.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L","baseScore":2.4,"baseSeverity":"LOW","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":0.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T17:31:31.105261Z","id":"CVE-2026-27308","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:*","matchCriteriaId":"B02A37FE-5D31-4892-A3E6-156A8FE62D28"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:*","matchCriteriaId":"0AA3D302-CFEE-4DFD-AB92-F53C87721BFF"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update10:*:*:*:*:*:*","matchCriteriaId":"645D1B5F-2DAB-4AB8-A465-AC37FF494F95"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update11:*:*:*:*:*:*","matchCriteriaId":"ED6D8996-0770-4C9F-BEA5-87EA479D40A5"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update12:*:*:*:*:*:*","matchCriteriaId":"4836086E-3D4A-4A07-A372-382D385CB490"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update13:*:*:*:*:*:*","matchCriteriaId":"CBC19168-4184-4B59-B9C8-E98844124EED"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update14:*:*:*:*:*:*","matchCriteriaId":"A60DCD92-9A5B-411C-9554-642C91D77FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update15:*:*:*:*:*:*","matchCriteriaId":"58CC65EF-60A3-4DFA-AA51-E5013F116CEA"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update16:*:*:*:*:*:*","matchCriteriaId":"2E3EBFB1-4488-4924-A2E2-B7E422D68345"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update17:*:*:*:*:*:*","matchCriteriaId":"A683F9B2-A0DC-4AA0-BE97-9E74FA200AB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update18:*:*:*:*:*:*","matchCriteriaId":"8689F35F-9A81-45D2-B782-DBA12306BA45"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update2:*:*:*:*:*:*","matchCriteriaId":"EB88D4FE-5496-4639-BAF2-9F29F24ABF29"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update3:*:*:*:*:*:*","matchCriteriaId":"43E0ED98-2C1F-40B8-AF60-FEB1D85619C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update4:*:*:*:*:*:*","matchCriteriaId":"76204873-C6E0-4202-8A03-0773270F1802"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update5:*:*:*:*:*:*","matchCriteriaId":"C1A22BE9-0D47-4BA8-8BDB-9B12D7A0F7C7"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update6:*:*:*:*:*:*","matchCriteriaId":"E3A83642-BF14-4C37-BD94-FA76AABE8ADC"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update7:*:*:*:*:*:*","matchCriteriaId":"A892E1DC-F2C8-4F53-8580-A2D1BEED5A25"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update8:*:*:*:*:*:*","matchCriteriaId":"DB97ADBA-C1A9-4EE0-9509-68CB12358AE5"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2023:update9:*:*:*:*:*:*","matchCriteriaId":"E17C38F0-9B0F-4433-9CBD-6E3D63EA9BDC"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:-:*:*:*:*:*:*","matchCriteriaId":"30779417-D4E5-4A01-BE0E-1CE1D134292A"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update1:*:*:*:*:*:*","matchCriteriaId":"80D7FC6A-F264-4CB1-A18D-B091EBA47882"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update2:*:*:*:*:*:*","matchCriteriaId":"E3DA0D20-93BA-4C76-A400-159853CD7277"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update3:*:*:*:*:*:*","matchCriteriaId":"5BAB6F21-61F1-43AB-88BA-553CD9AD6C0E"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update4:*:*:*:*:*:*","matchCriteriaId":"C85288B9-5D63-49EA-828A-8DB3BB2367F6"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update5:*:*:*:*:*:*","matchCriteriaId":"3882A011-5A01-48E7-B5E7-5A837B1CE245"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:2025:update6:*:*:*:*:*:*","matchCriteriaId":"AACCE621-3380-4144-BA1B-AA26FE96B902"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/coldfusion/apsb26-38.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-33018","sourceIdentifier":"security-advisories@github.com","published":"2026-04-14T22:16:30.213","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a Use-After-Free vulnerability via the load_gif() function in fromgif.c, where a single sixel_frame_t object is reused across all frames of an animated GIF and gif_init_frame() unconditionally frees and reallocates frame->pixels between frames without consulting the object's reference count. Because the public API explicitly provides sixel_frame_ref() to retain a frame and sixel_frame_get_pixels() to access the raw pixel buffer, a callback following this documented usage pattern will hold a dangling pointer after the second frame is decoded, resulting in a heap use-after-free confirmed by ASAN. Any application using sixel_helper_load_image_file() with a multi-frame callback to process user-supplied animated GIFs is affected, with a reliable crash as the minimum impact and potential for code execution. This issue has been fixed in version 1.8.7-r1."},{"lang":"es","value":"libsixel es una implementación de codificador/decodificador SIXEL derivada de sixel de kmiya. Las versiones 1.8.7 y anteriores contienen una vulnerabilidad de uso después de liberación a través de la función load_gif() en fromgif.c, donde un único objeto sixel_frame_t se reutiliza en todos los fotogramas de un GIF animado y gif_init_frame() libera y reasigna incondicionalmente frame -> pixels entre fotogramas sin consultar el contador de referencias del objeto. Debido a que la API pública proporciona explícitamente sixel_frame_ref() para retener un fotograma y sixel_frame_get_pixels() para acceder al búfer de píxeles sin procesar, una devolución de llamada que siga este patrón de uso documentado mantendrá un puntero colgante después de que se decodifique el segundo fotograma, lo que resultará en un uso después de liberación en el heap confirmado por ASAN. Cualquier aplicación que utilice sixel_helper_load_image_file() con una devolución de llamada multifotograma para procesar GIFs animados proporcionados por el usuario se ve afectada, con un bloqueo fiable como el impacto mínimo y potencial de ejecución de código. Este problema ha sido solucionado en la versión 1.8.7-r1."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"saitoha","product":"libsixel","versions":[{"version":"< 1.8.7-rc1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.0,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.0,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-16T13:52:34.921283Z","id":"CVE-2026-33018","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-416"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:saitoha:libsixel:*:*:*:*:*:*:*:*","versionEndExcluding":"1.8.7-r1","matchCriteriaId":"E16EAA6A-544F-4D16-829D-1B7C9979EA6A"}]}]}],"references":[{"url":"https://github.com/saitoha/libsixel/releases/tag/v1.8.7-r1","source":"security-advisories@github.com","tags":["Release Notes"]},{"url":"https://github.com/saitoha/libsixel/security/advisories/GHSA-w46f-jr9f-rgvp","source":"security-advisories@github.com","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-33019","sourceIdentifier":"security-advisories@github.com","published":"2026-04-14T22:16:30.380","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow leading to an out-of-bounds heap read in the --crop option handling of img2sixel, where positive coordinates up to INT_MAX are accepted without overflow-safe bounds checking. In sixel_encoder_do_clip(), the expression clip_w + clip_x overflows to a large negative value when clip_x is INT_MAX, causing the bounds guard to be skipped entirely, and the unclamped coordinate is passed through sixel_frame_clip() to clip(), which computes a source pointer far beyond the image buffer and passes it to memmove(). An attacker supplying a specially crafted crop argument with any valid image can trigger an out-of-bounds read in the heap, resulting in a reliable crash and potential information disclosure. This issue has been fixed in version 1.8.7-r1."},{"lang":"es","value":"libsixel es una implementación de codificador/decodificador SIXEL derivada de sixel de kmiya. Las versiones 1.8.7 y anteriores contienen un desbordamiento de entero que conduce a una lectura fuera de límites en el heap en el manejo de la opción '--crop' de img2sixel, donde se aceptan coordenadas positivas hasta INT_MAX sin verificación de límites segura contra desbordamientos. En sixel_encoder_do_clip(), la expresión clip_w + clip_x desborda a un valor negativo grande cuando clip_x es INT_MAX, haciendo que la protección de límites se omita por completo, y la coordenada no restringida se pasa a través de sixel_frame_clip() a clip(), que calcula un puntero de origen mucho más allá del búfer de imagen y lo pasa a memmove(). Un atacante que proporciona un argumento de recorte ('crop') especialmente diseñado con cualquier imagen válida puede desencadenar una lectura fuera de límites en el heap, lo que resulta en un fallo ('crash') fiable y una potencial revelación de información. Este problema ha sido solucionado en la versión 1.8.7-r1."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"saitoha","product":"libsixel","versions":[{"version":"< 1.8.7-r1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T18:54:19.432280Z","id":"CVE-2026-33019","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-125"},{"lang":"en","value":"CWE-190"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:saitoha:libsixel:*:*:*:*:*:*:*:*","versionEndExcluding":"1.8.7-r1","matchCriteriaId":"E16EAA6A-544F-4D16-829D-1B7C9979EA6A"}]}]}],"references":[{"url":"https://github.com/saitoha/libsixel/releases/tag/v1.8.7-r1","source":"security-advisories@github.com","tags":["Release Notes"]},{"url":"https://github.com/saitoha/libsixel/security/advisories/GHSA-c854-ffg9-g72c","source":"security-advisories@github.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://github.com/saitoha/libsixel/security/advisories/GHSA-c854-ffg9-g72c","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-33020","sourceIdentifier":"security-advisories@github.com","published":"2026-04-14T22:16:30.543","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow which leads to a heap buffer overflow via sixel_frame_convert_to_rgb888() in frame.c, where allocation size and pointer offset computations for palettised images (PAL1, PAL2, PAL4) are performed using int arithmetic before casting to size_t. For images whose pixel count exceeds INT_MAX / 4, the overflow produces an undersized heap allocation for the conversion buffer and a negative pointer offset for the normalization sub-buffer, after which sixel_helper_normalize_pixelformat() writes the full image data starting from the invalid pointer, causing massive heap corruption confirmed by ASAN. An attacker providing a specially crafted large palettised PNG can corrupt the heap of the victim process, resulting in a reliable crash and potential arbitrary code execution.\nThis issue has been fixed in version 1.8.7-r1."},{"lang":"es","value":"libsixel es una implementación de codificador/decodificador SIXEL derivada de sixel de kmiya. Las versiones 1.8.7 y anteriores contienen un desbordamiento de entero que conduce a un desbordamiento de búfer de montón a través de sixel_frame_convert_to_rgb888() en frame.c, donde los cálculos de tamaño de asignación y desplazamiento de puntero para imágenes paletizadas (PAL1, PAL2, PAL4) se realizan utilizando aritmética de enteros antes de la conversión a size_t. Para imágenes cuyo recuento de píxeles excede INT_MAX / 4, el desbordamiento produce una asignación de montón de tamaño insuficiente para el búfer de conversión y un desplazamiento de puntero negativo para el sub-búfer de normalización, después de lo cual sixel_helper_normalize_pixelformat() escribe los datos completos de la imagen comenzando desde el puntero inválido, causando una corrupción masiva del montón confirmada por ASAN. Un atacante que proporciona un PNG paletizado grande especialmente diseñado puede corromper el montón del proceso víctima, lo que resulta en un fallo fiable y una potencial ejecución de código arbitrario. Este problema ha sido solucionado en la versión 1.8.7-r1."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"saitoha","product":"libsixel","versions":[{"version":"< 1.8.7-r1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T13:30:43.489988Z","id":"CVE-2026-33020","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-122"},{"lang":"en","value":"CWE-190"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:saitoha:libsixel:*:*:*:*:*:*:*:*","versionEndExcluding":"1.8.7-r1","matchCriteriaId":"E16EAA6A-544F-4D16-829D-1B7C9979EA6A"}]}]}],"references":[{"url":"https://github.com/saitoha/libsixel/releases/tag/v1.8.7-r1","source":"security-advisories@github.com","tags":["Release Notes"]},{"url":"https://github.com/saitoha/libsixel/security/advisories/GHSA-2xgm-4x47-2x2p","source":"security-advisories@github.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://github.com/saitoha/libsixel/security/advisories/GHSA-2xgm-4x47-2x2p","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27290","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T23:16:25.813","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a search path to locate critical resources such as programs, then an attacker could modify that search path to point to a malicious program, which the targeted application would then execute. Exploitation of this issue does not require user interaction."},{"lang":"es","value":"Las versiones 2022.8 y anteriores de Adobe Framemaker están afectadas por una vulnerabilidad de ruta de búsqueda no confiable que podría permitir a los atacantes ejecutar código arbitrario en el contexto del usuario actual. Si la aplicación utiliza una ruta de búsqueda para localizar recursos críticos como programas, entonces un atacante podría modificar esa ruta de búsqueda para que apunte a un programa malicioso, que la aplicación objetivo ejecutaría entonces. La explotación de este problema no requiere interacción del usuario."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"Adobe Framemaker","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"2022.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T03:58:54.751602Z","id":"CVE-2026-27290","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-426"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:*","versionEndExcluding":"2022.9","matchCriteriaId":"6943B816-3A7D-47BF-9E01-DF86C9332C19"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/framemaker/apsb26-36.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27292","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T23:16:25.993","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Adobe Framemaker versions 2022.8 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."},{"lang":"es","value":"Las versiones 2022.8 y anteriores de Adobe Framemaker están afectadas por una vulnerabilidad de Use After Free que podría resultar en ejecución de código arbitrario en el contexto del usuario actual. La explotación de este problema requiere interacción del usuario, ya que la víctima debe abrir un archivo malicioso."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"Adobe Framemaker","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"2022.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T03:58:55.879040Z","id":"CVE-2026-27292","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-416"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:*","versionEndExcluding":"2022.9","matchCriteriaId":"6943B816-3A7D-47BF-9E01-DF86C9332C19"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/framemaker/apsb26-36.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27293","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T23:16:26.150","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."},{"lang":"es","value":"Las versiones 2022.8 y anteriores de Adobe Framemaker están afectadas por una vulnerabilidad de desbordamiento de búfer basado en montículo que podría resultar en ejecución de código arbitrario en el contexto del usuario actual. La explotación de este problema requiere interacción del usuario en el sentido de que una víctima debe abrir un archivo malicioso."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"Adobe Framemaker","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"2022.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T03:58:57.091863Z","id":"CVE-2026-27293","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-122"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:*","versionEndExcluding":"2022.9","matchCriteriaId":"6943B816-3A7D-47BF-9E01-DF86C9332C19"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/framemaker/apsb26-36.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27294","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T23:16:26.303","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."},{"lang":"es","value":"Las versiones 2022.8 y anteriores de Adobe Framemaker están afectadas por una vulnerabilidad de lectura fuera de límites al analizar un archivo manipulado, lo que podría resultar en una lectura más allá del final de una estructura de memoria asignada. Un atacante podría aprovechar esta vulnerabilidad para ejecutar código en el contexto del usuario actual. La explotación de este problema requiere interacción del usuario en que una víctima debe abrir un archivo malicioso."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"Adobe Framemaker","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"2022.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T03:58:58.344227Z","id":"CVE-2026-27294","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-125"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:*","versionEndExcluding":"2022.9","matchCriteriaId":"6943B816-3A7D-47BF-9E01-DF86C9332C19"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/framemaker/apsb26-36.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27295","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T23:16:26.460","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."},{"lang":"es","value":"Las versiones 2022.8 y anteriores de Adobe Framemaker están afectadas por una vulnerabilidad de escritura fuera de límites que podría resultar en ejecución de código arbitrario en el contexto del usuario actual. La explotación de este problema requiere interacción del usuario en el sentido de que una víctima debe abrir un archivo malicioso."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"Adobe Framemaker","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"2022.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T03:58:59.441654Z","id":"CVE-2026-27295","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-787"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:*","versionEndExcluding":"2022.9","matchCriteriaId":"6943B816-3A7D-47BF-9E01-DF86C9332C19"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/framemaker/apsb26-36.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27296","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T23:16:26.617","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."},{"lang":"es","value":"Las versiones 2022.8 y anteriores de Adobe Framemaker están afectadas por una vulnerabilidad de desbordamiento negativo de enteros (wrap o wraparound) que podría resultar en ejecución de código arbitrario en el contexto del usuario actual. La explotación de este problema requiere interacción del usuario en el sentido de que la víctima debe abrir un archivo malicioso."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"Adobe Framemaker","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"2022.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T03:59:00.770421Z","id":"CVE-2026-27296","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-191"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:*","versionEndExcluding":"2022.9","matchCriteriaId":"6943B816-3A7D-47BF-9E01-DF86C9332C19"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/framemaker/apsb26-36.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27297","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T23:16:26.770","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."},{"lang":"es","value":"Las versiones 2022.8 y anteriores de Adobe Framemaker están afectadas por una vulnerabilidad de desbordamiento inferior de enteros (wrap o wraparound) que podría resultar en ejecución de código arbitrario en el contexto del usuario actual. La explotación de este problema requiere interacción del usuario en que una víctima debe abrir un archivo malicioso."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"Adobe Framemaker","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"2022.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T03:59:03.373224Z","id":"CVE-2026-27297","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-191"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:*","versionEndExcluding":"2022.9","matchCriteriaId":"6943B816-3A7D-47BF-9E01-DF86C9332C19"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/framemaker/apsb26-36.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27298","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T23:16:26.930","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."},{"lang":"es","value":"Las versiones 2022.8 y anteriores de Adobe Framemaker están afectadas por una vulnerabilidad de 'Acceso a recursos usando tipo incompatible' ('Type Confusion') que podría resultar en ejecución de código arbitrario en el contexto del usuario actual. La explotación de este problema requiere interacción del usuario, ya que una víctima debe abrir un archivo malicioso."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"Adobe Framemaker","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"2022.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T03:59:04.718731Z","id":"CVE-2026-27298","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-843"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:*","versionEndExcluding":"2022.9","matchCriteriaId":"6943B816-3A7D-47BF-9E01-DF86C9332C19"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/framemaker/apsb26-36.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27299","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T23:16:27.083","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could leverage this vulnerability to access sensitive files or data on the system. Exploitation of this issue requires user interaction in that a victim must open a malicious file."},{"lang":"es","value":"Las versiones 2022.8 y anteriores de Adobe Framemaker se ven afectadas por una vulnerabilidad de validación de entrada incorrecta que podría conducir a la lectura arbitraria del sistema de archivos. Un atacante podría aprovechar esta vulnerabilidad para acceder a archivos o datos sensibles en el sistema. La explotación de este problema requiere interacción del usuario, en el sentido de que la víctima debe abrir un archivo malicioso."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"Adobe Framemaker","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"2022.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":4.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T13:28:05.897312Z","id":"CVE-2026-27299","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:*","versionEndExcluding":"2022.9","matchCriteriaId":"6943B816-3A7D-47BF-9E01-DF86C9332C19"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/framemaker/apsb26-36.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27300","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T23:16:27.240","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file."},{"lang":"es","value":"Adobe Framemaker versiones 2022.8 y anteriores están afectadas por una vulnerabilidad de Acceso a Puntero No Inicializado que podría conducir a la exposición de memoria. Un atacante podría aprovechar esta vulnerabilidad para divulgar información sensible. La explotación de este problema requiere interacción del usuario en el sentido de que una víctima debe abrir un archivo malicioso."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"Adobe Framemaker","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"2022.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T17:28:59.012073Z","id":"CVE-2026-27300","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-824"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:*","versionEndExcluding":"2022.9","matchCriteriaId":"6943B816-3A7D-47BF-9E01-DF86C9332C19"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/framemaker/apsb26-36.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27301","sourceIdentifier":"psirt@adobe.com","published":"2026-04-14T23:16:27.397","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file."},{"lang":"es","value":"Las versiones 2022.8 y anteriores de Adobe Framemaker están afectadas por una vulnerabilidad de desbordamiento de búfer basado en montículo que podría conducir a la exposición de memoria. Un atacante podría aprovechar esta vulnerabilidad para divulgar información sensible almacenada en la memoria. La explotación de este problema requiere interacción del usuario en el sentido de que la víctima debe abrir un archivo malicioso."}],"affected":[{"source":"psirt@adobe.com","affectedData":[{"vendor":"Adobe","product":"Adobe Framemaker","defaultStatus":"affected","versions":[{"version":"0","lessThanOrEqual":"2022.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@adobe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T17:29:48.371098Z","id":"CVE-2026-27301","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@adobe.com","type":"Secondary","description":[{"lang":"en","value":"CWE-122"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:*","versionEndExcluding":"2022.9","matchCriteriaId":"6943B816-3A7D-47BF-9E01-DF86C9332C19"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://helpx.adobe.com/security/products/framemaker/apsb26-36.html","source":"psirt@adobe.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-33021","sourceIdentifier":"security-advisories@github.com","published":"2026-04-14T23:16:27.660","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a use-after-free vulnerability in sixel_encoder_encode_bytes() because sixel_frame_init() stores the caller-owned pixel buffer pointer directly in frame->pixels without making a defensive copy. When a resize operation is triggered, sixel_frame_convert_to_rgb888() unconditionally frees this caller-owned buffer and replaces it with a new internal allocation, leaving the caller with a dangling pointer. Any subsequent access to the original buffer by the caller constitutes a use-after-free, confirmed by AddressSanitizer. An attacker who controls incoming frames can trigger this bug repeatedly and predictably, resulting in a reliable crash with potential for code execution. This issue has been fixed in version 1.8.7-r1."},{"lang":"es","value":"libsixel es una implementación de codificador/decodificador SIXEL derivada de sixel de kmiya. Las versiones 1.8.7 y anteriores contienen una vulnerabilidad de uso después de liberación en sixel_encoder_encode_bytes() porque sixel_frame_init() almacena el puntero del búfer de píxeles propiedad del llamador directamente en frame  ->  pixels sin hacer una copia defensiva. Cuando se activa una operación de redimensionamiento, sixel_frame_convert_to_rgb888() libera incondicionalmente este búfer propiedad del llamador y lo reemplaza con una nueva asignación interna, dejando al llamador con un puntero colgante. Cualquier acceso posterior al búfer original por parte del llamador constituye un uso después de liberación, confirmado por AddressSanitizer. Un atacante que controla los fotogramas entrantes puede activar este error de forma repetida y predecible, lo que resulta en un fallo fiable con potencial para la ejecución de código. Este problema ha sido solucionado en la versión 1.8.7-r1."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"saitoha","product":"libsixel","versions":[{"version":"< 1.8.7-r1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":4.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-16T13:54:16.495174Z","id":"CVE-2026-33021","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-416"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:saitoha:libsixel:*:*:*:*:*:*:*:*","versionEndExcluding":"1.8.7-r1","matchCriteriaId":"E16EAA6A-544F-4D16-829D-1B7C9979EA6A"}]}]}],"references":[{"url":"https://github.com/saitoha/libsixel/releases/tag/v1.8.7-r1","source":"security-advisories@github.com","tags":["Release Notes"]},{"url":"https://github.com/saitoha/libsixel/security/advisories/GHSA-j6m5-2cc7-3whc","source":"security-advisories@github.com","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-33023","sourceIdentifier":"security-advisories@github.com","published":"2026-04-14T23:16:27.820","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and prior, when built with the --with-gdk-pixbuf2 option, a use-after-free vulnerability exists in load_with_gdkpixbuf() in loader.c. The cleanup path manually frees the sixel_frame_t object and its internal buffers without consulting the reference count, even though the object was created via the refcounted constructor sixel_frame_new() and exposed to the public callback. A callback that calls sixel_frame_ref(frame) to retain a logically valid reference will hold a dangling pointer after sixel_helper_load_image_file() returns, and any subsequent access to the frame or its fields triggers a use-after-free confirmed by AddressSanitizer. The root cause is a consistency failure between two cleanup strategies in the same codebase: sixel_frame_unref() is used in load_with_builtin() but raw free() is used in load_with_gdkpixbuf(). An attacker supplying a crafted image to any application built against libsixel with gdk-pixbuf2 support can trigger this reliably, potentially leading to information disclosure, memory corruption, or code execution. This issue has been fixed in version 1.8.7-r1."},{"lang":"es","value":"libsixel es una implementación de codificador/decodificador SIXEL derivada del sixel de kmiya. En las versiones 1.8.7 y anteriores, cuando se compila con la opción --with-gdk-pixbuf2, existe una vulnerabilidad de uso después de liberación en load_with_gdkpixbuf() en loader.c. La ruta de limpieza libera manualmente el objeto sixel_frame_t y sus búferes internos sin consultar el recuento de referencias, a pesar de que el objeto fue creado a través del constructor con recuento de referencias sixel_frame_new() y expuesto a la devolución de llamada pública. Una devolución de llamada que llama a sixel_frame_ref(frame) para retener una referencia lógicamente válida mantendrá un puntero colgante después de que sixel_helper_load_image_file() regrese, y cualquier acceso posterior al marco o sus campos activa un uso después de liberación confirmado por AddressSanitizer. La causa raíz es una falla de consistencia entre dos estrategias de limpieza en la misma base de código: sixel_frame_unref() se usa en load_with_builtin() pero free() sin procesar se usa en load_with_gdkpixbuf(). Un atacante que suministre una imagen manipulada a cualquier aplicación compilada contra libsixel con soporte para gdk-pixbuf2 puede activar esto de manera fiable, lo que podría conducir a revelación de información, corrupción de memoria o ejecución de código. Este problema ha sido solucionado en la versión 1.8.7-r1."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"saitoha","product":"libsixel","versions":[{"version":"< 1.8.7-r1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-15T18:48:25.027963Z","id":"CVE-2026-33023","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-416"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:saitoha:libsixel:*:*:*:*:*:*:*:*","versionEndIncluding":"1.8.7","matchCriteriaId":"49AAE0F5-8747-4FA0-9E7F-37FC054A3198"}]}]}],"references":[{"url":"https://github.com/saitoha/libsixel/releases/tag/v1.8.7-r1","source":"security-advisories@github.com","tags":["Release Notes"]},{"url":"https://github.com/saitoha/libsixel/security/advisories/GHSA-hr25-g2j6-qjw6","source":"security-advisories@github.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://github.com/saitoha/libsixel/security/advisories/GHSA-hr25-g2j6-qjw6","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-28747","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2026-04-27T23:16:02.820","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be bypassed."},{"lang":"es","value":"Una vulnerabilidad de generación de clave débil existe en versiones específicas de firmware de cámaras Milesight AIOT, que permite eludir la autorización."}],"affected":[{"source":"ics-cert@hq.dhs.gov","affectedData":[{"vendor":"Milesight","product":"MS-Cxx63-PD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"51.7.0.77-r12","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx64-xPD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"51.7.0.77-r12","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx73-xPD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"51.7.0.77-r12","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx75-xxPD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"51.7.0.77-r12","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx83-xPD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"51.7.0.77-r12","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx74-PA","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3x.8.0.3-r11","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C8477-HPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.4-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C8477-PC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"48.8.0.4-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C5321-FPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"62.8.0.4-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx72-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx62-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx52-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-xxxGPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx61-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx67-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx71-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx41-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx76-PE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx65-PE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.5-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx62-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.5-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx72-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.5-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-CQxx31-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"CQ_63.8.0.5-r1","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-CQxx68-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"CQ_63.8.0.5-r1","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-CQxx72-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"CQ_63.8.0.5-r1","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-NxE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-xxC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-xxE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-xxG","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-xxH","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-xxT","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"PMC8266-FPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"PO_61.8.0.4_LPR","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"PMC8266-FGPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"PO_61.8.0.4_LPR","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"PM3322-E","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"PI_61.8.0.3_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RIPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5366-X12RIPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4RIPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RIVPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-RFIVPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4RIVPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-RFIVPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RIWG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4RIWG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5510-GVH","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_47.8.0.4_LPR-r7","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5510-GH","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_47.8.0.4_LPR-r6","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5511-GVH","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_47.8.0.4_LPR-r6","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2966-X12TPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5366-X12PE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4PE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2966-X12TVPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RVPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5366-X12VPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4VPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4441-X36RPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4441-X36RE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RWE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4WE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C2964-RFLPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C2972-RFLPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C2966-RFLWPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2866-X4TPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2866-X4TVPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2866-X4TGPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2841-X36TPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2841-X36TPC/W","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2867-X5TPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2961-X12TPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-FPC/P","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C2966-X12RLPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C2966-X12RLVPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C5366-X12LPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C5366-X12LVPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C5361-X12LPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-xxxxGOPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"45.8.0.2-AIoT-r4","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"SC211","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"C_21.1.0.8-r4","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"SP111","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"52.8.0.4-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-RFIPKG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.4-r1-NX","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx72-RFIPKG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.4-r1-NX","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-FIPKG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.4-r1-NX","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx72-FIPKG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.4-r1-NX","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"ADJACENT","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-28T13:40:48.550832Z","id":"CVE-2026-28747","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-113-03.json","source":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-03","source":"ics-cert@hq.dhs.gov"},{"url":"https://www.milesight.com/support/download/firmware","source":"ics-cert@hq.dhs.gov"}]}},{"cve":{"id":"CVE-2026-27785","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2026-04-28T00:16:23.127","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials."},{"lang":"es","value":"Versiones específicas de firmware del firmware de cámaras Milesight AIOT contienen credenciales codificadas de forma rígida."}],"affected":[{"source":"ics-cert@hq.dhs.gov","affectedData":[{"vendor":"Milesight","product":"MS-Cxx63-PD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"51.7.0.77-r12","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx64-xPD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"51.7.0.77-r12","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx73-xPD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"51.7.0.77-r12","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx75-xxPD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"51.7.0.77-r12","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx83-xPD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"51.7.0.77-r12","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx74-PA","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3x.8.0.3-r11","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C8477-HPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.4-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C8477-PC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"48.8.0.4-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C5321-FPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"62.8.0.4-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx72-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx62-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx52-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-xxxGPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx61-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx67-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx71-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx41-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx76-PE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx65-PE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.5-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx62-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.5-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx72-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.5-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-CQxx31-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"CQ_63.8.0.5-r1","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-CQxx68-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"CQ_63.8.0.5-r1","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-CQxx72-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"CQ_63.8.0.5-r1","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-NxE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-xxC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-xxE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-xxG","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-xxH","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-xxT","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"PMC8266-FPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"PO_61.8.0.4_LPR","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"PMC8266-FGPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"PO_61.8.0.4_LPR","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"PM3322-E","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"PI_61.8.0.3_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RIPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5366-X12RIPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4RIPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RIVPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-RFIVPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4RIVPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-RFIVPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RIWG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4RIWG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5510-GVH","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_47.8.0.4_LPR-r7","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5510-GH","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_47.8.0.4_LPR-r6","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5511-GVH","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_47.8.0.4_LPR-r6","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2966-X12TPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5366-X12PE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4PE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2966-X12TVPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RVPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5366-X12VPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4VPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4441-X36RPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4441-X36RE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RWE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4WE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C2964-RFLPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C2972-RFLPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C2966-RFLWPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2866-X4TPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2866-X4TVPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2866-X4TGPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2841-X36TPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2841-X36TPC/W","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2867-X5TPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2961-X12TPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-FPC/P","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C2966-X12RLPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C2966-X12RLVPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C5366-X12LPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C5366-X12LVPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C5361-X12LPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-xxxxGOPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"45.8.0.2-AIoT-r4","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"SC211","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"C_21.1.0.8-r4","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"SP111","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"52.8.0.4-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-RFIPKG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.4-r1-NX","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx72-RFIPKG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.4-r1-NX","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-FIPKG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.4-r1-NX","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx72-FIPKG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.4-r1-NX","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-28T12:40:31.458437Z","id":"CVE-2026-27785","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-798"}]}],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-113-03.json","source":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-03","source":"ics-cert@hq.dhs.gov"},{"url":"https://www.milesight.com/support/download/firmware","source":"ics-cert@hq.dhs.gov"}]}},{"cve":{"id":"CVE-2026-32644","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2026-04-28T01:16:00.600","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys."},{"lang":"es","value":"Versiones específicas de firmware de cámaras Milesight AIOT usan certificados SSL con claves privadas predeterminadas."}],"affected":[{"source":"ics-cert@hq.dhs.gov","affectedData":[{"vendor":"Milesight","product":"MS-Cxx63-PD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"51.7.0.77-r12","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx64-xPD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"51.7.0.77-r12","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx73-xPD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"51.7.0.77-r12","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx75-xxPD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"51.7.0.77-r12","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx83-xPD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"51.7.0.77-r12","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx74-PA","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3x.8.0.3-r11","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C8477-HPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.4-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C8477-PC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"48.8.0.4-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C5321-FPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"62.8.0.4-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx72-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx62-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx52-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-xxxGPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx61-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx67-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx71-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx41-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx76-PE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx65-PE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.5-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx62-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.5-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx72-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.5-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-CQxx31-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"CQ_63.8.0.5-r1","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-CQxx68-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"CQ_63.8.0.5-r1","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-CQxx72-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"CQ_63.8.0.5-r1","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-NxE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-xxC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-xxE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-xxG","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-xxH","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-xxT","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"PMC8266-FPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"PO_61.8.0.4_LPR","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"PMC8266-FGPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"PO_61.8.0.4_LPR","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"PM3322-E","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"PI_61.8.0.3_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RIPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5366-X12RIPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4RIPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RIVPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-RFIVPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4RIVPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-RFIVPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RIWG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4RIWG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5510-GVH","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_47.8.0.4_LPR-r7","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5510-GH","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_47.8.0.4_LPR-r6","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5511-GVH","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_47.8.0.4_LPR-r6","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2966-X12TPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5366-X12PE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4PE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2966-X12TVPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RVPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5366-X12VPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4VPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4441-X36RPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4441-X36RE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RWE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4WE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C2964-RFLPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C2972-RFLPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C2966-RFLWPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2866-X4TPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2866-X4TVPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2866-X4TGPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2841-X36TPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2841-X36TPC/W","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2867-X5TPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2961-X12TPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-FPC/P","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C2966-X12RLPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C2966-X12RLVPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C5366-X12LPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C5366-X12LVPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C5361-X12LPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-xxxxGOPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"45.8.0.2-AIoT-r4","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"SC211","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"C_21.1.0.8-r4","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"SP111","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"52.8.0.4-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-RFIPKG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.4-r1-NX","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx72-RFIPKG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.4-r1-NX","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-FIPKG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.4-r1-NX","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx72-FIPKG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.4-r1-NX","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.2,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-28T14:45:03.298830Z","id":"CVE-2026-32644","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-321"}]}],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-113-03.json","source":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-03","source":"ics-cert@hq.dhs.gov"},{"url":"https://www.milesight.com/support/download/firmware","source":"ics-cert@hq.dhs.gov"}]}},{"cve":{"id":"CVE-2026-32649","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2026-04-28T01:16:00.947","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras."},{"lang":"es","value":"Una vulnerabilidad de inyección de comandos existe en el servidor web de versiones específicas de firmware de cámaras Milesight."}],"affected":[{"source":"ics-cert@hq.dhs.gov","affectedData":[{"vendor":"Milesight","product":"MS-Cxx63-PD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"51.7.0.77-r12","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx64-xPD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"51.7.0.77-r12","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx73-xPD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"51.7.0.77-r12","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx75-xxPD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"51.7.0.77-r12","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx83-xPD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"51.7.0.77-r12","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx74-PA","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3x.8.0.3-r11","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C8477-HPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.4-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C8477-PC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"48.8.0.4-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C5321-FPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"62.8.0.4-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx72-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx62-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx52-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-xxxGPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx61-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx67-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx71-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx41-xxxPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx76-PE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx65-PE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"61.8.0.5-r2","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.5-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx62-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.5-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx72-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.5-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-CQxx31-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"CQ_63.8.0.5-r1","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-CQxx68-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"CQ_63.8.0.5-r1","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-CQxx72-xxxG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"CQ_63.8.0.5-r1","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-NxE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-xxC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-xxE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-xxG","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-xxH","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Nxxxx-xxT","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7x.9.0.19-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"PMC8266-FPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"PO_61.8.0.4_LPR","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"PMC8266-FGPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"PO_61.8.0.4_LPR","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"PM3322-E","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"PI_61.8.0.3_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RIPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5366-X12RIPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4RIPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RIVPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-RFIVPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4RIVPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-RFIVPG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RIWG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4RIWG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_63.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5510-GVH","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_47.8.0.4_LPR-r7","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5510-GH","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_47.8.0.4_LPR-r6","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5511-GVH","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_47.8.0.4_LPR-r6","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2966-X12TPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5366-X12PE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4PE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2966-X12TVPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RVPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS5366-X12VPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4VPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4441-X36RPE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4441-X36RE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS4466-X4RWE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-X4WE","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_61.8.0.4_LPR-r3","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C2964-RFLPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C2972-RFLPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C2966-RFLWPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2866-X4TPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2866-X4TVPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2866-X4TGPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2841-X36TPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2841-X36TPC/W","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2867-X5TPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS2961-X12TPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"TS8266-FPC/P","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C2966-X12RLPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C2966-X12RLVPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C5366-X12LPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C5366-X12LVPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-C5361-X12LPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"T_45.8.0.3-r9","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-xxxxGOPC","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"45.8.0.2-AIoT-r4","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"SC211","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"C_21.1.0.8-r4","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"SP111","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"52.8.0.4-r5","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-RFIPKG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.4-r1-NX","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx72-RFIPKG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.4-r1-NX","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx66-FIPKG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.4-r1-NX","versionType":"custom","status":"affected"}]},{"vendor":"Milesight","product":"MS-Cxx72-FIPKG1","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"63.8.0.4-r1-NX","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"HIGH","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-28T14:42:25.685037Z","id":"CVE-2026-32649","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-113-03.json","source":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-03","source":"ics-cert@hq.dhs.gov"},{"url":"https://www.milesight.com/support/download/firmware","source":"ics-cert@hq.dhs.gov"}]}},{"cve":{"id":"CVE-2026-0711","sourceIdentifier":"security@zyxel.com.tw","published":"2026-04-28T03:16:02.167","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges to execute OS commands on an affected device."},{"lang":"es","value":"Una vulnerabilidad de inyección de comandos de post-autenticación en las API relacionadas con EasyMesh de las versiones de firmware de Zyxel DX3300-T0 hasta la 5.50(ABVY.7.1)C0 podría permitir a un atacante autenticado y adyacente con privilegios de administrador ejecutar comandos del sistema operativo en un dispositivo afectado."}],"affected":[{"source":"security@zyxel.com.tw","affectedData":[{"vendor":"Zyxel","product":"DX3300-T0 firmware","defaultStatus":"unaffected","versions":[{"version":"<= 5.50(ABVY.7.1)C0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@zyxel.com.tw","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-28T00:00:00+00:00","id":"CVE-2026-0711","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@zyxel.com.tw","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:nr5307_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.00\\(acjt.3\\)c0","matchCriteriaId":"E3CFB41B-C3A8-42FC-98F2-D0CA9FC4B2C5"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:nr5307:-:*:*:*:*:*:*:*","matchCriteriaId":"27C408EF-36D8-4111-8CC5-C1278A884F67"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:nebula_fwa515_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.60\\(acpz.0\\)v0","matchCriteriaId":"82904F03-AE99-434C-AFDD-8AC6605269AA"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:nebula_fwa515:-:*:*:*:*:*:*:*","matchCriteriaId":"7C814005-F021-4AFC-8043-0B00EED3FBA6"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:dx3300-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abvy.7.2\\)c0","matchCriteriaId":"3D1FA8F1-2B41-41AA-82DD-97A8CE957A57"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:dx3300-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"6D3E176E-F728-4385-8533-4C694D43898A"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:dx3300-t1_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abvy.7.2\\)c0","matchCriteriaId":"A30578C5-2232-4596-ADD3-3826D5AC7298"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:dx3300-t1:-:*:*:*:*:*:*:*","matchCriteriaId":"2456F691-C182-4BE6-A08F-5E1717366DCA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:dx3301-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abvy.7.2\\)c0","matchCriteriaId":"4D323A56-1FC9-4B18-A73B-83369558039A"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:dx3301-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"3BBDC072-5D40-4130-9B5F-22FDA9BF909A"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:dx5401-b0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.17\\(abyo.7.2\\)c0","matchCriteriaId":"333EADF7-021A-447E-A741-20924B05E874"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:dx5401-b0:-:*:*:*:*:*:*:*","matchCriteriaId":"B293E564-2C48-442A-A415-34383DF3ADBA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:dx5401-b1_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.17\\(abyo.7.2\\)c0","matchCriteriaId":"A1166223-0BC7-44A9-9941-D22EFFEE903D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:dx5401-b1:-:*:*:*:*:*:*:*","matchCriteriaId":"AFE5C53C-4255-4AEE-A49E-36C1A2CF10F5"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ee3301-00_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.63\\(acmu.3.1\\)c0","matchCriteriaId":"5C612237-6809-4820-97A2-D7A1E177971F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ee3301-00:-:*:*:*:*:*:*:*","matchCriteriaId":"6360F4D5-AFA7-4BE2-A3DE-8936453FF7ED"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ee5301-00_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.63\\(acld.3.1\\)c0","matchCriteriaId":"78231491-3C65-47AD-9F59-1CDD5EF3A381"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ee5301-00:-:*:*:*:*:*:*:*","matchCriteriaId":"B28CD570-8DF0-428D-9EF6-87B05DD019D7"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ee6510-10_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.19\\(acjq.4.2\\)c0","matchCriteriaId":"CB6321BA-7B09-4758-A55C-55EBD73ED6B6"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ee6510-10:-:*:*:*:*:*:*:*","matchCriteriaId":"CD4AE46D-E374-4224-9A66-4291B6A10C00"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:emg3525-t50b_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abpm.9.8\\)c0","matchCriteriaId":"6D365F50-DE02-4861-AB54-67CEBC7E634C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:emg3525-t50b:-:*:*:*:*:*:*:*","matchCriteriaId":"9259E2F6-885D-4B44-8D40-20758DA599D2"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:emg5523-t50b_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abpm.9.8\\)c0","matchCriteriaId":"8C47A92E-1595-4A9F-A10E-F6195CD4CD46"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:emg5523-t50b:-:*:*:*:*:*:*:*","matchCriteriaId":"F3ECE0EB-C429-4716-ABFB-73540847EB9E"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex3300-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abvy.7.2\\)c0","matchCriteriaId":"C4E173F5-57FA-429E-8CAA-E47D6CA79436"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex3300-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"137F8B94-4176-4D9B-8704-28525E7352D1"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex3300-t1_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abvy.7.2\\)c0","matchCriteriaId":"C41A2CEB-DD8A-4396-809A-F4C5259373B8"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex3300-t1:-:*:*:*:*:*:*:*","matchCriteriaId":"F766221F-7478-4E39-B4CD-A2498ACEE754"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex3301-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abvy.7.2\\)c0","matchCriteriaId":"C413302B-9472-4C39-A5A2-3C3F18D8A4DA"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex3301-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"B37B17D8-76CF-4A26-B2DB-41B1BC9FD0A2"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex3500-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.44\\(achr.6\\)c0","matchCriteriaId":"94FC0334-D656-419E-9F6F-CE1F0BB63880"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex3500-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"8714EB1B-38E5-4295-AD26-EE13E2161DEA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex3501-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.44\\(achr.6\\)c0","matchCriteriaId":"38BB03D3-A558-484C-AB85-707763F8853F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex3501-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"A98F76BD-0404-46DD-AE6A-EB630FEC8904"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex3600-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.70\\(acif.3\\)c0","matchCriteriaId":"4E52AF49-FF16-4A0F-9F50-6F8F9C0EFA7F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex3600-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"D3BCC6A9-1CAE-459D-BE7D-AAB956BD1B92"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex5401-b0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.17\\(abyo.7.2\\)c0","matchCriteriaId":"F459F871-7B1A-4140-9202-CDEA9BF2CFE3"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex5401-b0:-:*:*:*:*:*:*:*","matchCriteriaId":"6B1B9D0C-AB6C-43E1-BFCA-50EF231510FC"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex5401-b1_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.17\\(abyo.7.2\\)c0","matchCriteriaId":"49F5F019-919C-4912-B2B6-4D6A5624F774"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex5401-b1:-:*:*:*:*:*:*:*","matchCriteriaId":"7213FA12-5CD6-4E9B-8387-A52AEF17EA10"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex5512-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.70\\(aceg.5.5\\)c0","matchCriteriaId":"ECFF8291-4F5E-4E34-98C6-BC985DD98AFF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex5512-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"F32FA3FB-CE89-4CC1-9D8D-765B90A122DF"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex5601-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.70\\(acdz.6\\)c0","matchCriteriaId":"1659651E-11BA-4A5E-AC88-51B56FE951FC"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex5601-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"ABFF2039-5DCC-4850-8BDA-3D418629C226"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex5601-t1_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.70\\(acdz.6\\)c0","matchCriteriaId":"F416BF40-DB7A-4F78-A887-45E62E25B58D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex5601-t1:-:*:*:*:*:*:*:*","matchCriteriaId":"D629D4B6-B2F2-45F1-9295-71751570C231"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex7501-b0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.18\\(achn.3.2\\)c0","matchCriteriaId":"4166B089-90E7-4B42-B968-6CB6336C5973"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex7501-b0:-:*:*:*:*:*:*:*","matchCriteriaId":"1CE049DE-A5DA-4A4F-BA30-BBD09FF34DE0"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:vmg3625-t50b_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abpm.9.8\\)c0","matchCriteriaId":"F35B4F0C-53E5-454F-B187-B9BDCDD7CABA"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:vmg3625-t50b:-:*:*:*:*:*:*:*","matchCriteriaId":"BB5E8468-D12F-4CBE-AC7E-27D5A928A85A"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:vmg8623-t50b_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abpm.9.8\\)c0","matchCriteriaId":"FD94B78C-9F9E-406C-A940-434B4DDE21E6"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:vmg8623-t50b:-:*:*:*:*:*:*:*","matchCriteriaId":"C3535B63-318C-4EB5-ADC8-0AF3FB443DFC"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ax7501-b0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.17\\(abpc.7.2\\)c0","matchCriteriaId":"A402953C-88D0-4797-9B6C-D649E3CB4555"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ax7501-b0:-:*:*:*:*:*:*:*","matchCriteriaId":"78473083-F702-4B81-AAA0-B66A0984FF6B"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ax7501-b1_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.17\\(abpc.7.2\\)c0","matchCriteriaId":"AA956C29-AA9E-433D-8613-D700B34C7C9C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ax7501-b1:-:*:*:*:*:*:*:*","matchCriteriaId":"780BBA7D-7E2C-4624-AA15-8A51F3DF428F"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:pe3301-00_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.63\\(acmt.3.1\\)c0","matchCriteriaId":"CFCE007D-5E4D-42ED-9F38-6909C7976745"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:pe3301-00:-:*:*:*:*:*:*:*","matchCriteriaId":"B4171802-2480-4F21-A17A-49D8D0E3727A"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:pe5301-01_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.63\\(acoj.3.1\\)c0","matchCriteriaId":"30CBAF7B-4B7B-4764-9DDA-A4A2FC710B0C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:pe5301-01:-:*:*:*:*:*:*:*","matchCriteriaId":"8CFFB6F6-F8ED-4AFA-B1D7-4E9C5D1F7897"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:px5302-00_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.44\\(acnm.0.1\\)c0","matchCriteriaId":"B3888E31-CE3A-416E-B24A-E6AA160D3E4E"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:px5302-00:-:*:*:*:*:*:*:*","matchCriteriaId":"27CF1A98-893C-4586-A6EF-A205B2204645"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:px5301-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.44\\(ackb.0.7\\)c0","matchCriteriaId":"B23A6540-2FE2-4B4B-A86C-B3F16D32BA68"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:px5301-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"7EBB4C27-DAEB-4297-98DC-3B22353B5184"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:we3300-00_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.70\\(acka.2\\)c0","matchCriteriaId":"B3DF52F9-8AF0-49BB-8482-82562BE1AAC5"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:we3300-00:-:*:*:*:*:*:*:*","matchCriteriaId":"532CBEBB-0D42-42F7-9916-7D8E360E0776"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:wx3100-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abvl.4.10\\)c0","matchCriteriaId":"906387F0-9AC2-4355-A7CE-08E13C76EEB5"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:wx3100-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"C2C56248-D12F-46DC-A52F-0607E4A5DCCC"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:we4600-00_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"6.70\\(ackt.1\\)c0","matchCriteriaId":"DDA6A438-CDD1-41F0-9216-BC3C042D9CA4"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:we4600-00:-:*:*:*:*:*:*:*","matchCriteriaId":"39E894F1-DA55-4E1A-90F6-002271E55B88"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:wx5600-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.70\\(aceb.6\\)c0","matchCriteriaId":"AB90CEA7-B554-49BF-9B23-C7B75AA5DAE3"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:wx5600-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"303DB62A-2A7E-4CB7-ADA0-29C23BFD41BE"}]}]}],"references":[{"url":"https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-vulnerabilities-in-certain-4g-lte-5g-nr-cpe-dsl-ethernet-cpe-fiber-onts-and-wireless-extenders-04-28-2026","source":"security@zyxel.com.tw","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-1460","sourceIdentifier":"security@zyxel.com.tw","published":"2026-04-28T03:16:02.313","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EX3301-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device."},{"lang":"es","value":"Una vulnerabilidad de inyección de comandos post-autenticación en el parámetro 'DomainName' del archivo de configuración DHCP en las versiones de firmware de Zyxel DX3301-T0 y EX3301-T0 hasta la 5.50(ABVY.7.1)C0 podría permitir a un atacante autenticado con privilegios de administrador ejecutar comandos del sistema operativo en un dispositivo afectado."}],"affected":[{"source":"security@zyxel.com.tw","affectedData":[{"vendor":"Zyxel","product":"DX3301-T0 firmware","defaultStatus":"unaffected","versions":[{"version":"<= 5.50(ABVY.7.1)C0","status":"affected"}]},{"vendor":"Zyxel","product":"EX3301-T0 firmware","defaultStatus":"unaffected","versions":[{"version":"<= 5.50(ABVY.7.1)C0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@zyxel.com.tw","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-28T00:00:00+00:00","id":"CVE-2026-1460","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@zyxel.com.tw","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:nebula_fwa70_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.51\\(acrf.0\\)v0","matchCriteriaId":"ACA5EF54-F74E-49CC-B8C1-73ECCE348C40"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:nebula_fwa70:-:*:*:*:*:*:*:*","matchCriteriaId":"5D6EB26F-F986-4051-A50F-46CB32096635"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:nebula_fwa505_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.60\\(acko.3\\)v0","matchCriteriaId":"830BF8ED-3CE2-476D-8529-CA55A8647CAD"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:nebula_fwa505:-:*:*:*:*:*:*:*","matchCriteriaId":"5052039B-5273-4CDF-AFA5-609855801D24"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:nebula_fwa510_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.60\\(acgd.1\\)v0","matchCriteriaId":"CACF5A53-A5B5-40ED-90E1-EE95F7870BBD"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:nebula_fwa510:-:*:*:*:*:*:*:*","matchCriteriaId":"80B7099C-DAA5-4902-A62B-B680C9450575"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:nebula_fwa515_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.60\\(acpz.1\\)v0","matchCriteriaId":"54F76733-2D49-4888-9678-3E506FE8265E"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:nebula_fwa515:-:*:*:*:*:*:*:*","matchCriteriaId":"7C814005-F021-4AFC-8043-0B00EED3FBA6"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:nebula_fwa710_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.60\\(acgc.2\\)v0","matchCriteriaId":"C9934637-E668-45CF-8375-8A7C12E43646"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:nebula_fwa710:-:*:*:*:*:*:*:*","matchCriteriaId":"92221518-C7EA-46D7-8037-A580CEA01093"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:nebula_lte3301-plus_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.18\\(acca.7\\)v0","matchCriteriaId":"EEEDA6F0-765C-4121-AAF7-9CE42CDAA853"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:nebula_lte3301-plus:-:*:*:*:*:*:*:*","matchCriteriaId":"42297A6A-3E50-4E9E-ABF6-58C77F222DC1"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:nebula_lte7461-m602_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.15\\(acev.4\\)v0","matchCriteriaId":"6AEE1A81-4D5C-42B2-B10B-BB1F9D106DF7"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:nebula_lte7461-m602:-:*:*:*:*:*:*:*","matchCriteriaId":"44AA94AF-24B0-4C91-A990-9418EA5A5DAC"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:nebula_nr5101_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.16\\(accg.1\\)v0","matchCriteriaId":"7D0775F7-602B-47A7-B07E-1BC4AB8BF29E"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:nebula_nr5101:-:*:*:*:*:*:*:*","matchCriteriaId":"F9F605B8-A892-4119-AB7A-D14CDC5DFC88"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:nebula_nr7101_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.16\\(accc.2\\)v0","matchCriteriaId":"A7D775A9-9D21-435D-A7AC-8F3D849554E1"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:nebula_nr7101:-:*:*:*:*:*:*:*","matchCriteriaId":"52096C1F-F73C-413E-9D37-82EFA4703AEC"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:dx3300-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abvy.7.2\\)c0","matchCriteriaId":"3D1FA8F1-2B41-41AA-82DD-97A8CE957A57"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:dx3300-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"6D3E176E-F728-4385-8533-4C694D43898A"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:dx3300-t1_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abvy.7.2\\)c0","matchCriteriaId":"A30578C5-2232-4596-ADD3-3826D5AC7298"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:dx3300-t1:-:*:*:*:*:*:*:*","matchCriteriaId":"2456F691-C182-4BE6-A08F-5E1717366DCA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:dx3301-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abvy.7.2\\)c0","matchCriteriaId":"4D323A56-1FC9-4B18-A73B-83369558039A"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:dx3301-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"3BBDC072-5D40-4130-9B5F-22FDA9BF909A"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:dx5401-b1_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.17\\(abyo.7.2\\)c0","matchCriteriaId":"A1166223-0BC7-44A9-9941-D22EFFEE903D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:dx5401-b1:-:*:*:*:*:*:*:*","matchCriteriaId":"AFE5C53C-4255-4AEE-A49E-36C1A2CF10F5"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ee3301-00_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.63\\(acmu.3.1\\)c0","matchCriteriaId":"5C612237-6809-4820-97A2-D7A1E177971F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ee3301-00:-:*:*:*:*:*:*:*","matchCriteriaId":"6360F4D5-AFA7-4BE2-A3DE-8936453FF7ED"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ee5301-00_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.63\\(acld.3.1\\)c0","matchCriteriaId":"78231491-3C65-47AD-9F59-1CDD5EF3A381"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ee5301-00:-:*:*:*:*:*:*:*","matchCriteriaId":"B28CD570-8DF0-428D-9EF6-87B05DD019D7"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ee6510-10_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.19\\(acjq.4.2\\)c0","matchCriteriaId":"CB6321BA-7B09-4758-A55C-55EBD73ED6B6"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ee6510-10:-:*:*:*:*:*:*:*","matchCriteriaId":"CD4AE46D-E374-4224-9A66-4291B6A10C00"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:emg3525-t50b_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abpm.9.8\\)c0","matchCriteriaId":"6D365F50-DE02-4861-AB54-67CEBC7E634C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:emg3525-t50b:-:*:*:*:*:*:*:*","matchCriteriaId":"9259E2F6-885D-4B44-8D40-20758DA599D2"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:emg5523-t50b_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abpm.9.8\\)c0","matchCriteriaId":"8C47A92E-1595-4A9F-A10E-F6195CD4CD46"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:emg5523-t50b:-:*:*:*:*:*:*:*","matchCriteriaId":"F3ECE0EB-C429-4716-ABFB-73540847EB9E"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex2210-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(acdi.2.5\\)c0","matchCriteriaId":"6B8CDF27-C9F7-4B6F-925F-28B20AF606EB"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex2210-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"A71E4E6F-357E-4DAA-B7D7-7CF44000F0CF"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex3300-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abvy.7.2\\)c0","matchCriteriaId":"C4E173F5-57FA-429E-8CAA-E47D6CA79436"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex3300-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"137F8B94-4176-4D9B-8704-28525E7352D1"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex3300-t1_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abvy.7.2\\)c0","matchCriteriaId":"C41A2CEB-DD8A-4396-809A-F4C5259373B8"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex3300-t1:-:*:*:*:*:*:*:*","matchCriteriaId":"F766221F-7478-4E39-B4CD-A2498ACEE754"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex3301-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abvy.7.2\\)c0","matchCriteriaId":"C413302B-9472-4C39-A5A2-3C3F18D8A4DA"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex3301-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"B37B17D8-76CF-4A26-B2DB-41B1BC9FD0A2"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex3500-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.44\\(achr.6\\)c0","matchCriteriaId":"94FC0334-D656-419E-9F6F-CE1F0BB63880"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex3500-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"8714EB1B-38E5-4295-AD26-EE13E2161DEA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex3501-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.44\\(achr.6\\)c0","matchCriteriaId":"38BB03D3-A558-484C-AB85-707763F8853F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex3501-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"A98F76BD-0404-46DD-AE6A-EB630FEC8904"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex3600-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.70\\(acif.3\\)c0","matchCriteriaId":"4E52AF49-FF16-4A0F-9F50-6F8F9C0EFA7F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex3600-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"D3BCC6A9-1CAE-459D-BE7D-AAB956BD1B92"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex5401-b1_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.17\\(abyo.7.2\\)c0","matchCriteriaId":"49F5F019-919C-4912-B2B6-4D6A5624F774"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex5401-b1:-:*:*:*:*:*:*:*","matchCriteriaId":"7213FA12-5CD6-4E9B-8387-A52AEF17EA10"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex5512-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.70\\(aceg.5.5\\)c0","matchCriteriaId":"ECFF8291-4F5E-4E34-98C6-BC985DD98AFF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex5512-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"F32FA3FB-CE89-4CC1-9D8D-765B90A122DF"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex5601-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.70\\(acdz.6\\)c0","matchCriteriaId":"1659651E-11BA-4A5E-AC88-51B56FE951FC"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex5601-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"ABFF2039-5DCC-4850-8BDA-3D418629C226"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex5601-t1_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.70\\(acdz.6\\)c0","matchCriteriaId":"F416BF40-DB7A-4F78-A887-45E62E25B58D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex5601-t1:-:*:*:*:*:*:*:*","matchCriteriaId":"D629D4B6-B2F2-45F1-9295-71751570C231"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex7501-b0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.18\\(achn.3.2\\)c0","matchCriteriaId":"4166B089-90E7-4B42-B968-6CB6336C5973"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex7501-b0:-:*:*:*:*:*:*:*","matchCriteriaId":"1CE049DE-A5DA-4A4F-BA30-BBD09FF34DE0"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ex7710-b0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.18\\(acak.1.7\\)c0","matchCriteriaId":"6EE63106-FEEE-4722-A4BE-12A1BD3E407C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ex7710-b0:-:*:*:*:*:*:*:*","matchCriteriaId":"07727D9C-723B-4761-B6B6-07FE1784D3C1"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:gm4100-b0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.18\\(accl.2.1\\)c0","matchCriteriaId":"8543CC65-F1EA-4D19-97E9-8EFC028E212D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:gm4100-b0:-:*:*:*:*:*:*:*","matchCriteriaId":"182AB7CA-DFD4-4C0A-958B-6794A39FFAEF"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:vmg3625-t50b_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abpm.9.8\\)c0","matchCriteriaId":"F35B4F0C-53E5-454F-B187-B9BDCDD7CABA"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:vmg3625-t50b:-:*:*:*:*:*:*:*","matchCriteriaId":"BB5E8468-D12F-4CBE-AC7E-27D5A928A85A"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:vmg4005-b50a_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.17\\(abqa.3.3\\)c0","matchCriteriaId":"E62FCD44-DBBD-4809-ADD8-C6596AB9C71D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:vmg4005-b50a:-:*:*:*:*:*:*:*","matchCriteriaId":"88F74228-AC0C-4150-974D-54D77BBF9A90"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:vmg4005-b60a_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.17\\(abqa.3.3\\)c0","matchCriteriaId":"434F9EDF-91E2-4113-B358-A51E1B33D488"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:vmg4005-b60a:-:*:*:*:*:*:*:*","matchCriteriaId":"30C1B91D-3EA0-4A1D-833A-6767A6C84DA3"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:vmg8623-t50b_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.50\\(abpm.9.8\\)c0","matchCriteriaId":"FD94B78C-9F9E-406C-A940-434B4DDE21E6"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:vmg8623-t50b:-:*:*:*:*:*:*:*","matchCriteriaId":"C3535B63-318C-4EB5-ADC8-0AF3FB443DFC"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:am7510-00_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.63\\(acor.0.2\\)c0","matchCriteriaId":"753A36DC-BC06-408D-90B3-00D7CE5261F3"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:am7510-00:-:*:*:*:*:*:*:*","matchCriteriaId":"0B70256B-4916-4CBC-ADCB-6CB31E805564"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:ax7501-b1_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.17\\(abpc.7.2\\)c0","matchCriteriaId":"AA956C29-AA9E-433D-8613-D700B34C7C9C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:ax7501-b1:-:*:*:*:*:*:*:*","matchCriteriaId":"780BBA7D-7E2C-4624-AA15-8A51F3DF428F"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:pe3301-00_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.63\\(acmt.3.1\\)c0","matchCriteriaId":"CFCE007D-5E4D-42ED-9F38-6909C7976745"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:pe3301-00:-:*:*:*:*:*:*:*","matchCriteriaId":"B4171802-2480-4F21-A17A-49D8D0E3727A"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:pe5301-01_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.63\\(acoj.3.1\\)c0","matchCriteriaId":"30CBAF7B-4B7B-4764-9DDA-A4A2FC710B0C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:pe5301-01:-:*:*:*:*:*:*:*","matchCriteriaId":"8CFFB6F6-F8ED-4AFA-B1D7-4E9C5D1F7897"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:px5301-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.44\\(ackb.0.7\\)c0","matchCriteriaId":"B23A6540-2FE2-4B4B-A86C-B3F16D32BA68"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:px5301-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"7EBB4C27-DAEB-4297-98DC-3B22353B5184"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:px5302-00_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.44\\(acnm.0.1\\)c0","matchCriteriaId":"B3888E31-CE3A-416E-B24A-E6AA160D3E4E"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:px5302-00:-:*:*:*:*:*:*:*","matchCriteriaId":"27CF1A98-893C-4586-A6EF-A205B2204645"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:we3300-00_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.70\\(acka.2\\)c0","matchCriteriaId":"B3DF52F9-8AF0-49BB-8482-82562BE1AAC5"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:we3300-00:-:*:*:*:*:*:*:*","matchCriteriaId":"532CBEBB-0D42-42F7-9916-7D8E360E0776"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:we4600-00_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"6.70\\(ackt.1\\)c0","matchCriteriaId":"DDA6A438-CDD1-41F0-9216-BC3C042D9CA4"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:we4600-00:-:*:*:*:*:*:*:*","matchCriteriaId":"39E894F1-DA55-4E1A-90F6-002271E55B88"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zyxel:wx5600-t0_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"5.70\\(aceb.6\\)c0","matchCriteriaId":"AB90CEA7-B554-49BF-9B23-C7B75AA5DAE3"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zyxel:wx5600-t0:-:*:*:*:*:*:*:*","matchCriteriaId":"303DB62A-2A7E-4CB7-ADA0-29C23BFD41BE"}]}]}],"references":[{"url":"https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-vulnerabilities-in-certain-4g-lte-5g-nr-cpe-dsl-ethernet-cpe-fiber-onts-and-wireless-extenders-04-28-2026","source":"security@zyxel.com.tw","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-23773","sourceIdentifier":"security_alert@emc.com","published":"2026-04-29T04:16:40.867","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery."},{"lang":"es","value":"Dell Disk Library para Mainframe, versión(es) DLm 8700/2700 contiene una vulnerabilidad de falsificación de petición del lado del servidor (SSRF). Un atacante con privilegios bajos con acceso remoto podría potencialmente explotar esta vulnerabilidad, lo que llevaría a una falsificación de petición del lado del servidor."}],"affected":[{"source":"security_alert@emc.com","affectedData":[{"vendor":"Dell","product":"Disk Library for mainframe DLm8700","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"7.0.1.0 or later","versionType":"semver","status":"affected"}]},{"vendor":"Dell","product":"Disk Library for mainframe DLm2700","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"7.0.1.0 or later","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security_alert@emc.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-29T13:54:18.332005Z","id":"CVE-2026-23773","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security_alert@emc.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000458131/dsa-2026-091-security-update-for-dell-disk-library-for-mainframe-vulnerabilities?lang=en","source":"security_alert@emc.com"}]}},{"cve":{"id":"CVE-2026-23479","sourceIdentifier":"security-advisories@github.com","published":"2026-05-05T17:17:02.577","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3."},{"lang":"es","value":"Redis es un almacén de estructuras de datos en memoria. En redis-server desde la versión 7.2.0 hasta la 8.6.3, el flujo de desbloqueo del cliente no maneja un retorno de error de 'processCommandAndResetClient' al reejecutar un comando bloqueado. Si un cliente bloqueado es desalojado durante este flujo, un atacante autenticado puede desencadenar un uso después de liberación que puede conducir a la ejecución remota de código. Esto ha sido parcheado en la versión 8.6.3."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"redis","product":"redis","versions":[{"version":">= 7.2.0, < 8.6.3","status":"affected"}]}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","affectedData":[{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"valkey","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:8.0.9-1.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"valkey","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:8.0.9-1.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis:7","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"9080020260521083756.9","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"valkey","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"0:8.0.9-1.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis:7","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"9060020260602115714.9","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"valkey-main","cpes":["cpe:/a:redhat:hummingbird:1"],"versions":[{"version":"9.0.4-0.1.hum1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"boost-main","cpes":["cpe:/a:redhat:hummingbird:1"],"versions":[{"version":"1.90.0-7.hum1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis:6/redis","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis","cpes":["cpe:/o:redhat:enterprise_linux:9"]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-05T00:00:00+00:00","id":"CVE-2026-23479","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-416"}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","description":[{"lang":"en","value":"CWE-416"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*","versionStartIncluding":"7.2.0","versionEndExcluding":"8.6.3","matchCriteriaId":"55566536-4FD7-4A12-864D-AD60A97EDB68"}]}]}],"references":[{"url":"https://github.com/redis/redis/releases/tag/8.6.3","source":"security-advisories@github.com","tags":["Release Notes"]},{"url":"https://github.com/redis/redis/security/advisories/GHSA-93m2-935m-8rj3","source":"security-advisories@github.com","tags":["Vendor Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:14316","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:25216","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:25219","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:25925","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:26306","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:26540","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:7662","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-23479","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2466780","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23479.json","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}]}},{"cve":{"id":"CVE-2026-23631","sourceIdentifier":"security-advisories@github.com","published":"2026-05-05T17:17:03.503","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3."},{"lang":"es","value":"Redis es un almacén de estructuras de datos en memoria. En todas las versiones de redis-server con scripting Lua, un atacante autenticado puede explotar el mecanismo de sincronización maestro-réplica para desencadenar un uso después de liberación en réplicas donde replica-read-only está deshabilitado o puede ser deshabilitado, lo que puede conducir a ejecución remota de código. Una solución alternativa es evitar que los usuarios ejecuten scripts Lua o evitar el uso de réplicas donde replica-read-only está deshabilitado. Esto está parcheado en la versión 8.6.3."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"redis","product":"redis","versions":[{"version":"< 8.6.3","status":"affected"}]}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","affectedData":[{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"valkey","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:8.0.9-1.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"valkey","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:8.0.9-1.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis:7","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"9080020260521083756.9","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"valkey","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"0:8.0.9-1.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis:7","cpes":["cpe:/a:redhat:rhel_e4s:9.4"],"versions":[{"version":"9040020260625094332.9","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis:7","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"9060020260602115714.9","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"valkey-main","cpes":["cpe:/a:redhat:hummingbird:1"],"versions":[{"version":"9.0.4-0.1.hum1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis:6/redis","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"boost","cpes":["cpe:/a:redhat:hummingbird:1"]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-06T03:56:10.112246Z","id":"CVE-2026-23631","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-416"}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","description":[{"lang":"en","value":"CWE-416"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*","versionEndExcluding":"8.6.3","matchCriteriaId":"D27823C5-96F2-4D85-89CF-9C5DEAC584E3"}]}]}],"references":[{"url":"https://github.com/redis/redis/releases/tag/8.6.3","source":"security-advisories@github.com","tags":["Release Notes"]},{"url":"https://github.com/redis/redis/security/advisories/GHSA-8ghh-qpmp-7826","source":"security-advisories@github.com","tags":["Mitigation","Vendor Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:14316","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:25216","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:25219","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:25925","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:26306","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:26540","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:33444","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-23631","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2466788","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23631.json","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}]}},{"cve":{"id":"CVE-2026-25243","sourceIdentifier":"security-advisories@github.com","published":"2026-05-05T17:17:03.667","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL rules. This is patched in version 8.6.3."},{"lang":"es","value":"Redis es un almacén de estructuras de datos en memoria. En versiones de redis-server hasta la 8.6.3, el comando RESTORE no valida correctamente los valores serializados. Un atacante autenticado con permiso para ejecutar RESTORE puede proporcionar una carga útil serializada manipulada que desencadena un acceso a memoria no válido y puede conducir a la ejecución remota de código. Una solución alternativa es restringir el acceso al comando RESTORE con reglas ACL. Esto está parcheado en la versión 8.6.3."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"redis","product":"redis","versions":[{"version":"< 8.6.3","status":"affected"}]}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","affectedData":[{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"valkey","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:8.0.9-1.el10_2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"valkey","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:8.0.9-1.el10_0","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis:6","cpes":["cpe:/a:redhat:enterprise_linux:8"],"versions":[{"version":"8100020260522105353.489197e6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis:6","cpes":["cpe:/a:redhat:rhel_aus:8.4"],"versions":[{"version":"8040020260618162855.522a0ee4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis:6","cpes":["cpe:/a:redhat:rhel_eus_long_life:8.4"],"versions":[{"version":"8040020260618162855.522a0ee4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis:6","cpes":["cpe:/a:redhat:rhel_aus:8.6"],"versions":[{"version":"8060020260623095617.ad008a3a","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis:6","cpes":["cpe:/a:redhat:rhel_eus_long_life:8.6"],"versions":[{"version":"8060020260623095617.ad008a3a","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.8 Telecommunications Update Service","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis:6","cpes":["cpe:/a:redhat:rhel_tus:8.8"],"versions":[{"version":"8080020260626132343.63b34585","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis:6","cpes":["cpe:/a:redhat:rhel_e4s:8.8"],"versions":[{"version":"8080020260626132343.63b34585","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"0:6.2.22-1.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis:7","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"9080020260521083756.9","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"valkey","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"0:8.0.9-1.el9_8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis","cpes":["cpe:/a:redhat:rhel_e4s:9.2"],"versions":[{"version":"0:6.2.7-1.el9_2.6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis","cpes":["cpe:/a:redhat:rhel_e4s:9.4"],"versions":[{"version":"0:6.2.7-1.el9_4.6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis:7","cpes":["cpe:/a:redhat:rhel_e4s:9.4"],"versions":[{"version":"9040020260618054637.9","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"0:6.2.22-1.el9_6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"redis:7","cpes":["cpe:/a:redhat:rhel_eus:9.6"],"versions":[{"version":"9060020260602115714.9","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"valkey-main","cpes":["cpe:/a:redhat:hummingbird:1"],"versions":[{"version":"9.0.4-0.1.hum1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"boost","cpes":["cpe:/a:redhat:hummingbird:1"]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-06T03:56:11.272472Z","id":"CVE-2026-25243","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-122"}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","description":[{"lang":"en","value":"CWE-122"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*","versionEndExcluding":"8.6.3","matchCriteriaId":"D27823C5-96F2-4D85-89CF-9C5DEAC584E3"}]}]}],"references":[{"url":"https://github.com/redis/redis/releases/tag/8.6.3","source":"security-advisories@github.com","tags":["Release Notes"]},{"url":"https://github.com/redis/redis/security/advisories/GHSA-c8h9-259x-jff4","source":"security-advisories@github.com","tags":["Mitigation","Vendor Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:14316","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:23229","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:25216","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:25219","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:25925","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:26008","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:26233","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:26306","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:26540","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:27716","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:27787","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:28139","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:28142","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:29817","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:33427","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-25243","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2466828","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25243.json","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}]}},{"cve":{"id":"CVE-2026-25588","sourceIdentifier":"security-advisories@github.com","published":"2026-05-05T17:17:03.800","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with the RedisTimeSeries module loaded can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL rules. This has been patched in version 1.12.14."},{"lang":"es","value":"RedisTimeSeries es un módulo de series temporales para Redis. En todas las versiones anteriores a la 1.12.14 de RedisTimeSeries, el módulo no valida correctamente los valores serializados procesados a través del comando Redis RESTORE. Un atacante autenticado con permiso para ejecutar RESTORE en un servidor con el módulo RedisTimeSeries cargado puede proporcionar una carga útil serializada manipulada que desencadena un acceso a memoria no válido y puede conducir a la ejecución remota de código. Una solución alternativa es restringir el acceso al comando RESTORE con reglas ACL. Esto ha sido parcheado en la versión 1.12.14."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"RedisTimeSeries","product":"RedisTimeSeries","versions":[{"version":"< 1.12.14","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-06T14:19:00.279250Z","id":"CVE-2026-25588","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-122"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redistimeseries:redistimeseries:*:*:*:*:*:*:*:*","versionEndExcluding":"1.12.14","matchCriteriaId":"6F340A97-7BFF-46C0-9676-F1E76164088E"}]}]}],"references":[{"url":"https://github.com/RedisTimeSeries/RedisTimeSeries/releases/tag/v1.12.14","source":"security-advisories@github.com","tags":["Patch","Product"]},{"url":"https://github.com/RedisTimeSeries/RedisTimeSeries/security/advisories/GHSA-7jwr-g5qv-w3gw","source":"security-advisories@github.com","tags":["Mitigation","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-25589","sourceIdentifier":"security-advisories@github.com","published":"2026-05-05T17:17:03.940","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with the RedisBloom module loaded can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL rules. This issue is fixed in version 2.8.20."},{"lang":"es","value":"RedisBloom es un módulo de estructuras de datos probabilísticas para Redis. En todas las versiones de RedisBloom anteriores a la 2.8.20, el módulo no valida correctamente los valores serializados procesados a través del comando RESTORE de Redis. Un atacante autenticado con permiso para ejecutar RESTORE en un servidor con el módulo RedisBloom cargado puede proporcionar una carga útil serializada manipulada que desencadena un acceso a memoria no válido y puede conducir a la ejecución remota de código. Una solución alternativa es restringir el acceso al comando RESTORE con reglas ACL. Este problema está solucionado en la versión 2.8.20."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"RedisBloom","product":"RedisBloom","versions":[{"version":"< 2.8.20","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-05T18:49:11.441299Z","id":"CVE-2026-25589","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-122"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redisbloom:redisbloom:*:*:*:*:*:*:*:*","versionEndExcluding":"2.8.20","matchCriteriaId":"F671B2DB-B74C-4B26-A496-005FF911B3D5"}]}]}],"references":[{"url":"https://github.com/RedisBloom/RedisBloom/releases/tag/v2.8.20","source":"security-advisories@github.com","tags":["Patch","Product"]},{"url":"https://github.com/RedisBloom/RedisBloom/security/advisories/GHSA-7862-34pw-44wv","source":"security-advisories@github.com","tags":["Mitigation","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-27960","sourceIdentifier":"security-advisories@github.com","published":"2026-05-05T19:16:21.380","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability that can be exploited by unauthenticated attackers to query the API as any existing user, including the default admin account. This issue has been fixed in version 6.9.13. As a workaround, the default admin can be disabled using the `APP__ADMIN__EXTERNALLY_MANAGED` configuration."},{"lang":"es","value":"OpenCTI es una plataforma de código abierto para la gestión de conocimiento de inteligencia de ciberamenazas y observables. En las versiones 6.6.0 a la 6.9.12, existe una vulnerabilidad de escalada de privilegios que puede ser explotada por atacantes no autenticados para consultar la API como cualquier usuario existente, incluyendo la cuenta de administrador predeterminada. Este problema ha sido corregido en la versión 6.9.13. Como solución alternativa, el administrador predeterminado puede ser deshabilitado utilizando la configuración 'APP__ADMIN__EXTERNALLY_MANAGED'."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"OpenCTI-Platform","product":"opencti","versions":[{"version":">= 6.6.0, < 6.9.13","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-06T15:16:02.544220Z","id":"CVE-2026-27960","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:citeum:opencti:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9.0","versionEndExcluding":"6.9.13","matchCriteriaId":"33B3585F-A14B-421D-88EC-1F075332CBA7"}]}]}],"references":[{"url":"https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-6vvv-vmfr-xhrx","source":"security-advisories@github.com","tags":["Mitigation","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-30923","sourceIdentifier":"security-advisories@github.com","published":"2026-05-05T19:16:21.567","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsecurity is one component of the ModSecurity v3 project. A segmentation fault occurs when a rule using the t:hexDecode transformation inspects a query string parameter containing a single character. An attacker can exploit this to crash worker processes, causing a denial of service. Service resumes once the attack stops as worker processes recover from the segfault. All versions before 3.0.15 of libModSecurity3 are affected. This has been patched in version 3.0.15."},{"lang":"es","value":"ModSecurity es un motor de cortafuegos de aplicaciones web (WAF) de código abierto y multiplataforma para Apache, IIS y Nginx. Libmodsecurity es un componente del proyecto ModSecurity v3. Una falla de segmentación ocurre cuando una regla que utiliza la transformación t:hexDecode inspecciona un parámetro de cadena de consulta que contiene un solo carácter. Un atacante puede explotar esto para bloquear los procesos de trabajo, causando una denegación de servicio. El servicio se reanuda una vez que el ataque se detiene, ya que los procesos de trabajo se recuperan de la falla de segmentación. Todas las versiones anteriores a la 3.0.15 de libModSecurity3 están afectadas. Esto ha sido parcheado en la versión 3.0.15."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"owasp-modsecurity","product":"ModSecurity","versions":[{"version":"< 3.0.15","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-05T19:20:55.329784Z","id":"CVE-2026-30923","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-125"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:owasp:modsecurity:*:*:*:*:*:*:*:*","versionEndExcluding":"3.0.15","matchCriteriaId":"4A7C1264-1CA1-4F7B-879E-F449E4776302"}]}]}],"references":[{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.15","source":"security-advisories@github.com","tags":["Patch","Product"]},{"url":"https://github.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-qrjc-3jpc-3h2g","source":"security-advisories@github.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://github.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-qrjc-3jpc-3h2g","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-31835","sourceIdentifier":"security-advisories@github.com","published":"2026-05-05T19:16:21.733","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vaultwarden is a Bitwarden-compatible server written in Rust. In versions 1.35.4 and earlier, the WebAuthn authentication flow in `validate_webauthn_login()` updates persistent credential metadata (1backup_eligible1 and 1backup_state flags1) based on unverified `authenticatorData` before signature validation is performed. An attacker who knows a user's password but cannot produce a valid WebAuthn signature can permanently modify the stored backup flags for that user's credential. If signature verification fails, the database update is not rolled back. This can result in a persistent denial of service of WebAuthn two-factor authentication for affected credentials. This issue has been fixed in version 1.35.5."},{"lang":"es","value":"Vaultwarden es un servidor compatible con Bitwarden escrito en Rust. En las versiones 1.35.4 y anteriores, el flujo de autenticación WebAuthn en 'validate_webauthn_login()' actualiza los metadatos de credenciales persistentes (1backup_eligible1 y 1backup_state flags1) basados en 'authenticatorData' no verificado antes de que se realice la validación de la firma. Un atacante que conoce la contraseña de un usuario pero no puede producir una firma WebAuthn válida puede modificar permanentemente los indicadores de respaldo almacenados para la credencial de ese usuario. Si la verificación de la firma falla, la actualización de la base de datos no se revierte. Esto puede resultar en una denegación de servicio persistente de la autenticación de dos factores de WebAuthn para las credenciales afectadas. Este problema ha sido solucionado en la versión 1.35.5."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"dani-garcia","product":"vaultwarden","versions":[{"version":"< 1.35.5","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-06T12:45:50.889395Z","id":"CVE-2026-31835","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-345"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:dani-garcia:vaultwarden:*:*:*:*:*:*:*:*","versionEndExcluding":"1.35.5","matchCriteriaId":"84C9FEC4-49EA-4F83-9E8F-9DA52A9A987E"}]}]}],"references":[{"url":"https://github.com/dani-garcia/vaultwarden/releases/tag/1.35.5","source":"security-advisories@github.com","tags":["Product","Release Notes"]},{"url":"https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-x7g7-cgx5-jhx2","source":"security-advisories@github.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-x7g7-cgx5-jhx2","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2024-52911","sourceIdentifier":"cve@mitre.org","published":"2026-05-05T20:16:34.923","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Bitcoin Core through 28.x has a security issue, the details of which are not disclosed. The earliest affected version is 0.14."},{"lang":"es","value":"Bitcoin Core hasta 28.x tiene un problema de seguridad, cuyos detalles no han sido revelados. La versión afectada más temprana es la 0.14."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-06T13:00:25.458655Z","id":"CVE-2024-52911","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://bitcoincore.org","source":"cve@mitre.org"},{"url":"https://bitcoincore.org/en/2026/05/05/disclose-cve-2024-52911/","source":"cve@mitre.org"},{"url":"https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-31893","sourceIdentifier":"security-advisories@github.com","published":"2026-05-05T20:16:35.373","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Tunnelblick is an open source graphic user interface for OpenVPN on macOS. In versions 3.3beta26 through 9.0beta01, any local user can read arbitrary root-owned files by exploiting a symlink following vulnerability in tunnelblick-helper, reachable through the world-accessible tunnelblickd Unix socket. The socket is configured with mode 0666, allowing any local user to connect. No authorization check is performed on the connecting client. The tunnelblick-helper process constructs a path to config.ovpn inside a user-controlled .tblk directory and reads it as root without symlink validation. An attacker can create a .tblk configuration with a symlinked config.ovpn pointing to any file and request tunnelblickd to read it. This issue has been fixed in versions 9.0beta02."},{"lang":"es","value":"Tunnelblick es una interfaz gráfica de usuario de código abierto para OpenVPN en macOS. En las versiones 3.3beta26 hasta la 9.0beta01, cualquier usuario local puede leer archivos arbitrarios propiedad de root explotando una vulnerabilidad de seguimiento de symlink en tunnelblick-helper, accesible a través del socket Unix tunnelblickd de acceso global. El socket está configurado con el modo 0666, permitiendo que cualquier usuario local se conecte. No se realiza ninguna comprobación de autorización en el cliente que se conecta. El proceso tunnelblick-helper construye una ruta a config.ovpn dentro de un directorio .tblk controlado por el usuario y lo lee como root sin validación de symlink. Un atacante puede crear una configuración .tblk con un config.ovpn con symlink apuntando a cualquier archivo y solicitar a tunnelblickd que lo lea. Este problema ha sido solucionado en las versiones 9.0beta02."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"Tunnelblick","product":"Tunnelblick","versions":[{"version":">= 3.3beta26, < 9.0beta02","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-05T19:37:28.228929Z","id":"CVE-2026-31893","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-61"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:tunnelblick:tunnelblick:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5.3","versionEndExcluding":"8.0.1","matchCriteriaId":"0091B93B-5FCA-4B34-8578-6D73399E5D7B"},{"vulnerable":true,"criteria":"cpe:2.3:a:tunnelblick:tunnelblick:3.3:beta26:*:*:*:*:*:*","matchCriteriaId":"DA65FDFE-43E0-4846-B674-4EF26613E294"},{"vulnerable":true,"criteria":"cpe:2.3:a:tunnelblick:tunnelblick:8.1:beta01:*:*:*:*:*:*","matchCriteriaId":"E86DA6F9-1B0E-496D-B000-3B53F32F46F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:tunnelblick:tunnelblick:8.1:beta02:*:*:*:*:*:*","matchCriteriaId":"5EEBCC0A-309F-4BF1-8B8E-548588FD9418"},{"vulnerable":true,"criteria":"cpe:2.3:a:tunnelblick:tunnelblick:8.1:beta03:*:*:*:*:*:*","matchCriteriaId":"F94C886A-E185-4A58-B072-56B4D0FA7FAC"},{"vulnerable":true,"criteria":"cpe:2.3:a:tunnelblick:tunnelblick:9.0:beta01:*:*:*:*:*:*","matchCriteriaId":"3BBF415C-6088-4399-B99F-421E08CD79A1"}]}]}],"references":[{"url":"https://github.com/Tunnelblick/Tunnelblick/releases/tag/v9.0beta02","source":"security-advisories@github.com","tags":["Product","Release Notes"]},{"url":"https://github.com/Tunnelblick/Tunnelblick/security/advisories/GHSA-927j-vcjf-hq69","source":"security-advisories@github.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://github.com/Tunnelblick/Tunnelblick/security/advisories/GHSA-927j-vcjf-hq69","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-32603","sourceIdentifier":"security-advisories@github.com","published":"2026-05-05T20:16:35.540","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial of service vulnerability exists in the Sandboxie kernel driver. An unprivileged process running inside a Standard Sandbox can send a malformed IOCTL to the \\Device\\SandboxieDriverApi driver, triggering an immediate kernel crash (BSOD). The vulnerability affects the Standard Sandbox configuration both with and without dropped administrator privileges, but does not affect the Security Hardened Sandbox configuration. This issue has been fixed in version 1.17.3. Users who cannot update can use the Security Hardened Sandbox configuration as a workaround."},{"lang":"es","value":"Sandboxie es un software de aislamiento de código abierto basado en sandbox para Windows. En las versiones 1.17.2 y anteriores, existe una vulnerabilidad de denegación de servicio local en el controlador kernel de Sandboxie. Un proceso sin privilegios ejecutándose dentro de un Sandbox Estándar puede enviar un IOCTL malformado al controlador \\Device\\SandboxieDriverApi, desencadenando un fallo inmediato del kernel (BSOD). La vulnerabilidad afecta la configuración de Sandbox Estándar tanto con como sin privilegios de administrador eliminados, pero no afecta la configuración de Sandbox Reforzado de Seguridad. Este problema ha sido solucionado en la versión 1.17.3. Los usuarios que no puedan actualizar pueden usar la configuración de Sandbox Reforzado de Seguridad como una solución alternativa."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"sandboxie-plus","product":"Sandboxie","versions":[{"version":"< 1.17.3","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.0,"impactScore":4.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-06T14:22:06.508141Z","id":"CVE-2026-32603","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sandboxie-plus:sandboxie:*:*:*:*:plus:*:*:*","versionEndExcluding":"1.17.3","matchCriteriaId":"69CB00B4-502D-4839-B404-93FA214C6978"}]}]}],"references":[{"url":"https://github.com/sandboxie-plus/Sandboxie/releases/tag/v1.17.3","source":"security-advisories@github.com","tags":["Release Notes"]},{"url":"https://github.com/sandboxie-plus/Sandboxie/security/advisories/GHSA-vvf8-cf4j-v8fv","source":"security-advisories@github.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://github.com/sandboxie-plus/Sandboxie/security/advisories/GHSA-vvf8-cf4j-v8fv","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-32699","sourceIdentifier":"security-advisories@github.com","published":"2026-05-05T20:16:35.693","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fails to validate the nick parameter during a POST request to the EditUser controller. Although the user interface prevents editing this field, a user can bypass this restriction by intercepting the request and modifying the nick form-data parameter to rename any account, including the administrator account. This leads to unauthorized modification of a field intended to be immutable."},{"lang":"es","value":"FacturaScripts es un software de código abierto de contabilidad y facturación. En las versiones 2025.92 y anteriores, la aplicación no valida el parámetro nick durante una solicitud POST al controlador EditUser. Aunque la interfaz de usuario impide editar este campo, un usuario puede eludir esta restricción interceptando la solicitud y modificando el parámetro form-data nick para renombrar cualquier cuenta, incluida la cuenta de administrador. Esto conduce a una modificación no autorizada de un campo destinado a ser inmutable."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"NeoRazorX","product":"facturascripts","versions":[{"version":"<= 2025.92","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-05T19:44:24.611038Z","id":"CVE-2026-32699","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-472"}]}],"references":[{"url":"https://github.com/NeoRazorX/facturascripts/security/advisories/GHSA-pp79-hqv6-vmc3","source":"security-advisories@github.com"},{"url":"https://github.com/NeoRazorX/facturascripts/security/advisories/GHSA-pp79-hqv6-vmc3","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-32934","sourceIdentifier":"security-advisories@github.com","published":"2026-05-05T20:16:35.853","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven into unbounded goroutine and memory growth by a remote client that opens many QUIC streams and sends only 1 byte per stream. When the worker pool is full, CoreDNS still spawns a goroutine per accepted stream to wait for a worker token. Additionally, active workers block indefinitely in io.ReadFull() with no per-stream read deadline, allowing an attacker to pin all workers by sending a single byte so the read blocks waiting for the second byte of the DoQ length prefix. This enables an unauthenticated remote attacker to cause memory exhaustion and OOM-kill. This issue has been fixed in version 1.14.3. No known workarounds exist."},{"lang":"es","value":"CoreDNS es un servidor DNS que encadena plugins. En versiones anteriores a la 1.14.3, el servidor DNS-over-QUIC (DoQ) puede ser llevado a un crecimiento ilimitado de goroutines y memoria por un cliente remoto que abre muchas transmisiones QUIC y envía solo 1 byte por transmisión. Cuando el pool de trabajadores está lleno, CoreDNS aún genera una goroutine por transmisión aceptada para esperar un token de trabajador. Además, los trabajadores activos se bloquean indefinidamente en io.ReadFull() sin un plazo de lectura por transmisión, lo que permite a un atacante inmovilizar a todos los trabajadores enviando un solo byte para que la lectura se bloquee esperando el segundo byte del prefijo de longitud DoQ. Esto permite a un atacante remoto no autenticado causar agotamiento de memoria y OOM-kill. Este problema ha sido solucionado en la versión 1.14.3. No existen soluciones alternativas conocidas."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"coredns","product":"coredns","versions":[{"version":"< 1.14.3","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-06T15:14:18.362180Z","id":"CVE-2026-32934","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:coredns.io:coredns:*:*:*:*:*:*:*:*","versionEndExcluding":"1.14.3","matchCriteriaId":"0B1F8FE2-314C-4C38-9F18-099ACCFF0AAD"}]}]}],"references":[{"url":"https://github.com/coredns/coredns/releases/tag/v1.14.3","source":"security-advisories@github.com","tags":["Release Notes"]},{"url":"https://github.com/coredns/coredns/security/advisories/GHSA-2wpx-qpw2-g5h5","source":"security-advisories@github.com","tags":["Exploit","Vendor Advisory"]},{"url":"https://github.com/coredns/coredns/security/advisories/GHSA-2wpx-qpw2-g5h5","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-32936","sourceIdentifier":"security-advisories@github.com","published":"2026-05-05T20:16:36.010","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and performs URL query parsing, base64 decoding, and DNS message unpacking before rejecting the request. Unlike the POST path, which applies a bounded read via http.MaxBytesReader limited to 65536 bytes, the GET path has no equivalent size validation before expensive processing. A remote, unauthenticated attacker can repeatedly send oversized DoH GET requests to force high CPU usage, large transient memory allocations, and elevated garbage-collection pressure, leading to denial of service. This issue has been fixed in version 1.14.3."},{"lang":"es","value":"CoreDNS es un servidor DNS que encadena complementos. En versiones anteriores a la 1.14.3, la ruta GET de DNS-over-HTTPS (DoH) acepta valores de parámetros de consulta 'dns=' sobredimensionados y realiza el análisis de la consulta URL, la decodificación base64 y el desempaquetado del mensaje DNS antes de rechazar la solicitud. A diferencia de la ruta POST, que aplica una lectura acotada a través de http.MaxBytesReader limitada a 65536 bytes, la ruta GET no tiene una validación de tamaño equivalente antes de un procesamiento costoso. Un atacante remoto no autenticado puede enviar repetidamente solicitudes GET de DoH sobredimensionadas para forzar un alto uso de CPU, grandes asignaciones de memoria transitoria y una presión elevada de recolección de basura, lo que lleva a una denegación de servicio. Este problema ha sido solucionado en la versión 1.14.3."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"coredns","product":"coredns","versions":[{"version":"< 1.14.3","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-05T19:32:21.653054Z","id":"CVE-2026-32936","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:coredns.io:coredns:*:*:*:*:*:*:*:*","versionEndExcluding":"1.14.3","matchCriteriaId":"0B1F8FE2-314C-4C38-9F18-099ACCFF0AAD"}]}]}],"references":[{"url":"https://github.com/coredns/coredns/releases/tag/v1.14.3","source":"security-advisories@github.com","tags":["Release Notes"]},{"url":"https://github.com/coredns/coredns/security/advisories/GHSA-63cw-r7xf-jmwr","source":"security-advisories@github.com","tags":["Exploit","Mitigation","Vendor Advisory"]},{"url":"https://github.com/coredns/coredns/security/advisories/GHSA-63cw-r7xf-jmwr","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Mitigation","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-28780","sourceIdentifier":"security@apache.org","published":"2026-05-05T22:16:00.390","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.\nIf mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue."},{"lang":"es","value":"Vulnerabilidad de desbordamiento de búfer basado en montículo en mod_proxy_ajp del Servidor HTTP Apache.\nSi mod_proxy_ajp se conecta a un servidor AJP malicioso, este servidor AJP puede enviar un mensaje AJP malicioso de vuelta a mod_proxy_ajp y hacer que escriba 4 bytes controlados por el atacante después del final de un búfer basado en montículo.\n\nEste problema afecta al Servidor HTTP Apache: hasta 2.4.66.\n\nSe recomienda a los usuarios actualizar a la versión 2.4.67, que corrige el problema."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache HTTP Server","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.4.66","versionType":"semver","status":"affected"}]}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","affectedData":[{"vendor":"Red Hat","product":"JBoss Core Services for RHEL 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"jbcs-httpd24-httpd","cpes":["cpe:/a:redhat:jboss_core_services:1::el8"],"versions":[{"version":"0:2.4.62-13.el8jbcs","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"JBoss Core Services on RHEL 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"jbcs-httpd24-httpd","cpes":["cpe:/a:redhat:jboss_core_services:1::el7"],"versions":[{"version":"0:2.4.62-13.el7jbcs","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"httpd","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:2.4.63-13.el10_2.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"httpd:2.4","cpes":["cpe:/a:redhat:enterprise_linux:8"],"versions":[{"version":"8100020260519200905.489197e6","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"httpd:2.4","cpes":["cpe:/a:redhat:rhel_aus:8.4"],"versions":[{"version":"8040020260702193120.522a0ee4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"httpd:2.4","cpes":["cpe:/a:redhat:rhel_eus_long_life:8.4"],"versions":[{"version":"8040020260702193120.522a0ee4","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"httpd:2.4","cpes":["cpe:/a:redhat:rhel_aus:8.6"],"versions":[{"version":"8060020260702195216.ad008a3a","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"httpd:2.4","cpes":["cpe:/a:redhat:rhel_eus_long_life:8.6"],"versions":[{"version":"8060020260702195216.ad008a3a","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.8 Telecommunications Update Service","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"httpd:2.4","cpes":["cpe:/a:redhat:rhel_tus:8.8"],"versions":[{"version":"8080020260702200145.63b34585","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"httpd:2.4","cpes":["cpe:/a:redhat:rhel_e4s:8.8"],"versions":[{"version":"8080020260702200145.63b34585","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"httpd","cpes":["cpe:/a:redhat:enterprise_linux:9"],"versions":[{"version":"0:2.4.62-13.el9_8.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat JBoss Core Services 2.4.62.SP4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"httpd","cpes":["cpe:/a:redhat:jboss_core_services:1"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"httpd","cpes":["cpe:/o:redhat:enterprise_linux:6"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"httpd","cpes":["cpe:/o:redhat:enterprise_linux:7"]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-06T15:49:38.049896Z","id":"CVE-2026-28780","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-122"}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","description":[{"lang":"en","value":"CWE-787"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*","versionEndExcluding":"2.4.67","matchCriteriaId":"8FF781BA-CF81-400B-A155-4DAE0BD856EE"}]}]}],"references":[{"url":"https://httpd.apache.org/security/vulnerabilities_24.html","source":"security@apache.org","tags":["Release Notes","Vendor Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2026/05/05/9","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:21391","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:21433","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22140","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:27200","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:27201","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36373","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36831","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36846","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-28780","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2466913","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28780.json","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}]}},{"cve":{"id":"CVE-2026-40934","sourceIdentifier":"security-advisories@github.com","published":"2026-05-05T22:16:00.820","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static file at ~/.local/share/jupyter/runtime/jupyter_cookie_secret and is never rotated when a user changes their password. After a password reset and server restart, any previously issued authentication cookie remains cryptographically valid because the signing key has not changed. An attacker who has captured a session cookie through any means retains full authenticated access to the server regardless of subsequent password changes. This affects deployments using password-based authentication, particularly shared or public-facing servers where credential rotation is expected to revoke existing sessions. This issue has been fixed in version 2.18.0."},{"lang":"es","value":"Jupyter Server es el backend para las aplicaciones web de Jupyter. En las versiones 2.17.0 y anteriores, el secreto utilizado para firmar las cookies de autenticación se persiste en un archivo estático en ~/.local/share/jupyter/runtime/jupyter_cookie_secret y nunca se rota cuando un usuario cambia su contraseña. Después de un restablecimiento de contraseña y un reinicio del servidor, cualquier cookie de autenticación emitida previamente permanece criptográficamente válida porque la clave de firma no ha cambiado. Un atacante que ha capturado una cookie de sesión por cualquier medio retiene acceso autenticado completo al servidor independientemente de los cambios de contraseña posteriores. Esto afecta a las implementaciones que utilizan autenticación basada en contraseña, particularmente servidores compartidos o de cara al público donde se espera que la rotación de credenciales revoque las sesiones existentes. Este problema ha sido solucionado en la versión 2.18.0."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"jupyter-server","product":"jupyter_server","versions":[{"version":"< 2.18.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-07T03:55:46.015938Z","id":"CVE-2026-40934","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-613"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:jupyter:jupyter_server:*:*:*:*:*:*:*:*","versionEndExcluding":"2.18.0","matchCriteriaId":"E0B6C703-7E28-4F23-9878-E157975C32A4"}]}]}],"references":[{"url":"https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5mrq-x3x5-8v8f","source":"security-advisories@github.com","tags":["Exploit","Mitigation","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-71251","sourceIdentifier":"security@unisoc.com","published":"2026-05-06T02:16:03.400","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed."},{"lang":"es","value":"En IMS, existe una posible caída del sistema debido a una validación de entrada incorrecta. Esto podría llevar a una denegación de servicio remota sin necesidad de privilegios de ejecución adicionales."}],"affected":[{"source":"security@unisoc.com","affectedData":[{"vendor":"Unisoc (Shanghai) Technologies Co., Ltd.","product":"SC7731E/SC9832E/SC9863A/T310/T610/T618/T7200/T7225/T7250/T7255/T7280/T7300/T8100/T9100/T8200/T8300","defaultStatus":"unaffected","versions":[{"version":"Android13/Android14/Android15/Android16","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@unisoc.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-06T14:37:57.701643Z","id":"CVE-2025-71251","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*","matchCriteriaId":"879FFD0C-9B38-4CAA-B057-1086D794D469"},{"vulnerable":true,"criteria":"cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*","matchCriteriaId":"2700BCC5-634D-4EC6-AB67-5B678D5F951D"},{"vulnerable":true,"criteria":"cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*","matchCriteriaId":"8538774C-906D-4B03-A3E7-FA7A55E0DA9E"},{"vulnerable":true,"criteria":"cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*","matchCriteriaId":"02882AB1-7993-47DD-84A0-8DF4272D85ED"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:sc7731e:-:*:*:*:*:*:*:*","matchCriteriaId":"AC867249-B767-4802-868D-6D0E356C8294"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:sc9832e:-:*:*:*:*:*:*:*","matchCriteriaId":"25BBD3C5-E87C-4730-970C-19DF855AC3A2"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:sc9863a:-:*:*:*:*:*:*:*","matchCriteriaId":"DE00DFDE-97DD-4D33-B580-73FEF677C71B"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t310:-:*:*:*:*:*:*:*","matchCriteriaId":"F20E00D8-2F00-4FA3-9455-37DC89908D96"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t610:-:*:*:*:*:*:*:*","matchCriteriaId":"CDC980D6-B797-4AE1-B553-35395AE80D07"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t618:-:*:*:*:*:*:*:*","matchCriteriaId":"39002ECE-636A-4FEB-9A0B-8127E8AAC844"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t7200:-:*:*:*:*:*:*:*","matchCriteriaId":"814A8ADD-9AFB-43AD-A341-E6475F4150ED"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t7225:-:*:*:*:*:*:*:*","matchCriteriaId":"02739649-98EC-45CC-8CF4-404A55FAE398"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t7250:-:*:*:*:*:*:*:*","matchCriteriaId":"855F9E13-B4E4-4E74-85C2-F6F9EF4DA916"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t7255:-:*:*:*:*:*:*:*","matchCriteriaId":"E51D591C-58C5-4F75-B631-58275E3F5776"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t7280:-:*:*:*:*:*:*:*","matchCriteriaId":"1B0FDCBD-BC38-4C7E-94ED-29F5EA852F39"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t7300:-:*:*:*:*:*:*:*","matchCriteriaId":"04D97A60-C848-4948-A84D-80332B1D5BBA"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t8100:-:*:*:*:*:*:*:*","matchCriteriaId":"F2DA04F2-5351-4043-A330-5397E627A222"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t8200:-:*:*:*:*:*:*:*","matchCriteriaId":"FC033D2C-ED1A-4EAB-A77B-8E1C88C74B0A"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t8300:-:*:*:*:*:*:*:*","matchCriteriaId":"DC7743D5-B187-48D4-BC77-D8DCDF263166"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t9100:-:*:*:*:*:*:*:*","matchCriteriaId":"9D1F3B9D-142F-4E70-8477-E26D921EF19A"}]}]}],"references":[{"url":"https://www.unisoc.com/en/support/product-security-bulletin/2051836844671422466","source":"security@unisoc.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-71253","sourceIdentifier":"security@unisoc.com","published":"2026-05-06T02:16:04.857","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed."},{"lang":"es","value":"En Modem IMS, existe una posible validación de entrada incorrecta. Esto podría llevar a una denegación de servicio remota sin necesidad de privilegios de ejecución adicionales."}],"affected":[{"source":"security@unisoc.com","affectedData":[{"vendor":"Unisoc (Shanghai) Technologies Co., Ltd.","product":"SC7731E/SC9832E/SC9863A/T310/T610/T618/T7200/T7225/T7250/T7255/T7280/T7300/T8100/T9100/T8200/T8300","defaultStatus":"unaffected","versions":[{"version":"Android13/Android14/Android15/Android16","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@unisoc.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-06T14:06:05.207342Z","id":"CVE-2025-71253","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*","matchCriteriaId":"879FFD0C-9B38-4CAA-B057-1086D794D469"},{"vulnerable":true,"criteria":"cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*","matchCriteriaId":"2700BCC5-634D-4EC6-AB67-5B678D5F951D"},{"vulnerable":true,"criteria":"cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*","matchCriteriaId":"8538774C-906D-4B03-A3E7-FA7A55E0DA9E"},{"vulnerable":true,"criteria":"cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*","matchCriteriaId":"02882AB1-7993-47DD-84A0-8DF4272D85ED"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:sc7731e:-:*:*:*:*:*:*:*","matchCriteriaId":"AC867249-B767-4802-868D-6D0E356C8294"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:sc9832e:-:*:*:*:*:*:*:*","matchCriteriaId":"25BBD3C5-E87C-4730-970C-19DF855AC3A2"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:sc9863a:-:*:*:*:*:*:*:*","matchCriteriaId":"DE00DFDE-97DD-4D33-B580-73FEF677C71B"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t310:-:*:*:*:*:*:*:*","matchCriteriaId":"F20E00D8-2F00-4FA3-9455-37DC89908D96"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t610:-:*:*:*:*:*:*:*","matchCriteriaId":"CDC980D6-B797-4AE1-B553-35395AE80D07"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t618:-:*:*:*:*:*:*:*","matchCriteriaId":"39002ECE-636A-4FEB-9A0B-8127E8AAC844"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t7200:-:*:*:*:*:*:*:*","matchCriteriaId":"814A8ADD-9AFB-43AD-A341-E6475F4150ED"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t7225:-:*:*:*:*:*:*:*","matchCriteriaId":"02739649-98EC-45CC-8CF4-404A55FAE398"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t7250:-:*:*:*:*:*:*:*","matchCriteriaId":"855F9E13-B4E4-4E74-85C2-F6F9EF4DA916"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t7255:-:*:*:*:*:*:*:*","matchCriteriaId":"E51D591C-58C5-4F75-B631-58275E3F5776"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t7280:-:*:*:*:*:*:*:*","matchCriteriaId":"1B0FDCBD-BC38-4C7E-94ED-29F5EA852F39"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t7300:-:*:*:*:*:*:*:*","matchCriteriaId":"04D97A60-C848-4948-A84D-80332B1D5BBA"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t8100:-:*:*:*:*:*:*:*","matchCriteriaId":"F2DA04F2-5351-4043-A330-5397E627A222"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t8200:-:*:*:*:*:*:*:*","matchCriteriaId":"FC033D2C-ED1A-4EAB-A77B-8E1C88C74B0A"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t8300:-:*:*:*:*:*:*:*","matchCriteriaId":"DC7743D5-B187-48D4-BC77-D8DCDF263166"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t9100:-:*:*:*:*:*:*:*","matchCriteriaId":"9D1F3B9D-142F-4E70-8477-E26D921EF19A"}]}]}],"references":[{"url":"https://www.unisoc.com/en/support/product-security-bulletin/2051836844671422466","source":"security@unisoc.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-71256","sourceIdentifier":"security@unisoc.com","published":"2026-05-06T02:16:05.213","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed."},{"lang":"es","value":"En el módem nr, existe una posible validación de entrada incorrecta. Esto podría llevar a una denegación de servicio remota sin necesidad de privilegios de ejecución adicionales."}],"affected":[{"source":"security@unisoc.com","affectedData":[{"vendor":"Unisoc (Shanghai) Technologies Co., Ltd.","product":"T8100/T9100/T8200/T8300","defaultStatus":"unaffected","versions":[{"version":"Android13/Android14/Android15/Android16","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@unisoc.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-06T12:55:53.778503Z","id":"CVE-2025-71256","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*","matchCriteriaId":"879FFD0C-9B38-4CAA-B057-1086D794D469"},{"vulnerable":true,"criteria":"cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*","matchCriteriaId":"2700BCC5-634D-4EC6-AB67-5B678D5F951D"},{"vulnerable":true,"criteria":"cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*","matchCriteriaId":"8538774C-906D-4B03-A3E7-FA7A55E0DA9E"},{"vulnerable":true,"criteria":"cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*","matchCriteriaId":"02882AB1-7993-47DD-84A0-8DF4272D85ED"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t8100:-:*:*:*:*:*:*:*","matchCriteriaId":"F2DA04F2-5351-4043-A330-5397E627A222"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t8200:-:*:*:*:*:*:*:*","matchCriteriaId":"FC033D2C-ED1A-4EAB-A77B-8E1C88C74B0A"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t8300:-:*:*:*:*:*:*:*","matchCriteriaId":"DC7743D5-B187-48D4-BC77-D8DCDF263166"},{"vulnerable":false,"criteria":"cpe:2.3:h:unisoc:t9100:-:*:*:*:*:*:*:*","matchCriteriaId":"9D1F3B9D-142F-4E70-8477-E26D921EF19A"}]}]}],"references":[{"url":"https://www.unisoc.com/en/support/product-security-bulletin/2051836844671422466","source":"security@unisoc.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-3208","sourceIdentifier":"security@wordfence.com","published":"2026-05-06T04:16:06.223","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mp_pix_image' WooCommerce API endpoint in all versions up to, and including, 8.7.11. This makes it possible for unauthenticated attackers to retrieve PIX payment QR code images for arbitrary orders. PIX QR codes contain sensitive merchant information including PIX keys (which may be CPF/CNPJ personal identifiers), transaction amounts, merchant name and city, and MercadoPago transaction references."},{"lang":"es","value":"El plugin de pagos de Mercado Pago para WooCommerce para WordPress es vulnerable a acceso no autorizado a datos debido a una verificación de capacidad faltante en el endpoint de la API de WooCommerce 'mp_pix_image' en todas las versiones hasta, e incluyendo, la 8.7.11. Esto hace posible que atacantes no autenticados recuperen imágenes de códigos QR de pago PIX para pedidos arbitrarios. Los códigos QR PIX contienen información sensible del comerciante, incluyendo claves PIX (que pueden ser identificadores personales CPF/CNPJ), montos de transacción, nombre y ciudad del comerciante, y referencias de transacción de MercadoPago."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"mercadopago","product":"Mercado Pago payments for WooCommerce","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"8.7.11","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-06T12:20:50.759573Z","id":"CVE-2026-3208","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/woocommerce-mercadopago/tags/8.7.10/src/Gateways/PixGateway.php#L358","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/woocommerce-mercadopago/tags/8.7.10/src/Gateways/PixGateway.php#L92","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=%2Fwoocommerce-mercadopago/tags/8.7.11&new_path=%2Fwoocommerce-mercadopago/tags/8.7.12","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/986e0252-b94d-4ac8-9083-0218fa8a651e?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-42452","sourceIdentifier":"security-advisories@github.com","published":"2026-05-08T23:16:38.827","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, /users/login issues a temporary JWT (temp_token) for TOTP-enabled accounts. That token carries a pendingTOTP state and should only be valid for the second-factor flow. However, the auth middleware accepts this token on regular authenticated endpoints. This effectively turns 2FA into single-factor (password) for impacted accounts. This issue has been patched in version 2.1.0."},{"lang":"es","value":"Termix es una plataforma de gestión de servidores basada en web con capacidades de terminal SSH, tunelización y edición de archivos. Antes de la versión 2.1.0, /users/login emite un JWT temporal (temp_token) para cuentas con TOTP habilitado. Ese token lleva un estado pendingTOTP y solo debería ser válido para el flujo del segundo factor. Sin embargo, el middleware de autenticación acepta este token en puntos finales autenticados regulares. Esto convierte efectivamente la 2FA en un factor único (contraseña) para las cuentas afectadas. Este problema ha sido parcheado en la versión 2.1.0."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"Termix-SSH","product":"Termix","versions":[{"version":"< 2.1.0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-12T02:14:12.163245Z","id":"CVE-2026-42452","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-304"}]}],"references":[{"url":"https://github.com/Termix-SSH/Termix/releases/tag/release-2.1.0-tag","source":"security-advisories@github.com"},{"url":"https://github.com/Termix-SSH/Termix/security/advisories/GHSA-vx59-rf9w-9jv8","source":"security-advisories@github.com"},{"url":"https://github.com/Termix-SSH/Termix/security/advisories/GHSA-vx59-rf9w-9jv8","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-42453","sourceIdentifier":"security-advisories@github.com","published":"2026-05-08T23:16:38.967","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, the extractArchive and compressFiles endpoints in file-manager.ts use double-quoted strings for shell command construction, unlike all other file manager operations which use single-quote escaping. Double quotes allow $(command) substitution, enabling command injection on the remote SSH host. This issue has been patched in version 2.1.0."},{"lang":"es","value":"Termix es una plataforma de gestión de servidores basada en web con capacidades de terminal SSH, tunelización y edición de archivos. Antes de la versión 2.1.0, los endpoints extractArchive y compressFiles en file-manager.ts utilizan cadenas de caracteres entre comillas dobles para la construcción de comandos de shell, a diferencia de todas las demás operaciones del gestor de archivos que utilizan el escape con comillas simples. Las comillas dobles permiten la sustitución de $(command), lo que posibilita la inyección de comandos en el host SSH remoto. Este problema ha sido parcheado en la versión 2.1.0."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"Termix-SSH","product":"Termix","versions":[{"version":"< 2.1.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T17:53:27.797695Z","id":"CVE-2026-42453","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]}],"references":[{"url":"https://github.com/Termix-SSH/Termix/releases/tag/release-2.1.0-tag","source":"security-advisories@github.com"},{"url":"https://github.com/Termix-SSH/Termix/security/advisories/GHSA-rvg4-7vvq-9c2w","source":"security-advisories@github.com"},{"url":"https://github.com/Termix-SSH/Termix/security/advisories/GHSA-rvg4-7vvq-9c2w","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2025-15633","sourceIdentifier":"psirt@hcl.com","published":"2026-05-09T06:16:07.413","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via unprotected endpoints lacking adequate security headers."},{"lang":"es","value":"Una vulnerabilidad de autorización impropia en HCL BigFix WebUI permite a un usuario autenticado sin privilegios de Operador Maestro acceder a datos internos (nombres de sitios, versiones y variables de configuración) y eludir los requisitos de privilegios a través de puntos finales desprotegidos que carecen de encabezados de seguridad adecuados."}],"affected":[{"source":"psirt@hcl.com","affectedData":[{"vendor":"HCLSoftware","product":"BigFix WebUI","defaultStatus":"unaffected","versions":[{"version":"all versions","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"psirt@hcl.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T17:29:56.867689Z","id":"CVE-2025-15633","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@hcl.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_api:*:*:*:*:*:*:*:*","versionEndExcluding":"33","matchCriteriaId":"8680650F-B404-4812-AD8D-F93A7F52C20B"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_application_administration:*:*:*:*:*:*:*:*","versionEndExcluding":"40","matchCriteriaId":"D8757E08-9B05-45FD-BEAC-7D27423C7FC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_cmep:*:*:*:*:*:*:*:*","versionEndExcluding":"22","matchCriteriaId":"DD60E500-25B7-42B4-8B0E-D84967B78AF4"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_common:*:*:*:*:*:*:*:*","versionEndExcluding":"101","matchCriteriaId":"E6441EA2-8CF7-4A3B-8AD8-BBE2A62E5DF4"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_content_app:*:*:*:*:*:*:*:*","versionEndExcluding":"28","matchCriteriaId":"CFE1EED8-C5C9-47CD-B20E-E5D113B4DF48"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_custom:*:*:*:*:*:*:*:*","versionEndExcluding":"50","matchCriteriaId":"92437F31-8DD7-4440-AF6A-02B5DDA55A3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_data_sync:*:*:*:*:*:*:*:*","versionEndExcluding":"37","matchCriteriaId":"9F3C0E3C-1CE1-43FC-9B4C-8D0EE77E3E10"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_extensions:*:*:*:*:*:*:*:*","versionEndExcluding":"14","matchCriteriaId":"0F22F7CB-24CC-445F-87D9-CB0B4346401E"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_framework:*:*:*:*:*:*:*:*","versionEndExcluding":"35","matchCriteriaId":"B7C2A16C-A840-47FF-9272-A17BD4CD7499"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_insights:*:*:*:*:*:*:*:*","versionEndExcluding":"32","matchCriteriaId":"97643BD1-2CE5-43A4-86C9-C25EE643E977"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_ivr:*:*:*:*:*:*:*:*","versionEndExcluding":"23","matchCriteriaId":"58DA2A15-7F8A-4D04-A158-18CBB803BF8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_mdm:*:*:*:*:*:*:*:*","versionEndExcluding":"29","matchCriteriaId":"A1287A97-8E7A-4B5F-BE14-2D871BD2E886"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_patch:*:*:*:*:*:*:*:*","versionEndExcluding":"54","matchCriteriaId":"5CA0410D-FC23-4F02-B460-3AAF36534B35"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_patch_policies:*:*:*:*:*:*:*:*","versionEndExcluding":"51","matchCriteriaId":"99FC5DA2-E98F-4EE7-ABC1-9CAE3141DE63"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_permissions_and_preferences:*:*:*:*:*:*:*:*","versionEndExcluding":"27","matchCriteriaId":"14A1AC9F-42FA-4CEA-9198-78F902069EB5"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_profile_management:*:*:*:*:*:*:*:*","versionEndExcluding":"33","matchCriteriaId":"7EC90454-5ACF-437A-98E5-4FA331436BAB"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_query:*:*:*:*:*:*:*:*","versionEndExcluding":"45","matchCriteriaId":"C9399A9A-9034-45E1-848A-96618F90AE9A"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_reports:*:*:*:*:*:*:*:*","versionEndExcluding":"24","matchCriteriaId":"76DCC419-4FDB-4863-847D-346BF4EC3458"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_scm:*:*:*:*:*:*:*:*","versionEndExcluding":"20","matchCriteriaId":"5AF61FBA-D9FA-4D8F-9C63-BDB7266281E3"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_software_distribution:*:*:*:*:*:*:*:*","versionEndExcluding":"54","matchCriteriaId":"78E47D3B-035E-4B5A-90FB-B15262EE93F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_take_action:*:*:*:*:*:*:*:*","versionEndExcluding":"37","matchCriteriaId":"8E08C0D1-A177-40F8-B5E0-EA14D66B38FC"}]}]}],"references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0130587","source":"psirt@hcl.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2025-15634","sourceIdentifier":"psirt@hcl.com","published":"2026-05-09T06:16:09.130","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page."},{"lang":"es","value":"Una vulnerabilidad de falta de autorización en HCL BigFix WebUI permite a un usuario autenticado sin los permisos adecuados ver información ambiental sensible mediante acceso directo a la URL de la página no autorizada."}],"affected":[{"source":"psirt@hcl.com","affectedData":[{"vendor":"HCLSoftware","product":"BigFix WebUI","defaultStatus":"unaffected","versions":[{"version":"all versions","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"psirt@hcl.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T15:20:44.562308Z","id":"CVE-2025-15634","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@hcl.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_api:*:*:*:*:*:*:*:*","versionEndExcluding":"33","matchCriteriaId":"8680650F-B404-4812-AD8D-F93A7F52C20B"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_application_administration:*:*:*:*:*:*:*:*","versionEndExcluding":"40","matchCriteriaId":"D8757E08-9B05-45FD-BEAC-7D27423C7FC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_cmep:*:*:*:*:*:*:*:*","versionEndExcluding":"22","matchCriteriaId":"DD60E500-25B7-42B4-8B0E-D84967B78AF4"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_common:*:*:*:*:*:*:*:*","versionEndExcluding":"101","matchCriteriaId":"E6441EA2-8CF7-4A3B-8AD8-BBE2A62E5DF4"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_content_app:*:*:*:*:*:*:*:*","versionEndExcluding":"28","matchCriteriaId":"CFE1EED8-C5C9-47CD-B20E-E5D113B4DF48"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_custom:*:*:*:*:*:*:*:*","versionEndExcluding":"50","matchCriteriaId":"92437F31-8DD7-4440-AF6A-02B5DDA55A3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_data_sync:*:*:*:*:*:*:*:*","versionEndExcluding":"37","matchCriteriaId":"9F3C0E3C-1CE1-43FC-9B4C-8D0EE77E3E10"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_extensions:*:*:*:*:*:*:*:*","versionEndExcluding":"14","matchCriteriaId":"0F22F7CB-24CC-445F-87D9-CB0B4346401E"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_framework:*:*:*:*:*:*:*:*","versionEndExcluding":"35","matchCriteriaId":"B7C2A16C-A840-47FF-9272-A17BD4CD7499"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_insights:*:*:*:*:*:*:*:*","versionEndExcluding":"32","matchCriteriaId":"97643BD1-2CE5-43A4-86C9-C25EE643E977"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_ivr:*:*:*:*:*:*:*:*","versionEndExcluding":"23","matchCriteriaId":"58DA2A15-7F8A-4D04-A158-18CBB803BF8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_mdm:*:*:*:*:*:*:*:*","versionEndExcluding":"29","matchCriteriaId":"A1287A97-8E7A-4B5F-BE14-2D871BD2E886"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_patch:*:*:*:*:*:*:*:*","versionEndExcluding":"54","matchCriteriaId":"5CA0410D-FC23-4F02-B460-3AAF36534B35"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_patch_policies:*:*:*:*:*:*:*:*","versionEndExcluding":"51","matchCriteriaId":"99FC5DA2-E98F-4EE7-ABC1-9CAE3141DE63"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_permissions_and_preferences:*:*:*:*:*:*:*:*","versionEndExcluding":"27","matchCriteriaId":"14A1AC9F-42FA-4CEA-9198-78F902069EB5"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_profile_management:*:*:*:*:*:*:*:*","versionEndExcluding":"33","matchCriteriaId":"7EC90454-5ACF-437A-98E5-4FA331436BAB"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_query:*:*:*:*:*:*:*:*","versionEndExcluding":"45","matchCriteriaId":"C9399A9A-9034-45E1-848A-96618F90AE9A"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_reports:*:*:*:*:*:*:*:*","versionEndExcluding":"24","matchCriteriaId":"76DCC419-4FDB-4863-847D-346BF4EC3458"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_scm:*:*:*:*:*:*:*:*","versionEndExcluding":"20","matchCriteriaId":"5AF61FBA-D9FA-4D8F-9C63-BDB7266281E3"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_software_distribution:*:*:*:*:*:*:*:*","versionEndExcluding":"54","matchCriteriaId":"78E47D3B-035E-4B5A-90FB-B15262EE93F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:hcltech:bigfix_webui_take_action:*:*:*:*:*:*:*:*","versionEndExcluding":"37","matchCriteriaId":"8E08C0D1-A177-40F8-B5E0-EA14D66B38FC"}]}]}],"references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0130587","source":"psirt@hcl.com","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-1749","sourceIdentifier":"hsrc@hikvision.com","published":"2026-05-09T09:16:08.823","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission."},{"lang":"es","value":"Hay una Vulnerabilidad de control de acceso en algunas versiones de HikCentral Professional. Esto podría permitir a un usuario no autenticado obtener el permiso de administrador."}],"affected":[{"source":"hsrc@hikvision.com","affectedData":[{"vendor":"Hikvision","product":"HikCentral Professional","versions":[{"version":"V2.4.0~V3.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"hsrc@hikvision.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":4.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T15:21:36.019611Z","id":"CVE-2026-1749","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerability-in-hikcentral-professional/","source":"hsrc@hikvision.com"}]}},{"cve":{"id":"CVE-2026-32683","sourceIdentifier":"hsrc@hikvision.com","published":"2026-05-09T09:16:08.973","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"Some EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transmission risk. Attackers can exploit this by eavesdropping on network requests to obtain data.Users are advised to upgrade the app to the latest version and enable the video encryption feature."},{"lang":"es","value":"Algunos productos EZVIZ utilizan versiones antiguas de módulos de funciones en la nube con interfaces de API heredadas, lo que plantea un riesgo de transmisión de datos. Los atacantes pueden explotar esto al interceptar solicitudes de red para obtener datos. Se aconseja a los usuarios que actualicen la aplicación a la última versión y activen la función de cifrado de vídeo."}],"affected":[{"source":"hsrc@hikvision.com","affectedData":[{"vendor":"EZVIZ","product":"EZVIZ APP","versions":[{"version":"iOS: Versions prior to 7.3.1","status":"affected"},{"version":"Android: Versions prior to 7.3.0.0210","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"hsrc@hikvision.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T17:29:08.128087Z","id":"CVE-2026-32683","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-319"}]}],"references":[{"url":"https://www.ezviz.com/inter/trust-center/security/security-notice/2026.05.08","source":"hsrc@hikvision.com"},{"url":"https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerability-in-cloud-function-modules-of-some-hikvisi/","source":"hsrc@hikvision.com"}]}},{"cve":{"id":"CVE-2025-14179","sourceIdentifier":"security@php.net","published":"2026-05-10T05:16:09.853","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements."},{"lang":"es","value":"En versiones de PHP 8.2.* anteriores a 8.2.31, 8.3.* anteriores a 8.3.31, 8.4.* anteriores a 8.4.21, y 8.5.* anteriores a 8.5.6, el controlador PDO Firebird maneja incorrectamente los bytes NUL al preparar consultas SQL. Durante la construcción de consultas token por token, un token de cadena que contiene un byte NUL se copia mediante strncat(), lo que se detiene en el byte NUL, eliminando la comilla de cierre y haciendo que los tokens SQL subsiguientes se interpreten como parte de la cadena. Esto permite la inyección SQL cuando los valores controlados por el atacante se citan mediante PDO::quote() y se incrustan en sentencias SQL."}],"affected":[{"source":"security@php.net","affectedData":[{"vendor":"PHP Group","product":"PHP","defaultStatus":"affected","packageName":"pdo_firebird","versions":[{"version":"8.2.*","lessThan":"8.2.31","versionType":"semver","status":"affected"},{"version":"8.3.*","lessThan":"8.3.31","versionType":"semver","status":"affected"},{"version":"8.4.*","lessThan":"8.4.21","versionType":"semver","status":"affected"},{"version":"8.5.*","lessThan":"8.5.6","versionType":"semver","status":"affected"}]}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","affectedData":[{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"php","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"php8.4","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"php","cpes":["cpe:/o:redhat:enterprise_linux:6"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"php","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"php:7.4/php","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"php:8.2/php","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"php","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"php:8.2/php","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"php:8.3/php","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"php","cpes":["cpe:/a:redhat:hummingbird:1"]}]}],"metrics":{"cvssMetricV40":[{"source":"security@php.net","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:Amber","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"YES","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"MODERATE","providerUrgency":"AMBER"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T15:23:23.501909Z","id":"CVE-2025-14179","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@php.net","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionStartIncluding":"8.2.0","versionEndExcluding":"8.2.31","matchCriteriaId":"A892B6FF-F4EB-40C6-8DD0-D2246A71D271"},{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionStartIncluding":"8.3.0","versionEndExcluding":"8.3.31","matchCriteriaId":"9DBBB51D-F0C4-4CEC-9B6B-33D0BF0044A5"},{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionStartIncluding":"8.4.0","versionEndExcluding":"8.4.21","matchCriteriaId":"BA663C03-392C-41CC-BD11-4A1245203C42"},{"vulnerable":true,"criteria":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","versionStartIncluding":"8.5.0","versionEndExcluding":"8.5.6","matchCriteriaId":"6101DA12-5AA1-4882-A52A-61FB74254F9A"}]}]}],"references":[{"url":"https://github.com/php/php-src/security/advisories/GHSA-w476-322c-wpvm","source":"security@php.net","tags":["Vendor Advisory"]},{"url":"https://access.redhat.com/security/cve/CVE-2025-14179","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2468567","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14179.json","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}]}},{"cve":{"id":"CVE-2021-47907","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:27.247","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Rocket LMS 1.1 contains a persistent cross-site scripting vulnerability in the support ticket module that allows authenticated users to inject malicious script code through the title parameter. Attackers can submit support tickets with embedded HTML/JavaScript payloads that execute in the browsers of other users viewing the message history, enabling session hijacking and phishing attacks."},{"lang":"es","value":"Rocket LMS 1.1 contiene una vulnerabilidad de cross-site scripting persistente en el módulo de tickets de soporte que permite a usuarios autenticados inyectar código de script malicioso a través del parámetro de título. Los atacantes pueden enviar tickets de soporte con cargas útiles HTML/JavaScript incrustadas que se ejecutan en los navegadores de otros usuarios que ven el historial de mensajes, lo que permite el secuestro de sesión y ataques de phishing."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Rocketsoft","product":"Rocket LMS","versions":[{"version":"1.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T16:16:50.637462Z","id":"CVE-2021-47907","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://lms.rocket-soft.org/","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50677","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/rocket-lms-persistent-cross-site-scripting-via-support-tickets","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47910","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:27.890","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"AccessPress Social Icons 1.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by entering JavaScript payloads into the 'icon title' field. Attackers can store XSS payloads like image tags with onerror event handlers that execute when the plugin page is viewed, affecting all users who access the plugin interface."},{"lang":"es","value":"AccessPress Social Icons 1.8.2 contiene una vulnerabilidad de cross-site scripting almacenado que permite a atacantes autenticados inyectar scripts maliciosos al introducir cargas útiles de JavaScript en el campo 'icon title'. Los atacantes pueden almacenar cargas útiles de XSS como etiquetas de imagen con manejadores de eventos onerror que se ejecutan cuando se visualiza la página del plugin, afectando a todos los usuarios que acceden a la interfaz del plugin."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Accesspressthemes","product":"AccessPress Social Icons","versions":[{"version":"1.8.2","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T13:16:37.450302Z","id":"CVE-2021-47910","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://accesspressthemes.com/","source":"disclosure@vulncheck.com"},{"url":"https://wordpress.org/plugins/accesspress-social-icons/","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50515","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wordpress-plugin-accesspress-social-icons-stored-xss","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47922","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:28.033","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Slider by Soliloquy 2.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the title parameter. Attackers can add JavaScript payloads in the title field when creating or editing sliders, which executes in the browsers of users viewing the slider on both administrative and frontend pages."},{"lang":"es","value":"Slider de Soliloquy 2.6.2 contiene una vulnerabilidad de cross-site scripting almacenado que permite a atacantes autenticados inyectar scripts maliciosos a través del parámetro de título. Los atacantes pueden añadir cargas útiles de JavaScript en el campo de título al crear o editar sliders, que se ejecuta en los navegadores de los usuarios que ven el slider tanto en páginas administrativas como en páginas de frontend."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Soliloquywp","product":"Slider by Soliloquy","versions":[{"version":"2.6.2","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T14:46:56.546666Z","id":"CVE-2021-47922","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://soliloquywp.com/","source":"disclosure@vulncheck.com"},{"url":"https://wordpress.org/plugins/soliloquy-lite/","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50563","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wordpress-plugin-slider-by-soliloquy-stored-xss","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47923","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:28.170","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitrary values into the OCSESSID cookie. Attackers can set malicious OCSESSID cookie values that the server accepts and maintains, enabling session takeover and unauthorized access to user accounts."},{"lang":"es","value":"OpenCart 3.0.3.8 contiene una vulnerabilidad de fijación de sesión que permite a los atacantes secuestrar sesiones de usuario inyectando valores arbitrarios en la cookie OCSESSID. Los atacantes pueden establecer valores maliciosos para la cookie OCSESSID que el servidor acepta y mantiene, lo que permite la toma de control de la sesión y el acceso no autorizado a las cuentas de usuario."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Opencart","product":"opencart","versions":[{"version":"3.0.3.8","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T15:14:23.062449Z","id":"CVE-2021-47923","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-290"}]}],"references":[{"url":"https://www.exploit-db.com/exploits/50555","source":"disclosure@vulncheck.com"},{"url":"https://www.opencart.com/","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/opencart-session-fixation-via-ocsessid-cookie","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47924","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:28.307","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Ultimate Product Catalogue 5.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the price parameter. Attackers can submit POST requests to post.php with HTML/JavaScript payloads in the price field to execute arbitrary code when the product is viewed."},{"lang":"es","value":"Ultimate Product Catalog 5.8.2 contiene una vulnerabilidad de cross-site scripting almacenado que permite a atacantes autenticados inyectar scripts maliciosos a través del parámetro 'price'. Los atacantes pueden enviar solicitudes POST a post.php con cargas útiles HTML/JavaScript en el campo 'price' para ejecutar código arbitrario cuando se visualiza el producto."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Etoilewebdesign","product":"Ultimate Product Catalogue","defaultStatus":"unaffected","versions":[{"version":"5.8.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-12T02:37:22.138280Z","id":"CVE-2021-47924","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://wordpress.org/plugins/ultimate-product-catalogue/","source":"disclosure@vulncheck.com"},{"url":"https://www.etoilewebdesign.com","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50534","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wordpress-plugin-ultimate-product-catalog-stored-xss-via-price","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47925","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:28.437","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"CMDBuild 3.3.2 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject arbitrary web script or HTML via crafted input in card creation and file upload endpoints. Attackers can inject XSS payloads through Employee card parameters or SVG file attachments in the classes endpoint, which execute when other users view the affected records or preview attachments."},{"lang":"es","value":"CMDBuild 3.3.2 contiene múltiples vulnerabilidades de cross-site scripting almacenado que permiten a atacantes autenticados inyectar scripts web o HTML arbitrarios a través de entradas manipuladas en los puntos finales de creación de tarjetas y carga de archivos. Los atacantes pueden inyectar cargas útiles de XSS a través de los parámetros de la tarjeta de Empleado o adjuntos de archivos SVG en el punto final de clases, que se ejecutan cuando otros usuarios ven los registros afectados o previsualizan los adjuntos."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Cmdbuild","product":"CMDBuild","versions":[{"version":"CMDBuild 3.3.2","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T11:55:26.749432Z","id":"CVE-2021-47925","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://www.cmdbuild.org","source":"disclosure@vulncheck.com"},{"url":"https://www.cmdbuild.org/en/download/latest-version","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50527","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/cmdbuild-multiple-stored-cross-site-scripting","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47926","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:28.573","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating forms with script tags in the form name field. Attackers can craft form names containing JavaScript code that executes when other logged-in users access the form management page, enabling session hijacking or credential theft."},{"lang":"es","value":"Contact Form to Email 1.3.24 contiene una vulnerabilidad de cross-site scripting almacenado que permite a atacantes autenticados inyectar scripts maliciosos al crear formularios con etiquetas de script en el campo de nombre del formulario. Los atacantes pueden elaborar nombres de formulario que contienen código JavaScript que se ejecuta cuando otros usuarios con sesión iniciada acceden a la página de gestión de formularios, lo que permite el secuestro de sesión o el robo de credenciales."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Form2Email","product":"Contact Form to Email","versions":[{"version":"1.3.24","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T16:14:03.547475Z","id":"CVE-2021-47926","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://form2email.dwbooster.com/","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50524","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wordpress-contact-form-to-email-stored-xss","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47927","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:28.707","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"WordPress Plugin WP Symposium Pro 2021.10 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting insufficient sanitization of the forum name parameter. Attackers can submit POST requests to the admin setup page with JavaScript payloads in the wps_admin_forum_add_name parameter, which are stored and executed when the forum is accessed."},{"lang":"es","value":"El plugin de WordPress WP Symposium Pro 2021.10 contiene una vulnerabilidad de cross-site scripting almacenado que permite a atacantes autenticados inyectar scripts maliciosos explotando la sanitización insuficiente del parámetro del nombre del foro. Los atacantes pueden enviar solicitudes POST a la página de configuración de administración con cargas útiles de JavaScript en el parámetro wps_admin_forum_add_name, las cuales son almacenadas y ejecutadas cuando se accede al foro."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Wpsymposiumpro","product":"WP Symposium Pro","versions":[{"version":"2021.10","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T13:17:54.815158Z","id":"CVE-2021-47927","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"http://www.wpsymposiumpro.com/","source":"disclosure@vulncheck.com"},{"url":"https://wordpress.org/plugins/wp-symposium-pro/","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50514","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wordpress-plugin-wp-symposium-pro-stored-xss-via-wps-admin-forum-add-name","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47928","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:28.863","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Opencart TMD Vendor System 3.x contains a blind SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the product_id parameter. Attackers can craft malicious SQL queries using time-based or content-based blind injection techniques to enumerate usernames, emails, and password reset codes from the oc_user table."},{"lang":"es","value":"Opencart TMD Vendor System 3.x contiene una vulnerabilidad de inyección SQL ciega que permite a atacantes no autenticados extraer información de la base de datos inyectando código SQL a través del parámetro product_id. Los atacantes pueden elaborar consultas SQL maliciosas utilizando técnicas de inyección ciega basadas en tiempo o basadas en contenido para enumerar nombres de usuario, correos electrónicos y códigos de restablecimiento de contraseña de la tabla oc_user."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"opencartextensions","product":"Extension TMD Vendor System","versions":[{"version":"3.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T14:44:41.827204Z","id":"CVE-2021-47928","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://www.exploit-db.com/exploits/50493","source":"disclosure@vulncheck.com"},{"url":"https://www.opencartextensions.in/","source":"disclosure@vulncheck.com"},{"url":"https://www.opencartextensions.in/opencart-multi-vendor-multi-seller-marketplace","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/opencart-tmd-vendor-system-3-x-blind-sql-injection-via-product-route","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47929","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:29.017","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Filterable Portfolio Gallery 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by entering payloads in the title field. Attackers can store JavaScript code like image tags with onerror handlers that execute when the gallery is previewed, affecting all users viewing the page."},{"lang":"es","value":"Filterable Portfolio Gallery 1.0 contiene una vulnerabilidad de cross-site scripting almacenado que permite a atacantes autenticados inyectar JavaScript malicioso al introducir payloads en el campo de título. Los atacantes pueden almacenar código JavaScript como etiquetas de imagen con manejadores onerror que se ejecutan cuando se previsualiza la galería, afectando a todos los usuarios que ven la página."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Filterable-Portfolio","product":"Filterable Portfolio Gallery","versions":[{"version":"1.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T15:14:54.278307Z","id":"CVE-2021-47929","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"http://www.filterable-portfolio.com/","source":"disclosure@vulncheck.com"},{"url":"https://wordpress.org/plugins/fg-gallery/","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50458","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wordpress-plugin-filterable-portfolio-gallery-stored-xss","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47930","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:29.163","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Attackers can send POST requests to the com_baforms component with malicious JSON payloads in the 'id' field parameter to extract sensitive database information."},{"lang":"es","value":"Balbooa Joomla Forms Builder 2.0.6 contiene una vulnerabilidad de inyección SQL no autenticada en el gestor de envío de formularios que permite a atacantes remotos ejecutar consultas SQL arbitrarias. Los atacantes pueden enviar solicitudes POST al componente com_baforms con cargas útiles JSON maliciosas en el parámetro de campo 'id' para extraer información sensible de la base de datos."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Balbooa","product":"Balbooa Joomla Forms Builder","versions":[{"version":"2.0.6","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-12T02:38:10.344812Z","id":"CVE-2021-47930","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://www.balbooa.com/","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50447","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/balbooa-joomla-forms-builder-sql-injection-unauthenticated","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47931","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:29.293","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Exponent CMS 2.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Title and Text Block parameters in the text editing endpoint. Attackers can inject iframe payloads with embedded SVG onload events to execute arbitrary JavaScript. The application also exposes database credentials in responses and lacks brute-force protection on authentication endpoints."},{"lang":"es","value":"Exponent CMS 2.6 contiene una vulnerabilidad de cross-site scripting almacenado que permite a atacantes autenticados inyectar scripts maliciosos a través de los parámetros Title y Text Block en el endpoint de edición de texto. Los atacantes pueden inyectar cargas útiles de iframe con eventos SVG onload incrustados para ejecutar JavaScript arbitrario, y la aplicación también expone credenciales de base de datos en las respuestas y carece de protección contra fuerza bruta en los endpoints de autenticación."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Exponentcms","product":"Exponent CMS","versions":[{"version":"0","lessThanOrEqual":"2.6","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T11:32:08.472634Z","id":"CVE-2021-47931","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://www.exploit-db.com/exploits/50611","source":"disclosure@vulncheck.com"},{"url":"https://www.exponentcms.org/","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/exponent-cms-multiple-vulnerabilities-stored-xss-authentication","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47932","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:29.427","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts by submitting crafted requests to the AJAX handler. Attackers can send POST requests to the tcp_register_and_login_ajax action with tcp_role set to administrator to gain full administrative access without authentication."},{"lang":"es","value":"WordPress TheCartPress 1.5.3.6 contiene una vulnerabilidad de escalada de privilegios sin autenticación que permite a los atacantes crear cuentas de administrador al enviar solicitudes manipuladas al gestor AJAX. Los atacantes pueden enviar solicitudes POST a la acción tcp_register_and_login_ajax con tcp_role establecido como administrador para obtener acceso administrativo completo sin autenticación."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"thecartpress","product":"TheCartPress","versions":[{"version":"0","lessThanOrEqual":"1.5.3.6","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T16:11:17.457007Z","id":"CVE-2021-47932","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://wordpress.org/plugin/thecartpress","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50378","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wordpress-thecartpress-privilege-escalation-unauthenticated","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47933","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:29.560","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint. Attackers can upload PHP files with arbitrary names to the config_file endpoint to achieve remote code execution on the server."},{"lang":"es","value":"WordPress MStore API 2.0.6 contiene una vulnerabilidad de carga arbitraria de archivos que permite a atacantes no autenticados cargar archivos maliciosos enviando solicitudes POST al endpoint de la API REST. Los atacantes pueden cargar archivos PHP con nombres arbitrarios al endpoint config_file para lograr la ejecución remota de código en el servidor."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"mstore","product":"MStore API","versions":[{"version":"2.0.6","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T13:18:54.223360Z","id":"CVE-2021-47933","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://wordpress.org/plugins/mstore-api/","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50379","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wordpress-mstore-api-arbitrary-file-upload","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47936","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:29.830","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resume attachments. Attackers can upload PHP payloads through the careers job application endpoint and execute system commands via POST requests to the uploaded file in the upload directory."},{"lang":"es","value":"OpenCATS 0.9.4 contiene una vulnerabilidad de ejecución remota de código que permite a atacantes no autenticados ejecutar comandos arbitrarios mediante la carga de archivos PHP maliciosos disfrazados como adjuntos de currículum. Los atacantes pueden cargar cargas útiles PHP a través del punto final de solicitud de empleo de carreras y ejecutar comandos del sistema a través de solicitudes POST al archivo cargado en el directorio de carga."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Opencats","product":"OpenCATS","versions":[{"version":"0","lessThanOrEqual":"0.9.4","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T15:16:56.979826Z","id":"CVE-2021-47936","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://github.com/opencats/OpenCATS","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50585","source":"disclosure@vulncheck.com"},{"url":"https://www.opencats.org/","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/opencats-remote-code-execution-via-resume-upload","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47937","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:29.960","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"e107 CMS 2.3.0 contains a remote code execution vulnerability that allows authenticated users with theme installation permissions to execute arbitrary commands by uploading malicious theme files. Attackers can upload a crafted theme package through the theme.php endpoint that deploys a web shell to the e107_themes directory, then execute system commands via the payload.php script."},{"lang":"es","value":"e107 CMS 2.3.0 contiene una vulnerabilidad de ejecución remota de código que permite a usuarios autenticados con permisos de instalación de temas ejecutar comandos arbitrarios mediante la carga de archivos de temas maliciosos. Los atacantes pueden cargar un paquete de tema manipulado a través del endpoint theme.PHP que despliega una web shell en el directorio e107_themes, y luego ejecutar comandos del sistema a través del script payload.PHP."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"E107","product":"e107 CMS","versions":[{"version":"2.3.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-12T02:38:47.959169Z","id":"CVE-2021-47937","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-434"}]}],"references":[{"url":"https://e107.org/","source":"disclosure@vulncheck.com"},{"url":"https://e107.org/download","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50315","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/e107-cms-authenticated-remote-code-execution-via-theme-upload","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47938","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:30.100","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that allows authenticated attackers to execute arbitrary PHP code by injecting malicious code into the sat_code parameter. Attackers can authenticate, submit a POST request to /modules/system/admin.php?fct=autotasks&op=mod with crafted sat_code containing PHP commands, which creates an executable file that accepts arbitrary commands via GET parameters."},{"lang":"es","value":"ImpressCMS 1.4.2 contiene una vulnerabilidad de ejecución remota de código en la interfaz administrativa de autotareas que permite a atacantes autenticados ejecutar código PHP arbitrario inyectando código malicioso en el parámetro sat_code. Los atacantes pueden autenticarse, enviar una solicitud POST a /modules/system/admin.php?fct=autotasks&op=mod con un sat_code manipulado que contenga comandos PHP, lo que crea un archivo ejecutable que acepta comandos arbitrarios a través de parámetros GET."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Impresscms","product":"ImpressCMS","versions":[{"version":"1.4.2","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T11:21:56.282230Z","id":"CVE-2021-47938","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://www.exploit-db.com/exploits/50298","source":"disclosure@vulncheck.com"},{"url":"https://www.impresscms.org/","source":"disclosure@vulncheck.com"},{"url":"https://www.impresscms.org/modules/downloads/","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/impresscms-remote-code-execution-via-autotasks","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47939","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:30.233","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation permissions to execute arbitrary system commands by injecting PHP code into module parameters. Attackers can send POST requests to /manager/index.php with malicious PHP code in the 'post' parameter to create modules that execute arbitrary commands when invoked."},{"lang":"es","value":"Evolution CMS 3.1.6 contiene una vulnerabilidad de ejecución remota de código que permite a usuarios autenticados con permisos de creación de módulos ejecutar comandos de sistema arbitrarios inyectando código PHP en los parámetros del módulo. Los atacantes pueden enviar solicitudes POST a /manager/index.php con código PHP malicioso en el parámetro 'post' para crear módulos que ejecuten comandos arbitrarios cuando sean invocados."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Evo","product":"Evolution CMS","versions":[{"version":"3.1.6","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T16:08:34.856231Z","id":"CVE-2021-47939","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://evo.im/","source":"disclosure@vulncheck.com"},{"url":"https://github.com/evolution-cms/evolution/releases","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50296","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/evolution-cms-authenticated-remote-code-execution-via-module-creation","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47940","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:30.363","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting the AJAX fileupload action. Attackers can send POST requests to the admin-ajax.php endpoint with the download_from_files_617_fileupload action, manipulating the allowExt parameter to bypass file type restrictions and upload executable files like PHP shells to the web root."},{"lang":"es","value":"El plugin de WordPress Download From Files versión 1.48 y anteriores contiene una vulnerabilidad de carga arbitraria de archivos que permite a atacantes no autenticados cargar archivos maliciosos explotando la acción AJAX fileupload. Los atacantes pueden enviar solicitudes POST al endpoint admin-ajax.php con la acción download_from_files_617_fileupload, manipulando el parámetro allowExt para eludir las restricciones de tipo de archivo y cargar archivos ejecutables como shells PHP a la raíz web."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"download-from-files","product":"Download From Files","versions":[{"version":"0","lessThanOrEqual":"1.48","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T13:19:46.205460Z","id":"CVE-2021-47940","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://wordpress.org/plugins/download-from-files/","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50287","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wordpress-download-from-files-arbitrary-file-upload","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47941","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:30.493","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wp_sap cookie parameter. Attackers can craft SQL payloads in the cookie to extract sensitive database information including usernames, passwords, and other confidential data from the WordPress database."},{"lang":"es","value":"El plugin de WordPress Survey & Poll 1.5.7.3 contiene una vulnerabilidad de inyección SQL que permite a atacantes no autenticados ejecutar consultas SQL arbitrarias inyectando código malicioso a través del parámetro de cookie wp_sap. Los atacantes pueden elaborar cargas útiles SQL en la cookie para extraer información sensible de la base de datos, incluyendo nombres de usuario, contraseñas y otros datos confidenciales de la base de datos de WordPress."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Modalsurvey","product":"Survey & Poll","versions":[{"version":"1.5.7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T14:43:45.454866Z","id":"CVE-2021-47941","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"http://modalsurvey.pantherius.com/","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50269","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wordpress-plugin-survey-poll-sql-injection-via-sss-params","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47943","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:30.627","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"TextPattern CMS 4.8.7 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by uploading malicious PHP files through the file upload functionality. Attackers can upload a PHP shell via the Files section in the content area and execute commands by accessing the uploaded file at /textpattern/files/ with GET parameters passed to the system function."},{"lang":"es","value":"TextPattern CMS 4.8.7 contiene una vulnerabilidad de ejecución remota de código que permite a atacantes autenticados ejecutar comandos arbitrarios mediante la carga de archivos PHP maliciosos a través de la funcionalidad de carga de archivos. Los atacantes pueden cargar un shell PHP a través de la sección Archivos en el área de contenido y ejecutar comandos accediendo al archivo cargado en /textpattern/files/ con parámetros GET pasados a la función del sistema."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Textpattern","product":"TextPattern CMS","versions":[{"version":"4.8.7","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T15:17:34.109986Z","id":"CVE-2021-47943","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-434"}]}],"references":[{"url":"https://www.exploit-db.com/exploits/49996","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50415","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/textpattern-cms-remote-code-execution-via-file-upload","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47944","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:30.760","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"memono Notepad 4.2 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character buffers into note fields. Attackers can generate a payload containing 350000 repeated characters and paste it twice into a new note to trigger an application crash on iOS devices."},{"lang":"es","value":"memono Notepad 4.2 contiene una vulnerabilidad de denegación de servicio que permite a los atacantes colapsar la aplicación al pegar búferes de caracteres excesivamente largos en los campos de notas. Los atacantes pueden generar una carga útil que contenga 350000 caracteres repetidos y pegarla dos veces en una nueva nota para desencadenar un colapso de la aplicación en dispositivos iOS."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"memono","product":"Notepad","versions":[{"version":"4.2","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-12T02:39:43.699075Z","id":"CVE-2021-47944","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-789"}]}],"references":[{"url":"https://www.exploit-db.com/exploits/49977","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/memono-notepad-denial-of-service-via-buffer-overflow","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47945","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:30.897","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privileges when the service starts."},{"lang":"es","value":"Argus Surveillance DVR 4.0 contiene una vulnerabilidad de ruta de servicio sin comillas en el servicio DVRWatchdog que permite a atacantes locales escalar privilegios explotando la ruta del binario del servicio. Los atacantes pueden colocar un ejecutable malicioso en el directorio Program Files para ser ejecutado con privilegios de LocalSystem cuando el servicio se inicia."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"argus","product":"Argus Surveillance DVR","versions":[{"version":"Argus Surveillance DVR 4.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T11:03:57.245976Z","id":"CVE-2021-47945","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-428"}]}],"references":[{"url":"https://www.exploit-db.com/exploits/50261","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/argus-surveillance-dvr-unquoted-service-path-privilege-escalation","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47946","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:31.027","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"OpenCart 3.0.3.6 contains a cross-site request forgery vulnerability in the /account/edit endpoint that allows unauthenticated attackers to modify victim account details by tricking users into visiting malicious pages. Attackers can craft CSRF payloads that change victim email addresses and account information, then use password reset functionality to gain unauthorized access to compromised accounts."},{"lang":"es","value":"OpenCart 3.0.36 contiene una vulnerabilidad de falsificación de petición en sitios cruzados en el endpoint /account/edit que permite a atacantes no autenticados modificar los detalles de la cuenta de la víctima engañando a los usuarios para que visiten páginas maliciosas. Los atacantes pueden crear cargas útiles de CSRF que cambian las direcciones de correo electrónico y la información de la cuenta de la víctima, y luego usar la funcionalidad de restablecimiento de contraseña para obtener acceso no autorizado a las cuentas comprometidas."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Opencart","product":"OpenCart","versions":[{"version":"3.0.3.6","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T16:05:52.054158Z","id":"CVE-2021-47946","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"references":[{"url":"https://www.exploit-db.com/exploits/49407","source":"disclosure@vulncheck.com"},{"url":"https://www.opencart.com","source":"disclosure@vulncheck.com"},{"url":"https://www.opencart.com/index.php?route=cms/download","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/opencart-account-takeover-via-cross-site-request-forgery","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47947","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:31.180","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Projectsend r1295 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input in the 'name' parameter of files-edit.php. Attackers can inject JavaScript payloads through the file name field that execute in the browser when the file is viewed by other users, particularly affecting System Administrator users on the Dashboard page."},{"lang":"es","value":"Projectsend r1295 contiene una vulnerabilidad de cross-site scripting almacenado que permite a atacantes autenticados inyectar scripts maliciosos al enviar entradas manipuladas en el parámetro 'name' de files-edit.php. Los atacantes pueden inyectar cargas útiles de JavaScript a través del campo de nombre de archivo que se ejecutan en el navegador cuando el archivo es visto por otros usuarios, afectando particularmente a los usuarios Administradores del Sistema en la página del Panel de Control."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Projectsend","product":"Projectsend","versions":[{"version":"r1295","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T13:20:12.953365Z","id":"CVE-2021-47947","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://www.exploit-db.com/exploits/50240","source":"disclosure@vulncheck.com"},{"url":"https://www.projectsend.org/","source":"disclosure@vulncheck.com"},{"url":"https://www.projectsend.org/download/387/","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/projectsend-r1295-stored-cross-site-scripting-via-files-edit-php","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47948","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:31.323","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"WordPress GetPaid Plugin 2.4.6 contains an HTML injection vulnerability that allows authenticated attackers to inject arbitrary HTML code by exploiting the Help Text field in payment forms. Attackers can inject malicious HTML including image tags and scripts into the Help Text field during payment form creation, which gets stored in the database and executed in the browser when the form is viewed."},{"lang":"es","value":"El Plugin GetPaid de WordPress 2.4.6 contiene una vulnerabilidad de inyección HTML que permite a atacantes autenticados inyectar código HTML arbitrario explotando el campo 'Help Text' en los formularios de pago. Los atacantes pueden inyectar HTML malicioso, incluyendo etiquetas de imagen y scripts, en el campo 'Help Text' durante la creación del formulario de pago, el cual se almacena en la base de datos y se ejecuta en el navegador cuando se visualiza el formulario."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"invoicing","product":"Payments Plugin GetPaid","versions":[{"version":"2.4.6","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T14:43:10.809325Z","id":"CVE-2021-47948","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-80"}]}],"references":[{"url":"https://wordpress.org/plugins/invoicing/","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50246","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wordpress-getpaid-plugin-html-injection-via-help-text","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47949","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:31.453","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by exploiting symlink attacks through the filemanager controller endpoint. Attackers can manipulate the completeStartingPath parameter in POST requests to /filemanager/controller to create symbolic links, read sensitive files like database credentials, and execute arbitrary shell commands through the /websites/fetchFolderDetails endpoint."},{"lang":"es","value":"CyberPanel 2.1 contiene una vulnerabilidad de ejecución de comandos que permite a atacantes autenticados leer archivos arbitrarios y ejecutar código remoto explotando ataques de enlaces simbólicos a través del endpoint del controlador de filemanager. Los atacantes pueden manipular el parámetro completeStartingPath en solicitudes POST a /filemanager/controller para crear enlaces simbólicos, leer archivos sensibles como credenciales de base de datos, y ejecutar comandos de shell arbitrarios a través del endpoint /websites/fetchFolderDetails."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Cyberpanel","product":"CyberPanel","versions":[{"version":"<= 2.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T12:50:59.565034Z","id":"CVE-2021-47949","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-59"}]}],"references":[{"url":"https://cyberpanel.net/","source":"disclosure@vulncheck.com"},{"url":"https://github.com/usmannasir/cyberpanel","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50230","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/cyberpanel-authenticated-remote-code-execution-via-symlink-attack","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47951","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:31.720","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"WordPress Picture Gallery 1.4.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Edit Content URL field in the Access Control settings. Attackers can enter JavaScript payloads in the plugin options that are stored in the database and executed when the functionality is triggered, enabling session hijacking or credential theft."},{"lang":"es","value":"WordPress Picture Gallery 1.4.2 contiene una vulnerabilidad de cross-site scripting almacenada que permite a atacantes autenticados inyectar scripts maliciosos a través del campo 'Edit Content URL' en la configuración de control de acceso. Los atacantes pueden introducir cargas útiles de JavaScript en las opciones del plugin que se almacenan en la base de datos y se ejecutan cuando se activa la funcionalidad, lo que permite el secuestro de sesión o el robo de credenciales."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"picture-gallery","product":"Picture Gallery","versions":[{"version":"1.4.2","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T11:01:28.553319Z","id":"CVE-2021-47951","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://wordpress.org/plugins/picture-gallery/","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50187","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wordpress-picture-gallery-stored-xss-via-edit-content-url","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2021-47953","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:31.853","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by sending crafted requests to the account/password endpoint. Attackers can trick authenticated users into submitting hidden forms with new password values in the 'password' and 'confirm' parameters to hijack accounts."},{"lang":"es","value":"OpenCart 3.0.3.7 contiene una vulnerabilidad de falsificación de petición en sitios cruzados que permite a los atacantes cambiar contraseñas de usuario enviando peticiones manipuladas al endpoint account/password. Los atacantes pueden engañar a usuarios autenticados para que envíen formularios ocultos con nuevos valores de contraseña en los parámetros 'password' y 'confirm' para secuestrar cuentas."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Opencart","product":"OpenCart","versions":[{"version":"3.0.3.7","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T16:00:40.286356Z","id":"CVE-2021-47953","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"references":[{"url":"https://www.exploit-db.com/exploits/49970","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/opencart-cross-site-request-forgery-via-account-password","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2022-50943","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:31.997","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies."},{"lang":"es","value":"Moodle LMS 4.0 contiene una vulnerabilidad de cross-site scripting que permite a atacantes no autenticados inyectar scripts maliciosos mediante el envío de cargas útiles a través del parámetro de búsqueda. Los atacantes pueden inyectar código JavaScript a través del campo de búsqueda en course/search.PHP para ejecutar scripts arbitrarios en los navegadores de los usuarios y robar cookies de sesión."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Moodle","product":"Moodle LMS","versions":[{"version":"4.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T16:30:40.253373Z","id":"CVE-2022-50943","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionEndIncluding":"4.0.0","matchCriteriaId":"639D19A8-5F1A-4CC4-A14A-8FA12A4B5C17"}]}]}],"references":[{"url":"https://git.in.moodle.com/moodle","source":"disclosure@vulncheck.com","tags":["Product"]},{"url":"https://moodle.org/","source":"disclosure@vulncheck.com","tags":["Product"]},{"url":"https://www.exploit-db.com/exploits/51115","source":"disclosure@vulncheck.com","tags":["Exploit","VDB Entry"]},{"url":"https://www.vulncheck.com/advisories/moodle-lms-cross-site-scripting-via-course-search-php","source":"disclosure@vulncheck.com","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-50944","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:32.137","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious files through the image parameter. Attackers can upload PHP files with embedded code to the admin posts.php endpoint with source=add_post parameter, and the uploaded files are executed by the server."},{"lang":"es","value":"Aero CMS 0.0.1 contiene una vulnerabilidad de inyección de código PHP que permite a atacantes autenticados ejecutar código PHP arbitrario al subir archivos maliciosos a través del parámetro image. Los atacantes pueden subir archivos PHP con código incrustado al endpoint admin posts.php con el parámetro source=add_post, y los archivos subidos son ejecutados por el servidor."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"MegaTKC","product":"Aero CMS","versions":[{"version":"0.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T13:15:12.864246Z","id":"CVE-2022-50944","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://github.com/MegaTKC/AeroCMS","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/51085","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/aero-cms-php-code-injection-via-posts-php","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2022-50946","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:32.400","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"WordPress Plugin Netroics Blog Posts Grid 1.0 contains a stored cross-site scripting vulnerability that allows authenticated editors to inject malicious scripts by failing to sanitize the post_title parameter. Attackers with editor privileges can inject script payloads through the testimonial title field that execute in the browsers of other users viewing the draft post, enabling cookie theft and session hijacking."},{"lang":"es","value":"El plugin de WordPress Netroics Blog Posts Grid 1.0 contiene una vulnerabilidad de cross-site scripting almacenado que permite a los editores autenticados inyectar scripts maliciosos al no sanear el parámetro post_title. Atacantes con privilegios de editor pueden inyectar cargas útiles de script a través del campo de título de testimonio que se ejecutan en los navegadores de otros usuarios que ven la publicación en borrador, lo que permite el robo de cookies y el secuestro de sesión."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"netroics","product":"Netroics Blog Posts Grid","versions":[{"version":"1.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T15:09:41.872880Z","id":"CVE-2022-50946","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://downloads.wordpress.org/plugin/netroics-blog-posts-grid.zip","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/51008","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wordpress-plugin-netroics-blog-posts-grid-stored-xss","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2022-50947","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:32.523","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"WordPress Plugin Testimonial Slider and Showcase 2.2.6 contains a stored cross-site scripting vulnerability that allows authenticated editors to inject malicious scripts by failing to sanitize the post_title parameter. Attackers with editor privileges can inject JavaScript payloads through the testimonial title field that execute in the browsers of users viewing the draft post, enabling cookie theft and session hijacking."},{"lang":"es","value":"El plugin de WordPress Testimonial Slider and Showcase 2.2.6 contiene una vulnerabilidad de cross-site scripting almacenado que permite a editores autenticados inyectar scripts maliciosos al no sanear el parámetro post_title. Atacantes con privilegios de editor pueden inyectar cargas útiles de JavaScript a través del campo de título del testimonio que se ejecutan en los navegadores de los usuarios que ven la publicación en borrador, lo que permite el robo de cookies y el secuestro de sesión."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"RadiusTheme","product":"Testimonial Slider and Showcase","versions":[{"version":"2.2.6","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-12T02:34:38.852828Z","id":"CVE-2022-50947","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://wordpress.org","source":"disclosure@vulncheck.com"},{"url":"https://wordpress.org/plugins/testimonial-slider-and-showcase/","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/51007","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wordpress-plugin-testimonial-slider-and-showcase-stored-xss","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2022-50948","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:32.657","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Motopress Hotel Booking Lite 4.2.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting payloads in accommodation type fields. Attackers can inject script tags through the title and excerpt parameters when creating accommodation types, which execute in the browser when visitors access the accommodations page."},{"lang":"es","value":"Motopress Hotel Booking Lite 4.2.4 contiene una vulnerabilidad de cross-site scripting almacenado que permite a atacantes autenticados inyectar scripts maliciosos al enviar cargas útiles en los campos de tipo de alojamiento. Los atacantes pueden inyectar etiquetas de script a través de los parámetros de título y extracto al crear tipos de alojamiento, que se ejecutan en el navegador cuando los visitantes acceden a la página de alojamientos."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Motopress","product":"Motopress Hotel Booking Lite","versions":[{"version":"4.2.4","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T16:48:44.904355Z","id":"CVE-2022-50948","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://motopress.com/","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50951","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/motopress-hotel-booking-lite-stored-cross-site-scripting","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2022-50967","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:34.610","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the tickets/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers."},{"lang":"es","value":"uBidAuction 2.0.1 contiene una vulnerabilidad de cross-site scripting reflejado en el módulo tickets/manage. Los parámetros date_created, date_from, date_to y created_at en la funcionalidad de filtro no están correctamente saneados, lo que permite a atacantes remotos inyectar scripts maliciosos a través de solicitudes GET manipuladas que se ejecutan en los navegadores de las víctimas."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"uBidAuction","product":"uBidAuction","defaultStatus":"unaffected","versions":[{"version":"2.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T14:48:02.440058Z","id":"CVE-2022-50967","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://www.apphp.com/codemarket/items/48/ubidauction-php-classic-and-bid-auctions-script","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50693","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ubidauction-tickets-manage-reflected-xss","source":"disclosure@vulncheck.com"},{"url":"https://www.vulnerability-lab.com/get_content.php?id=2289","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2022-50968","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:34.737","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the auctions/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers."},{"lang":"es","value":"uBidAuction 2.0.1 contiene una vulnerabilidad de cross-site scripting reflejado en el módulo auctions/manage. Los parámetros date_created, date_from, date_to y created_at en la funcionalidad de filtro no se sanean correctamente, lo que permite a atacantes remotos inyectar scripts maliciosos a través de solicitudes GET manipuladas que se ejecutan en los navegadores de las víctimas."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"uBidAuction","product":"uBidAuction","defaultStatus":"unaffected","versions":[{"version":"2.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T15:12:20.837284Z","id":"CVE-2022-50968","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://www.apphp.com/codemarket/items/48/ubidauction-php-classic-and-bid-auctions-script","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50693","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ubidauction-auctions-manage-reflected-xss","source":"disclosure@vulncheck.com"},{"url":"https://www.vulnerability-lab.com/get_content.php?id=2289","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2022-50969","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:34.867","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"uBidAuction 2.0.1 contains a reflected cross-site scripting vulnerability in the backend/mailingLog/manage module. The date_created, date_from, date_to, and created_at parameters in the filter functionality are not properly sanitized, allowing remote attackers to inject malicious scripts via crafted GET requests that execute in victims' browsers."},{"lang":"es","value":"uBidAuction 2.0.1 contiene una vulnerabilidad de cross-site scripting reflejado en el módulo backend/mailingLog/manage. Los parámetros date_created, date_from, date_to y created_at en la funcionalidad de filtro no se sanean correctamente, permitiendo a atacantes remotos inyectar scripts maliciosos a través de solicitudes GET manipuladas que se ejecutan en los navegadores de las víctimas."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"uBidAuction","product":"uBidAuction","defaultStatus":"unaffected","versions":[{"version":"2.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-12T02:36:35.783427Z","id":"CVE-2022-50969","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://www.apphp.com/codemarket/items/48/ubidauction-php-classic-and-bid-auctions-script","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50693","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ubidauction-mailinglog-manage-reflected-xss","source":"disclosure@vulncheck.com"},{"url":"https://www.vulnerability-lab.com/get_content.php?id=2289","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2022-50970","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-10T13:16:34.993","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"WordPress Plugin AAWP 3.16 contains a reflected cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by manipulating the tab parameter. Attackers can craft URLs with XSS payloads in the tab parameter of the aawp-settings admin page to execute arbitrary JavaScript in the context of authenticated users."},{"lang":"es","value":"El plugin de WordPress AAWP 3.16 contiene una vulnerabilidad de cross-site scripting reflejado que permite a atacantes autenticados inyectar scripts maliciosos manipulando el parámetro tab. Los atacantes pueden crear URLs con cargas útiles de XSS en el parámetro tab de la página de administración aawp-settings para ejecutar JavaScript arbitrario en el contexto de usuarios autenticados."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Getaawp","product":"WordPress Plugin AAWP","versions":[{"version":"3.16","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-11T13:38:24.797581Z","id":"CVE-2022-50970","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://getaawp.com/","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/50643","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/wordpress-plugin-aawp-reflected-xss-via-tab-parameter","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-47179","sourceIdentifier":"security-advisories@github.com","published":"2026-05-29T18:17:12.500","lastModified":"2026-07-25T10:10:00.167","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns the contents of any Docker Compose include directive declared in a project's compose file before any path-traversal validation runs. Because ProjectService.CreateProject writes attacker-supplied compose content to disk without validating include paths, an authenticated user can create a project whose compose file declares include: ['../../../../etc/passwd'], then read the include via the project file API. The result is arbitrary read of any file readable by the Arcane backend process, including /app/data/arcane.db (the SQLite database containing every user's password hash and API key), enabling escalation to admin and, via Arcane's Docker control plane, RCE on the host. This vulnerability is fixed in 1.19.4."},{"lang":"es","value":"Arcane es una interfaz para gestionar contenedores Docker, imágenes, redes y volúmenes. Antes de la versión 1.19.4, ProjectService.GetProjectFileContent devuelve el contenido de cualquier directiva 'include' de Docker Compose declarada en el archivo compose de un proyecto antes de que se ejecute cualquier validación de recorrido de ruta. Debido a que ProjectService.CreateProject escribe contenido compose suministrado por el atacante en el disco sin validar las rutas de 'include', un usuario autenticado puede crear un proyecto cuyo archivo compose declara 'include': ['.. / .. / .. / ../etc/pass1d'], luego leer el 'include' a través de la API del archivo del proyecto. El resultado es la lectura arbitraria de cualquier archivo legible por el proceso backend de Arcane, incluyendo /app/data/arcane.db (la base de datos SQLite que contiene el hash de contraseña y la clave API de cada usuario), lo que permite la escalada a administrador y, a través del plano de control Docker de Arcane, RCE en el host. Esta vulnerabilidad está corregida en la versión 1.19.4."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"getarcaneapp","product":"arcane","versions":[{"version":"< 1.19.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-02T15:44:09.404804Z","id":"CVE-2026-47179","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://github.com/getarcaneapp/arcane/commit/b6cbffabf61dbc3f12a28d3b5830e3c6b7e67daf","source":"security-advisories@github.com"},{"url":"https://github.com/getarcaneapp/arcane/security/advisories/GHSA-c3px-h233-h6fq","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-46287","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-06-08T17:16:46.770","lastModified":"2026-07-25T11:10:00.100","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: txgbe: fix RTNL assertion warning when remove module\n\nFor the copper NIC with external PHY, the driver called\nphylink_connect_phy() during probe and phylink_disconnect_phy() during\nremove. It caused an RTNL assertion warning in phylink_disconnect_phy()\nupon module remove.\n\nTo fix this, add rtnl_lock() and rtnl_unlock() around the\nphylink_disconnect_phy() in remove function.\n\n ------------[ cut here ]------------\n RTNL: assertion failed at drivers/net/phy/phylink.c (2351)\n WARNING: drivers/net/phy/phylink.c:2351 at\nphylink_disconnect_phy+0xd8/0xf0 [phylink], CPU#0: rmmod/4464\n Modules linked in: ...\n CPU: 0 UID: 0 PID: 4464 Comm: rmmod Kdump: loaded Not tainted 7.0.0-rc4+\n Hardware name: Micro-Star International Co., Ltd. MS-7E16/X670E GAMING\nPLUS WIFI (MS-7E16), BIOS 1.90 12/31/2024\n RIP: 0010:phylink_disconnect_phy+0xe4/0xf0 [phylink]\n Code: 5b 41 5c 41 5d 41 5e 41 5f 5d 31 c0 31 d2 31 f6 31 ff e9 3a 38 8f e7\n48 8d 3d 48 87 e2 ff ba 2f 09 00 00 48 c7 c6 c1 22 24 c0 <67> 48 0f b9 3a\ne9 34 ff ff ff 66 90 90 90 90 90 90 90 90 90 90 90\n RSP: 0018:ffffce7288363ac0 EFLAGS: 00010246\n RAX: 0000000000000000 RBX: ffff89654b2a1a00 RCX: 0000000000000000\n RDX: 000000000000092f RSI: ffffffffc02422c1 RDI: ffffffffc0239020\n RBP: ffffce7288363ae8 R08: 0000000000000000 R09: 0000000000000000\n R10: 0000000000000000 R11: 0000000000000000 R12: ffff8964c4022000\n R13: ffff89654fce3028 R14: ffff89654ebb4000 R15: ffffffffc0226348\n FS:  0000795e80d93780(0000) GS:ffff896c52857000(0000)\nknlGS:0000000000000000\n CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00005b528b592000 CR3: 0000000170d0f000 CR4: 0000000000f50ef0\n PKRU: 55555554\n Call Trace:\n  <TASK>\n  txgbe_remove_phy+0xbb/0xd0 [txgbe]\n  txgbe_remove+0x4c/0xb0 [txgbe]\n  pci_device_remove+0x41/0xb0\n  device_remove+0x43/0x80\n  device_release_driver_internal+0x206/0x270\n  driver_detach+0x4a/0xa0\n  bus_remove_driver+0x83/0x120\n  driver_unregister+0x2f/0x60\n  pci_unregister_driver+0x40/0x90\n  txgbe_driver_exit+0x10/0x850 [txgbe]\n  __do_sys_delete_module.isra.0+0x1c3/0x2f0\n  __x64_sys_delete_module+0x12/0x20\n  x64_sys_call+0x20c3/0x2390\n  do_syscall_64+0x11c/0x1500\n  ? srso_alias_return_thunk+0x5/0xfbef5\n  ? do_syscall_64+0x15a/0x1500\n  ? srso_alias_return_thunk+0x5/0xfbef5\n  ? do_fault+0x312/0x580\n  ? srso_alias_return_thunk+0x5/0xfbef5\n  ? __handle_mm_fault+0x9d5/0x1040\n  ? srso_alias_return_thunk+0x5/0xfbef5\n  ? count_memcg_events+0x101/0x1d0\n  ? srso_alias_return_thunk+0x5/0xfbef5\n  ? handle_mm_fault+0x1e8/0x2f0\n  ? srso_alias_return_thunk+0x5/0xfbef5\n  ? do_user_addr_fault+0x2f8/0x820\n  ? srso_alias_return_thunk+0x5/0xfbef5\n  ? irqentry_exit+0xb2/0x600\n  ? srso_alias_return_thunk+0x5/0xfbef5\n  ? exc_page_fault+0x92/0x1c0\n  entry_SYSCALL_64_after_hwframe+0x76/0x7e"},{"lang":"es","value":"En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nnet: txgbe: corrige la advertencia de aserción RTNL al eliminar el módulo\n\nPara la NIC de cobre con PHY externo, el controlador llamó a\nphylink_connect_phy() durante la sonda y phylink_disconnect_phy() durante\nla eliminación. Esto causó una advertencia de aserción RTNL en phylink_disconnect_phy()\nal eliminar el módulo.\n\nPara solucionar esto, añada rtnl_lock() y rtnl_unlock() alrededor de\nphylink_disconnect_phy() en la función de eliminación.\n\n ------------[ cortar aquí ]------------\n RTNL: aserción fallida en drivers/net/phy/phylink.c (2351)\n ADVERTENCIA: drivers/net/phy/phylink.c:2351 en\nphylink_disconnect_phy+0xd8/0xf0 [phylink], CPU#0: rmmod/4464\n Módulos enlazados: ...\n CPU: 0 UID: 0 PID: 4464 Comm: rmmod Kdump: cargado No contaminado 7.0.0-rc4+\n Nombre del hardware: Micro-Star International Co., Ltd. MS-7E16/X670E GAMING\nPLUS WIFI (MS-7E16), BIOS 1.90 12/31/2024\n RIP: 0010:phylink_disconnect_phy+0xe4/0xf0 [phylink]\n Código: 5b 41 5c 41 5d 41 5e 41 5f 5d 31 c0 31 d2 31 f6 31 ff e9 3a 38 8f e7\n48 8d 3d 48 87 e2 ff ba 2f 09 00 00 48 c7 c6 c1 22 24 c0 <67> 48 0f b9 3a\ne9 34 ff ff ff 66 90 90 90 90 90 90 90 90 90 90 90\n RSP: 0018:ffffce7288363ac0 EFLAGS: 00010246\n RAX: 0000000000000000 RBX: ffff89654b2a1a00 RCX: 0000000000000000\n RDX: 000000000000092f RSI: ffffffffc02422c1 RDI: ffffffffc0239020\n RBP: ffffce7288363ae8 R08: 0000000000000000 R09: 0000000000000000\n R10: 0000000000000000 R11: 0000000000000000 R12: ffff8964c4022000\n R13: ffff89654fce3028 R14: ffff89654ebb4000 R15: ffffffffc0226348\n FS:  0000795e80d93780(0000) GS:ffff896c52857000(0000)\nknlGS:0000000000000000\n CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00005b528b592000 CR3: 0000000170d0f000 CR4: 0000000000f50ef0\n PKRU: 55555554\n Rastro de llamadas:\n  <TAREA>\n  txgbe_remove_phy+0xbb/0xd0 [txgbe]\n  txgbe_remove+0x4c/0xb0 [txgbe]\n  pci_device_remove+0x41/0xb0\n  device_remove+0x43/0x80\n  device_release_driver_internal+0x206/0x270\n  driver_detach+0x4a/0xa0\n  bus_remove_driver+0x83/0x120\n  driver_unregister+0x2f/0x60\n  pci_unregister_driver+0x40/0x90\n  txgbe_driver_exit+0x10/0x850 [txgbe]\n  __do_sys_delete_module.isra.0+0x1c3/0x2f0\n  __x64_sys_delete_module+0x12/0x20\n  x64_sys_call+0x20c3/0x2390\n  do_syscall_64+0x11c/0x1500\n  ? srso_alias_return_thunk+0x5/0xfbef5\n  ? do_syscall_64+0x15a/0x1500\n  ? srso_alias_return_thunk+0x5/0xfbef5\n  ? do_fault+0x312/0x580\n  ? srso_alias_return_thunk+0x5/0xfbef5\n  ? __handle_mm_fault+0x9d5/0x1040\n  ? srso_alias_return_thunk+0x5/0xfbef5\n  ? count_memcg_events+0x101/0x1d0\n  ? srso_alias_return_thunk+0x5/0xfbef5\n  ? handle_mm_fault+0x1e8/0x2f0\n  ? srso_alias_return_thunk+0x5/0xfbef5\n  ? do_user_addr_fault+0x2f8/0x820\n  ? srso_alias_return_thunk+0x5/0xfbef5\n  ? irqentry_exit+0xb2/0x600\n  ? srso_alias_return_thunk+0x5/0xfbef5\n  ? exc_page_fault+0x92/0x1c0\n  entry_SYSCALL_64_after_hwframe+0x76/0x7e"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/wangxun/txgbe/txgbe_phy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"02b2a6f91b9042552bc3aa728622bda97e3916fa","lessThan":"0305e7118451c7c363c18f8113b0d8e0077ffa4c","versionType":"git","status":"affected"},{"version":"02b2a6f91b9042552bc3aa728622bda97e3916fa","lessThan":"3e223a7fd41ce6fffdb10577df9350385262bf33","versionType":"git","status":"affected"},{"version":"02b2a6f91b9042552bc3aa728622bda97e3916fa","lessThan":"d29cafc7e4ee9e28a150ba17e9a565ec5d881fbc","versionType":"git","status":"affected"},{"version":"02b2a6f91b9042552bc3aa728622bda97e3916fa","lessThan":"6c5ec52c68a6a442c8a159615ae092512562318a","versionType":"git","status":"affected"},{"version":"02b2a6f91b9042552bc3aa728622bda97e3916fa","lessThan":"e159f05e12cc1111a3103b99375ddf0dfd0e7d63","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/wangxun/txgbe/txgbe_phy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","versionType":"semver","status":"unaffected"},{"version":"6.6.140","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.88","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.27","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.4","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-617"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.6.140","matchCriteriaId":"C002EFE2-D23C-430B-ACB7-0A4317429511"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"6.12.88","matchCriteriaId":"5AFBE0EC-CCDF-4207-AE92-ABF958125CA4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"6.18.27","matchCriteriaId":"A10AC84F-C058-47D5-85B4-E6E51A613B74"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.19","versionEndExcluding":"7.0.4","matchCriteriaId":"CDB78D6D-22C3-4154-B0D0-94AF1CE5C2E3"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/0305e7118451c7c363c18f8113b0d8e0077ffa4c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"]},{"url":"https://git.kernel.org/stable/c/3e223a7fd41ce6fffdb10577df9350385262bf33","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"]},{"url":"https://git.kernel.org/stable/c/6c5ec52c68a6a442c8a159615ae092512562318a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"]},{"url":"https://git.kernel.org/stable/c/d29cafc7e4ee9e28a150ba17e9a565ec5d881fbc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"]},{"url":"https://git.kernel.org/stable/c/e159f05e12cc1111a3103b99375ddf0dfd0e7d63","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"]}]}},{"cve":{"id":"CVE-2026-64256","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:04.630","lastModified":"2026-07-25T10:17:04.630","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: don't wrap around quota ids in dqiterate\n\nLOLLM noticed that q_id is an unsigned 32-bit variable.  If it happens\nto be set to XFS_DQ_ID_MAX due to a filesystem that actually has a dquot\nfor ID_MAX, then this addition will truncate to zero and the iteration\nstarts over.  Fix this by casting to u64."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/xfs/scrub/dqiterate.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"21d7500929c8a0b10e22a6755850c6f9a9280284","lessThan":"249e311c2ba392ceaf9ebfc145a46922946f069a","versionType":"git","status":"affected"},{"version":"21d7500929c8a0b10e22a6755850c6f9a9280284","lessThan":"d1c4c40599c376aeb0c93068a2ae344e79ee4b90","versionType":"git","status":"affected"},{"version":"21d7500929c8a0b10e22a6755850c6f9a9280284","lessThan":"2b14fe1e0924c6b901f4256456342569c5397abe","versionType":"git","status":"affected"},{"version":"21d7500929c8a0b10e22a6755850c6f9a9280284","lessThan":"d766e4e5e85d829629c3ba503802fe1303d7b591","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/xfs/scrub/dqiterate.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/249e311c2ba392ceaf9ebfc145a46922946f069a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2b14fe1e0924c6b901f4256456342569c5397abe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d1c4c40599c376aeb0c93068a2ae344e79ee4b90","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d766e4e5e85d829629c3ba503802fe1303d7b591","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64257","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:05.817","lastModified":"2026-07-25T10:17:05.817","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: reject overlapping data areas in SMB2 responses\n\nCommit 53b7c271f06b (\"smb: client: restrict implied bcc[0] exemption to\nresponses without data area\") restricted the implied bcc[0] length\nexception to responses without a data area. However, the overlap\nhandling in __smb2_calc_size() clears data_length, which can make an\ninvalid response appear to have no data area and so qualify for the\nexception.\n\nTrack data area overlap separately and reject such responses before\napplying the length compatibility exceptions."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/client/smb2misc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"31c6312608c60b72a1feb99a5afb680645a3e8a3","lessThan":"445ece263131780dee273d727a4d6f11934feec7","versionType":"git","status":"affected"},{"version":"573e502d14714d2947e22e7eff40ec20a6a44a42","lessThan":"36bfa52459e45c0d5b668de2f1c91f6dc5c67775","versionType":"git","status":"affected"},{"version":"419ec1b604d7fb60c10aec2dc062371f9fcd4940","lessThan":"4a9d2657d3e05f6ed09c148cb127b4e58702275f","versionType":"git","status":"affected"},{"version":"ceb875a375dedbf51c9425c1d13a2d7a8435c08c","lessThan":"fdafa1e68dc75045b7b617e6e7d2854950804d83","versionType":"git","status":"affected"},{"version":"6e9d10f62773b99bd927940fd9cbdfe7207e23ff","lessThan":"57cba95f0e97c6f6e45e6731da30aff091bd7460","versionType":"git","status":"affected"},{"version":"53b7c271f06be4dd5cfc8c6ef552a8355c891a7f","lessThan":"8986c932905ea508d66da421eb2eb6e676ace1fe","versionType":"git","status":"affected"},{"version":"8d0bbc78046d264bbf6a574ea6f9072258a43e35","versionType":"git","status":"affected"},{"version":"b6a381c01e2ac98a48e32ac0f2a45bbadd9e26b0","versionType":"git","status":"affected"},{"version":"5.10.261","lessThan":"5.11","versionType":"semver","status":"affected"},{"version":"5.15.212","lessThan":"5.16","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/client/smb2misc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.2-rc3","status":"affected"},{"version":"0","lessThan":"7.2-rc3","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/36bfa52459e45c0d5b668de2f1c91f6dc5c67775","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/445ece263131780dee273d727a4d6f11934feec7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4a9d2657d3e05f6ed09c148cb127b4e58702275f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/57cba95f0e97c6f6e45e6731da30aff091bd7460","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8986c932905ea508d66da421eb2eb6e676ace1fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fdafa1e68dc75045b7b617e6e7d2854950804d83","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64258","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:05.930","lastModified":"2026-07-25T10:17:05.930","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref\n\nIf a copy into the userspace ring buffer fails, a request will be\nterminated and fuse_uring_req_end() will set ent->fuse_req to NULL but\nit will leave the entry on ent_w_req_queue in FRRS_FUSE_REQ state. This\ncan lead to a NULL deref if the request expiration logic scans\nent_w_req_queue in the window before the entry is moved off it.\n\nFix this by taking the entry off ent_w_req_queue and changing its state\nfrom FRRS_FUSE_REQ to FRRS_INVALID before terminating the request."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/fuse/dev_uring.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4fea593e625cd50d4d11be227007849b12f17bfb","lessThan":"0b466cf1b96e191b06b496c4de79da15315c3a9a","versionType":"git","status":"affected"},{"version":"4fea593e625cd50d4d11be227007849b12f17bfb","lessThan":"0a7f33010c0e4cd92937e088a54350381fd0fbf2","versionType":"git","status":"affected"},{"version":"4fea593e625cd50d4d11be227007849b12f17bfb","lessThan":"1c57a69be962d459c5e705f5cb4355b841b3461c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/fuse/dev_uring.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0a7f33010c0e4cd92937e088a54350381fd0fbf2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0b466cf1b96e191b06b496c4de79da15315c3a9a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1c57a69be962d459c5e705f5cb4355b841b3461c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64259","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:06.033","lastModified":"2026-07-25T10:17:06.033","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse-uring: make a fuse_req on SQE commit only findable after memcpy\n\nBad userspace might try to trick us and send commit SQEs request\nunique / commit-id of requests that are not even send to\nfuse-server (io_uring_cmd_done() not called) yet.\n\nfuse_uring_commit_fetch() ends the fuse request when the ring entry\nhas a wrong state, but that could have caused a use-after-free\nwith the memcpy operations in fuse_uring_send_in_task().\nIn order to avoid such races the call of fuse_uring_add_to_pq()\nis moved after the copy operations and just before completing\nthe io-uring request - malicious userspace cannot find the request\nanymore until all prepration work in fuse-client/kernel is completed.\n\nThis also moves fuse_uring_add_to_pq() a bit up in the code to\navoid a forward declaration. Also not with a preparation commit,\nto make it easier to back port to older kernels."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/fuse/dev_uring.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c090c8abae4b6b77a1bee116aa6c385456ebef96","lessThan":"e1711479e9068ea31b31353a702a51e639c3d059","versionType":"git","status":"affected"},{"version":"c090c8abae4b6b77a1bee116aa6c385456ebef96","lessThan":"a635f427d57e2012102ae4886b48d8955c59fb86","versionType":"git","status":"affected"},{"version":"c090c8abae4b6b77a1bee116aa6c385456ebef96","lessThan":"1efd3d474fc0ba74dfd984249bca78807d739812","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/fuse/dev_uring.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1efd3d474fc0ba74dfd984249bca78807d739812","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a635f427d57e2012102ae4886b48d8955c59fb86","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e1711479e9068ea31b31353a702a51e639c3d059","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64260","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:06.137","lastModified":"2026-07-25T10:17:06.137","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse-uring: Avoid queue->stopped races and set/read that value under lock\n\nThere are several readers of queue->stopped that check the value\nunder lock, but fuse_uring_commit_fetch() did not and actually\nthe value was not set under the lock in fuse_uring_abort_end_requests()\neither. Especially in fuse_uring_commit_fetch it is important\nto check under a lock, because due to races 'struct fuse_req'\nmight be freed with fuse_request_end, but another thread/cpu\nmight already do teardown work."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/fuse/dev_uring.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4a9bfb9b6850fec0685447aed280533cf980de70","lessThan":"39c8e925b207afceffaa5382416ed405e0223a03","versionType":"git","status":"affected"},{"version":"4a9bfb9b6850fec0685447aed280533cf980de70","lessThan":"4021a3a79eee551d95fe1e1e7c1b195d34ba8c08","versionType":"git","status":"affected"},{"version":"4a9bfb9b6850fec0685447aed280533cf980de70","lessThan":"b70a3aca16934c196f92abb17b01c1647b9bb63c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/fuse/dev_uring.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/39c8e925b207afceffaa5382416ed405e0223a03","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4021a3a79eee551d95fe1e1e7c1b195d34ba8c08","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b70a3aca16934c196f92abb17b01c1647b9bb63c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64261","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:06.243","lastModified":"2026-07-25T10:17:06.243","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues\n\nfuse_uring_async_stop_queues() might run when the last reference\non ring->queue_refs was already dropped.\n\nIn order to avoid an early destruction a reference on struct fuse_conn\nis now taken before starting fuse_uring_async_stop_queues() and that\nreference is only released when that delayed work queue terminates."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/fuse/dev_uring.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4a9bfb9b6850fec0685447aed280533cf980de70","lessThan":"23a356e0bd96c8d5fb3ddff069f692bf10cab5c1","versionType":"git","status":"affected"},{"version":"4a9bfb9b6850fec0685447aed280533cf980de70","lessThan":"95d7f50aff2a5f71557263ff25b97b2951f32bf8","versionType":"git","status":"affected"},{"version":"4a9bfb9b6850fec0685447aed280533cf980de70","lessThan":"d351da75066955144515cb2f9aa959f24a04287a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/fuse/dev_uring.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/23a356e0bd96c8d5fb3ddff069f692bf10cab5c1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/95d7f50aff2a5f71557263ff25b97b2951f32bf8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d351da75066955144515cb2f9aa959f24a04287a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64262","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:06.350","lastModified":"2026-07-25T10:17:06.350","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse-uring: end fuse_req on io-uring cancel task work\n\nWhen io_uring delivers task work with tw.cancel set (PF_EXITING,\nPF_KTHREAD fallback, or percpu_ref_is_dying on the ring context),\nfuse_uring_send_in_task() takes the cancel branch, assigns\n-ECANCELED, and falls through to fuse_uring_send(). That path only\nflips the entry to FRRS_USERSPACE and completes the io_uring cmd;\nit never discharges the ring entry's owning reference to the\nfuse_req that fuse_uring_add_req_to_ring_ent() handed it at\ndispatch time.\n\n    fuse_uring_send_in_task()\n      tw.cancel == true\n        err = -ECANCELED\n      fuse_uring_send(ent, cmd, err, issue_flags)\n        ent->state = FRRS_USERSPACE\n        list_move(&ent->list, &queue->ent_in_userspace)\n        ent->cmd = NULL\n        io_uring_cmd_done(-ECANCELED)\n        /* ent->fuse_req still set, req still hashed */\n\nThe fuse_req stays linked on fpq->processing[hash] and\nfuse_request_end() is never invoked. The originating syscall\nthread blocks in D-state in request_wait_answer() until\nfuse_abort_conn() runs, which can be the entire connection\nlifetime. For FR_BACKGROUND requests fc->num_background is never\ndecremented either, so repeated cancels inflate the counter until\nmax_background is hit and all later background ops stall. tw.cancel does\nnot imply a connection abort (e.g. a single io_uring worker thread exits\nwhile the fuse connection stays up), so this cannot be left for\nfuse_abort_conn() to clean up.\n\nEnding the req but still routing the entry through fuse_uring_send()\nis not enough: that leaves a req-less entry on ent_in_userspace, and\nent_list_request_expired() dereferences ent->fuse_req unconditionally\non the head of that list, which would then NULL-deref.\n\nFix the cancel branch to release the entry directly. Remove it from the\nqueue, complete the io_uring cmd, end the fuse_req, free the entry, and\ndrop its queue_refs (waking the teardown waiter if it was the last)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/fuse/dev_uring.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c2c9af9a0b13261c36909036057a116f2edb5e1a","lessThan":"bb476ef8e1027a9d509fbaaf81f5061a07e9e5a7","versionType":"git","status":"affected"},{"version":"c2c9af9a0b13261c36909036057a116f2edb5e1a","lessThan":"4f45f276d5b4412eade6f74f2e37f3adba0473ed","versionType":"git","status":"affected"},{"version":"c2c9af9a0b13261c36909036057a116f2edb5e1a","lessThan":"bea4fe98204b6ce7eb8e29f7bf867dd7619b3ddd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/fuse/dev_uring.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4f45f276d5b4412eade6f74f2e37f3adba0473ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb476ef8e1027a9d509fbaaf81f5061a07e9e5a7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bea4fe98204b6ce7eb8e29f7bf867dd7619b3ddd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64263","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:06.460","lastModified":"2026-07-25T10:17:06.460","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse-uring: fix moving cancelled entry to ent_in_userspace list\n\nfuse_uring_cancel() moves entries that are available (these have no reqs\nattached) to the ent_in_userspace list. ent_list_request_expired()\nchecks the first entry on ent_in_userspace and dereferences\nent->fuse_req unconditionally, which will crash on a cancelled entry\nthat was moved to this list.\n\nFix this by freeing the entry and dropping queue_refs directly in\nfuse_uring_cancel(). This is safe because cancel is the cancel handler\nitself - after io_uring_cmd_done(), no more cancels will be dispatched\nfor this command, and teardown serializes with cancel via queue->lock.\n\nSince cancel now decrements queue_refs, fuse_uring_abort() must no\nlonger gate fuse_uring_abort_end_requests() on queue_refs > 0, as\ncancelled entries may have already dropped queue_refs while requests are\nstill queued. Remove the gate so abort always flushes requests and stops\nqueues."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/fuse/dev_uring.c","fs/fuse/dev_uring_i.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4fea593e625cd50d4d11be227007849b12f17bfb","lessThan":"50f3e03db823cabc41fe35c27d77c2bdb112baad","versionType":"git","status":"affected"},{"version":"4fea593e625cd50d4d11be227007849b12f17bfb","lessThan":"e8afc85acdf329361b2d8df2ad9b52364686235f","versionType":"git","status":"affected"},{"version":"4fea593e625cd50d4d11be227007849b12f17bfb","lessThan":"198f45eeb9f78b2a2d6d8be95e4e43468eb2c6bc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/fuse/dev_uring.c","fs/fuse/dev_uring_i.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/198f45eeb9f78b2a2d6d8be95e4e43468eb2c6bc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/50f3e03db823cabc41fe35c27d77c2bdb112baad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e8afc85acdf329361b2d8df2ad9b52364686235f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64264","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:06.563","lastModified":"2026-07-25T10:17:06.563","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse-uring: fix EFAULT clobber in fuse_uring_commit\n\ncopy_from_user() returns the number of bytes not copied as an unsigned\nresidual on failure (1..sizeof(struct fuse_out_header)). fuse_uring_commit\nstores that residual in ssize_t err, sets req->out.h.error to -EFAULT,\nthen jumps to out: with err still holding the positive residual.\n\n    err = copy_from_user(&req->out.h, &ent->headers->in_out,\n                         sizeof(req->out.h));\n    if (err) {\n        req->out.h.error = -EFAULT;\n        goto out;          /* err is the positive residual */\n    }\n    ...\n    out:\n        fuse_uring_req_end(ent, req, err);\n\nfuse_uring_req_end() then runs\n\n    if (error)\n        req->out.h.error = error;\n\nwhich overwrites the just-assigned -EFAULT with the positive residual.\nFUSE callers such as fuse_simple_request() test err < 0 to detect\nfailure, so the positive value is interpreted as success and the\ncaller proceeds with an uninitialised or partial req->out.args.\n\nFix by assigning err = -EFAULT in the failure branch before jumping\nto out, so fuse_uring_req_end() receives a negative errno and sets\nreq->out.h.error to -EFAULT."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/fuse/dev_uring.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c090c8abae4b6b77a1bee116aa6c385456ebef96","lessThan":"0483fffdeeb363f320e6bf5fc0f0306007507306","versionType":"git","status":"affected"},{"version":"c090c8abae4b6b77a1bee116aa6c385456ebef96","lessThan":"fe604c08d874648a69187f6380e5c7858627dc04","versionType":"git","status":"affected"},{"version":"c090c8abae4b6b77a1bee116aa6c385456ebef96","lessThan":"3a0a8bc51a13951c5141262bf770eeea3e0b6228","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/fuse/dev_uring.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0483fffdeeb363f320e6bf5fc0f0306007507306","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3a0a8bc51a13951c5141262bf770eeea3e0b6228","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe604c08d874648a69187f6380e5c7858627dc04","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64265","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:06.667","lastModified":"2026-07-25T10:17:06.667","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: clear intr_entry in fuse_resend and fuse_remove_pending_req\n\nWhen fuse_resend() moves a request from fpq->processing back to\nfiq->pending, it sets FR_PENDING and clears FR_SENT but does not\nremove the requests intr_entry from fiq->interrupts.  If the\nrequest had FR_INTERRUPTED set from a prior signal, intr_entry\nremains dangling on fiq->interrupts.  When the requesting task\nthen receives a fatal signal, fuse_remove_pending_req() sees\nFR_PENDING=1, removes the request from fiq->pending and frees it\nvia the refcount path, also without cleaning intr_entry.  The\nstale intr_entry causes use-after-free when fuse_read_interrupt()\niterates fiq->interrupts:\n  - list_del_init(&req->intr_entry) -> UAF write on freed slab\n  - req->in.h.unique -> UAF read, data leaked to userspace\n\nRemove intr_entry from fiq->interrupts in fuse_resend() for\ninterrupted requests before they are placed back on fiq->pending.\n\nAdd a WARN_ON if the intr_entry is not empty on request destruction."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/fuse/dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"760eac73f9f69aa28fcb3050b4946c2dcc656d12","lessThan":"1d8ecd0cd696a5df0b2f72046a4ccee5d2a8ec2c","versionType":"git","status":"affected"},{"version":"760eac73f9f69aa28fcb3050b4946c2dcc656d12","lessThan":"7366e6f4d2b4c7002b13fb01219e83679dad4127","versionType":"git","status":"affected"},{"version":"760eac73f9f69aa28fcb3050b4946c2dcc656d12","lessThan":"893479015cb6442fd389d3b553ab3036c9541715","versionType":"git","status":"affected"},{"version":"760eac73f9f69aa28fcb3050b4946c2dcc656d12","lessThan":"f8fce75fedf73ac72aa09163deb8f4291fdcaad2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/fuse/dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1d8ecd0cd696a5df0b2f72046a4ccee5d2a8ec2c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7366e6f4d2b4c7002b13fb01219e83679dad4127","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/893479015cb6442fd389d3b553ab3036c9541715","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f8fce75fedf73ac72aa09163deb8f4291fdcaad2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64266","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:06.783","lastModified":"2026-07-25T10:17:06.783","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: re-lock request before returning from fuse_ref_folio()\n\nfuse_ref_folio() unlocks the request but does not re-lock it before\nreturning. fuse_chan_abort() can end the request and the async end\ncallback (eg fuse_writepage_free()) can free the args while the\nsubsequent copy chain logic after fuse_ref_folio() accesses them,\nleading to use-after-free issues.\n\nFix this by locking the request in fuse_ref_folio() before returning."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/fuse/dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c3021629a0d820247ee12b6c5192a1d5380e21c6","lessThan":"1f9156714592356b4fda57beac7eab9c2a462dd3","versionType":"git","status":"affected"},{"version":"c3021629a0d820247ee12b6c5192a1d5380e21c6","lessThan":"5630da218a45ba80f0aba0846cbe8aa655da122b","versionType":"git","status":"affected"},{"version":"c3021629a0d820247ee12b6c5192a1d5380e21c6","lessThan":"1ca605cfa59377f0143fb35b5b01360f37d1b7c4","versionType":"git","status":"affected"},{"version":"c3021629a0d820247ee12b6c5192a1d5380e21c6","lessThan":"0e4a5a000123d81234e27a2f8187688cf608f755","versionType":"git","status":"affected"},{"version":"c3021629a0d820247ee12b6c5192a1d5380e21c6","lessThan":"e6aa539720c3d8def69683ed0c07cf9faea4e8be","versionType":"git","status":"affected"},{"version":"c3021629a0d820247ee12b6c5192a1d5380e21c6","lessThan":"be353caffa8640f5e25fb3714ce8b0cef5e410e5","versionType":"git","status":"affected"},{"version":"c3021629a0d820247ee12b6c5192a1d5380e21c6","lessThan":"65a1c2551f7e16085acbb54aedde1feaa559ba7a","versionType":"git","status":"affected"},{"version":"c3021629a0d820247ee12b6c5192a1d5380e21c6","lessThan":"b5befa80fdbe287a98480effed9564712924add5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/fuse/dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.35","status":"affected"},{"version":"0","lessThan":"2.6.35","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0e4a5a000123d81234e27a2f8187688cf608f755","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1ca605cfa59377f0143fb35b5b01360f37d1b7c4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1f9156714592356b4fda57beac7eab9c2a462dd3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5630da218a45ba80f0aba0846cbe8aa655da122b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/65a1c2551f7e16085acbb54aedde1feaa559ba7a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5befa80fdbe287a98480effed9564712924add5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be353caffa8640f5e25fb3714ce8b0cef5e410e5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e6aa539720c3d8def69683ed0c07cf9faea4e8be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64267","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:06.910","lastModified":"2026-07-25T10:17:06.910","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: avoid 32-bit prune notification count wrap\n\nFUSE_NOTIFY_PRUNE validates the nodeid payload length with:\n\n    size - sizeof(outarg) != outarg.count * sizeof(u64)\n\nOn 32-bit kernels, size_t is also 32 bits, so the daemon-controlled\ncount multiplication can wrap.  A prune notification with count\n0x20000000 and no nodeid payload passes the check, enters the copy\nloop, and asks the device copy path to read nodeids that are not\npresent in the userspace write buffer.  In QEMU this reaches the\nfuse_copy_fill() BUG_ON(!err) path.\n\nValidate the payload length with array_size() instead.  That accepts\nexactly the same valid messages, but avoids wrapping arithmetic before\nthe copy loop consumes the count."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/fuse/dev.c","fs/fuse/notify.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3f29d59e92a96d843c2ff10ebfed92ac26878658","lessThan":"6e2d84fdeac05bfd858e84a76353fdb84f23a43e","versionType":"git","status":"affected"},{"version":"3f29d59e92a96d843c2ff10ebfed92ac26878658","lessThan":"c78c4b242299bc581e4987e5c2786c6f4760c516","versionType":"git","status":"affected"},{"version":"3f29d59e92a96d843c2ff10ebfed92ac26878658","lessThan":"54243797cedf55447b4c5d560e8cd709900061ae","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/fuse/dev.c","fs/fuse/notify.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/54243797cedf55447b4c5d560e8cd709900061ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e2d84fdeac05bfd858e84a76353fdb84f23a43e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c78c4b242299bc581e4987e5c2786c6f4760c516","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64268","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:07.013","lastModified":"2026-07-25T10:17:07.013","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: bound Read Response placement to the RREAD length\n\nIn drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each\ninbound Read Response DDP segment at sge->laddr + wqe->processed and then\naccumulates wqe->processed, but it never checks the running total against\nthe sink buffer length on continuation segments. siw_check_sge() resolves\nand validates the sink memory only on the first fragment (the if (!*mem)\nbranch), and siw_rresp_check_ntoh() compares the cumulative length against\nwqe->bytes only on the final segment (the !frx->more_ddp_segs guard).\n\nA connected siw peer that answers an outstanding RREAD with Read Response\nsegments that keep the DDP Last flag clear, carrying more total payload\nthan the RREAD requested, drives wqe->processed past the validated sink\nbuffer; the next siw_rx_data() call writes out of bounds at\nsge->laddr + wqe->processed. siw runs iWARP over ordinary routable TCP,\nso the peer is the remote end of an established RDMA connection and needs\nno local privilege.\n\nBound every segment before placement, exactly as siw_proc_send() and\nsiw_proc_write() already do for their tagged and untagged paths, and\nterminate the connection with a base-or-bounds DDP error when the\nRead Response would overrun the sink buffer.\n\nThis is the second receive-path length fix for this file. A separate\nchange rejects an MPA FPDU length that underflows the per-fragment\nremainder in the header decode; that guard does not cover this case,\nbecause here each individual segment length is self-consistent and only\nthe accumulated placement offset overruns the buffer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/sw/siw/siw_qp_rx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8b6a361b8c482f22ac99c3273285ff16b23fba91","lessThan":"a31b6d18ded3cc32d9ee85a6ff0726d4274887b2","versionType":"git","status":"affected"},{"version":"8b6a361b8c482f22ac99c3273285ff16b23fba91","lessThan":"595e6537ad1a210da32cbb9a7f91aa73090915ba","versionType":"git","status":"affected"},{"version":"8b6a361b8c482f22ac99c3273285ff16b23fba91","lessThan":"3ef7e052cbd05a8b13a51a07b185a39ec93ee1cf","versionType":"git","status":"affected"},{"version":"8b6a361b8c482f22ac99c3273285ff16b23fba91","lessThan":"b2e26c955f8dd7e8d3f16c858db05245ea4fa817","versionType":"git","status":"affected"},{"version":"8b6a361b8c482f22ac99c3273285ff16b23fba91","lessThan":"6bc89f34a4597f9f6d41f7a60c67a3153bfe8851","versionType":"git","status":"affected"},{"version":"8b6a361b8c482f22ac99c3273285ff16b23fba91","lessThan":"423a78ff7928c2601013f73ec6d896f5597d0df5","versionType":"git","status":"affected"},{"version":"8b6a361b8c482f22ac99c3273285ff16b23fba91","lessThan":"75c93cd3c421890f49ea93f0b978b9b7bb10e5e3","versionType":"git","status":"affected"},{"version":"8b6a361b8c482f22ac99c3273285ff16b23fba91","lessThan":"7d29f7e9dbd844cae4d3e559cf78324b9642fd6b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/sw/siw/siw_qp_rx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3ef7e052cbd05a8b13a51a07b185a39ec93ee1cf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/423a78ff7928c2601013f73ec6d896f5597d0df5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/595e6537ad1a210da32cbb9a7f91aa73090915ba","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6bc89f34a4597f9f6d41f7a60c67a3153bfe8851","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/75c93cd3c421890f49ea93f0b978b9b7bb10e5e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d29f7e9dbd844cae4d3e559cf78324b9642fd6b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a31b6d18ded3cc32d9ee85a6ff0726d4274887b2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b2e26c955f8dd7e8d3f16c858db05245ea4fa817","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64269","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:07.160","lastModified":"2026-07-25T10:17:07.160","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg\n\nWhen the server answers an RTRS READ, rdma_write_sg() builds the source\nscatter/gather entry for the IB_WR_RDMA_WRITE that returns data to the\npeer. Its length is taken directly from the wire descriptor:\n\n  plist->length = le32_to_cpu(id->rd_msg->desc[0].len);\n\nrd_msg points into the chunk buffer that the remote peer filled via\nRDMA-WRITE-WITH-IMM (rtrs_srv_rdma_done() -> process_io_req() ->\nprocess_read()), so desc[0].len is attacker-controlled and, before this\nchange, was only rejected when zero. The source address is the fixed\nchunk start (dma_addr[msg_id]) and the source lkey is the PD-wide\nlocal_dma_lkey, which is not tied to the chunk's MR mapping, so the verbs\nlayer does not constrain the transfer length to max_chunk_size. msg_id\nand off are bounded against queue_depth and max_chunk_size in\nrtrs_srv_rdma_done(), but desc[0].len is a separate field that was not\nchecked against the chunk size.\n\nA peer that advertises desc[0].len larger than max_chunk_size can make\nthe posted RDMA write read past the chunk's mapped region. The resulting\nbehaviour depends on the IOMMU configuration: with no IOMMU or in\npassthrough mode the read may extend into memory adjacent to the chunk\nand be returned to the peer, which can disclose host memory; with a\ntranslating IOMMU the out-of-range access is expected to fault and abort\nthe connection. In either case the transfer exceeds what the protocol\npermits and is driven by a remote peer.\n\nReject a descriptor length above max_chunk_size, mirroring the existing\noff >= max_chunk_size bound in rtrs_srv_rdma_done(). Legitimate clients\ndo not exceed it: the client sets desc[0].len to its MR length, which is\ncapped at the negotiated max_io_size (max_chunk_size - MAX_HDR_SIZE)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/ulp/rtrs/rtrs-srv.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9cb837480424e78ed585376f944088246685aec3","lessThan":"68c09762172f6224e9ddf9b0a60bacbb36e443eb","versionType":"git","status":"affected"},{"version":"9cb837480424e78ed585376f944088246685aec3","lessThan":"6cada540150894e81042a0ae0c796a21a9a877da","versionType":"git","status":"affected"},{"version":"9cb837480424e78ed585376f944088246685aec3","lessThan":"2912f3d40355dabc08fdbaaf2764d02445fe88dc","versionType":"git","status":"affected"},{"version":"9cb837480424e78ed585376f944088246685aec3","lessThan":"6f40246f4312fdbab5a13cc440adebf95eb2aa66","versionType":"git","status":"affected"},{"version":"9cb837480424e78ed585376f944088246685aec3","lessThan":"5a45d0aa1fa50a333ce5763ade744e2d89838667","versionType":"git","status":"affected"},{"version":"9cb837480424e78ed585376f944088246685aec3","lessThan":"da3e44add94b05dfde56f898421922f5cf35705f","versionType":"git","status":"affected"},{"version":"9cb837480424e78ed585376f944088246685aec3","lessThan":"963af8d97a8c6a117134a8d0db1415e0489200b1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/ulp/rtrs/rtrs-srv.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.8","status":"affected"},{"version":"0","lessThan":"5.8","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2912f3d40355dabc08fdbaaf2764d02445fe88dc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5a45d0aa1fa50a333ce5763ade744e2d89838667","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/68c09762172f6224e9ddf9b0a60bacbb36e443eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6cada540150894e81042a0ae0c796a21a9a877da","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6f40246f4312fdbab5a13cc440adebf95eb2aa66","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/963af8d97a8c6a117134a8d0db1415e0489200b1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/da3e44add94b05dfde56f898421922f5cf35705f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64270","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:07.293","lastModified":"2026-07-25T10:17:07.293","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: mms114 - reject an oversized device packet size\n\nmms114_interrupt() reads a packet of touch data from the device into a\nfixed-size on-stack buffer\n\n\tstruct mms114_touch touch[MMS114_MAX_TOUCH];\n\nwhich holds MMS114_MAX_TOUCH (10) events of MMS114_EVENT_SIZE (8) bytes,\ni.e. 80 bytes. The length of the I2C read into it is taken verbatim from\nthe device:\n\n\tpacket_size = mms114_read_reg(data, MMS114_PACKET_SIZE);\n\tif (packet_size <= 0)\n\t\tgoto out;\n\t...\n\terror = __mms114_read_reg(data, MMS114_INFORMATION, packet_size,\n\t\t\t(u8 *)touch);\n\npacket_size is a single device register byte (0x0F) and the only check\nis the lower bound packet_size <= 0; it is never bounded against the\nsize of touch[]. A malfunctioning, malicious or counterfeit controller\n(or an attacker tampering with the I2C bus) can report a packet_size of\nup to 255, so __mms114_read_reg() writes up to 175 bytes past the end of\ntouch[] on the IRQ-thread stack: a stack out-of-bounds write that can\noverwrite the stack canary, saved registers and the return address.\n\nA well-formed device never reports more than the buffer holds, so reject\nan oversized packet and drop the report, consistent with the handler's\nother error paths, rather than reading past the buffer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/input/touchscreen/mms114.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"07b8481d4aff73d6f451f25e74ea10240ff5131e","lessThan":"5d2ea15ba03bf17ed143ff1a0995a4206edc3fb6","versionType":"git","status":"affected"},{"version":"07b8481d4aff73d6f451f25e74ea10240ff5131e","lessThan":"b78150729762d47c14fe29a2582bdca5568e62b8","versionType":"git","status":"affected"},{"version":"07b8481d4aff73d6f451f25e74ea10240ff5131e","lessThan":"8301c335305344d4da4ab9442b6a399dacfe5b8d","versionType":"git","status":"affected"},{"version":"07b8481d4aff73d6f451f25e74ea10240ff5131e","lessThan":"f3d5e77b27fded71dcb97f409262bf0abba0410e","versionType":"git","status":"affected"},{"version":"07b8481d4aff73d6f451f25e74ea10240ff5131e","lessThan":"66725039f7090afe14c31bd259e2059a68f04023","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/input/touchscreen/mms114.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.6","status":"affected"},{"version":"0","lessThan":"3.6","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5d2ea15ba03bf17ed143ff1a0995a4206edc3fb6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/66725039f7090afe14c31bd259e2059a68f04023","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8301c335305344d4da4ab9442b6a399dacfe5b8d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b78150729762d47c14fe29a2582bdca5568e62b8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f3d5e77b27fded71dcb97f409262bf0abba0410e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64271","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:07.410","lastModified":"2026-07-25T10:17:07.410","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: touchwin - reset the packet index on every complete packet\n\ntw_interrupt() accumulates each non-zero serial byte into a fixed\nthree-byte buffer with a running index that is only reset once a full\npacket has been received *and* the device's two Y bytes agree:\n\n\ttw->data[tw->idx++] = data;\n\tif (tw->idx == TW_LENGTH && tw->data[1] == tw->data[2]) {\n\t\t...\n\t\ttw->idx = 0;\n\t}\n\nThe reset is gated on tw->data[1] == tw->data[2], a value the device\ncontrols.  A malicious, malfunctioning or counterfeit Touchwindow\nperipheral can stream non-zero bytes whose 2nd and 3rd bytes differ: the\nindex reaches TW_LENGTH without the equality holding, is never reset, and\nkeeps growing, so tw->data[tw->idx++] walks off the end of the three-byte\narray and the rest of the heap-allocated struct tw, one attacker-chosen\nbyte at a time -- an unbounded, device-driven heap out-of-bounds write.\n\nReset the index on every completed packet and report an event only when\nthe two Y bytes match, like the other serio touchscreen drivers do."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/input/touchscreen/touchwin.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"11ea3173d5f2de71d037ef58ac43395795fed2bc","lessThan":"ed9b66905407eb3d02df1aaeed82eb7a7f0eb508","versionType":"git","status":"affected"},{"version":"11ea3173d5f2de71d037ef58ac43395795fed2bc","lessThan":"044167cba2384bcd783547ad5e30ecd292b30919","versionType":"git","status":"affected"},{"version":"11ea3173d5f2de71d037ef58ac43395795fed2bc","lessThan":"6c9f29f128dd4057404838259af4c645318487e1","versionType":"git","status":"affected"},{"version":"11ea3173d5f2de71d037ef58ac43395795fed2bc","lessThan":"431ad239f2924dff337c3fccb9246597c1b63185","versionType":"git","status":"affected"},{"version":"11ea3173d5f2de71d037ef58ac43395795fed2bc","lessThan":"70e4248793762df9832fd4fc2fc6ac7924572c36","versionType":"git","status":"affected"},{"version":"11ea3173d5f2de71d037ef58ac43395795fed2bc","lessThan":"3e6f007b43e2fc6546e21fa74ee62c38984a6672","versionType":"git","status":"affected"},{"version":"11ea3173d5f2de71d037ef58ac43395795fed2bc","lessThan":"a8d87184576c889759e3aab899799a482f1e1a5b","versionType":"git","status":"affected"},{"version":"11ea3173d5f2de71d037ef58ac43395795fed2bc","lessThan":"478cdd736f2ce3114f90e775d7358136d3977b94","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/input/touchscreen/touchwin.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.19","status":"affected"},{"version":"0","lessThan":"2.6.19","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/044167cba2384bcd783547ad5e30ecd292b30919","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3e6f007b43e2fc6546e21fa74ee62c38984a6672","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/431ad239f2924dff337c3fccb9246597c1b63185","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/478cdd736f2ce3114f90e775d7358136d3977b94","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c9f29f128dd4057404838259af4c645318487e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/70e4248793762df9832fd4fc2fc6ac7924572c36","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a8d87184576c889759e3aab899799a482f1e1a5b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed9b66905407eb3d02df1aaeed82eb7a7f0eb508","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64272","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:07.550","lastModified":"2026-07-25T10:17:07.550","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: mms114 - fix touch indexing for MMS134S and MMS136\n\nThe MMS134S and MMS136 touch controllers have an event size of 6 bytes\nrather than 8 bytes. When __mms114_read_reg() reads the touch data\npacket from the device into the touch buffer, the events are packed\ntightly at 6-byte intervals. However, the driver iterates through the\nevents using standard C array indexing (touch[index]), where each\nelement is sizeof(struct mms114_touch) (8 bytes) apart. As a result, any\ntouch events beyond the first one are read from incorrect offsets and\nparsed improperly.\n\nFix this by explicitly calculating the byte offset for each touch event\nbased on the device's specific event size."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/input/touchscreen/mms114.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"53fefdd1d3a3403d8c44e28898d1031d8763b913","lessThan":"112666835071d935fef764aab590339e97216d4a","versionType":"git","status":"affected"},{"version":"53fefdd1d3a3403d8c44e28898d1031d8763b913","lessThan":"7c00a0787af7164438bdbc97fcae9733cfc58d21","versionType":"git","status":"affected"},{"version":"53fefdd1d3a3403d8c44e28898d1031d8763b913","lessThan":"75b12874b4172533b9efc349db328cb1a59c3981","versionType":"git","status":"affected"},{"version":"53fefdd1d3a3403d8c44e28898d1031d8763b913","lessThan":"a747c4eb02656afdbd92eea83b88e92715a23977","versionType":"git","status":"affected"},{"version":"53fefdd1d3a3403d8c44e28898d1031d8763b913","lessThan":"a6ac4e24c1a8a533bb61035184fdcc7eede4cc8d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/input/touchscreen/mms114.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/112666835071d935fef764aab590339e97216d4a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/75b12874b4172533b9efc349db328cb1a59c3981","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7c00a0787af7164438bdbc97fcae9733cfc58d21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a6ac4e24c1a8a533bb61035184fdcc7eede4cc8d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a747c4eb02656afdbd92eea83b88e92715a23977","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64273","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:07.660","lastModified":"2026-07-25T10:17:07.660","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: iforce - bound the device-reported force-feedback effect index\n\niforce_process_packet() handles a status report (packet id 0x02) by\ntaking a force-feedback effect index straight from the device wire and\nusing it to address the per-effect state array:\n\n\ti = data[1] & 0x7f;\n\tif (data[1] & 0x80) {\n\t\tif (!test_and_set_bit(FF_CORE_IS_PLAYED,\n\t\t\t\t      iforce->core_effects[i].flags))\n\t\t\t...\n\t} else if (test_and_clear_bit(FF_CORE_IS_PLAYED,\n\t\t\t\t      iforce->core_effects[i].flags)) {\n\t\t...\n\t}\n\nThe index is masked only with 0x7f, so it ranges 0..127, but\ncore_effects[] holds only IFORCE_EFFECTS_MAX (32) entries.  For an index\nof 32..127 the test_and_set_bit()/test_and_clear_bit() is an\nout-of-bounds single-bit read-modify-write past the array.  core_effects[]\nis the second-to-last member of struct iforce, so the write lands in the\ntrailing members and beyond the embedding kzalloc()'d iforce_serio /\niforce_usb object.\n\ndata[1] is unvalidated device payload on both transports (the USB\ninterrupt endpoint and serio), and the status path is not gated on force\nfeedback being present, so a malicious or counterfeit device can set or\nclear a bit at an attacker-chosen offset past the object.\n\nReject an out-of-range index instead of indexing with it.  Bound against\nthe array dimension IFORCE_EFFECTS_MAX rather than dev->ff->max_effects so\nthe check guarantees memory safety regardless of how many effects the\ndevice registered.  A legitimate \"effect started/stopped\" status always\ncarries an index below IFORCE_EFFECTS_MAX, so well-formed devices are\nunaffected; the neighbouring mark_core_as_ready() loop is already bounded\nand is left untouched."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/input/joystick/iforce/iforce-packets.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b1b79e89bc33e4c682d3df7ae2aadc62b5a0c310","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d10b0507fa0f5b46764b178e3271f9012f2df677","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6c0f2901c9d325d4a0574c4237fd507810d225ff","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c21295616a8a52b9a5f18cd4ca8c73030eda3d4f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e5fa31f0550b55d80045669ae9080dd5b88abffa","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"70019779325f2bb5f5a4098e91e79c655f50fcef","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a40250f97c312e000e3616c9074022311a0efbc3","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"0e9943d2e4c63496b6ca84bc66fd3c71d40558e2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/input/joystick/iforce/iforce-packets.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0e9943d2e4c63496b6ca84bc66fd3c71d40558e2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c0f2901c9d325d4a0574c4237fd507810d225ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/70019779325f2bb5f5a4098e91e79c655f50fcef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a40250f97c312e000e3616c9074022311a0efbc3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b1b79e89bc33e4c682d3df7ae2aadc62b5a0c310","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c21295616a8a52b9a5f18cd4ca8c73030eda3d4f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d10b0507fa0f5b46764b178e3271f9012f2df677","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5fa31f0550b55d80045669ae9080dd5b88abffa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64274","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:07.797","lastModified":"2026-07-25T10:17:07.797","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: goodix - clamp the device-reported contact count\n\ngoodix_ts_read_input_report() copies the number of touch points reported\nby the device into an on-stack buffer\n\n\tu8 point_data[2 + GOODIX_MAX_CONTACT_SIZE * GOODIX_MAX_CONTACTS];\n\nwhich is sized for at most GOODIX_MAX_CONTACTS (10) contacts. The only\nruntime check bounds the per-interrupt count against ts->max_touch_num,\nbut that value is taken verbatim from a 4-bit field of the device\nconfiguration block and is never clamped:\n\n\tts->max_touch_num = ts->config[MAX_CONTACTS_LOC] & 0x0f;\n\nThe nibble can be 0..15, so a malfunctioning, malicious or counterfeit\ncontroller (or an attacker tampering with the I2C bus) can advertise up\nto 15 contacts. goodix_ts_read_input_report() then accepts a touch_num\nof up to 15 and the second goodix_i2c_read() writes\nts->contact_size * (touch_num - 1) bytes past the one-contact header into\npoint_data - up to 30 bytes (45 with the 9-byte report format) beyond the\n92-byte buffer: a stack out-of-bounds write.\n\nClamp max_touch_num to GOODIX_MAX_CONTACTS, the number of contacts\npoint_data[] is sized for, when reading it from the configuration."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/input/touchscreen/goodix.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a7ac7c95d4682883d141c5d7a7544d2818f0a09f","lessThan":"e825f352ef5271255cd08cc994b0dc25648a2f38","versionType":"git","status":"affected"},{"version":"a7ac7c95d4682883d141c5d7a7544d2818f0a09f","lessThan":"4bfea9c3a0981c1c7fc5d1a1b27197b2de247902","versionType":"git","status":"affected"},{"version":"a7ac7c95d4682883d141c5d7a7544d2818f0a09f","lessThan":"98b2caef249183b572c04451365246f919707845","versionType":"git","status":"affected"},{"version":"a7ac7c95d4682883d141c5d7a7544d2818f0a09f","lessThan":"719d1a2c83a46be6bf81af905e4f6adb3d32dc28","versionType":"git","status":"affected"},{"version":"a7ac7c95d4682883d141c5d7a7544d2818f0a09f","lessThan":"46addbd13dbf4aacb71cfbca964a5e552d0f45ae","versionType":"git","status":"affected"},{"version":"a7ac7c95d4682883d141c5d7a7544d2818f0a09f","lessThan":"3b32303460155603d25444274856013d211d5e1f","versionType":"git","status":"affected"},{"version":"a7ac7c95d4682883d141c5d7a7544d2818f0a09f","lessThan":"2a67668690129953e898923260a2dd1c7c196495","versionType":"git","status":"affected"},{"version":"a7ac7c95d4682883d141c5d7a7544d2818f0a09f","lessThan":"5ed62a96e06be4e94b8296b7932afee550a70e04","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/input/touchscreen/goodix.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.1","status":"affected"},{"version":"0","lessThan":"4.1","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2a67668690129953e898923260a2dd1c7c196495","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3b32303460155603d25444274856013d211d5e1f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/46addbd13dbf4aacb71cfbca964a5e552d0f45ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4bfea9c3a0981c1c7fc5d1a1b27197b2de247902","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5ed62a96e06be4e94b8296b7932afee550a70e04","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/719d1a2c83a46be6bf81af905e4f6adb3d32dc28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/98b2caef249183b572c04451365246f919707845","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e825f352ef5271255cd08cc994b0dc25648a2f38","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64275","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:07.927","lastModified":"2026-07-25T10:17:07.927","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: elan_i2c - prevent division by zero and arithmetic underflow\n\nThe Elan I2C touchpad driver queries the device for its physical\ndimensions and trace counts to calculate the device resolution and width.\nHowever, if the device firmware or device tree provides invalid zero\nvalues for x_traces or y_traces, it results in a fatal division-by-zero\nexception leading to a kernel panic during device probe.\n\nAdd checks to ensure these parameters are non-zero before performing\nthe division. If invalid trace values are detected, fall back to a safe\ndefault of 1.\n\nAdditionally, prevent an arithmetic underflow in the touch reporting\nlogic. Previously, if the calculated or fallback width was smaller than\nETP_FWIDTH_REDUCE (90), the subtraction would underflow, resulting in a\nmassive unsigned integer being reported to userspace. Clamp the adjusted\nwidth to a minimum of 0 to safely handle small physical dimensions and\nfallback scenarios.\n\nCompleting the probe with safe fallback values ensures the sysfs nodes\nare created, keeping the firmware update path intact so a recovery\nfirmware can be flashed to the device."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/input/mouse/elan_i2c_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6696777c6506fa52b2a0282121195843ed855be6","lessThan":"59d4cc5e7a9785e4bdc9c55273274c6b49d4b58d","versionType":"git","status":"affected"},{"version":"6696777c6506fa52b2a0282121195843ed855be6","lessThan":"f6d10af2036d1d4a847a74fe47ebbf93bce3c84c","versionType":"git","status":"affected"},{"version":"6696777c6506fa52b2a0282121195843ed855be6","lessThan":"2f281ff0163a38fdc4cb4061f0c241e643283a5e","versionType":"git","status":"affected"},{"version":"6696777c6506fa52b2a0282121195843ed855be6","lessThan":"8c1db3418a419e788691746b9c47f863c2fd4890","versionType":"git","status":"affected"},{"version":"6696777c6506fa52b2a0282121195843ed855be6","lessThan":"feb4866a42ec94764c7eb58012256f6f37664727","versionType":"git","status":"affected"},{"version":"6696777c6506fa52b2a0282121195843ed855be6","lessThan":"01e0317c256c560d8dcce2e9825eb6142ee34611","versionType":"git","status":"affected"},{"version":"6696777c6506fa52b2a0282121195843ed855be6","lessThan":"6bac57d8fe2a077b8a85b4140eeb7999078158eb","versionType":"git","status":"affected"},{"version":"6696777c6506fa52b2a0282121195843ed855be6","lessThan":"df2b818fa009c10ff6ba875a1663ff001cda9558","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/input/mouse/elan_i2c_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.19","status":"affected"},{"version":"0","lessThan":"3.19","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/01e0317c256c560d8dcce2e9825eb6142ee34611","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2f281ff0163a38fdc4cb4061f0c241e643283a5e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/59d4cc5e7a9785e4bdc9c55273274c6b49d4b58d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6bac57d8fe2a077b8a85b4140eeb7999078158eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8c1db3418a419e788691746b9c47f863c2fd4890","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/df2b818fa009c10ff6ba875a1663ff001cda9558","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f6d10af2036d1d4a847a74fe47ebbf93bce3c84c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/feb4866a42ec94764c7eb58012256f6f37664727","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64276","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:08.060","lastModified":"2026-07-25T10:17:08.060","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count\n\nrmi_f30_map_gpios() allocates gpioled_key_map with\nmin(gpioled_count, TRACKSTICK_RANGE_END) == at most 6 entries, but\nrmi_f30_attention() iterates the full f30->gpioled_count (device query\nregister, range 0..31) and dereferences gpioled_key_map[i], and\ninput->keycodemax is set to the full gpioled_count while input->keycode\npoints at the 6-entry allocation.\n\nA device that reports gpioled_count > 6 with GPIO support enabled\ntherefore causes an out-of-bounds read on the attention interrupt and\nout-of-bounds read/write through the EVIOCGKEYCODE/EVIOCSKEYCODE ioctls,\nwhich bound the index only against keycodemax. This is the same defect\nas the F3A handler, which was copied from F30.\n\nSize the keymap for the full gpioled_count; the mapping loop still\nassigns only the first min(gpioled_count, TRACKSTICK_RANGE_END) entries."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/input/rmi4/rmi_f30.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3e64fcbdbd10e46dede502d507dbcc104837cd59","lessThan":"8c6d18d61bb6fe0e6edf848413391c590552e8a9","versionType":"git","status":"affected"},{"version":"3e64fcbdbd10e46dede502d507dbcc104837cd59","lessThan":"d162a1ead7de404d8b41a093c83ed0db6487cded","versionType":"git","status":"affected"},{"version":"3e64fcbdbd10e46dede502d507dbcc104837cd59","lessThan":"f0be9eba946e9200b43265e0a748d38bd0a56954","versionType":"git","status":"affected"},{"version":"3e64fcbdbd10e46dede502d507dbcc104837cd59","lessThan":"26c895928d7118436a24f564587cb4aefc40cdd8","versionType":"git","status":"affected"},{"version":"3e64fcbdbd10e46dede502d507dbcc104837cd59","lessThan":"4e3689c26854356f41fbaa1eafa382e58ac79e00","versionType":"git","status":"affected"},{"version":"3e64fcbdbd10e46dede502d507dbcc104837cd59","lessThan":"e849c6f51e6877104c765da084e001ec37c8e119","versionType":"git","status":"affected"},{"version":"3e64fcbdbd10e46dede502d507dbcc104837cd59","lessThan":"bfe622efecd4ff0a792d0ecd1a8dce535a902f50","versionType":"git","status":"affected"},{"version":"3e64fcbdbd10e46dede502d507dbcc104837cd59","lessThan":"d577e46785d45484b2ab7e7309c49b18764bf56c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/input/rmi4/rmi_f30.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.14","status":"affected"},{"version":"0","lessThan":"4.14","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/26c895928d7118436a24f564587cb4aefc40cdd8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4e3689c26854356f41fbaa1eafa382e58ac79e00","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8c6d18d61bb6fe0e6edf848413391c590552e8a9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bfe622efecd4ff0a792d0ecd1a8dce535a902f50","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d162a1ead7de404d8b41a093c83ed0db6487cded","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d577e46785d45484b2ab7e7309c49b18764bf56c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e849c6f51e6877104c765da084e001ec37c8e119","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f0be9eba946e9200b43265e0a748d38bd0a56954","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64277","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:08.197","lastModified":"2026-07-25T10:17:08.197","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - bound the F3A keymap to the GPIO count\n\nrmi_f3a_initialize() takes the GPIO count from the device query register\n(f3a->gpio_count = buf & RMI_F3A_GPIO_COUNT, range 0..127).\nrmi_f3a_map_gpios() then allocates gpio_key_map with\nmin(gpio_count, TRACKSTICK_RANGE_END) == at most 6 entries, but\nrmi_f3a_attention() iterates the full gpio_count and dereferences\ngpio_key_map[i], and input->keycodemax is set to the full gpio_count\nwhile input->keycode points at the 6-entry allocation.\n\nA device that reports gpio_count > 6 therefore causes an out-of-bounds\nread of gpio_key_map[] on every attention interrupt, and out-of-bounds\naccesses through the input core's default keymap ioctls: EVIOCGKEYCODE\nreads past the buffer (leaking adjacent slab memory to user space) and\nEVIOCSKEYCODE writes a caller-controlled value past it, for any process\nable to open the evdev node, since input_default_getkeycode() and\ninput_default_setkeycode() only bound the index against keycodemax.\n\nSize the keymap for the full gpio_count. The mapping loop is unchanged:\nit still assigns only the first min(gpio_count, TRACKSTICK_RANGE_END)\nentries; the remaining slots stay KEY_RESERVED (devm_kcalloc zero-fills)\nand are skipped when reporting."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/input/rmi4/rmi_f3a.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9e4c596bfd004f447a652205163234dfd4aafa69","lessThan":"502ad7caaa1a445b734c827fa256e5311df67e3d","versionType":"git","status":"affected"},{"version":"9e4c596bfd004f447a652205163234dfd4aafa69","lessThan":"3480e24bc4e178aaa009edb25b6ee12df199e210","versionType":"git","status":"affected"},{"version":"9e4c596bfd004f447a652205163234dfd4aafa69","lessThan":"35ed74d32d8260bdfb14a94caf402bf0866bdeec","versionType":"git","status":"affected"},{"version":"9e4c596bfd004f447a652205163234dfd4aafa69","lessThan":"ba57f430328534501962d60d651e385ffd7af9ca","versionType":"git","status":"affected"},{"version":"9e4c596bfd004f447a652205163234dfd4aafa69","lessThan":"850117b637bcb1dcc14be0cf09ac819a8707b42c","versionType":"git","status":"affected"},{"version":"9e4c596bfd004f447a652205163234dfd4aafa69","lessThan":"8db211aed83733073b0814adaeeab61d4521474e","versionType":"git","status":"affected"},{"version":"9e4c596bfd004f447a652205163234dfd4aafa69","lessThan":"64fb0e1161ccc6b9e48b8df61f07d3c34c01ec42","versionType":"git","status":"affected"},{"version":"9e4c596bfd004f447a652205163234dfd4aafa69","lessThan":"57c10915f2c16c90e0d46ad00876bf39ece40fc2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/input/rmi4/rmi_f3a.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3480e24bc4e178aaa009edb25b6ee12df199e210","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/35ed74d32d8260bdfb14a94caf402bf0866bdeec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/502ad7caaa1a445b734c827fa256e5311df67e3d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/57c10915f2c16c90e0d46ad00876bf39ece40fc2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/64fb0e1161ccc6b9e48b8df61f07d3c34c01ec42","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/850117b637bcb1dcc14be0cf09ac819a8707b42c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8db211aed83733073b0814adaeeab61d4521474e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba57f430328534501962d60d651e385ffd7af9ca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64278","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:08.330","lastModified":"2026-07-25T10:17:08.330","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: imx-lpi2c: mark I2C adapter when hardware is powered down\n\nOn some i.MX platforms, certain I2C client drivers keep a periodic\nworkqueue which continues to trigger I2C transfers.\n\nDuring system suspend/resume, there exists a time window between:\n  - suspend_noirq and the system entering suspend\n  - the system starting to resume and resume_noirq\n\nIn this window, the I2C controller resources such as clock and pinctrl\nmay already be disabled or not yet restored.\n\nIf a workqueue triggers an I2C transfer in this period, the driver\nattempts to access I2C registers while the hardware resources are\nunavailable, which may lead to system hang.\n\nMark the I2C adapter as suspended during noirq suspend and block new\ntransfers until resume, ensuring that I2C transfers are only issued\nwhen hardware resources are available."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/i2c/busses/i2c-imx-lpi2c.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1ee867e465c1b0216ec02d4c0d334c4e89919cec","lessThan":"b2523f26979e0b5bd1422772176b2233fcd1f6d0","versionType":"git","status":"affected"},{"version":"1ee867e465c1b0216ec02d4c0d334c4e89919cec","lessThan":"5800647d19d3f1f747fda4dc67e55d6afa6ee119","versionType":"git","status":"affected"},{"version":"1ee867e465c1b0216ec02d4c0d334c4e89919cec","lessThan":"218cfe364b55b2768221629bd4a69ad190b7fbbc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/i2c/busses/i2c-imx-lpi2c.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/218cfe364b55b2768221629bd4a69ad190b7fbbc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5800647d19d3f1f747fda4dc67e55d6afa6ee119","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b2523f26979e0b5bd1422772176b2233fcd1f6d0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64279","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:08.437","lastModified":"2026-07-25T10:17:08.437","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: core: fix adapter deregistration race\n\nAdapters can be looked up by their id using i2c_get_adapter() which\ntakes a reference to the embedded struct device.\n\nRemove the adapter from the IDR before tearing it down during\nderegistration (and on registration failure) to make sure its resources\nare not accessed after having been freed (e.g. the device name)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/i2c/i2c-core-base.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"35fc37f8188177e3ba3e7f99a6e3300e490e9181","lessThan":"d39282f552dd6c35b9b84b4af78f1198c24f3373","versionType":"git","status":"affected"},{"version":"35fc37f8188177e3ba3e7f99a6e3300e490e9181","lessThan":"11dfa37bf544cc806f21742ca2fd2d841bd7032e","versionType":"git","status":"affected"},{"version":"35fc37f8188177e3ba3e7f99a6e3300e490e9181","lessThan":"9882a9bd74db08e7bae5821a7050627ae92d3380","versionType":"git","status":"affected"},{"version":"35fc37f8188177e3ba3e7f99a6e3300e490e9181","lessThan":"bb234487a447a99315add1b46aa57b72e163e1eb","versionType":"git","status":"affected"},{"version":"35fc37f8188177e3ba3e7f99a6e3300e490e9181","lessThan":"b6d2af6fe9c1f5ec0484536753c979cbd40a8ac3","versionType":"git","status":"affected"},{"version":"35fc37f8188177e3ba3e7f99a6e3300e490e9181","lessThan":"35dbd1f1f603401155cbd3a180bb18e3a3b675b8","versionType":"git","status":"affected"},{"version":"35fc37f8188177e3ba3e7f99a6e3300e490e9181","lessThan":"b1a58ed9eab146b36f41a55db8f5d7ce9fdedf3f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/i2c/i2c-core-base.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.31","status":"affected"},{"version":"0","lessThan":"2.6.31","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/11dfa37bf544cc806f21742ca2fd2d841bd7032e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/35dbd1f1f603401155cbd3a180bb18e3a3b675b8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9882a9bd74db08e7bae5821a7050627ae92d3380","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b1a58ed9eab146b36f41a55db8f5d7ce9fdedf3f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6d2af6fe9c1f5ec0484536753c979cbd40a8ac3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb234487a447a99315add1b46aa57b72e163e1eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d39282f552dd6c35b9b84b4af78f1198c24f3373","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64280","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:08.553","lastModified":"2026-07-25T10:17:08.553","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()\n\nafu_ioctl_dma_map() accepts a 64-bit length from userspace via\nDFL_FPGA_PORT_DMA_MAP ioctl without an upper bound check. The value\nis passed to afu_dma_pin_pages() where npages is derived as\nlength >> PAGE_SHIFT and passed to pin_user_pages_fast() which takes\nint nr_pages, causing implicit truncation if length is very large.\n\nValidate map.length at the ioctl entry point before calling\nafu_dma_map_region(), rejecting values whose page count exceeds\nINT_MAX."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/fpga/dfl-afu-main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fa8dda1edef9ebc3af467c644c5533ac97171e12","lessThan":"59070040fd12e0b78d7b4d341d9f9a183237c5ff","versionType":"git","status":"affected"},{"version":"fa8dda1edef9ebc3af467c644c5533ac97171e12","lessThan":"fb2c0eab51ae5b02d2bae7d67c2cfbec39b57231","versionType":"git","status":"affected"},{"version":"fa8dda1edef9ebc3af467c644c5533ac97171e12","lessThan":"fc3b071a7c8dc0f5d56defddf6e6fd5aaa3e1e27","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/fpga/dfl-afu-main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.19","status":"affected"},{"version":"0","lessThan":"4.19","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/59070040fd12e0b78d7b4d341d9f9a183237c5ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb2c0eab51ae5b02d2bae7d67c2cfbec39b57231","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc3b071a7c8dc0f5d56defddf6e6fd5aaa3e1e27","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64281","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:08.667","lastModified":"2026-07-25T10:17:08.667","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: wake sq waiters when the transport closes\n\nThreads parked in svc_rdma_sq_wait() on sc_sq_ticket_wait or\nsc_send_wait can hang indefinitely in TASK_UNINTERRUPTIBLE state\nacross transport teardown, pinning svc_xprt references and\nblocking svc_rdma_free().\n\nThe close path sets XPT_CLOSE before invoking xpo_detach and both\nwait_event predicates include an XPT_CLOSE term, but the\npredicates are re-evaluated only on wakeup. sc_sq_ticket_wait has\nno completion-driven wake path; it is advanced solely by the\nchained ticket handoff inside svc_rdma_sq_wait() itself. Without\nan explicit wake at close, parked threads never observe\nXPT_CLOSE, hold their svc_xprt_get reference forever, and\nsvc_rdma_free() blocks on xpt_ref dropping to zero.\n\nTwo close entry points reach this transport. Local teardown runs\nsvc_rdma_detach() from svc_handle_xprt() -> svc_delete_xprt() ->\nxpo_detach() on a worker thread. A remote disconnect arrives at\nsvc_rdma_cma_handler(), which calls svc_xprt_deferred_close():\nthat sets XPT_CLOSE and enqueues the transport but does not\naccess either RDMA waitqueue, so a worker already parked in\nsvc_rdma_sq_wait() never re-evaluates its predicate. With every\nworker parked on this transport, no thread is available to run\nthe local teardown either, and the wake site there is\nunreachable.\n\nIntroduce svc_rdma_xprt_deferred_close(), a thin svcrdma wrapper\nthat calls svc_xprt_deferred_close() and then wakes both\nsc_sq_ticket_wait and sc_send_wait. Convert the svcrdma producers\nthat called svc_xprt_deferred_close() directly:\nsvc_rdma_cma_handler(), qp_event_handler(),\nsvc_rdma_post_send_err(), svc_rdma_wc_send(), the sendto drop\npath, the rw completion error paths, and the recvfrom flush and\nread-list error paths.\n\nWake both waitqueues from svc_rdma_detach() as well. The\nsynchronous svc_xprt_close() path (backchannel ENOTCONN, device\nremoval via svc_rdma_xprt_done) reaches detach without flowing\nthrough svc_xprt_deferred_close() and therefore does not invoke\nthe new helper.\n\n[ cel: add svc_rdma_xprt_deferred_close() to complete the fix ]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/linux/sunrpc/svc_rdma.h","net/sunrpc/xprtrdma/svc_rdma_recvfrom.c","net/sunrpc/xprtrdma/svc_rdma_rw.c","net/sunrpc/xprtrdma/svc_rdma_sendto.c","net/sunrpc/xprtrdma/svc_rdma_transport.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ccc89b9d1ed233349cfe8d87b842e7351b74d8de","lessThan":"40eedc4253dbda0b29b7961200534dfcecb48ace","versionType":"git","status":"affected"},{"version":"ccc89b9d1ed233349cfe8d87b842e7351b74d8de","lessThan":"e5248a7426030db1e126363f72afdb3b71339a5c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/linux/sunrpc/svc_rdma.h","net/sunrpc/xprtrdma/svc_rdma_recvfrom.c","net/sunrpc/xprtrdma/svc_rdma_rw.c","net/sunrpc/xprtrdma/svc_rdma_sendto.c","net/sunrpc/xprtrdma/svc_rdma_transport.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/40eedc4253dbda0b29b7961200534dfcecb48ace","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5248a7426030db1e126363f72afdb3b71339a5c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64282","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:08.787","lastModified":"2026-07-25T10:17:08.787","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Don't leak PFN when kvm_translate_vncr() races MMU notifier\n\nIn the case that kvm_translate_vncr() races with an MMU notifier the\nearly return does not release a reference on the faulted in PFN. Add\nthe necessary call to kvm_release_faultin_page() for the unused PFN."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/arm64/kvm/nested.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"069a05e53549685d2b5e54ceb51db1fd04aa50d7","lessThan":"0c93681aea0a1b8be14730a88abe77c840272e41","versionType":"git","status":"affected"},{"version":"069a05e53549685d2b5e54ceb51db1fd04aa50d7","lessThan":"cd1067ccc0dbc18890a74db116d00a4bc3c7f2f7","versionType":"git","status":"affected"},{"version":"069a05e53549685d2b5e54ceb51db1fd04aa50d7","lessThan":"9f76b039a72d7e06374aa96862f0232ed53f7787","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/arm64/kvm/nested.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0c93681aea0a1b8be14730a88abe77c840272e41","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f76b039a72d7e06374aa96862f0232ed53f7787","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd1067ccc0dbc18890a74db116d00a4bc3c7f2f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64283","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:08.910","lastModified":"2026-07-25T10:17:08.910","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: guest_memfd: Treat memslot binding offset+size as unsigned values\n\nWhen binding a memslot to a guest_memfd file, treat the offset and size as\nunsigned values to fix a bug where the sum of the two can result in a false\nnegative when checking for overflow against the size of the file.  Passing\nunsigned values also avoids relying on somewhat obscure checks in other\nflows for safety, and tracks the offset and size as they are intended to be\ntracked, as unsigned values.\n\nOn 64-bit kernels, the number of pages a memslot contains and thus the size\n(and offset) of its guest_memfd binding are unsigned 64-bit values.  Taking\nthe offset+size as an loff_t instead of a uoff_t inadvertently converts\nthe unsigned value to a signed value if the offset and/or size is massive.\n\nLocally storing the offset and size as signed values is benign in and of\nitself (though even that is *extremely* difficult to discern), but\noperating on their sum is not.\n\nFor the offset, KVM explicitly checks against a negative value, which might\nseem like a bug as KVM could incorrectly reject a legitimate binding, but\nthat's not actually the case as KVM_CREATE_GUEST_MEMFD takes a signed value\nfor its size, i.e. a would-be-negative offset is also greater than the\nmaximum possible size of any guest_memfd file.\n\nRegarding the size, while KVM lacks an explicit check for a negative value,\ni.e. seemingly has a flawed overflow check, KVM restricts the number of\npages in a single memslot to the largest positive signed 32-bit value:\n\n        if (id < KVM_USER_MEM_SLOTS &&\n            (mem->memory_size >> PAGE_SHIFT) > KVM_MEM_MAX_NR_PAGES)\n                return -EINVAL;\n\nand so that maximum \"size\" will ever be is 0x7fffffff000.\n\nThe sum of the two is, however, problematic.  While the size is restricted\nby KVM's memslot logic, the offset is not, i.e. the offset is completely\nunchecked until the \"offset + size > i_size_read(inode)\" check.  If the\noffset is the (nearly) largest possible _positive_ value, then adding size\nto the offset can result in a signed, negative 64-bit value.  When compared\nagainst the size of the file (guaranteed to be positive), the negative sum\nis always smaller, and KVM incorrectly allows the absurd offset.\n\nOpportunistically add missing includes in kvm_mm.h (instead of relying on\nits parents)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["virt/kvm/guest_memfd.c","virt/kvm/kvm_mm.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a7800aa80ea4d5356b8474c2302812e9d4926fa6","lessThan":"f3a98d5881b9bd4807f49156143565f6aabcef1e","versionType":"git","status":"affected"},{"version":"a7800aa80ea4d5356b8474c2302812e9d4926fa6","lessThan":"eba85fee7fc6cf28fec38a5bf3c378bef9a79ca6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["virt/kvm/guest_memfd.c","virt/kvm/kvm_mm.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/eba85fee7fc6cf28fec38a5bf3c378bef9a79ca6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f3a98d5881b9bd4807f49156143565f6aabcef1e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64284","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:09.033","lastModified":"2026-07-25T10:17:09.033","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits\n\nMove the handling of fastpath userspace exits into vendor code to ensure\nKVM runs vendor specific operations that need to run before userspace gains\ncontrol of the vCPU.  E.g. for VMX (and soon to be for SVM as well), KVM\nneeds to flush the PML buffer prior to exiting to userspace, otherwise any\nmemory written by the final KVM_RUN might never be flagged as dirty.\n\nNote, waiting to snapshot CR0 and CR3 until svm_handle_exit() is flawed in\ngeneral, as that risks consuming stale state in a fastpath handler.  That\nwill be addressed in a future change."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/x86/kvm/svm/svm.c","arch/x86/kvm/vmx/vmx.c","arch/x86/kvm/x86.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f7f39c50edb9d336274371953275e0d3503b9b75","lessThan":"b3436d9b9b1affe1c3191ac9831308923f5f03c3","versionType":"git","status":"affected"},{"version":"f7f39c50edb9d336274371953275e0d3503b9b75","lessThan":"4ad73ef0e7966ecfe67de0060537b4cb14d9acd4","versionType":"git","status":"affected"},{"version":"f7f39c50edb9d336274371953275e0d3503b9b75","lessThan":"f2ca2b5326211bd38490f0497eb583721ce0bbc0","versionType":"git","status":"affected"},{"version":"f7f39c50edb9d336274371953275e0d3503b9b75","lessThan":"0ffedf43910e44b76c2c1db4e9fbf12b268190c1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/x86/kvm/svm/svm.c","arch/x86/kvm/vmx/vmx.c","arch/x86/kvm/x86.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0ffedf43910e44b76c2c1db4e9fbf12b268190c1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4ad73ef0e7966ecfe67de0060537b4cb14d9acd4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b3436d9b9b1affe1c3191ac9831308923f5f03c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f2ca2b5326211bd38490f0497eb583721ce0bbc0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64285","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:09.140","lastModified":"2026-07-25T10:17:09.140","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SEV: Pin source page for write when adding CPUID data for SNP guest\n\nWhen populating a guest_memfd instance with the initial CPUID data for an\nSNP guest, acquire a writable pin on the source page as KVM will write back\nthe \"correct\" CPUID information if the userspace provided data is rejected\nby trusted firmware.  Because KVM writes to the source page using a kernel\nmapping, pinning for read could result in KVM clobbering read-only memory.\n\nNote, well-behaved VMMs are unlikely to be affected, as CPUID information\nis almost always dynamically generated by userspace, i.e. it's unlikely for\nthe CPUID information to be backed by a read-only mapping.\n\n[sean: rewrite shortlog and changelog, tag for stable@]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/x86/kvm/svm/sev.c","arch/x86/kvm/vmx/tdx.c","include/linux/kvm_host.h","virt/kvm/guest_memfd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2a62345b30529e488beb6a1220577b3495933724","lessThan":"dcdb476f5fc5701ec06c23efe3e3529f07ca391e","versionType":"git","status":"affected"},{"version":"2a62345b30529e488beb6a1220577b3495933724","lessThan":"f13e900599089b10113ceb36013423f0837c6792","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/x86/kvm/svm/sev.c","arch/x86/kvm/vmx/tdx.c","include/linux/kvm_host.h","virt/kvm/guest_memfd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/dcdb476f5fc5701ec06c23efe3e3529f07ca391e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f13e900599089b10113ceb36013423f0837c6792","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64286","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:09.243","lastModified":"2026-07-25T10:17:09.243","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU\n\nflush_hyp_vcpu() copies the host vCPU context into the hyp's private\nvCPU on every run. ctxt_to_vcpu() expects a guest context to have a\nNULL __hyp_running_vcpu, which is only ever set on the host context, so\nthat it resolves the vCPU via container_of(). While this is generally\nthe case, flush_hyp_vcpu() copies the context verbatim and does not\nenforce this, so a value provided by the host is dereferenced at EL2\n(host -> EL2).\n\nFix by clearing __hyp_running_vcpu after the copy."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/arm64/kvm/hyp/nvhe/hyp-main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"be66e67f175096f283c9d5614c4991fc9e7ed975","lessThan":"477145860dba4c30f0b4e36f02f4c5291c1c888b","versionType":"git","status":"affected"},{"version":"be66e67f175096f283c9d5614c4991fc9e7ed975","lessThan":"dfaef40d8a1533940fc1af788d70fce07362b4ce","versionType":"git","status":"affected"},{"version":"be66e67f175096f283c9d5614c4991fc9e7ed975","lessThan":"6bea2f8becdb20d34378493c3b77a9b9cf8c6cfa","versionType":"git","status":"affected"},{"version":"be66e67f175096f283c9d5614c4991fc9e7ed975","lessThan":"d4f4d61715d1061ba83b88196a3605662be30750","versionType":"git","status":"affected"},{"version":"be66e67f175096f283c9d5614c4991fc9e7ed975","lessThan":"e8042f6e1d7befb2fb6b10a75918642bcd0acf9a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/arm64/kvm/hyp/nvhe/hyp-main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.2","status":"affected"},{"version":"0","lessThan":"6.2","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/477145860dba4c30f0b4e36f02f4c5291c1c888b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6bea2f8becdb20d34378493c3b77a9b9cf8c6cfa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d4f4d61715d1061ba83b88196a3605662be30750","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dfaef40d8a1533940fc1af788d70fce07362b4ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e8042f6e1d7befb2fb6b10a75918642bcd0acf9a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64287","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:09.353","lastModified":"2026-07-25T10:17:09.353","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU\n\nflush_hyp_vcpu() copies the host vGIC state into the hyp's private vCPU\non every run. The vGIC list register save and restore use used_lrs as\ntheir loop bound and expect it to stay within the number of implemented\nlist registers. While this is generally the case, flush_hyp_vcpu()\ncopies vgic_v3 verbatim and does not enforce this, so a value provided\nby the host is used at EL2 to index vgic_lr[] and access ICH_LR<n>_EL2\n(host -> EL2).\n\nFix by clamping used_lrs to the number of implemented list registers\nafter the copy, as the trusted path already does in\nvgic_flush_lr_state(). The number of implemented list registers is\nconstant after init, so it is replicated once from\nkvm_vgic_global_state.nr_lr into hyp_gicv3_nr_lr rather than read on\nevery entry."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/arm64/include/asm/kvm_hyp.h","arch/arm64/kvm/arm.c","arch/arm64/kvm/hyp/nvhe/hyp-main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"be66e67f175096f283c9d5614c4991fc9e7ed975","lessThan":"2c5e72b9fbf83fdfa724e9f1af0f418ccf8739b8","versionType":"git","status":"affected"},{"version":"be66e67f175096f283c9d5614c4991fc9e7ed975","lessThan":"9fa301d8298778dd799fa4dcf7a7f440715d146e","versionType":"git","status":"affected"},{"version":"be66e67f175096f283c9d5614c4991fc9e7ed975","lessThan":"c646431865f4b1a5b14067233fa27b11e05e0d46","versionType":"git","status":"affected"},{"version":"be66e67f175096f283c9d5614c4991fc9e7ed975","lessThan":"7fca3fcef81c713bc82a37bf741e0f28e6d04a6f","versionType":"git","status":"affected"},{"version":"be66e67f175096f283c9d5614c4991fc9e7ed975","lessThan":"8cc8bbbfab14c22c5551d0dd19b208a44b141c76","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/arm64/include/asm/kvm_hyp.h","arch/arm64/kvm/arm.c","arch/arm64/kvm/hyp/nvhe/hyp-main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.2","status":"affected"},{"version":"0","lessThan":"6.2","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2c5e72b9fbf83fdfa724e9f1af0f418ccf8739b8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7fca3fcef81c713bc82a37bf741e0f28e6d04a6f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8cc8bbbfab14c22c5551d0dd19b208a44b141c76","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9fa301d8298778dd799fa4dcf7a7f440715d146e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c646431865f4b1a5b14067233fa27b11e05e0d46","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64288","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:09.473","lastModified":"2026-07-25T10:17:09.473","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB\n\nVNCR TLB invalidation occurs from MMU notifiers or TLBI instructions,\nand either can race against a vcpu not being onlined yet (no pseudo-TLB\nallocated). Similarly, the TLB might be invalid, and the invalidation\nshould be skipped in this case.\n\nBoth kvm_invalidate_vncr_ipa() and kvm_invalidate_vncr_va() are\nexpected to perform the same checks, except that the latter doesn't\ncheck for the allocation and blindly dereferences the pointer.\n\nSolve this by introducing a new iterator built on top of the usual\nkvm_for_each_vcpu() that checks for both of the above conditions,\nand convert the two users to it."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/arm64/kvm/nested.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4ffa72ad8f37e73bbb6c0baa88557bcb4fd39929","lessThan":"7c73a269a880b1399baacfb9d521415e6ef7ecc2","versionType":"git","status":"affected"},{"version":"4ffa72ad8f37e73bbb6c0baa88557bcb4fd39929","lessThan":"5fd30133af864a1de0a0bd87d3fe3cf23205fbc7","versionType":"git","status":"affected"},{"version":"4ffa72ad8f37e73bbb6c0baa88557bcb4fd39929","lessThan":"4be6cbeb93d26994bd1827ddbce391e3c4395c8f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/arm64/kvm/nested.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4be6cbeb93d26994bd1827ddbce391e3c4395c8f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5fd30133af864a1de0a0bd87d3fe3cf23205fbc7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7c73a269a880b1399baacfb9d521415e6ef7ecc2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64289","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:09.603","lastModified":"2026-07-25T10:17:09.603","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Set upper bounds on cache invalidation entry_num and entry_len\n\niommufd_hwpt_invalidate() takes a user-controlled entry_num and entry_len,\neach bounded only by U32_MAX. An entry_len beyond the kernel's struct size\nmakes the copy helper verify the extra bytes are zero, scanning that excess\nin one uninterruptible pass; a multi-gigabyte value over zeroed user memory\ntrips the soft-lockup watchdog.\n\nA large entry_num is the other half, driving the backend invalidation loop\nwith no reschedule. The VT-d nested handler, for one, copies each entry and\nflushes caches per iteration, pinning the CPU on a non-preemptible kernel.\n\nCap both in the ioctl. entry_len is held under PAGE_SIZE, above any request\nstruct, and entry_num under 1 << 19, the order of a hardware invalidation\nqueue and well beyond any real batch, bounding the per-call loop length."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iommu/iommufd/hw_pagetable.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8c6eabae3807e048b9f17733af5e20500fbf858c","lessThan":"d2bd041e0efaf7d81789779b135279d18b33d6d5","versionType":"git","status":"affected"},{"version":"8c6eabae3807e048b9f17733af5e20500fbf858c","lessThan":"32ca4aed2a66205b072fcfecabe220289a8149ff","versionType":"git","status":"affected"},{"version":"8c6eabae3807e048b9f17733af5e20500fbf858c","lessThan":"2c6381d90898089287e0a358f06f89f6b4b389f2","versionType":"git","status":"affected"},{"version":"8c6eabae3807e048b9f17733af5e20500fbf858c","lessThan":"4d70986002f2f3eaaed89124fb2522bded38b016","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iommu/iommufd/hw_pagetable.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2c6381d90898089287e0a358f06f89f6b4b389f2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/32ca4aed2a66205b072fcfecabe220289a8149ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4d70986002f2f3eaaed89124fb2522bded38b016","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2bd041e0efaf7d81789779b135279d18b33d6d5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64290","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:09.730","lastModified":"2026-07-25T10:17:09.730","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Break the loop on failure in iommufd_fault_fops_read()\n\nOn a copy_to_user() failure inside the inner list_for_each_entry, only the\ninner loop breaks; the outer while re-fetches the just-restored fault group\nand retries the failing copy_to_user() forever, spinning the reader at 100%\nCPU with fault->mutex held.\n\nCheck rc after the inner loop and break the outer while as well."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iommu/iommufd/eventq.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"07838f7fd529c8a6de44b601d4b7057e6c8d36ed","lessThan":"5539da127d03c1f6c2e2a49fdfbe331a0ccbdea8","versionType":"git","status":"affected"},{"version":"07838f7fd529c8a6de44b601d4b7057e6c8d36ed","lessThan":"f66c16b175509642ee7082df57c9bf3deaebae1a","versionType":"git","status":"affected"},{"version":"07838f7fd529c8a6de44b601d4b7057e6c8d36ed","lessThan":"172fc8b19825a0f5884c38f2289188284e2d45ee","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iommu/iommufd/eventq.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/172fc8b19825a0f5884c38f2289188284e2d45ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5539da127d03c1f6c2e2a49fdfbe331a0ccbdea8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f66c16b175509642ee7082df57c9bf3deaebae1a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64291","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:09.837","lastModified":"2026-07-25T10:17:09.837","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Set veventq_depth upper bound\n\niommufd_veventq_alloc() accepts any !0 veventq_depth from userspace, with\nan upper bound at U32_MAX.\n\nThis leaves a vulnerability where userspace can allocate excessively large\nqueues to exhaust kernel memory reserves.\n\nCap the veventq_depth (maximum number of entries) to 1 << 19, matching the\nmaximum number of entries in the SMMUv3 EVTQ (the largest use case today)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iommu/iommufd/eventq.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e36ba5ab808ef6237c3148d469c8238674230e2b","lessThan":"f565297edf316016be4a1a9e2eb9f39359313f43","versionType":"git","status":"affected"},{"version":"e36ba5ab808ef6237c3148d469c8238674230e2b","lessThan":"e7b5e55652746b1221b9c10ff80eae8a154101ba","versionType":"git","status":"affected"},{"version":"e36ba5ab808ef6237c3148d469c8238674230e2b","lessThan":"6ebf2eb46fbd5b40393ff8fbb847ba96925beaff","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iommu/iommufd/eventq.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6ebf2eb46fbd5b40393ff8fbb847ba96925beaff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e7b5e55652746b1221b9c10ff80eae8a154101ba","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f565297edf316016be4a1a9e2eb9f39359313f43","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64292","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:09.937","lastModified":"2026-07-25T10:17:09.937","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Move vevent memory allocation outside spinlock\n\nThe veventq memory allocation happens inside the spinlock. Given its depth\nis decided by the user space, this leaves a vulnerability, where userspace\ncan allocate large queues to exhaust atomic memory reserves.\n\nMove the allocation outside the spinlock and use GFP_NOWAIT, which can fail\nfast under memory pressure without dipping into the GFP_ATOMIC reserves or\ndirect-reclaiming from the threaded IRQ handler. On allocation failure,\nqueue the lost_events_header (so userspace learns of the drop) and return\n-ENOMEM so the caller learns of the kernel-side memory pressure.\n\nThis is intentionally distinct from the queue-overflow path, which also\nqueues the lost_events_header but returns 0: a full queue is an expected\nuserspace-pacing condition rather than a kernel error.\n\nA subsequent change will cap the upper bound of the veventq_depth."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iommu/iommufd/driver.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e36ba5ab808ef6237c3148d469c8238674230e2b","lessThan":"779480ea79551c31964e74b9aef0e730faa3aa11","versionType":"git","status":"affected"},{"version":"e36ba5ab808ef6237c3148d469c8238674230e2b","lessThan":"6c5fc40200cd0a87d66a368eee00df4d1cca946e","versionType":"git","status":"affected"},{"version":"e36ba5ab808ef6237c3148d469c8238674230e2b","lessThan":"47443565d10c51366c9382dbc8597cd6c460b8a2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iommu/iommufd/driver.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/47443565d10c51366c9382dbc8597cd6c460b8a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c5fc40200cd0a87d66a368eee00df4d1cca946e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/779480ea79551c31964e74b9aef0e730faa3aa11","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64293","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:10.047","lastModified":"2026-07-25T10:17:10.047","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read\n\nThe bound-check in iommufd_veventq_fops_read() for the normal vEVENT\npath uses sizeof(hdr) where the surrounding code uses sizeof(*hdr):\n\n\tif (!vevent_for_lost_events_header(cur) &&\n\t    sizeof(hdr) + cur->data_len > count - done) {\n\nhdr is declared as struct iommufd_vevent_header *, so sizeof(hdr)\nevaluates to the size of the pointer.  Surrounding code uses\nsizeof(*hdr) consistently:\n\n\tif (done >= count || sizeof(*hdr) > count - done) {\n\t...\n\tif (copy_to_user(buf + done, hdr, sizeof(*hdr))) {\n\t...\n\tdone += sizeof(*hdr);\n\nstruct iommufd_vevent_header is currently 8 bytes (two __u32 fields,\nflags and sequence), so on 64-bit (sizeof(void *) == 8) the two\nexpressions happen to be equal and the check works as intended.\n\nOn 32-bit (sizeof(void *) == 4) the check under-counts the header by\n4 bytes: a vEVENT whose data_len causes 8 + cur->data_len to exceed\ncount - done while 4 + cur->data_len does not will pass the check,\nthen the loop will copy_to_user 8 bytes of header followed by data_len\nbytes of payload, writing past the user-supplied buffer.\n\nIt is also a latent bug for any future expansion of struct\niommufd_vevent_header beyond sizeof(void *) on 64-bit; the check\nshould not depend on the type happening to match the host pointer\nwidth.\n\nUse sizeof(*hdr) to match the rest of the function and the actual\namount that will be copied."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iommu/iommufd/eventq.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e36ba5ab808ef6237c3148d469c8238674230e2b","lessThan":"04a177f91160ee18da98f5689482cf0f589ec869","versionType":"git","status":"affected"},{"version":"e36ba5ab808ef6237c3148d469c8238674230e2b","lessThan":"0cdbb97a4dbd69abdd2ab998b4fbc7803d4b0b72","versionType":"git","status":"affected"},{"version":"e36ba5ab808ef6237c3148d469c8238674230e2b","lessThan":"be93d186ae88a92e7aa77e122d4e661fa57b1e39","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iommu/iommufd/eventq.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/04a177f91160ee18da98f5689482cf0f589ec869","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0cdbb97a4dbd69abdd2ab998b4fbc7803d4b0b72","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be93d186ae88a92e7aa77e122d4e661fa57b1e39","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64294","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:10.160","lastModified":"2026-07-25T10:17:10.160","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm: do file ownership checks with the proper mount idmap\n\nEver since idmapped mounts were introduced, inode ownership checks (for\nside-channel protection) in mincore() and madvise(MADV_PAGEOUT) were done\nagainst the nop_mnt_idmap, which completely ignores the file's mount's\nidmap.  This results in odd edgecases like:\n\n1) mount/bind-mount with an idmap userA:userB:1\n2) userB runs an owner_or_capable() check on file that is owned by userA\non-disk/in-memory, but owned by userB after idmap translation\n3) owner_or_capable() mysteriously fails as the correct idmap wasn't supplied\n\nIn the case of mincore/madvise MADV_PAGEOUT, this is usually benign,\nbecause file_permission(file, MAY_WRITE) will probably succeed, as it uses\nthe proper idmap internally, but it does not need to be the case on e.g a\n0444 file where even the owner itself doesn't have permissions to write to\nit.\n\nSince this is clearly not trivial to get right, introduce a\nfile_owner_or_capable() that can carry the correct semantics, and switch\nthe various users in mm to it.\n\nThe issue was found by manual code inspection & an off-list discussion\nwith Jan Kara."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/linux/fs.h","mm/filemap.c","mm/madvise.c","mm/mincore.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9caccd41541a6f7d6279928d9f971f6642c361af","lessThan":"744b23aa430d52f5c8e4dbff7d71496d6643bed2","versionType":"git","status":"affected"},{"version":"9caccd41541a6f7d6279928d9f971f6642c361af","lessThan":"8344bdf0629457e532797b42d9d2bbf2a2900bbf","versionType":"git","status":"affected"},{"version":"9caccd41541a6f7d6279928d9f971f6642c361af","lessThan":"5c942ad7df75925ee166e7f0fb36892d8dde376b","versionType":"git","status":"affected"},{"version":"9caccd41541a6f7d6279928d9f971f6642c361af","lessThan":"04ba248d02d9eaa3d9077b00a6134caa75fa3e90","versionType":"git","status":"affected"},{"version":"9caccd41541a6f7d6279928d9f971f6642c361af","lessThan":"e187bc02f8fa4226d62814592cf064ee4557c470","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/linux/fs.h","mm/filemap.c","mm/madvise.c","mm/mincore.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.12","status":"affected"},{"version":"0","lessThan":"5.12","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/04ba248d02d9eaa3d9077b00a6134caa75fa3e90","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5c942ad7df75925ee166e7f0fb36892d8dde376b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/744b23aa430d52f5c8e4dbff7d71496d6643bed2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8344bdf0629457e532797b42d9d2bbf2a2900bbf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e187bc02f8fa4226d62814592cf064ee4557c470","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64295","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:10.277","lastModified":"2026-07-25T10:17:10.277","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm: page_ext: add count limit to page_ext_iter_next to prevent invalid PFN access\n\nThe page_ext iteration API does not validate if the PFN still belongs to a\nvalid section while advancing the iterator.  When dynamically adding\nmemory in the hotplug path, it can lead to a NULL pointer dereference\nduring page_ext_lookup at the boundary of the last valid section when\niterator count equals __pgcount.\n\nThe for_each_page_ext() macro calls page_ext_iter_next() as its loop\nincrement.  for_each_page_ext() does a \"__page_ext =\npage_ext_iter_next(&__iter)\" at the end.  This causes page_ext_iter_next()\nto increment iter->index past __pgcount and call page_ext_lookup(start_pfn\n+ __pgcount).  During memory hotplug (online), the PFN at start_pfn +\n__pgcount may belong to a section that has not yet been initialized,\ncausing page_ext_lookup() to trigger a NULL pointer dereference.\n\n[   14.555124][  T846] Call trace:\n[   14.555125][  T846]  lookup_page_ext+0x6c/0x108 (P)\n[   14.555127][  T846]  page_ext_lookup+0x30/0x3c\n[   14.555129][  T846]  __reset_page_owner+0x11c/0x260\n[   14.571201][  T846]  __free_pages_ok+0x5e8/0x8e0\n[   14.571204][  T846]  __free_pages_core+0x78/0xf0\n[   14.571206][  T846]  generic_online_page+0x14/0x24\n[   14.597782][  T846]  online_pages+0x178/0x30c\n[   14.597784][  T846]  memory_block_change_state+0x284/0x32c\n[   14.597787][  T846]  memory_subsys_online+0x4c/0x64\n[   14.597789][  T846]  device_online+0x88/0xb0\n[   14.597791][  T846]  online_memory_block+0x30/0x40\n[   14.597793][  T846]  walk_memory_blocks+0xac/0xe8\n[   14.597794][  T846]  add_memory_resource+0x280/0x298\n[   14.656161][  T846]  add_memory+0x60/0x98\n\nMove the iteration boundary enforcement inside the iterator functions, so\ncallers cannot inadvertently access beyond the requested range."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/linux/page_ext.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9039b9096ea27a20f0349d1537537663c935c8ed","lessThan":"8dcaa0f87a88d720d13106f3a306c6b61d189d86","versionType":"git","status":"affected"},{"version":"9039b9096ea27a20f0349d1537537663c935c8ed","lessThan":"377b1cd6bbcf327338cd951cc2fd74bc75540235","versionType":"git","status":"affected"},{"version":"9039b9096ea27a20f0349d1537537663c935c8ed","lessThan":"ffd017237cfe99e6e5602ab14179b0e6878a0840","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/linux/page_ext.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/377b1cd6bbcf327338cd951cc2fd74bc75540235","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8dcaa0f87a88d720d13106f3a306c6b61d189d86","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ffd017237cfe99e6e5602ab14179b0e6878a0840","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64296","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:10.390","lastModified":"2026-07-25T10:17:10.390","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: bound uniname advance in exfat_find_dir_entry()\n\nIn exfat_find_dir_entry(), each TYPE_EXTEND (file name) entry advances the\noutput pointer by a fixed amount while the loop guard only tracks the\naccumulated name length:\n\n\tif (++order == 2)\n\t\tuniname = p_uniname->name;\n\telse\n\t\tuniname += EXFAT_FILE_NAME_LEN;\n\tlen = exfat_extract_uni_name(ep, entry_uniname);\n\tname_len += len;\n\tunichar = *(uniname+len);\n\t*(uniname+len) = 0x0;\n\nuniname grows by EXFAT_FILE_NAME_LEN (15) per name entry, but name_len\ngrows only by the actual extracted length, which is shorter when a name\nfragment contains an early NUL.  The only guard is\n`name_len >= MAX_NAME_LENGTH`, so a crafted directory with many short\nname fragments lets uniname run far past the\np_uniname->name[MAX_NAME_LENGTH + 3] buffer while name_len stays small,\ncausing an out-of-bounds read and write at *(uniname+len).\n\nThe sibling extractor exfat_get_uniname_from_ext_entry() already stops\non a short fragment (the lockstep `len != EXFAT_FILE_NAME_LEN` guard\nadded in commit d42334578eba (\"exfat: check if filename entries exceeds\nmax filename length\")); exfat_find_dir_entry() never got the\nequivalent.  Track the per-entry write offset as a count and reject a\nfragment once the offset, or the offset plus the extracted length, would\nexceed MAX_NAME_LENGTH, before forming the output pointer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/exfat/dir.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ca06197382bde0a3bc20215595d1c9ce20c6e341","lessThan":"72a2589d82eb001c94b74bcfe6f9a599bd9bef60","versionType":"git","status":"affected"},{"version":"ca06197382bde0a3bc20215595d1c9ce20c6e341","lessThan":"fae76a94b35ee8c0e2eb6f64caca01d75c6d34e4","versionType":"git","status":"affected"},{"version":"ca06197382bde0a3bc20215595d1c9ce20c6e341","lessThan":"cf85180b8a015029ee147694eaf4e0b3537e9432","versionType":"git","status":"affected"},{"version":"ca06197382bde0a3bc20215595d1c9ce20c6e341","lessThan":"ce4736c1e6c4cfbf1ac409a8c328a0b69546c9a0","versionType":"git","status":"affected"},{"version":"ca06197382bde0a3bc20215595d1c9ce20c6e341","lessThan":"727bf7783a2936ffd55c628dddfd69343e511dcf","versionType":"git","status":"affected"},{"version":"ca06197382bde0a3bc20215595d1c9ce20c6e341","lessThan":"33c0b96d7e1672be1de0053786637ea46fb81507","versionType":"git","status":"affected"},{"version":"ca06197382bde0a3bc20215595d1c9ce20c6e341","lessThan":"c8e041c68c0bbb73aa62371ee63947bb6949d8b2","versionType":"git","status":"affected"},{"version":"ca06197382bde0a3bc20215595d1c9ce20c6e341","lessThan":"3a1230e7b043c62737b05a3e9275ca83a43ad20a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/exfat/dir.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.7","status":"affected"},{"version":"0","lessThan":"5.7","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/33c0b96d7e1672be1de0053786637ea46fb81507","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3a1230e7b043c62737b05a3e9275ca83a43ad20a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/727bf7783a2936ffd55c628dddfd69343e511dcf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/72a2589d82eb001c94b74bcfe6f9a599bd9bef60","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c8e041c68c0bbb73aa62371ee63947bb6949d8b2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ce4736c1e6c4cfbf1ac409a8c328a0b69546c9a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf85180b8a015029ee147694eaf4e0b3537e9432","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fae76a94b35ee8c0e2eb6f64caca01d75c6d34e4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64297","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:10.530","lastModified":"2026-07-25T10:17:10.530","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmodule: decompress: check return value of module_extend_max_pages()\n\nmodule_extend_max_pages() calls kvrealloc() internally and returns\n-ENOMEM on allocation failure. The return value is never checked.\n\nIf the initial allocation fails, info->pages remains NULL and\ninfo->max_pages remains 0. Subsequent calls to module_get_next_page()\nwill attempt to dynamically grow the array by calling\nmodule_extend_max_pages(info, 0) since info->used_pages is 0. This\nresults in kvrealloc(NULL, 0) returning ZERO_SIZE_PTR, which is treated\nas a success, leading to a dereference of ZERO_SIZE_PTR and a kernel\noops.\n\nFix: add the missing error check after module_extend_max_pages() and\nreturn immediately on failure. This matches the pattern used by every\nother kvrealloc() caller in the module loading path.\n\n[Sami: Corrected the analysis in the commit message.]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/module/decompress.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b1ae6dc41eaaa98bb75671e0f3665bfda248c3e7","lessThan":"e7f174715f9f0cbcb9e87b52e4fc4ef149baac98","versionType":"git","status":"affected"},{"version":"b1ae6dc41eaaa98bb75671e0f3665bfda248c3e7","lessThan":"afcc0515bbdd28d509a2b5870faaa89b137f5d53","versionType":"git","status":"affected"},{"version":"b1ae6dc41eaaa98bb75671e0f3665bfda248c3e7","lessThan":"168072baf9ad516d5a06046514c7fea4c0671990","versionType":"git","status":"affected"},{"version":"b1ae6dc41eaaa98bb75671e0f3665bfda248c3e7","lessThan":"a82e170637e050a803b4f37542371ef216bf66d2","versionType":"git","status":"affected"},{"version":"b1ae6dc41eaaa98bb75671e0f3665bfda248c3e7","lessThan":"e7da02659c229f73492fb1ed87ceda4090153aaa","versionType":"git","status":"affected"},{"version":"b1ae6dc41eaaa98bb75671e0f3665bfda248c3e7","lessThan":"786d2d84416a9a1c1a47b71a68d679d886284be2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/module/decompress.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/168072baf9ad516d5a06046514c7fea4c0671990","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/786d2d84416a9a1c1a47b71a68d679d886284be2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a82e170637e050a803b4f37542371ef216bf66d2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/afcc0515bbdd28d509a2b5870faaa89b137f5d53","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e7da02659c229f73492fb1ed87ceda4090153aaa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e7f174715f9f0cbcb9e87b52e4fc4ef149baac98","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64298","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:10.657","lastModified":"2026-07-25T10:17:10.657","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4: include MAY_WRITE in open permission mask for O_TRUNC\n\nPOSIX requires write permission to truncate a file, so an open() that\nspecifies O_TRUNC must be authorized for write access regardless of the\nO_ACCMODE access mode.\n\nnfs_open_permission_mask() builds the access mask passed to\nnfs_may_open(), which is the local authorization gate for OPENs the\nclient serves itself from a cached write delegation via the\ncan_open_delegated() path in nfs4_try_open_cached().  The mask is\nderived from O_ACCMODE alone, so an open(O_RDONLY | O_TRUNC) against a\nfile the caller cannot write requests only MAY_READ and passes the\nlocal check.  The OPEN is then satisfied locally and the truncation is\nissued to the server as a SETATTR(size=0) over the delegation stateid,\nwhich the server accepts under standard write-delegation semantics.\nPOSIX requires that this open fail with EACCES.\n\nInclude MAY_WRITE in the mask whenever O_TRUNC is set so the local\ncheck matches the access the server would have enforced."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/nfs/dir.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"af22f94ae02ab9dd4fd7fe628c8434a59cc293be","lessThan":"4817c8974315b666e895b7d1bb83cd3664c323b1","versionType":"git","status":"affected"},{"version":"af22f94ae02ab9dd4fd7fe628c8434a59cc293be","lessThan":"cb148a2762d644bff1894728e8835a9a4b84f9ea","versionType":"git","status":"affected"},{"version":"af22f94ae02ab9dd4fd7fe628c8434a59cc293be","lessThan":"30fdf4df6c3c00efec947e4ddf97f0fdd4473628","versionType":"git","status":"affected"},{"version":"af22f94ae02ab9dd4fd7fe628c8434a59cc293be","lessThan":"22c1fd1355ad4ca27aa7f0fa02719122dd92d9de","versionType":"git","status":"affected"},{"version":"af22f94ae02ab9dd4fd7fe628c8434a59cc293be","lessThan":"6bd7d0a06b53c4e797e1a9cea0d2d41aa1b26230","versionType":"git","status":"affected"},{"version":"af22f94ae02ab9dd4fd7fe628c8434a59cc293be","lessThan":"a937e92c1d00534b5c2e3e9f4381b7e988180797","versionType":"git","status":"affected"},{"version":"af22f94ae02ab9dd4fd7fe628c8434a59cc293be","lessThan":"e36501b7d4abdcd6d69a7cb901b2f286b7a3d041","versionType":"git","status":"affected"},{"version":"af22f94ae02ab9dd4fd7fe628c8434a59cc293be","lessThan":"5140f099ecd8a2f2808b7f7b720ee1bad8468974","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/nfs/dir.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.24","status":"affected"},{"version":"0","lessThan":"2.6.24","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/22c1fd1355ad4ca27aa7f0fa02719122dd92d9de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/30fdf4df6c3c00efec947e4ddf97f0fdd4473628","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4817c8974315b666e895b7d1bb83cd3664c323b1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5140f099ecd8a2f2808b7f7b720ee1bad8468974","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6bd7d0a06b53c4e797e1a9cea0d2d41aa1b26230","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a937e92c1d00534b5c2e3e9f4381b7e988180797","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb148a2762d644bff1894728e8835a9a4b84f9ea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e36501b7d4abdcd6d69a7cb901b2f286b7a3d041","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64299","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:10.793","lastModified":"2026-07-25T10:17:10.793","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Prevent out-of-bounds read in glob matching\n\nString event fields are not necessarily NUL-terminated, so the filter\npredicate functions (filter_pred_string(), filter_pred_strloc() and\nfilter_pred_strrelloc()) pass the field length to the regex match\ncallbacks, and the length-aware matchers honour it.\n\nregex_match_glob() was the exception: it ignored the length and called\nglob_match(), which scans the string until it hits a NUL byte. Some\nstring fields are not NUL-terminated. One example is the dynamic char\narray of the xfs_* namespace tracepoints, which is copied without a\ntrailing NUL. For such a field, glob matching reads past the end of\nthe event field, causing a KASAN slab-out-of-bounds read in\nglob_match(), reached via regex_match_glob() and filter_match_preds()\nfrom the xfs_lookup tracepoint.\n\nAdd a length-bounded glob_match_len() and use it from regex_match_glob()\nso glob matching always stops at the field boundary. The matching loop\nis factored into a shared helper so glob_match() keeps its behaviour."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/linux/glob.h","kernel/trace/trace_events_filter.c","lib/glob.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"60f1d5e3bac44b598f67d36062da96c095d2b700","lessThan":"265f3a690f6c7d69ef7d2ca50b04b4853a211df3","versionType":"git","status":"affected"},{"version":"60f1d5e3bac44b598f67d36062da96c095d2b700","lessThan":"ee5b8888d3248618251fb69a2fad92afcb81557e","versionType":"git","status":"affected"},{"version":"60f1d5e3bac44b598f67d36062da96c095d2b700","lessThan":"56d4c9ab84714eebb285a2fee68aaedf81e3ef15","versionType":"git","status":"affected"},{"version":"60f1d5e3bac44b598f67d36062da96c095d2b700","lessThan":"35ae19764eabfe9c29029d3b5713c86e6855acdf","versionType":"git","status":"affected"},{"version":"60f1d5e3bac44b598f67d36062da96c095d2b700","lessThan":"ebb55902856973906c8bb339a3a34824ed4a5086","versionType":"git","status":"affected"},{"version":"60f1d5e3bac44b598f67d36062da96c095d2b700","lessThan":"2dad64a97e1df47f5d9ccb17fa319aa348617226","versionType":"git","status":"affected"},{"version":"60f1d5e3bac44b598f67d36062da96c095d2b700","lessThan":"e5d5f3bd053a5f14787526c9f0f55ef900d43ac6","versionType":"git","status":"affected"},{"version":"60f1d5e3bac44b598f67d36062da96c095d2b700","lessThan":"0a6070839b1ef276d5b05bedfb787743e140fb17","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/linux/glob.h","kernel/trace/trace_events_filter.c","lib/glob.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.10","status":"affected"},{"version":"0","lessThan":"4.10","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0a6070839b1ef276d5b05bedfb787743e140fb17","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/265f3a690f6c7d69ef7d2ca50b04b4853a211df3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2dad64a97e1df47f5d9ccb17fa319aa348617226","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/35ae19764eabfe9c29029d3b5713c86e6855acdf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/56d4c9ab84714eebb285a2fee68aaedf81e3ef15","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5d5f3bd053a5f14787526c9f0f55ef900d43ac6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ebb55902856973906c8bb339a3a34824ed4a5086","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ee5b8888d3248618251fb69a2fad92afcb81557e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64300","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:10.930","lastModified":"2026-07-25T10:17:10.930","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf/aux: Fix page UAF in map_range()\n\nmap_range() reads rb->aux_pages[], rb->aux_nr_pages and rb->aux_pgoff via\nperf_mmap_to_page() while holding only event->mmap_mutex. Those fields are\nserialized by rb->aux_mutex, and mmap_mutex is per event.\n\nThus, two events sharing one rb via PERF_EVENT_IOC_SET_OUTPUT can race\nrb_alloc_aux() with map_range(), leading to a page-UAF scenario as follows:\n\n  CPU 0                           CPU 1\n  =====                           =====\n  rb_alloc_aux()                  map_range()\n  [1]: allocate rb->aux_pages[0]\n  [2]: rb->aux_nr_pages++\n                                  [3]: perf_mmap_to_page()\n                                         returns rb->aux_pages[0]\n                                  [4]: map it as VM_PFNMAP\n  [5]: rb->aux_pgoff = 1\n\n  munmap the page\n  [6]: free rb->aux_pages[0]\n\nPages mapped as VM_PFNMAP have no refcount protection, so CPU 1 holds a\nmapping to a freed physical frame.\n\nFix this by taking rb->aux_mutex across the page walk in map_range()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/events/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b709eb872e19a19607bbb6d2975bc264d59735cf","lessThan":"c8b7e113f7b61eef2f017e6329c27c2331058c5a","versionType":"git","status":"affected"},{"version":"b709eb872e19a19607bbb6d2975bc264d59735cf","lessThan":"0cff05bd2186020f8706233e261016d149cc24db","versionType":"git","status":"affected"},{"version":"b709eb872e19a19607bbb6d2975bc264d59735cf","lessThan":"5948aaf64f81f217a25dcc2bf6c0779bca19566c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/events/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0cff05bd2186020f8706233e261016d149cc24db","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5948aaf64f81f217a25dcc2bf6c0779bca19566c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c8b7e113f7b61eef2f017e6329c27c2331058c5a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64301","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:11.043","lastModified":"2026-07-25T10:17:11.043","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nregulator: scmi: fix of_node refcount leak in scmi_regulator_probe()\n\nscmi_regulator_probe() calls of_find_node_by_name() which takes a\nreference on the returned device node. On the error path where\nprocess_scmi_regulator_of_node() fails, the function returns without\ncalling of_node_put() on the child node, leaking the reference.\n\nAdd of_node_put(np) on the error path to properly release the\nreference."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/regulator/scmi-regulator.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0fbeae70ee7ce98e18a47337cd1f205dd88589e9","lessThan":"1e446e8f8c763be3de7d0362e024cdf46194ffef","versionType":"git","status":"affected"},{"version":"0fbeae70ee7ce98e18a47337cd1f205dd88589e9","lessThan":"637c11e3d8d43a7ee654591cda8d17c55a9234fa","versionType":"git","status":"affected"},{"version":"0fbeae70ee7ce98e18a47337cd1f205dd88589e9","lessThan":"e2baf8ea13fb4b10bec2c4751aea05c00dabcd0f","versionType":"git","status":"affected"},{"version":"0fbeae70ee7ce98e18a47337cd1f205dd88589e9","lessThan":"3e1441a4d06d35a314961e40057bd1f0106bbc14","versionType":"git","status":"affected"},{"version":"0fbeae70ee7ce98e18a47337cd1f205dd88589e9","lessThan":"22cb337370e6539b0418832c6040e9b00c1b74ca","versionType":"git","status":"affected"},{"version":"0fbeae70ee7ce98e18a47337cd1f205dd88589e9","lessThan":"a935b64548fcfe1d5b4dbdd31dddfb0d7019367f","versionType":"git","status":"affected"},{"version":"0fbeae70ee7ce98e18a47337cd1f205dd88589e9","lessThan":"fa11039d6cdff84584a3ef8cc1f5e1b56e045da2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/regulator/scmi-regulator.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.11","status":"affected"},{"version":"0","lessThan":"5.11","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1e446e8f8c763be3de7d0362e024cdf46194ffef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/22cb337370e6539b0418832c6040e9b00c1b74ca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3e1441a4d06d35a314961e40057bd1f0106bbc14","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/637c11e3d8d43a7ee654591cda8d17c55a9234fa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a935b64548fcfe1d5b4dbdd31dddfb0d7019367f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2baf8ea13fb4b10bec2c4751aea05c00dabcd0f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fa11039d6cdff84584a3ef8cc1f5e1b56e045da2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64302","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:11.170","lastModified":"2026-07-25T10:17:11.170","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mm: Fix freeing of PMD-sized vmemmap pages\n\nCommit bf9e4e30f353 (\"x86/mm: use pagetable_free()\"), switched from\nfreeing non-boot page tables through __free_pages() to\npagetable_free().\n\nHowever, the function is also called to free vmemmap pages.\n\nGiven that vmemmap pages are not page tables, already the page_ptdesc(page)\nis wrong. But worse, pagetable_free() calls:\n\n\t__free_pages(page, compound_order(page));\n\nSince vmemmap pages are not compound pages (see vmemmap_alloc_block())\n-- except for HVO, which doesn't apply here -- only first page of a\nPMD-sized vmemmap page is freed, leaking the other ones.\n\nFix it by properly decoupling pagetable and vmemmap freeing.\nfree_pagetable() no longer has to mess with SECTION_INFO, as only the\nvmemmap is marked like that in register_page_bootmem_memmap().\n\nThe indentation in remove_pmd_table() is messed up. Fix that while\ntouching it.\n\nBootmem info handling will soon be fixed up. For now, handle it\nsimilar to free_pagetable(), just avoiding the ifdef.\n\n[ dhansen: changelog munging. More imperative voice ]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/x86/mm/init_64.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a1593c90896babf33e947910c7aecb9f50bab993","lessThan":"add1e4112e00b619614784bf630aeebfdefa23e1","versionType":"git","status":"affected"},{"version":"bf9e4e30f3538391745a99bc2268ec4f5e4a401e","lessThan":"03f6ecbc446c33b38fd452cd3c494092a8116967","versionType":"git","status":"affected"},{"version":"bf9e4e30f3538391745a99bc2268ec4f5e4a401e","lessThan":"39406c05f8f150f1685839acd38ffdd69ff92031","versionType":"git","status":"affected"},{"version":"6.18.7","lessThan":"6.18.39","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/x86/mm/init_64.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/03f6ecbc446c33b38fd452cd3c494092a8116967","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/39406c05f8f150f1685839acd38ffdd69ff92031","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/add1e4112e00b619614784bf630aeebfdefa23e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64303","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:11.277","lastModified":"2026-07-25T10:17:11.277","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: fsl-lpspi: terminate the RX channel on TX prepare failure path\n\nWhen dmaengine_prep_slave_sg() fails for the TX channel, the error path\nterminates the TX DMA channel but leaves the RX channel running. Since\nthe RX channel was already submitted and issued prior to preparing\nthe TX descriptor, returning -EINVAL causes the SPI core to unmap the\nDMA buffers while the RX DMA engine continues writing to them, leading\nto potential memory corruption or use-after-free.\n\nTerminate the RX channel before returning on the TX prepare failure path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/spi/spi-fsl-lpspi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"09c04466ce7ea494993c0635ba5edb6d2222a806","lessThan":"ad370d1c7a9a832f77b2341513cd31188c9443af","versionType":"git","status":"affected"},{"version":"09c04466ce7ea494993c0635ba5edb6d2222a806","lessThan":"cce2063404b2341e7b2bbf85eddfcd70a31a0033","versionType":"git","status":"affected"},{"version":"09c04466ce7ea494993c0635ba5edb6d2222a806","lessThan":"af39a2698f69b584d14a00cffe0f51a2caa15337","versionType":"git","status":"affected"},{"version":"09c04466ce7ea494993c0635ba5edb6d2222a806","lessThan":"e65505d91fa036a238968e4c10744244d1b968c4","versionType":"git","status":"affected"},{"version":"09c04466ce7ea494993c0635ba5edb6d2222a806","lessThan":"d5c1060218a3749c8a18b36f8169d910fce20639","versionType":"git","status":"affected"},{"version":"09c04466ce7ea494993c0635ba5edb6d2222a806","lessThan":"808033d80d5c9f8adf7e8de9317389270ce13430","versionType":"git","status":"affected"},{"version":"09c04466ce7ea494993c0635ba5edb6d2222a806","lessThan":"9d000bdd250d649a11cd7f733175686877344582","versionType":"git","status":"affected"},{"version":"09c04466ce7ea494993c0635ba5edb6d2222a806","lessThan":"01980b5da56e573d62798d0ff6c86bcaa2b22cbe","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/spi/spi-fsl-lpspi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.2","status":"affected"},{"version":"0","lessThan":"5.2","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/01980b5da56e573d62798d0ff6c86bcaa2b22cbe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/808033d80d5c9f8adf7e8de9317389270ce13430","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9d000bdd250d649a11cd7f733175686877344582","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ad370d1c7a9a832f77b2341513cd31188c9443af","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af39a2698f69b584d14a00cffe0f51a2caa15337","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cce2063404b2341e7b2bbf85eddfcd70a31a0033","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d5c1060218a3749c8a18b36f8169d910fce20639","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e65505d91fa036a238968e4c10744244d1b968c4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64304","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:11.403","lastModified":"2026-07-25T10:17:11.403","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - validate RSA CRT component lengths\n\nThe generic RSA key parser (rsa_helper.c) bounds each CRT component (p,\nq, dp, dq, qinv) by the modulus size n_sz, but qat_rsa_setkey_crt()\nallocates half-size DMA buffers (key_sz / 2) and right-aligns each\ncomponent with:\n\n    memcpy(dst + half_key_sz - len, src, len)\n\nWhen a CRT component is larger than half_key_sz the subtraction\nunderflows and memcpy writes past the DMA buffer, causing memory\ncorruption.\n\nAdd a len > half_key_sz check next to the existing !len check for each\nof the five CRT components so the driver falls back to the non-CRT path\ninstead of writing out of bounds."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/intel/qat/qat_common/qat_asym_algs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"879f77e9071f029e1c9bd5a75814ecf51370f846","lessThan":"6d99c5fadd2df488103f64d6475b63ba6852202b","versionType":"git","status":"affected"},{"version":"879f77e9071f029e1c9bd5a75814ecf51370f846","lessThan":"c34369473bfe92a0b46ec78d6358e30341c7f481","versionType":"git","status":"affected"},{"version":"879f77e9071f029e1c9bd5a75814ecf51370f846","lessThan":"1002719d13072a5e4be1e993aa61dffb4a604e82","versionType":"git","status":"affected"},{"version":"879f77e9071f029e1c9bd5a75814ecf51370f846","lessThan":"500319830d76911c120dc0b9605f8c16d7702844","versionType":"git","status":"affected"},{"version":"879f77e9071f029e1c9bd5a75814ecf51370f846","lessThan":"3d61a214fdcda41f1ebfabbb483404032a7b4d91","versionType":"git","status":"affected"},{"version":"879f77e9071f029e1c9bd5a75814ecf51370f846","lessThan":"6fb62b767f3e27661e8f8d2f7b85f4e098fcdb1a","versionType":"git","status":"affected"},{"version":"879f77e9071f029e1c9bd5a75814ecf51370f846","lessThan":"ce42224487c504aee4b7ff3a7342e7b4d7e28cc9","versionType":"git","status":"affected"},{"version":"879f77e9071f029e1c9bd5a75814ecf51370f846","lessThan":"b3ac78756588059729b9195fcc9f4b37d54057a5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/intel/qat/qat_common/qat_asym_algs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.8","status":"affected"},{"version":"0","lessThan":"4.8","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1002719d13072a5e4be1e993aa61dffb4a604e82","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3d61a214fdcda41f1ebfabbb483404032a7b4d91","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/500319830d76911c120dc0b9605f8c16d7702844","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d99c5fadd2df488103f64d6475b63ba6852202b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6fb62b767f3e27661e8f8d2f7b85f4e098fcdb1a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b3ac78756588059729b9195fcc9f4b37d54057a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c34369473bfe92a0b46ec78d6358e30341c7f481","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ce42224487c504aee4b7ff3a7342e7b4d7e28cc9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64305","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:11.530","lastModified":"2026-07-25T10:17:11.530","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - protect service table iterations with service_lock\n\nThe service_table list is protected by service_lock when entries are\nadded or removed (in adf_service_add() and adf_service_remove()), but\nseveral functions iterate over the list without holding this lock.\n\nA concurrent adf_service_register() or adf_service_unregister() call\ncould modify the list during traversal, leading to list corruption or\na use-after-free.\n\nFix this by holding service_lock across all list_for_each_entry()\niterations of service_table in adf_dev_init(), adf_dev_start(),\nadf_dev_stop(), adf_dev_shutdown(), adf_dev_restarting_notify(),\nadf_dev_restarted_notify(), and adf_error_notifier().\n\nThe lock ordering is safe: callers of the static helpers (adf_dev_up()\nand adf_dev_down()) acquire state_lock before service_lock, and no\nevent_hld callback or service_lock holder ever acquires state_lock in\nthe reverse order."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/intel/qat/qat_common/adf_init.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d8cba25d2c68992a6e7c1d329b690a9ebe01167d","lessThan":"222fa7b453b612f4407f260146d89a2ce2bc831d","versionType":"git","status":"affected"},{"version":"d8cba25d2c68992a6e7c1d329b690a9ebe01167d","lessThan":"c3c5925791cff3b84d313293fd60f384d877d793","versionType":"git","status":"affected"},{"version":"d8cba25d2c68992a6e7c1d329b690a9ebe01167d","lessThan":"0dbcecea740d943002c1cbdafa39bdfc108e32a5","versionType":"git","status":"affected"},{"version":"d8cba25d2c68992a6e7c1d329b690a9ebe01167d","lessThan":"5c6f845e77ec35f9b7b047cc8f9789bf397cdd3e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/intel/qat/qat_common/adf_init.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.17","status":"affected"},{"version":"0","lessThan":"3.17","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0dbcecea740d943002c1cbdafa39bdfc108e32a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/222fa7b453b612f4407f260146d89a2ce2bc831d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5c6f845e77ec35f9b7b047cc8f9789bf397cdd3e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c3c5925791cff3b84d313293fd60f384d877d793","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64306","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:11.653","lastModified":"2026-07-25T10:17:11.653","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: drbg - Fix returning success on failure in CTR_DRBG\n\ndrbg_ctr_generate() sometimes returns success when it fails, leaving the\noutput buffer uninitialized.  Fix it."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["crypto/drbg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cde001e4c3c3625c60b68a83eb1f1c2572dee07a","lessThan":"074db6db03a0aaa78f05ca9d4838053713796665","versionType":"git","status":"affected"},{"version":"cde001e4c3c3625c60b68a83eb1f1c2572dee07a","lessThan":"7b03312491f9fe6ba4d60c4023e7e61d2d1fed96","versionType":"git","status":"affected"},{"version":"cde001e4c3c3625c60b68a83eb1f1c2572dee07a","lessThan":"75597e8774f319152744d24e0683d9393540a951","versionType":"git","status":"affected"},{"version":"cde001e4c3c3625c60b68a83eb1f1c2572dee07a","lessThan":"cc42fb40171c249bb859071d81b4eb007398a0bc","versionType":"git","status":"affected"},{"version":"cde001e4c3c3625c60b68a83eb1f1c2572dee07a","lessThan":"bbbac12083eff489b35d848332f0dff311131344","versionType":"git","status":"affected"},{"version":"cde001e4c3c3625c60b68a83eb1f1c2572dee07a","lessThan":"23b8b188cb32e5531d0f8d3af9506f8959cb369e","versionType":"git","status":"affected"},{"version":"cde001e4c3c3625c60b68a83eb1f1c2572dee07a","lessThan":"a9e886f73dd717027028bb7e3bbca93601ecdfc7","versionType":"git","status":"affected"},{"version":"cde001e4c3c3625c60b68a83eb1f1c2572dee07a","lessThan":"39a31ad9e2a5ed7e9c9c6f711dca96c8c8f5f26b","versionType":"git","status":"affected"},{"version":"f60b0fa8bbddde66f1d197be07120264b555c84a","versionType":"git","status":"affected"},{"version":"3.12.44","lessThan":"3.13","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["crypto/drbg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.1","status":"affected"},{"version":"0","lessThan":"4.1","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/074db6db03a0aaa78f05ca9d4838053713796665","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/23b8b188cb32e5531d0f8d3af9506f8959cb369e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/39a31ad9e2a5ed7e9c9c6f711dca96c8c8f5f26b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/75597e8774f319152744d24e0683d9393540a951","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7b03312491f9fe6ba4d60c4023e7e61d2d1fed96","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a9e886f73dd717027028bb7e3bbca93601ecdfc7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bbbac12083eff489b35d848332f0dff311131344","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cc42fb40171c249bb859071d81b4eb007398a0bc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64307","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:11.800","lastModified":"2026-07-25T10:17:11.800","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG)\n\nSashiko notes:\n\n> if SEV initialization fails and KVM is actively running normal VMs, could a\n> userspace process trigger this code path via /dev/sev ioctls (e.g.,\n> SEV_PDH_GEN) and zero out MSR_VM_HSAVE_PA globally? Would the next VMRUN\n> execution for an active VM trigger a general protection fault and crash the\n> host?\n\nRefuse to re-try initialization if SNP is not already initialized for\nSNP_CONFIG.\n\nThis is technically an ABI break: before if SNP initialization failed it\ncould be transparently retriggered by this ioctl, and if no VMs were\nrunning, everything worked fine. Hopefully this is enough of a corner case\nthat nobody will notice, but someone does, there are a few options:\n\n* do something like symbol_get() for kvm and refuse to initialize if KVM is\n  loaded\n* check each cpu's HSAVE_PA for non-zero data before re-initializing\n* once initialization has failed, continue to refuse to initialize until\n  the ccp module is unloaded"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/ccp/sev-dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1c3506ea8599a3ad1b9aae5cbd573134f8d18db7","lessThan":"345a6e869b33687e9268044bcaeeefd7c61da675","versionType":"git","status":"affected"},{"version":"ceac7fb89e8da465aec3ac3c20477f912f5c3a6c","lessThan":"441ea32cf2755a0dc593557056b00b7caa0651f5","versionType":"git","status":"affected"},{"version":"ceac7fb89e8da465aec3ac3c20477f912f5c3a6c","lessThan":"20f548cdac94860a164e5ebba4f7e4a01051cb06","versionType":"git","status":"affected"},{"version":"ceac7fb89e8da465aec3ac3c20477f912f5c3a6c","lessThan":"08f0e65e784c4b20e6e620dd4f68d8636073a3d2","versionType":"git","status":"affected"},{"version":"6.12.75","lessThan":"6.12.97","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/ccp/sev-dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/08f0e65e784c4b20e6e620dd4f68d8636073a3d2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/20f548cdac94860a164e5ebba4f7e4a01051cb06","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/345a6e869b33687e9268044bcaeeefd7c61da675","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/441ea32cf2755a0dc593557056b00b7caa0651f5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64308","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:11.917","lastModified":"2026-07-25T10:17:11.917","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD)\n\nSashiko notes:\n\n> if SEV initialization fails and KVM is actively running normal VMs, could a\n> userspace process trigger this code path via /dev/sev ioctls (e.g.,\n> SEV_PDH_GEN) and zero out MSR_VM_HSAVE_PA globally? Would the next VMRUN\n> execution for an active VM trigger a general protection fault and crash the\n> host?\n\nThe SEV firmware docs for SNP_VLEK_LOAD note:\n\n> On SNP_SHUTDOWN, the VLEK is deleted.\n\nThat is, the initialization/shutdown wrapper here is pointless, because the\nfirmware immediately throws away the key anyway. Instead, refuse to do\nanything if SNP has not been previously initialized.\n\nThis is an ABI break: before, this was a no-op and almost certainly a\nmistake by userspace, and now it returns -ENODEV. ABI compatibility could be\nmaintained here by simply returning 0 in the check instead."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/ccp/sev-dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1c3506ea8599a3ad1b9aae5cbd573134f8d18db7","lessThan":"61cf5eef20657bff9ca235fe938a99ce5ff65c06","versionType":"git","status":"affected"},{"version":"ceac7fb89e8da465aec3ac3c20477f912f5c3a6c","lessThan":"92567ed9306d5a3d1b007eb4faeff30cc3ffc3e4","versionType":"git","status":"affected"},{"version":"ceac7fb89e8da465aec3ac3c20477f912f5c3a6c","lessThan":"8836801847b9479ac046cb18a24981e1b0b05e9d","versionType":"git","status":"affected"},{"version":"ceac7fb89e8da465aec3ac3c20477f912f5c3a6c","lessThan":"f91e9dbb5845d1e5abf1028e6df57dcf61583e1b","versionType":"git","status":"affected"},{"version":"6.12.75","lessThan":"6.12.96","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/ccp/sev-dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/61cf5eef20657bff9ca235fe938a99ce5ff65c06","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8836801847b9479ac046cb18a24981e1b0b05e9d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/92567ed9306d5a3d1b007eb4faeff30cc3ffc3e4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f91e9dbb5845d1e5abf1028e6df57dcf61583e1b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64309","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:12.030","lastModified":"2026-07-25T10:17:12.030","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)\n\nSashiko notes:\n\n> if SEV initialization fails and KVM is actively running normal VMs, could a\n> userspace process trigger this code path via /dev/sev ioctls (e.g.,\n> SEV_PDH_GEN) and zero out MSR_VM_HSAVE_PA globally? Would the next VMRUN\n> execution for an active VM trigger a general protection fault and crash the\n> host?\n\nThe SNP_COMMIT command does not require the firmware to be in any\nparticular state. Skip initializing it if it was previously uninitialized.\n\nThe SEV-SNP firmware specification doc 56860 does not mention SNP_COMMIT in\nTable 5 as a command that is allowed in the UNINIT state, but it is in fact\nallowed and a future documentation update will reflect that."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/ccp/sev-dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1c3506ea8599a3ad1b9aae5cbd573134f8d18db7","lessThan":"74768f73854d647a6462f252dc8782ab8a835211","versionType":"git","status":"affected"},{"version":"ceac7fb89e8da465aec3ac3c20477f912f5c3a6c","lessThan":"7a361c74bb12f3398c388905f1d325be642cd36e","versionType":"git","status":"affected"},{"version":"ceac7fb89e8da465aec3ac3c20477f912f5c3a6c","lessThan":"67ed191b4c8bdf432a3f32d1eb302880b4795cd1","versionType":"git","status":"affected"},{"version":"ceac7fb89e8da465aec3ac3c20477f912f5c3a6c","lessThan":"5a1364da2f04217a36e2fdfa2db4ee025b383a20","versionType":"git","status":"affected"},{"version":"6.12.75","lessThan":"6.12.96","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/ccp/sev-dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5a1364da2f04217a36e2fdfa2db4ee025b383a20","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/67ed191b4c8bdf432a3f32d1eb302880b4795cd1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/74768f73854d647a6462f252dc8782ab8a835211","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7a361c74bb12f3398c388905f1d325be642cd36e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64310","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:12.147","lastModified":"2026-07-25T10:17:12.147","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp - Do not initialize SNP for SEV ioctls\n\nSashiko notes:\n\n> if SEV initialization fails and KVM is actively running normal VMs, could a\n> userspace process trigger this code path via /dev/sev ioctls (e.g.,\n> SEV_PDH_GEN) and zero out MSR_VM_HSAVE_PA globally? Would the next VMRUN\n> execution for an active VM trigger a general protection fault and crash the\n> host?\n\nsev_move_to_init_state() is called for ioctls requiring only SEV firmware:\nSEV_PEK_GEN, SEV_PDH_GEN, SEV_PEK_CSR, SEV_PEK_CERT_IMPORT, and\nSEV_PDH_CERT_EXPORT. After the firmware command, it does SEV_SHUTDOWN on\nthe SEV firmware. Since these commands do not require SNP to be\ninitialized, skip it by calling __sev_platform_init_locked() which only\ninitializes the SEV firmware. This way SNP is not Initialized at all, and\nHSAVE_PA is not cleared.\n\nThe previous code saved any SEV initialization firmware error to\ninit_args.error and then threw it away and hardcoded the return value of\nINVALID_PLATFORM_STATE regardless of the real firmware error. This patch\nchanges it to surface the underlying error, which is hopefully both more\nuseful and doesn't cause any problems.\n\nNote that it is still safe to call __sev_firmware_shutdown() directly: it\ncalls __sev_snp_shutdown_locked(), which skips SNP shutdown if SNP was not\ninitialized."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/ccp/sev-dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1c3506ea8599a3ad1b9aae5cbd573134f8d18db7","lessThan":"5181e88da99c3d1d41e25db3472a62b8d4b42cdd","versionType":"git","status":"affected"},{"version":"ceac7fb89e8da465aec3ac3c20477f912f5c3a6c","lessThan":"9e983d0a74a6a2348e4ce61647ec8a4dfbe198ac","versionType":"git","status":"affected"},{"version":"ceac7fb89e8da465aec3ac3c20477f912f5c3a6c","lessThan":"d51207735e7c224cf591fa260c557a451a69a5cf","versionType":"git","status":"affected"},{"version":"ceac7fb89e8da465aec3ac3c20477f912f5c3a6c","lessThan":"fb1758e74b8061aacfbce7bbb7a7cc650537e167","versionType":"git","status":"affected"},{"version":"6.12.75","lessThan":"6.12.96","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/ccp/sev-dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5181e88da99c3d1d41e25db3472a62b8d4b42cdd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9e983d0a74a6a2348e4ce61647ec8a4dfbe198ac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d51207735e7c224cf591fa260c557a451a69a5cf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb1758e74b8061aacfbce7bbb7a7cc650537e167","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64311","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:12.263","lastModified":"2026-07-25T10:17:12.263","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: loongson - Remove broken and unused loongson-rng\n\nThe loongson-rng rng_alg has several vulnerabilities, including not\nproviding forward security, and a use-after-free bug due to the use of\nwait_for_completion_interruptible().\n\nMeanwhile, the rng_alg framework doesn't really have any purpose in the\nfirst place other than to access the software algorithms crypto/drbg.c\nand crypto/jitterentropy.c.  Hardware-specific rng_algs have no\nin-kernel user, and unlike hwrng there's no feed into the actual Linux\nRNG.  As such, there's really no point to this code.  There are of\ncourse other rng_alg drivers that are similarly unused, but they're\nsimilarly in the process of being phased out, e.g.\nhttps://lore.kernel.org/r/20260529193648.18172-1-ebiggers@kernel.org and\nhttps://lore.kernel.org/r/20260529220430.34135-1-ebiggers@kernel.org\n\nGiven that, there's no point in fixing forward these vulnerabilities,\nand it makes much more sense to simply roll back the addition of this\ndriver.  If this platform provides TRNG (not PRNG) functionality, it\ncould make sense to add a hwrng driver, but it would be quite different."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["MAINTAINERS","arch/loongarch/configs/loongson32_defconfig","arch/loongarch/configs/loongson64_defconfig","drivers/crypto/Kconfig","drivers/crypto/Makefile","drivers/crypto/loongson/Kconfig","drivers/crypto/loongson/Makefile","drivers/crypto/loongson/loongson-rng.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"766b2d724c8df071031412eea902b566a0049c31","lessThan":"037ec8353711c79353b12d5634e0c9ff363a9efa","versionType":"git","status":"affected"},{"version":"766b2d724c8df071031412eea902b566a0049c31","lessThan":"43de8b9f01b7dd2f6ca5360c6bf2f203c02288dc","versionType":"git","status":"affected"},{"version":"766b2d724c8df071031412eea902b566a0049c31","lessThan":"af3d1bb9a09daf928fc3f173689fb7904d6a6d4f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["MAINTAINERS","arch/loongarch/configs/loongson32_defconfig","arch/loongarch/configs/loongson64_defconfig","drivers/crypto/Kconfig","drivers/crypto/Makefile","drivers/crypto/loongson/Kconfig","drivers/crypto/loongson/Makefile","drivers/crypto/loongson/loongson-rng.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/037ec8353711c79353b12d5634e0c9ff363a9efa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/43de8b9f01b7dd2f6ca5360c6bf2f203c02288dc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af3d1bb9a09daf928fc3f173689fb7904d6a6d4f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64312","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:12.373","lastModified":"2026-07-25T10:17:12.373","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: pcrypt - restore callback for non-parallel fallback\n\npcrypt installs pcrypt_aead_done() on the child AEAD request before\ntrying to submit it through padata.  If padata_do_parallel() returns\n-EBUSY, pcrypt falls back to calling the child AEAD directly.\n\nThat fallback must not keep the padata completion callback.  Otherwise\nan asynchronous completion runs pcrypt_aead_done() even though the\nrequest was never enrolled in padata.\n\nRestore the original request callback and callback data before calling\nthe child AEAD directly.  This keeps the fallback path aligned with a\ndirect AEAD request while leaving the parallel path unchanged."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["crypto/pcrypt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a92ccd3618e42333ac6f150ecdac14dca298bc7a","lessThan":"81ce16d938db9b88cdc231522c0358395ae8c6b5","versionType":"git","status":"affected"},{"version":"96001f52ae8c70e2c736d3e1e5dc53d5b521e5ca","lessThan":"3920c5f6edc341729d20d0507e466c6d3b11f372","versionType":"git","status":"affected"},{"version":"92834692a539b5b7f409e467a14667d64713b732","lessThan":"ae93c5b3e2a2968b56d772ca1d06615927b7cc36","versionType":"git","status":"affected"},{"version":"5edae7a9a35606017ee6e05911c290acee9fee5a","lessThan":"82789a44415e3e31168229421b138278dfb16412","versionType":"git","status":"affected"},{"version":"7ddab756f2de5b7b43c122ebebdf37f400fb2b6f","lessThan":"4711ca06bd169a2cbc9cc59a6de2ed512c41a880","versionType":"git","status":"affected"},{"version":"662f2f13e66d3883b9238b0b96b17886179e60e2","lessThan":"c4bd2f4c35b0e15b6040c2f7e7e7986780c066cf","versionType":"git","status":"affected"},{"version":"662f2f13e66d3883b9238b0b96b17886179e60e2","lessThan":"83fa1397d5853de1e27dd52ec44b068ff358ca18","versionType":"git","status":"affected"},{"version":"662f2f13e66d3883b9238b0b96b17886179e60e2","lessThan":"ed459fe319376e876de433d12b6c6772e612ca36","versionType":"git","status":"affected"},{"version":"dd8bf8eb5beba1e7c3b11a9a5a58ccbf345a69e6","versionType":"git","status":"affected"},{"version":"fca8aed12218f96b38e374ff264d78ea1fbd23cc","versionType":"git","status":"affected"},{"version":"a8e0074ffb38c9a5964a221bb998034d016c93a2","versionType":"git","status":"affected"},{"version":"5.10.231","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.15.174","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.120","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.64","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.2","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"4.19.325","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.4.287","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"6.11.11","lessThan":"6.12","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["crypto/pcrypt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3920c5f6edc341729d20d0507e466c6d3b11f372","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4711ca06bd169a2cbc9cc59a6de2ed512c41a880","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/81ce16d938db9b88cdc231522c0358395ae8c6b5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/82789a44415e3e31168229421b138278dfb16412","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/83fa1397d5853de1e27dd52ec44b068ff358ca18","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae93c5b3e2a2968b56d772ca1d06615927b7cc36","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c4bd2f4c35b0e15b6040c2f7e7e7986780c066cf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed459fe319376e876de433d12b6c6772e612ca36","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64313","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:12.517","lastModified":"2026-07-25T10:17:12.517","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ecc - Fix carry overflow in vli multiplication\n\nThe carry flag calculation fails when r01.m_high is saturated\n(0xFFFFFFFFFFFFFFFF) and addition of lower bits overflows.\n\nThe condition (r01.m_high < product.m_high) doesn't handle the case\nwhere r01.m_high == product.m_high and an additional carry exists\nfrom lower-bit overflow.\n\nWhen commit 3c4b23901a0c (\"crypto: ecdh - Add ECDH software support\")\nintroduced crypto/ecc.c, it split the muladd() function in the\nmicro-ecc library into separate mul_64_64() and add_128_128() helpers.\nIt seems the check got lost in translation.\n\nAdd proper handling for this boundary by accounting for the carry\nfrom the lower addition."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["crypto/ecc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3c4b23901a0c766879dff680cd6bdab47bcdbbd2","lessThan":"d11b2bb99bec1f5557c01cac42231e23745f49b8","versionType":"git","status":"affected"},{"version":"3c4b23901a0c766879dff680cd6bdab47bcdbbd2","lessThan":"b709e0e768766abe29a49e1c1922a1604be602f4","versionType":"git","status":"affected"},{"version":"3c4b23901a0c766879dff680cd6bdab47bcdbbd2","lessThan":"24a54dfa06d09813b4802a374fad3d2c0e16a884","versionType":"git","status":"affected"},{"version":"3c4b23901a0c766879dff680cd6bdab47bcdbbd2","lessThan":"677450e5ef850c4d28b7956aa01104548c2a894e","versionType":"git","status":"affected"},{"version":"3c4b23901a0c766879dff680cd6bdab47bcdbbd2","lessThan":"5275e0fca256d081e2e7d4ba3dd8216c6e50d44e","versionType":"git","status":"affected"},{"version":"3c4b23901a0c766879dff680cd6bdab47bcdbbd2","lessThan":"774ddddf5eb26eeca177350413e3e2bc50930ee9","versionType":"git","status":"affected"},{"version":"3c4b23901a0c766879dff680cd6bdab47bcdbbd2","lessThan":"ebaae7c4251cc0cdb2602f334d4f08a3e82d271e","versionType":"git","status":"affected"},{"version":"3c4b23901a0c766879dff680cd6bdab47bcdbbd2","lessThan":"27b536a2ec8e2f85a0380c2d13c9ecbc7aaab406","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["crypto/ecc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.8","status":"affected"},{"version":"0","lessThan":"4.8","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/24a54dfa06d09813b4802a374fad3d2c0e16a884","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/27b536a2ec8e2f85a0380c2d13c9ecbc7aaab406","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5275e0fca256d081e2e7d4ba3dd8216c6e50d44e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/677450e5ef850c4d28b7956aa01104548c2a894e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/774ddddf5eb26eeca177350413e3e2bc50930ee9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b709e0e768766abe29a49e1c1922a1604be602f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d11b2bb99bec1f5557c01cac42231e23745f49b8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ebaae7c4251cc0cdb2602f334d4f08a3e82d271e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64314","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:12.647","lastModified":"2026-07-25T10:17:12.647","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: chacha20poly1305 - validate poly1305 template argument\n\nchachapoly_create() still accepts the compatibility poly1305 parameter\nin the template name, but it assumes the second template argument is\nalways present and immediately passes it to strcmp().\n\nWhen the argument is missing, crypto_attr_alg_name() returns an error\npointer. Check for that before comparing the name so malformed template\ninstantiations fail with an error instead of dereferencing the error\npointer in strcmp().\n\nThis matches the surrounding Crypto API template pattern where\ncrypto_attr_alg_name() results are validated before string-specific use."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["crypto/chacha20poly1305.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a298765e28adaea199f722142c10dae7e24dedf8","lessThan":"0016d3c21c6ab60a20be7f565cefb5999f3adeb6","versionType":"git","status":"affected"},{"version":"a298765e28adaea199f722142c10dae7e24dedf8","lessThan":"e74df53b36cdc6b6b9e5488ec883d1d55624737f","versionType":"git","status":"affected"},{"version":"a298765e28adaea199f722142c10dae7e24dedf8","lessThan":"265b861bece38318b8e0fc8fac0643d4ef906d31","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["crypto/chacha20poly1305.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0016d3c21c6ab60a20be7f565cefb5999f3adeb6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/265b861bece38318b8e0fc8fac0643d4ef906d31","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e74df53b36cdc6b6b9e5488ec883d1d55624737f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64315","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:12.750","lastModified":"2026-07-25T10:17:12.750","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: caam - use print_hex_dump_devel to guard key hex dumps\n\nUse print_hex_dump_devel() for dumping sensitive key material in\n*_setkey() to avoid leaking secrets at runtime when CONFIG_DYNAMIC_DEBUG\nis enabled."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/caam/caamalg_qi2.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8d818c1055013d355d36188f21c7535687374f6c","lessThan":"1ec775f6a124cce6278ae58b7d1c78a3bc6eef23","versionType":"git","status":"affected"},{"version":"8d818c1055013d355d36188f21c7535687374f6c","lessThan":"bcf3cf74dfb6981e18b22cbf561f859a0f7faa26","versionType":"git","status":"affected"},{"version":"8d818c1055013d355d36188f21c7535687374f6c","lessThan":"6407dc85d0a4306681cf6c9be7f05e05dcb67a37","versionType":"git","status":"affected"},{"version":"8d818c1055013d355d36188f21c7535687374f6c","lessThan":"c8cfe11e48b2a4646fa662fcaa92e14810a28d46","versionType":"git","status":"affected"},{"version":"8d818c1055013d355d36188f21c7535687374f6c","lessThan":"8904b425cfcafe6a820c94b9bdf4b10f7d70f9d7","versionType":"git","status":"affected"},{"version":"8d818c1055013d355d36188f21c7535687374f6c","lessThan":"d0b8cafd529b4ec759190c6081f7a76efb563a8f","versionType":"git","status":"affected"},{"version":"8d818c1055013d355d36188f21c7535687374f6c","lessThan":"59057f5d4e9a195c6dd61695ad3bc4481ddf4f14","versionType":"git","status":"affected"},{"version":"8d818c1055013d355d36188f21c7535687374f6c","lessThan":"8005dc808bcce7d6cc2ae015a3cde1683bee602d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/caam/caamalg_qi2.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.20","status":"affected"},{"version":"0","lessThan":"4.20","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1ec775f6a124cce6278ae58b7d1c78a3bc6eef23","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/59057f5d4e9a195c6dd61695ad3bc4481ddf4f14","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6407dc85d0a4306681cf6c9be7f05e05dcb67a37","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8005dc808bcce7d6cc2ae015a3cde1683bee602d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8904b425cfcafe6a820c94b9bdf4b10f7d70f9d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bcf3cf74dfb6981e18b22cbf561f859a0f7faa26","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c8cfe11e48b2a4646fa662fcaa92e14810a28d46","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d0b8cafd529b4ec759190c6081f7a76efb563a8f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64316","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:12.877","lastModified":"2026-07-25T10:17:12.877","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: caam - use print_hex_dump_devel to guard key hex dumps\n\nUse print_hex_dump_devel() for dumping sensitive key material in\n*_setkey() and gen_split_key() to avoid leaking secrets at runtime when\nCONFIG_DYNAMIC_DEBUG is enabled."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/caam/caamalg.c","drivers/crypto/caam/caamalg_qi.c","drivers/crypto/caam/caamhash.c","drivers/crypto/caam/key_gen.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6e005503199b9bf1b385949c05897fd6567b5af4","lessThan":"45c0e3615e5bca5f1fc93357af8d19975c092d4f","versionType":"git","status":"affected"},{"version":"6e005503199b9bf1b385949c05897fd6567b5af4","lessThan":"8b56ba10105ca34a4b75f7e33d41d96a63815591","versionType":"git","status":"affected"},{"version":"6e005503199b9bf1b385949c05897fd6567b5af4","lessThan":"9a53dc0a0ae0486e164e5af3de5f99ab42c5a23e","versionType":"git","status":"affected"},{"version":"6e005503199b9bf1b385949c05897fd6567b5af4","lessThan":"ebd37eef6e4f435e18829c0c0c9ba3a6618cb2dd","versionType":"git","status":"affected"},{"version":"6e005503199b9bf1b385949c05897fd6567b5af4","lessThan":"cea7302d5d05df74cfb4107897b1ca34163c06b9","versionType":"git","status":"affected"},{"version":"6e005503199b9bf1b385949c05897fd6567b5af4","lessThan":"6f7b8e0321f3a8fbbd267d2ac15c671ab59e919e","versionType":"git","status":"affected"},{"version":"6e005503199b9bf1b385949c05897fd6567b5af4","lessThan":"8cf5fb0503129e53052fe29302379cf83891d0fb","versionType":"git","status":"affected"},{"version":"6e005503199b9bf1b385949c05897fd6567b5af4","lessThan":"3f57657b6ea23f933371f2c2846322f441773cee","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/caam/caamalg.c","drivers/crypto/caam/caamalg_qi.c","drivers/crypto/caam/caamhash.c","drivers/crypto/caam/key_gen.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3f57657b6ea23f933371f2c2846322f441773cee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/45c0e3615e5bca5f1fc93357af8d19975c092d4f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6f7b8e0321f3a8fbbd267d2ac15c671ab59e919e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b56ba10105ca34a4b75f7e33d41d96a63815591","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8cf5fb0503129e53052fe29302379cf83891d0fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9a53dc0a0ae0486e164e5af3de5f99ab42c5a23e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cea7302d5d05df74cfb4107897b1ca34163c06b9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ebd37eef6e4f435e18829c0c0c9ba3a6618cb2dd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64317","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:13.010","lastModified":"2026-07-25T10:17:13.010","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nisofs: bound Rock Ridge symlink components to the SL record\n\nget_symlink_chunk() and the SL handling in\nparse_rock_ridge_inode_internal() walk the variable-length components of\na Rock Ridge \"SL\" (symbolic link) record.  Each component is a two-byte\nheader (flags, len) followed by len bytes of text, so it occupies\nslp->len + 2 bytes.  Both loops read slp->len and advance to the next\ncomponent, and get_symlink_chunk() additionally does\nmemcpy(rpnt, slp->text, slp->len), but neither checks that the component\nlies within the SL record before dereferencing it.\n\nA crafted SL record whose component declares a len that runs past the\nrecord (rr->len) therefore triggers an out-of-bounds read of up to 255\nbytes.  When the record sits at the tail of its backing buffer - for\nexample a small kmalloc()ed continuation block reached through a CE\nrecord - the read crosses the allocation; get_symlink_chunk() then\ncopies the out-of-bounds bytes into the symlink body returned to user\nspace by readlink(), disclosing adjacent kernel memory.\n\nISO 9660 images are routinely mounted from untrusted removable media -\ndesktop environments auto-mount them (e.g. via udisks2) without\nCAP_SYS_ADMIN - so the record contents are attacker-controlled.\n\nReject any component that does not fit in the remaining record bytes\nbefore using it.  In get_symlink_chunk() return NULL, like the existing\noutput-buffer (plimit) checks, so a malformed record makes readlink()\nfail with -EIO rather than silently returning a truncated target; in\nparse_rock_ridge_inode_internal() stop the inode-size walk."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/isofs/rock.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1015e1c4b2fadd9c09704e24738e46598778c869","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"36fe7d25dbc40da0c6b1dd4513a4f69ac6164eee","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a22cb6bb54dc167047ea9e70d97dfbc2c15649e3","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b736b12108fd116c41777628f5a333791604df26","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6bf41db09ef935d76fcc84ccf213b42c18de95ee","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b5699642640d6cff357638738c5293985cd5a53d","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9830725078c8483c6831ec10222ae724806ea36b","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5fa1d6a5ec2356d2107dead614437c66fa7138b1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/isofs/rock.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1015e1c4b2fadd9c09704e24738e46598778c869","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/36fe7d25dbc40da0c6b1dd4513a4f69ac6164eee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5fa1d6a5ec2356d2107dead614437c66fa7138b1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6bf41db09ef935d76fcc84ccf213b42c18de95ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9830725078c8483c6831ec10222ae724806ea36b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a22cb6bb54dc167047ea9e70d97dfbc2c15649e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5699642640d6cff357638738c5293985cd5a53d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b736b12108fd116c41777628f5a333791604df26","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64318","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:13.147","lastModified":"2026-07-25T10:17:13.147","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\npartitions: aix: bound the pp_count scan to the ppe array\n\naix_partition() reads the physical volume descriptor into a fixed-size\nstruct pvd and then scans its physical-partition-extent array:\n\n\tint numpps = be16_to_cpu(pvd->pp_count);\n\t...\n\tfor (i = 0; i < numpps; i += 1) {\n\t\tstruct ppe *p = pvd->ppe + i;\n\t\t...\n\t\tlp_ix = be16_to_cpu(p->lp_ix);\n\npvd points at a single kmalloc()'d struct pvd whose ppe[] member holds a\nfixed ARRAY_SIZE(pvd->ppe) (1016) entries, but the loop runs up to the\non-disk pp_count.  pp_count is an unvalidated __be16 read straight from\nthe descriptor, so a crafted AIX image with pp_count larger than 1016\ndrives the loop to read pvd->ppe[i] past the end of the allocation (up\nto 65535 entries, ~2 MB out of bounds).\n\nThe partition scan runs without mounting anything, when a block device\nwith a crafted AIX/IBM partition table appears (an attacker-supplied\nimage attached with losetup -P, or a device auto-scanned by udev), via\nmsdos_partition() -> aix_partition().\n\nClamp the scan to the number of entries the ppe[] array can hold."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["block/partitions/aix.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6","lessThan":"09861651617ba0fec089e8b9477439e68398c110","versionType":"git","status":"affected"},{"version":"6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6","lessThan":"5eacdb1967378f5e5591cd27a2d8cdee2df1a599","versionType":"git","status":"affected"},{"version":"6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6","lessThan":"b5e9c09309e18fd9839ad007c238120353ca0cc4","versionType":"git","status":"affected"},{"version":"6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6","lessThan":"fd94a779020f2ecc8b2607f4c20b34acb1763b9a","versionType":"git","status":"affected"},{"version":"6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6","lessThan":"4671bb74bba05fdd4acf670a35758c29e8c97b83","versionType":"git","status":"affected"},{"version":"6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6","lessThan":"ce93228e2193a17d2c58b656e439bb39fe5c3af8","versionType":"git","status":"affected"},{"version":"6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6","lessThan":"44f37ee92fdcd377c41bdf6a31cdd8cc7d4c410e","versionType":"git","status":"affected"},{"version":"6ceea22bbbc84fcf6bf0913bb3db8a657e9002f6","lessThan":"2dc0bfd2fe355fb930de63c2f2eb8ced8570c579","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["block/partitions/aix.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.11","status":"affected"},{"version":"0","lessThan":"3.11","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/09861651617ba0fec089e8b9477439e68398c110","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2dc0bfd2fe355fb930de63c2f2eb8ced8570c579","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/44f37ee92fdcd377c41bdf6a31cdd8cc7d4c410e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4671bb74bba05fdd4acf670a35758c29e8c97b83","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5eacdb1967378f5e5591cd27a2d8cdee2df1a599","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5e9c09309e18fd9839ad007c238120353ca0cc4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ce93228e2193a17d2c58b656e439bb39fe5c3af8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fd94a779020f2ecc8b2607f4c20b34acb1763b9a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64319","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:13.290","lastModified":"2026-07-25T10:17:13.290","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-auth: validate reply message payload bounds against transfer length\n\nnvmet_auth_reply() accesses the variable-length rval[] array using\nattacker-controlled hl (hash length) and dhvlen (DH value length) fields\nwithout verifying they fit within the allocated buffer of tl bytes.\n\nA malicious NVMe-oF initiator can craft a DHCHAP_REPLY message with a\nsmall transfer length but large hl/dhvlen values, causing out-of-bounds\nheap reads when the target processes the DH public key (rval + 2*hl) or\nperforms the host response memcmp.\n\nWith DH authentication configured, the OOB pointer is passed directly to\nsg_init_one() and read by crypto_kpp_compute_shared_secret(), reaching\nup to 526 bytes past the buffer. This is exploitable pre-authentication.\n\nAdd bounds validation ensuring sizeof(*data) + 2*hl + dhvlen <= tl before\nany access to the variable-length fields.\n\nDiscovered by Atuin - Automated Vulnerability Discovery Engine."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/fabrics-cmd-auth.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"80cd28b56ab62d3e7ed0a7bf05282e6d3ee5b2a0","versionType":"git","status":"affected"},{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"999f6205ede984a786f35f727b01f971b98e215d","versionType":"git","status":"affected"},{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"6d7649c1231dac14d906985d2936967e23041c26","versionType":"git","status":"affected"},{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"caa71b3a43ea5c13fe7141cb019ebcb03b8ac857","versionType":"git","status":"affected"},{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"3a413ece2504c70aa34a20be4dafec04e8c741f9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/fabrics-cmd-auth.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3a413ece2504c70aa34a20be4dafec04e8c741f9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d7649c1231dac14d906985d2936967e23041c26","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/80cd28b56ab62d3e7ed0a7bf05282e6d3ee5b2a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/999f6205ede984a786f35f727b01f971b98e215d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/caa71b3a43ea5c13fe7141cb019ebcb03b8ac857","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64320","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:13.407","lastModified":"2026-07-25T10:17:13.407","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page\n\nnvmet_execute_disc_get_log_page() validates only the dword alignment\nof the host-supplied Log Page Offset (lpo).  The 64-bit offset is then\nadded to a small kzalloc'd buffer that holds the discovery log page\nand the result is passed straight to nvmet_copy_to_sgl(), which\nmemcpy()s data_len bytes out to the host with no source-side bound\ncheck:\n\n    u64 offset      = nvmet_get_log_page_offset(req->cmd);  /* 64-bit host */\n    size_t data_len = nvmet_get_log_page_len(req->cmd);     /* 32-bit host */\n    ...\n    if (offset & 0x3) { ... }                               /* only check */\n    ...\n    alloc_len = sizeof(*hdr) + entry_size * discovery_log_entries(req);\n    buffer = kzalloc(alloc_len, GFP_KERNEL);\n    ...\n    status = nvmet_copy_to_sgl(req, 0, buffer + offset, data_len);\n\nThe Discovery controller is unauthenticated -- nvmet_host_allowed()\nreturns true unconditionally for the discovery subsystem -- so the call\nis reachable pre-authentication by any TCP/RDMA/FC peer that can reach\nthe nvmet target.  With a discovery log page of ~1 KiB, an attacker\nrequesting up to 4 KiB starting at offset == alloc_len reads the next\nslab page out and gets its content returned over the fabric (an\nempirical run on a default nvmet-tcp loopback target leaked 81\ncanonical kernel pointers in one Get Log Page response).  Pointing the\noffset at unmapped kernel memory faults the in-kernel memcpy and\ncrashes (or panics, on panic_on_oops=1) the target host instead.\n\nThe attacker-controlled source-side offset pattern\n\"nvmet_copy_to_sgl(req, 0, buffer + ATTACKER_OFFSET, ...)\" is unique\nto nvmet_execute_disc_get_log_page in the entire nvmet codebase: every\nother Get Log Page handler in admin-cmd.c either ignores lpo (and\nsilently starts every response at offset 0) or tracks a local\ndestination offset with a fixed source pointer.\n\nValidate the host-supplied offset against the log page size, cap the\ncopy length to what is actually available, and zero-fill any remainder\nof the host transfer buffer.  The zero-fill matches the existing\nshort-response pattern in nvmet_execute_get_log_changed_ns()\n(admin-cmd.c) and prevents leaking transport SGL contents when the\nhost asks for more bytes than the log page contains."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/discovery.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a07b4970f464f13640e28e16dad6cfa33647cc99","lessThan":"33b974eb626154ae9348f2bac7de84cb2a3d9dd4","versionType":"git","status":"affected"},{"version":"a07b4970f464f13640e28e16dad6cfa33647cc99","lessThan":"56c021a0869260d04c4b65d1471936aaf9177114","versionType":"git","status":"affected"},{"version":"a07b4970f464f13640e28e16dad6cfa33647cc99","lessThan":"a29b316b9bbfd269f323ab4ba9906a894025680f","versionType":"git","status":"affected"},{"version":"a07b4970f464f13640e28e16dad6cfa33647cc99","lessThan":"53cd102a7a56079b11b897835bd9b94c14e6322c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/discovery.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.8","status":"affected"},{"version":"0","lessThan":"4.8","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/33b974eb626154ae9348f2bac7de84cb2a3d9dd4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/53cd102a7a56079b11b897835bd9b94c14e6322c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/56c021a0869260d04c4b65d1471936aaf9177114","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a29b316b9bbfd269f323ab4ba9906a894025680f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64321","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:13.530","lastModified":"2026-07-25T10:17:13.530","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: target: rdma: fix ndev refcount leak on queue connect\n\nnvmet_rdma_queue_connect() calls nvmet_rdma_find_get_device() which\nacquires a reference on the returned ndev via kref_get(). On the path\nwhere the host queue backlog is exceeded and the function returns\nNVME_SC_CONNECT_CTRL_BUSY, reference of ndev is not released, leaking\nthe kref.\n\nFix this by adding a goto to the existing put_device label before the\nearly return."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/rdma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"31deaeb11ba7a885116c9c30892b9f763c04d59c","lessThan":"d65fe42820b890a6a4644de0a95a812471f79ad3","versionType":"git","status":"affected"},{"version":"31deaeb11ba7a885116c9c30892b9f763c04d59c","lessThan":"a8803c4f0ac3fa7df5551bbb5a8800c434a94357","versionType":"git","status":"affected"},{"version":"31deaeb11ba7a885116c9c30892b9f763c04d59c","lessThan":"5828517d17eda27f21d29ea14800c9e0a57bad11","versionType":"git","status":"affected"},{"version":"31deaeb11ba7a885116c9c30892b9f763c04d59c","lessThan":"badc53620fe813b3a9f727ef9526f98567c2c898","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/rdma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5828517d17eda27f21d29ea14800c9e0a57bad11","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a8803c4f0ac3fa7df5551bbb5a8800c434a94357","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/badc53620fe813b3a9f727ef9526f98567c2c898","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d65fe42820b890a6a4644de0a95a812471f79ad3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64322","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:13.640","lastModified":"2026-07-25T10:17:13.640","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nudf: validate sparing table length as an entry count, not a byte count\n\nudf_load_sparable_map() accepts a sparing table when\n\n\tsizeof(*st) + le16_to_cpu(st->reallocationTableLen) > sb->s_blocksize\n\nis false, i.e. it treats reallocationTableLen as a number of BYTES that\nmust fit in the block.  But the table is walked as an array of 8-byte\nsparingEntry elements:\n\n\tfor (i = 0; i < le16_to_cpu(st->reallocationTableLen); i++) {\n\t\tstruct sparingEntry *entry = &st->mapEntry[i];\n\t\t... entry->origLocation ...\n\t}\n\nin udf_get_pblock_spar15() and udf_relocate_blocks().  A\nreallocationTableLen of N therefore passes the check whenever\nsizeof(*st) + N <= blocksize, yet the consumers index\nsizeof(*st) + N * sizeof(struct sparingEntry) bytes -- up to ~8x the\nblock.  On a crafted UDF image this is an out-of-bounds read in\nudf_get_pblock_spar15(); udf_relocate_blocks() additionally feeds the\nsame length to udf_update_tag(), whose crc_itu_t() reads far past the\nblock, and its memmove() through st->mapEntry[] is an out-of-bounds\nwrite.\n\nValidate reallocationTableLen as the entry count it is, with\nstruct_size()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/udf/super.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1df2ae31c724e57be9d7ac00d78db8a5dabdd050","lessThan":"eeb0f3e193f8e523d03e4c9e084f6b4875f50e8e","versionType":"git","status":"affected"},{"version":"1df2ae31c724e57be9d7ac00d78db8a5dabdd050","lessThan":"0a9b79a951cfd70a9d31ca01ae2d08a20bb730e9","versionType":"git","status":"affected"},{"version":"1df2ae31c724e57be9d7ac00d78db8a5dabdd050","lessThan":"2d726135099313958f8975532a2e15322ff150ce","versionType":"git","status":"affected"},{"version":"1df2ae31c724e57be9d7ac00d78db8a5dabdd050","lessThan":"7285276aa50d2839afb5957ffd491ad282dc8f72","versionType":"git","status":"affected"},{"version":"1df2ae31c724e57be9d7ac00d78db8a5dabdd050","lessThan":"2a219acb2ce674d99bbd1b7b35ed8c384dac7200","versionType":"git","status":"affected"},{"version":"1df2ae31c724e57be9d7ac00d78db8a5dabdd050","lessThan":"04f4599a9efb90992d072a814960edf0cd62805d","versionType":"git","status":"affected"},{"version":"1df2ae31c724e57be9d7ac00d78db8a5dabdd050","lessThan":"7f7774b9da0ef17b87bfa238cf966ad0b3376150","versionType":"git","status":"affected"},{"version":"1df2ae31c724e57be9d7ac00d78db8a5dabdd050","lessThan":"3ec997bd5508e9b25210b5bbec89031629cdb093","versionType":"git","status":"affected"},{"version":"e240873cb4a9fd18de60a817100a96fe670d4359","versionType":"git","status":"affected"},{"version":"9ae30e324a96d0328a575329d7a95a09b3318601","versionType":"git","status":"affected"},{"version":"b1c5701ad6b3e5d21d16f65475651cfaaa41e7aa","versionType":"git","status":"affected"},{"version":"a9f1af04f086656246f30354fb4564ce3b08c4a0","versionType":"git","status":"affected"},{"version":"4836ee563d65bb492f907cbe267a5761b9693e4d","versionType":"git","status":"affected"},{"version":"2.6.32.60","lessThan":"2.6.33","versionType":"semver","status":"affected"},{"version":"2.6.34.14","lessThan":"2.6.35","versionType":"semver","status":"affected"},{"version":"3.0.37","lessThan":"3.1","versionType":"semver","status":"affected"},{"version":"3.2.23","lessThan":"3.3","versionType":"semver","status":"affected"},{"version":"3.4.5","lessThan":"3.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/udf/super.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.5","status":"affected"},{"version":"0","lessThan":"3.5","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/04f4599a9efb90992d072a814960edf0cd62805d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0a9b79a951cfd70a9d31ca01ae2d08a20bb730e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2a219acb2ce674d99bbd1b7b35ed8c384dac7200","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2d726135099313958f8975532a2e15322ff150ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3ec997bd5508e9b25210b5bbec89031629cdb093","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7285276aa50d2839afb5957ffd491ad282dc8f72","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f7774b9da0ef17b87bfa238cf966ad0b3376150","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eeb0f3e193f8e523d03e4c9e084f6b4875f50e8e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64323","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:13.790","lastModified":"2026-07-25T10:17:13.790","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nudf: validate VAT header length against the VAT inode size\n\nudf_load_vat() takes the virtual partition's start offset straight from\nthe on-disk VAT 2.0 header without checking it against the VAT inode\nsize:\n\n\tmap->s_type_specific.s_virtual.s_start_offset =\n\t\tle16_to_cpu(vat20->lengthHeader);\n\tmap->s_type_specific.s_virtual.s_num_entries =\n\t\t(sbi->s_vat_inode->i_size -\n\t\t\tmap->s_type_specific.s_virtual.s_start_offset) >> 2;\n\nlengthHeader is a fully attacker-controlled 16-bit value.  If it exceeds\nthe VAT inode size, the s_num_entries subtraction underflows to a huge\ncount, which defeats the \"block > s_num_entries\" bound in\nudf_get_pblock_virt15(); and on the ICB-inline path that function reads\n\n\t((__le32 *)(iinfo->i_data + s_start_offset))[block]\n\nso a large s_start_offset indexes past the inode's in-ICB data.  Mounting\na crafted UDF image with a virtual (VAT) partition then triggers an\nout-of-bounds read.\n\nReject a VAT whose header length does not leave room for at least one\nentry within the VAT inode."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/udf/super.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fa5e08156335d0687c85b4e724db9448fb166601","lessThan":"0ad2d09a8d66fa8dc6f9b70d660b5fb4478ea934","versionType":"git","status":"affected"},{"version":"fa5e08156335d0687c85b4e724db9448fb166601","lessThan":"883962731420ec271ed8c1cd76524f4b17faa982","versionType":"git","status":"affected"},{"version":"fa5e08156335d0687c85b4e724db9448fb166601","lessThan":"2900e02a0dd4fc30ac9840e7ce4ca0b041ab0d63","versionType":"git","status":"affected"},{"version":"fa5e08156335d0687c85b4e724db9448fb166601","lessThan":"bb0d384c1f42a5b7ace0bd88fee80b9bb1d49acb","versionType":"git","status":"affected"},{"version":"fa5e08156335d0687c85b4e724db9448fb166601","lessThan":"55287a3555ff0515b3aff181d2c08c0462a41709","versionType":"git","status":"affected"},{"version":"fa5e08156335d0687c85b4e724db9448fb166601","lessThan":"e610fb113cdfa8bf4247c9bf4f2337b81ad4ddad","versionType":"git","status":"affected"},{"version":"fa5e08156335d0687c85b4e724db9448fb166601","lessThan":"74580fdf022909e184223cacc364feb826982d96","versionType":"git","status":"affected"},{"version":"fa5e08156335d0687c85b4e724db9448fb166601","lessThan":"d8202786b3d75125c84ebc4de6d946f92fde0ee8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/udf/super.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.26","status":"affected"},{"version":"0","lessThan":"2.6.26","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0ad2d09a8d66fa8dc6f9b70d660b5fb4478ea934","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2900e02a0dd4fc30ac9840e7ce4ca0b041ab0d63","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/55287a3555ff0515b3aff181d2c08c0462a41709","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/74580fdf022909e184223cacc364feb826982d96","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/883962731420ec271ed8c1cd76524f4b17faa982","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb0d384c1f42a5b7ace0bd88fee80b9bb1d49acb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8202786b3d75125c84ebc4de6d946f92fde0ee8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e610fb113cdfa8bf4247c9bf4f2337b81ad4ddad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64324","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:13.923","lastModified":"2026-07-25T10:17:13.923","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nudf: validate free block extents against the partition length\n\nudf_free_blocks() checks the logical block number and count against the\npartition length, but drops the extent offset from that final bound.  A\ncrafted extent can pass the guard while logicalBlockNum + offset + count\npoints past the partition, which later indexes past the space bitmap\narray.\n\nA single ftruncate(2) on a file backed by such an extent reliably\npanics the kernel.  This is a local availability issue.  On desktop\nsystems where UDisks/polkit allows the active user to mount removable\nUDF media without CAP_SYS_ADMIN, an unprivileged local user can supply\nthe crafted filesystem and trigger the panic by truncating a writable\nfile on it.  Systems that require root or CAP_SYS_ADMIN to mount the\nimage have a higher prerequisite.\n\nNo confidentiality or integrity impact is claimed: the reproduced\nprimitive is an out-of-bounds read of a bitmap pointer slot followed by\na kernel panic.\n\nUse the already computed logicalBlockNum + offset + count value for the\npartition length check.  Also make load_block_bitmap() reject an\nout-of-range block group before indexing s_block_bitmap[], so corrupted\ncallers cannot walk past the flexible array."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/udf/balloc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"934f815345c09c290a9b9a9cfdddc203ec2117e8","lessThan":"fdd6229d2ae9914c1f25d1041db0f4f312a4fa76","versionType":"git","status":"affected"},{"version":"22cc7323f090646c8cfb5939e6f15bdc2ed3fd27","lessThan":"b54aee5652fcd7c23a0904a4623ec462c3edc70c","versionType":"git","status":"affected"},{"version":"7c4fa9ebfce69619d132fe703dc2e2cf62a13723","lessThan":"12af328d2ee8d68e81ba612246d0b54b22d23e1f","versionType":"git","status":"affected"},{"version":"5cc9745e2ea11aef7d5c9a42bc36f6cd3e1b4cc3","lessThan":"fb49099206c5c57af28a157249fa7bcb5518f99e","versionType":"git","status":"affected"},{"version":"56e69e59751d20993f243fb7dd6991c4e522424c","lessThan":"9442d75429b0c556292a7454fe888d54259f5240","versionType":"git","status":"affected"},{"version":"56e69e59751d20993f243fb7dd6991c4e522424c","lessThan":"335202ab25b01fdd45889ff25eab70864686dea3","versionType":"git","status":"affected"},{"version":"56e69e59751d20993f243fb7dd6991c4e522424c","lessThan":"be87de7789a82a030a4896bc7683415ec9fa6f2b","versionType":"git","status":"affected"},{"version":"56e69e59751d20993f243fb7dd6991c4e522424c","lessThan":"5f0419457f89dce1a3f1c8e62a3adf2f39ab8168","versionType":"git","status":"affected"},{"version":"097420e48e30f51e8f4f650b5c946f5af63ec1a3","versionType":"git","status":"affected"},{"version":"5def895b42ef16a2da6402818cba8d7ec8ede1ef","versionType":"git","status":"affected"},{"version":"05fb2bf477d3fe5421bd4cb699574737f52bd88b","versionType":"git","status":"affected"},{"version":"5.10.224","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.15.165","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.105","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.46","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"4.19.320","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.4.282","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"6.10.5","lessThan":"6.11","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/udf/balloc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/12af328d2ee8d68e81ba612246d0b54b22d23e1f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/335202ab25b01fdd45889ff25eab70864686dea3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5f0419457f89dce1a3f1c8e62a3adf2f39ab8168","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9442d75429b0c556292a7454fe888d54259f5240","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b54aee5652fcd7c23a0904a4623ec462c3edc70c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be87de7789a82a030a4896bc7683415ec9fa6f2b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb49099206c5c57af28a157249fa7bcb5518f99e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fdd6229d2ae9914c1f25d1041db0f4f312a4fa76","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64325","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:14.097","lastModified":"2026-07-25T10:17:14.097","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon\n\nThis patch is based on a BUG as reported by Bongani Hlope at\nhttps://lore.kernel.org/all/20260502125824.425d7159@bongani-mini.home.org.za/\n\nWhen a channel-switch announcement (CSA) beacon is received,\ncfg80211 queues a wiphy work item that eventually calls\nmt7921_channel_switch_rx_beacon(). If the station disconnects\n(or the channel context is otherwise torn down) between the\ntime the work is queued and the time it runs, the driver's\ndev->new_ctx pointer can already have been cleared to NULL.\nmt7921_channel_switch_rx_beacon() then dereferences new_ctx\nunconditionally, triggering a NULL pointer dereference at\naddress 0x0:\n\n  BUG: kernel NULL pointer dereference, address: 0000000000000000\n  RIP: 0010:mt7921_channel_switch_rx_beacon+0x1f/0x100 [mt7921_common]\n\nThe same missing guard exists in mt7925_channel_switch_rx_beacon(),\nwhich shares the same code pattern introduced by the same commit.\n\nAdd an early-return NULL check for dev->new_ctx in both\nmt7921_channel_switch_rx_beacon() and\nmt7925_channel_switch_rx_beacon(). When new_ctx is NULL there is\nno pending channel switch to process, so returning immediately is\nthe correct and safe action.\n\nOops-Analysis: http://oops.fenrus.org/reports/lkml/20260502125824.425d7159@bongani-mini.home.org.za/report.html"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/mediatek/mt76/mt7921/main.c","drivers/net/wireless/mediatek/mt76/mt7925/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8aa2f59260eb66fc80378c158922ccb741ccc491","lessThan":"77e7b127472a191e086e1e0b1b051703f33b1801","versionType":"git","status":"affected"},{"version":"8aa2f59260eb66fc80378c158922ccb741ccc491","lessThan":"351dd7d2c80d23e56dcce6faa4e62bea5b0877c7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/mediatek/mt76/mt7921/main.c","drivers/net/wireless/mediatek/mt76/mt7925/main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/351dd7d2c80d23e56dcce6faa4e62bea5b0877c7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/77e7b127472a191e086e1e0b1b051703f33b1801","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64326","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:14.207","lastModified":"2026-07-25T10:17:14.207","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nblock: skip sync_blockdev() on surprise removal in bdev_mark_dead()\n\nbdev_mark_dead()'s @surprise == true means the device is already gone.\nThe filesystem callback fs_bdev_mark_dead() honours this and skips\nsync_filesystem(), but the bare block device path (no ->mark_dead op)\nlost its !surprise guard when the holder ->mark_dead callback was wired\nup (see Fixes), and now calls sync_blockdev() unconditionally, which can\nhang forever waiting on writeback that can no longer complete.\n\nsyzkaller hit this via nvme_reset_work()'s \"I/O queues lost\" path:\nnvme_mark_namespaces_dead() -> blk_mark_disk_dead() ->\nbdev_mark_dead(bdev, true) -> sync_blockdev() blocks in\nfolio_wait_writeback(), wedging the reset worker and every task waiting\non it.\n\nSkip the sync on surprise removal, matching fs_bdev_mark_dead();\ninvalidate_bdev() still runs. Orderly removal (surprise == false) is\nunchanged.\n\nFound by FuzzNvme(Syzkaller with FEMU fuzzing framework)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["block/bdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d8530de5a6e82be0ce17a5fdf727a394bcf6444c","lessThan":"d6998ddd507c81e3829489a6ead23f17f5acb7fe","versionType":"git","status":"affected"},{"version":"d8530de5a6e82be0ce17a5fdf727a394bcf6444c","lessThan":"f41cf35ee2a1e31374b3f54e7579c55153506e70","versionType":"git","status":"affected"},{"version":"d8530de5a6e82be0ce17a5fdf727a394bcf6444c","lessThan":"9818bcae3c0ca1dde4b9a334125c46676e0a9b29","versionType":"git","status":"affected"},{"version":"d8530de5a6e82be0ce17a5fdf727a394bcf6444c","lessThan":"aa4c4a9315764b2b7a7182e72cc5ea87520436b4","versionType":"git","status":"affected"},{"version":"d8530de5a6e82be0ce17a5fdf727a394bcf6444c","lessThan":"49f06cff50a4ccf3b7a1a662ceb892b3b21a527a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["block/bdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/49f06cff50a4ccf3b7a1a662ceb892b3b21a527a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9818bcae3c0ca1dde4b9a334125c46676e0a9b29","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aa4c4a9315764b2b7a7182e72cc5ea87520436b4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d6998ddd507c81e3829489a6ead23f17f5acb7fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f41cf35ee2a1e31374b3f54e7579c55153506e70","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64327","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:14.327","lastModified":"2026-07-25T10:17:14.327","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks\n\nWhen parsing endpoint descriptors, ffs_data_got_descs() generates the\neps_addrmap which contains the endpoint direction. However, epfile->in\nwas previously only populated in ffs_func_eps_enable() which executes\nupon USB host connection. As a result, early userspace ioctls like\nFUNCTIONFS_DMABUF_ATTACH that run before the host connects would see\nepfile->in as 0, leading to incorrect DMA directions.\n\nBy moving the initialization to ffs_epfiles_create(), epfile->in is\naccurate before userspace opens the endpoint files."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/gadget/function/f_fs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7b07a2a7ca02a20124b552be96c5a56910795488","lessThan":"82cf1142e5ccf2b6d6d22ef713aaf3e5f2b5716b","versionType":"git","status":"affected"},{"version":"7b07a2a7ca02a20124b552be96c5a56910795488","lessThan":"9e04055ab5fc0470a0031ee6934739f9aa8f34a5","versionType":"git","status":"affected"},{"version":"7b07a2a7ca02a20124b552be96c5a56910795488","lessThan":"f99f32ea9aa976afcbec20647ed33b50a52002c1","versionType":"git","status":"affected"},{"version":"7b07a2a7ca02a20124b552be96c5a56910795488","lessThan":"82cfd4739011bdc7e87b5d585703427e89ddfaa5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/gadget/function/f_fs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/82cf1142e5ccf2b6d6d22ef713aaf3e5f2b5716b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/82cfd4739011bdc7e87b5d585703427e89ddfaa5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9e04055ab5fc0470a0031ee6934739f9aa8f34a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f99f32ea9aa976afcbec20647ed33b50a52002c1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64328","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:14.430","lastModified":"2026-07-25T10:17:14.430","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_fs: Fix DMA fence leak\n\nIn ffs_dmabuf_transfer(), a ffs_dma_fence object is kmalloc'd, with the\nunderlying dma_fence later initialized by dma_fence_init(), which sets\nits kref counter to 1. Then, dma_resv_add_fence() gets a second\nreference, and a pointer to the ffs_dma_fence is passed as the\nusb_request's \"context\" field.\n\nThe dma-resv mechanism will manage the second reference, but the first\nreference is never properly released; the ffs_dmabuf_cleanup() function\ndecreases the reference count, but only to balance with the reference\ngrab in ffs_dmabuf_signal_done().\n\nThe code will then slowly leak memory as more ffs_dma_fence objects are\ncreated without being ever freed.\n\nAddress this issue by transferring ownership of the fence to the DMA\nreservation object, by calling dma_fence_put() right after\ndma_resv_add_fence(). The ffs_dma_fence then gets properly discarded\nafter being signalled."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/gadget/function/f_fs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7b07a2a7ca02a20124b552be96c5a56910795488","lessThan":"b7475b2dce5e121e687280ba5732ccefe77ffd2f","versionType":"git","status":"affected"},{"version":"7b07a2a7ca02a20124b552be96c5a56910795488","lessThan":"e086c16962a1b0142e2675610e9c06fcfcd4c3a8","versionType":"git","status":"affected"},{"version":"7b07a2a7ca02a20124b552be96c5a56910795488","lessThan":"0cae3d6109427c455bad0a18dfb3e2a91657e38a","versionType":"git","status":"affected"},{"version":"7b07a2a7ca02a20124b552be96c5a56910795488","lessThan":"baa6b6068a3f2bf2ed525a1cb37975905dadc658","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/gadget/function/f_fs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0cae3d6109427c455bad0a18dfb3e2a91657e38a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b7475b2dce5e121e687280ba5732ccefe77ffd2f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/baa6b6068a3f2bf2ed525a1cb37975905dadc658","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e086c16962a1b0142e2675610e9c06fcfcd4c3a8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64329","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:14.540","lastModified":"2026-07-25T10:17:14.540","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove\n\nThe threaded IRQ handler ccg_irq_handler() calls ucsi_notify_common(),\nwhich on a connector-change event calls ucsi_connector_change() and\nschedules connector work.  In ucsi_ccg_remove(), ucsi_destroy() frees\nuc->ucsi (kfree) before free_irq() is called, so a handler invocation\nalready in flight may access the freed object after ucsi_destroy().\n\n  CPU 0 (remove)            | CPU 1 (threaded IRQ)\n    ucsi_destroy(uc->ucsi)  |   ccg_irq_handler()\n      kfree(ucsi) // FREE   |     ucsi_notify_common(uc->ucsi) // USE\n\nMove free_irq() before ucsi_destroy() in the remove path.  It is kept\nafter ucsi_unregister(): ucsi_unregister() cancels connector work whose\nhandler issues GET_CONNECTOR_STATUS through ucsi_send_command_common(),\nwhich waits for a completion that is signalled from the IRQ handler, so\nthe IRQ must stay active until that work has been cancelled.\n\nThe probe error path already orders free_irq() before ucsi_destroy().\n\nThis bug was found by static analysis."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/typec/ucsi/ucsi_ccg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2","lessThan":"f1adeb1ff8bef1467d6961059810795d02bbad5d","versionType":"git","status":"affected"},{"version":"e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2","lessThan":"99381e762273a2410a3f0216000be32b013c0ea9","versionType":"git","status":"affected"},{"version":"e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2","lessThan":"1a160076d3d0dcd4a98a4599ad96eec0790b099b","versionType":"git","status":"affected"},{"version":"e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2","lessThan":"c32df11147822d22facee8fa30c2e8971d12f426","versionType":"git","status":"affected"},{"version":"e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2","lessThan":"86c9ee928c4a370e323e432aaf8dca79c4ba7c85","versionType":"git","status":"affected"},{"version":"e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2","lessThan":"f5c772b76bbd95de8be51cf849c6098f6af6fcf9","versionType":"git","status":"affected"},{"version":"e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2","lessThan":"dbb500bad02146b388041877574829016591ddc8","versionType":"git","status":"affected"},{"version":"e32fd989ac1c45f993fbe89ad0a89aa9ea6993d2","lessThan":"1f0bdc2884b67de337215079bba166df0cdf4ac5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/typec/ucsi/ucsi_ccg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.5","status":"affected"},{"version":"0","lessThan":"5.5","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1a160076d3d0dcd4a98a4599ad96eec0790b099b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1f0bdc2884b67de337215079bba166df0cdf4ac5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/86c9ee928c4a370e323e432aaf8dca79c4ba7c85","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/99381e762273a2410a3f0216000be32b013c0ea9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c32df11147822d22facee8fa30c2e8971d12f426","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dbb500bad02146b388041877574829016591ddc8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1adeb1ff8bef1467d6961059810795d02bbad5d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f5c772b76bbd95de8be51cf849c6098f6af6fcf9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64330","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:14.673","lastModified":"2026-07-25T10:17:14.673","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: tcpm: Validate SVID index in svdm_consume_modes()\n\nIn svdm_consume_modes(), the SVID value is read from pmdata->svids using\npmdata->svid_index as an array index without bounds validation:\n\n    paltmode->svid = pmdata->svids[pmdata->svid_index];\n\nIf pmdata->svid_index is driven beyond SVID_DISCOVERY_MAX (16), it results\nin an out-of-bounds read of the pmdata->svids array. Because pd_mode_data\nis embedded inside struct tcpm_port, indexing past svids reads into\nadjacent fields. In particular:\n- At index 16, it reads the altmodes count.\n- At index 18 and beyond, it reads into altmode_desc[], which contains\n  partner-supplied SVDM Discovery Modes VDOs.\n\nBy injecting a chosen SVID into altmode_desc[0].vdo and driving svid_index\nto 20, the partner can force paltmode->svid to be loaded with an arbitrary,\npartner- chosen SVID, which is then registered via\ntypec_partner_register_altmode().\n\nFix this by validating that pmdata->svid_index is non-negative and strictly\nless than pmdata->nsvids before accessing the pmdata->svids array inside\nsvdm_consume_modes()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/typec/tcpm/tcpm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4ab8c18d4d67321cc7b660559de17511d4fc0237","lessThan":"89ff289cbf5d3b659a2babc5ccaae4eaf7e7cf53","versionType":"git","status":"affected"},{"version":"4ab8c18d4d67321cc7b660559de17511d4fc0237","lessThan":"d638ec188e95fe60f4b01106ffd41958f8fb3c2c","versionType":"git","status":"affected"},{"version":"4ab8c18d4d67321cc7b660559de17511d4fc0237","lessThan":"f8163c414de8640f2ca82ce4dc93409d4cdc2fad","versionType":"git","status":"affected"},{"version":"4ab8c18d4d67321cc7b660559de17511d4fc0237","lessThan":"012406f89abc52d1d5f07aa5653b519ebf6d2407","versionType":"git","status":"affected"},{"version":"4ab8c18d4d67321cc7b660559de17511d4fc0237","lessThan":"c6d2af3b217a525741c472f0ab45d7d274b8468f","versionType":"git","status":"affected"},{"version":"4ab8c18d4d67321cc7b660559de17511d4fc0237","lessThan":"3e1b1ac47e8163627f159f30d80d51b914620dd4","versionType":"git","status":"affected"},{"version":"4ab8c18d4d67321cc7b660559de17511d4fc0237","lessThan":"313ca06e7e224ca1dfadd5722fe71fb8bc276b8b","versionType":"git","status":"affected"},{"version":"4ab8c18d4d67321cc7b660559de17511d4fc0237","lessThan":"7b681dd5fbf60b24a13c14661e5b7735759fb491","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/typec/tcpm/tcpm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.19","status":"affected"},{"version":"0","lessThan":"4.19","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/012406f89abc52d1d5f07aa5653b519ebf6d2407","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/313ca06e7e224ca1dfadd5722fe71fb8bc276b8b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3e1b1ac47e8163627f159f30d80d51b914620dd4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7b681dd5fbf60b24a13c14661e5b7735759fb491","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/89ff289cbf5d3b659a2babc5ccaae4eaf7e7cf53","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c6d2af3b217a525741c472f0ab45d7d274b8468f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d638ec188e95fe60f4b01106ffd41958f8fb3c2c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f8163c414de8640f2ca82ce4dc93409d4cdc2fad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64331","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:14.813","lastModified":"2026-07-25T10:17:14.813","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusbip: vudc: fix NULL deref in vep_dequeue()\n\nvep_alloc_request() wasn't initializing vrequest->udc, so cancellations\non the FunctionFS AIO path were arriving in vep_dequeue without a valid\nUDC reference.\n\nSince vrequest->udc is never actually properly used anywhere, we opt to\nremove it, and update vep_dequeue to obtain a reference to the udc with\nep_to_vudc(), consistent with the other vep_ ops.\n\nAFAICT this bug has existed for ~10 years. Seems that nobody has really\nstressed the FunctionFS AIO path on usbip's vudc.\n\nI tested this fix in a QEMU aarch64 guest driving FunctionFS endpoints\nvia AIO. Before the fix, running `usbip attach` from the host would\ncause the guest to oops with the following backtrace:\n\nCall trace:\n vep_dequeue+0x1c/0xe4 (P)\n usb_ep_dequeue+0x14/0x20\n ffs_aio_cancel+0x24/0x34\n __arm64_sys_io_cancel+0xb0/0x124\n do_el0_svc+0x68/0x100\n el0_svc+0x18/0x5c\n el0t_64_sync_handler+0x98/0xdc\n el0t_64_sync+0x154/0x158"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/usbip/vudc.h","drivers/usb/usbip/vudc_dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b6a0ca11186759ad7045d68a5447b1e89f658384","lessThan":"9858c91d9ee6a13c45311569039413729fc9b757","versionType":"git","status":"affected"},{"version":"b6a0ca11186759ad7045d68a5447b1e89f658384","lessThan":"1226293ec9bed3d4cc5b05eeeb811d315ca51652","versionType":"git","status":"affected"},{"version":"b6a0ca11186759ad7045d68a5447b1e89f658384","lessThan":"3750f75f29f99c0223601e2ee73ad084adec47bd","versionType":"git","status":"affected"},{"version":"b6a0ca11186759ad7045d68a5447b1e89f658384","lessThan":"d0ebf9cc7c2ddf95a7cfc654b940bdacb7edde97","versionType":"git","status":"affected"},{"version":"b6a0ca11186759ad7045d68a5447b1e89f658384","lessThan":"0025276175fbbe0dcbf3f84d090b0adee769e9d9","versionType":"git","status":"affected"},{"version":"b6a0ca11186759ad7045d68a5447b1e89f658384","lessThan":"347b59e9f96719d89b6ef555d02a18ada1a5846f","versionType":"git","status":"affected"},{"version":"b6a0ca11186759ad7045d68a5447b1e89f658384","lessThan":"0443e4416aa1ee97748d1ed904eaf3352c60045e","versionType":"git","status":"affected"},{"version":"b6a0ca11186759ad7045d68a5447b1e89f658384","lessThan":"c5371e0b91b24159a3ebaa61e70b0980bcf03c0a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/usbip/vudc.h","drivers/usb/usbip/vudc_dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.7","status":"affected"},{"version":"0","lessThan":"4.7","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0025276175fbbe0dcbf3f84d090b0adee769e9d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0443e4416aa1ee97748d1ed904eaf3352c60045e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1226293ec9bed3d4cc5b05eeeb811d315ca51652","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/347b59e9f96719d89b6ef555d02a18ada1a5846f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3750f75f29f99c0223601e2ee73ad084adec47bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9858c91d9ee6a13c45311569039413729fc9b757","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c5371e0b91b24159a3ebaa61e70b0980bcf03c0a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d0ebf9cc7c2ddf95a7cfc654b940bdacb7edde97","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64332","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:14.950","lastModified":"2026-07-25T10:17:14.950","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: ulpi: fix memory leak on registration failure\n\nThe allocated device name is never freed on early ULPI device\nregistration failures.\n\nFix this by initialising the device structure earlier and releasing the\ninitial reference whenever registration fails."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/common/ulpi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f","lessThan":"d5b32f36c50894ac2df8fa184e6f35f3a6665ecd","versionType":"git","status":"affected"},{"version":"289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f","lessThan":"691e61e5d4cfc5a1b061e937f8cbf2126bfc19a0","versionType":"git","status":"affected"},{"version":"289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f","lessThan":"88187a43135c79d0e43573b4d8f880bbb919eceb","versionType":"git","status":"affected"},{"version":"289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f","lessThan":"5c098f20f15db7f9126129686d1c6da2ce8bbeb0","versionType":"git","status":"affected"},{"version":"289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f","lessThan":"624c57147df1977e0d3da53f1da7117861b9cf19","versionType":"git","status":"affected"},{"version":"289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f","lessThan":"1967a7f0cd5c08eb479196daa5aaa4b7b7a7bd04","versionType":"git","status":"affected"},{"version":"289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f","lessThan":"e5493c9a98ffe083acf13ac064828ae598ba3c16","versionType":"git","status":"affected"},{"version":"289fcff4bcdb1dcc0ce8788b7ea0f58a9e4a495f","lessThan":"8af6812795869a66e9b26044f455b13deecdb69c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/common/ulpi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.2","status":"affected"},{"version":"0","lessThan":"4.2","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1967a7f0cd5c08eb479196daa5aaa4b7b7a7bd04","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5c098f20f15db7f9126129686d1c6da2ce8bbeb0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/624c57147df1977e0d3da53f1da7117861b9cf19","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/691e61e5d4cfc5a1b061e937f8cbf2126bfc19a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/88187a43135c79d0e43573b4d8f880bbb919eceb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8af6812795869a66e9b26044f455b13deecdb69c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d5b32f36c50894ac2df8fa184e6f35f3a6665ecd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5493c9a98ffe083acf13ac064828ae598ba3c16","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64333","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:15.080","lastModified":"2026-07-25T10:17:15.080","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: digi_acceleport: fix write buffer corruption\n\nThe digi_write_inb_command() is supposed to wait for the write urb to\nbecome available or return an error, but instead it updates the transfer\nbuffer and tries to resubmit the urb on timeout.\n\nTo make things worse, for commands like break control where no timeout\nis used, the driver would corrupt the urb immediately due to a broken\njiffies comparison (on 32-bit machines this takes five minutes of uptime\nto trigger due to INITIAL_JIFFIES).\n\nFix this by adding the missing return on timeout and waiting\nindefinitely when no timeout has been specified as intended.\n\nThis issue was (sort of) flagged by Sashiko when reviewing an unrelated\nchange to the driver."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/serial/digi_acceleport.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5d9dc88bdf8897788b0eed57113e9eca7fd42ea9","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2f296974acc279f05f284441bfe3064074958d11","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e60e4873e9178da9f4f2674e4c2ff085d5a84f79","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"699dfb6917503b3cda4d5da6941cf79c3c1b4c8b","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a274b3794fe1852c3d9fe6d900b94053c0b03410","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1243f120790042c2ac92e84e797dacc75fff4366","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a3a13fdc53103b07335918e2cdeb465038a71725","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"24ca1fea8f2753bf33e1d458ec1ae5d9b7796a65","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/serial/digi_acceleport.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1243f120790042c2ac92e84e797dacc75fff4366","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/24ca1fea8f2753bf33e1d458ec1ae5d9b7796a65","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2f296974acc279f05f284441bfe3064074958d11","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5d9dc88bdf8897788b0eed57113e9eca7fd42ea9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/699dfb6917503b3cda4d5da6941cf79c3c1b4c8b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a274b3794fe1852c3d9fe6d900b94053c0b03410","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3a13fdc53103b07335918e2cdeb465038a71725","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e60e4873e9178da9f4f2674e4c2ff085d5a84f79","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64334","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:15.207","lastModified":"2026-07-25T10:17:15.207","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: digi_acceleport: fix hard lockup on disconnect\n\nIf submitting the OOB write urb fails persistently (e.g if the device is\nbeing disconnected) the driver would loop indefinitely with interrupts\ndisabled.\n\nCheck for urb submission errors when sending OOB commands to avoid\nhanging if, for example, open(), set_termios() or close() races with a\nphysical disconnect.\n\nThis is issue was flagged by Sashiko when reviewing an unrelated change\nto the driver."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/serial/digi_acceleport.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6e51147c2744d15730084dc89cc99180d3de4184","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6a8592ace932081ea11aea41c460a1ca0f6344a4","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5a82d842e8c35227d7227f19e5e654df1451782c","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"bcfeae431db9986c2b313e6a760f2ac8df61e138","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2067b3838da6e4af03bae3630414193188d754b2","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2b7dc482f859f2d027db07ff0efc1c5df5b3451a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"79bc131df0e50f8f663c1fdbbe952aaf193a8d39","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5c1ea24b53bf3bfb859f0a05573997487975da23","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/serial/digi_acceleport.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2067b3838da6e4af03bae3630414193188d754b2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2b7dc482f859f2d027db07ff0efc1c5df5b3451a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5a82d842e8c35227d7227f19e5e654df1451782c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5c1ea24b53bf3bfb859f0a05573997487975da23","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6a8592ace932081ea11aea41c460a1ca0f6344a4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e51147c2744d15730084dc89cc99180d3de4184","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/79bc131df0e50f8f663c1fdbbe952aaf193a8d39","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bcfeae431db9986c2b313e6a760f2ac8df61e138","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64335","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:15.337","lastModified":"2026-07-25T10:17:15.337","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: digi_acceleport: fix broken rx after throttle\n\nIf the port is closed while throttled, the read urb is never resubmitted\nand the port will not receive any further data until the device is\nreconnected (or the driver is rebound).\n\nClear the throttle flags and submit the urb if needed when opening the\nport."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/serial/digi_acceleport.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"4f3f6f44db71e469933a7c36c5d57d937ba0a21b","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d5d2660caef78d4c996d34d123574c8e86f5b5ac","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"61954033326fc7e637ed2aeeb4b52021e0ee4657","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"8d50a910194f66566a5eb252b33283855c8d5203","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"abacd67e6f689c62d8a13e3da25f4272bc9ad4af","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"eab394781e9321c0c7e97a24fd092387cb262f40","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"92fa3e1a49848509ea3f7995751963fc65095998","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"83a3dfc018943b05b6daf3a6f891833e1aabfa1f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/serial/digi_acceleport.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4f3f6f44db71e469933a7c36c5d57d937ba0a21b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/61954033326fc7e637ed2aeeb4b52021e0ee4657","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/83a3dfc018943b05b6daf3a6f891833e1aabfa1f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8d50a910194f66566a5eb252b33283855c8d5203","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/92fa3e1a49848509ea3f7995751963fc65095998","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/abacd67e6f689c62d8a13e3da25f4272bc9ad4af","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d5d2660caef78d4c996d34d123574c8e86f5b5ac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eab394781e9321c0c7e97a24fd092387cb262f40","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64336","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:15.463","lastModified":"2026-07-25T10:17:15.463","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: keyspan_pda: fix information leak\n\nThe write() callback is supposed to return the number of characters\naccepted or a negative errno. Since the addition of write fifo support\nthe keyspan_pda implementation will however return the number characters\nsubmitted to the device if the write urb is not already in use. If this\nnumber is larger than the number of characters passed to write(), the\nline discipline continues writing data from beyond the tty write buffer.\n\nFix the information leak by making sure that keyspan_pda_write_start()\nreturns zero on success as intended."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/serial/keyspan_pda.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"034e38e8f68767fb5438ae3e608ee82919674177","lessThan":"b069b7029862fafaff331d4c664d97d4ae828d6d","versionType":"git","status":"affected"},{"version":"034e38e8f68767fb5438ae3e608ee82919674177","lessThan":"e52ca411f50539ff1d0c877b9312771ca8a858c1","versionType":"git","status":"affected"},{"version":"034e38e8f68767fb5438ae3e608ee82919674177","lessThan":"2f7a6b8ab3845bd1da02604f1a874b52a4555a72","versionType":"git","status":"affected"},{"version":"034e38e8f68767fb5438ae3e608ee82919674177","lessThan":"e1494191a3aac665d3a2fce16169a97c346253ec","versionType":"git","status":"affected"},{"version":"034e38e8f68767fb5438ae3e608ee82919674177","lessThan":"cf6ca0aefae03958cfb5b189b0adbfb25c06bfac","versionType":"git","status":"affected"},{"version":"034e38e8f68767fb5438ae3e608ee82919674177","lessThan":"d4b12b6b395e43a2b1d80be3745631fcaa9c047b","versionType":"git","status":"affected"},{"version":"034e38e8f68767fb5438ae3e608ee82919674177","lessThan":"6bfc8d01ac4068eced509f8fc74d0cd205e4dcec","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/serial/keyspan_pda.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.11","status":"affected"},{"version":"0","lessThan":"5.11","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2f7a6b8ab3845bd1da02604f1a874b52a4555a72","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6bfc8d01ac4068eced509f8fc74d0cd205e4dcec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b069b7029862fafaff331d4c664d97d4ae828d6d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf6ca0aefae03958cfb5b189b0adbfb25c06bfac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d4b12b6b395e43a2b1d80be3745631fcaa9c047b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e1494191a3aac665d3a2fce16169a97c346253ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e52ca411f50539ff1d0c877b9312771ca8a858c1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64337","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:15.590","lastModified":"2026-07-25T10:17:15.590","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: mtu3: unmap request DMA on queue failure\n\nmtu3_gadget_queue() maps the request before checking whether\nthe QMU GPD ring can accept another transfer. the request is\nreturned with -EAGAIN before it is linked on the endpoint\nrequest list if mtu3_prepare_transfer() fails.\n\nNormal completion and dequeue paths unmap requests from\nmtu3_req_complete(), but this error path never reaches that\nhelper, so the DMA mapping is left active. Unmap the request\nbefore returning from the failed queue path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/mtu3/mtu3_gadget.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"df2069acb00569a6299d6e11aa1865eeba463848","lessThan":"3cee30f1138281a1d247bb053a1ad4f7c5b04e98","versionType":"git","status":"affected"},{"version":"df2069acb00569a6299d6e11aa1865eeba463848","lessThan":"f3c4026524d3660c73ef2838b99776d37631e039","versionType":"git","status":"affected"},{"version":"df2069acb00569a6299d6e11aa1865eeba463848","lessThan":"e8f739a3860d043dcc135371637e82f53132efe5","versionType":"git","status":"affected"},{"version":"df2069acb00569a6299d6e11aa1865eeba463848","lessThan":"4183874b7925f4a98b400cf857bea26ee87da236","versionType":"git","status":"affected"},{"version":"df2069acb00569a6299d6e11aa1865eeba463848","lessThan":"00c3fef4c2dc2c7cbd8281f8fda09d1913420f09","versionType":"git","status":"affected"},{"version":"df2069acb00569a6299d6e11aa1865eeba463848","lessThan":"8c29d9cfab1c3cf0d0b7fcdf9255597be30aa3e1","versionType":"git","status":"affected"},{"version":"df2069acb00569a6299d6e11aa1865eeba463848","lessThan":"835b0596d4c9bdef93f842d8f826978fb4956b74","versionType":"git","status":"affected"},{"version":"df2069acb00569a6299d6e11aa1865eeba463848","lessThan":"0bddda5a11665c210339de76d27ebbd1a2e0b43c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/mtu3/mtu3_gadget.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.10","status":"affected"},{"version":"0","lessThan":"4.10","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/00c3fef4c2dc2c7cbd8281f8fda09d1913420f09","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0bddda5a11665c210339de76d27ebbd1a2e0b43c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3cee30f1138281a1d247bb053a1ad4f7c5b04e98","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4183874b7925f4a98b400cf857bea26ee87da236","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/835b0596d4c9bdef93f842d8f826978fb4956b74","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8c29d9cfab1c3cf0d0b7fcdf9255597be30aa3e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e8f739a3860d043dcc135371637e82f53132efe5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f3c4026524d3660c73ef2838b99776d37631e039","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64338","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:15.717","lastModified":"2026-07-25T10:17:15.717","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: misc: uss720: unregister parport on probe failure\n\nuss720_probe() registers a parport before reading the 1284 register used\nto detect unsupported Belkin F5U002 adapters. If get_1284_register()\nfails, the error path drops the driver private data and the USB device\nreference, but leaves the parport device registered.\n\nLeaving the port registered is more than a private allocation leak:\nparport_register_port() has already reserved a parport number and\nregistered the parport bus device, while pp->private_data still points at\nthe private data that the common error path is about to release.\n\nUndo the pre-announce registration in the get_1284_register() failure\nbranch before jumping to the common private-data cleanup path. Clear\npriv->pp first, matching the disconnect path and avoiding a stale pointer\nin the private data.\n\nThis issue was identified during our ongoing static-analysis research while\nreviewing kernel code."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/misc/uss720.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"04736c1bc32197f7d859e01a96ae80a16659931d","lessThan":"6bbb98bec71b577fda4f4b48f7aea5874b04a576","versionType":"git","status":"affected"},{"version":"4eaf2331a77996bbbaf2b824d452ac8ebda7e6e7","lessThan":"93563243377f8e9b46cc94d9c4f06533dd31b141","versionType":"git","status":"affected"},{"version":"8fc246a8a456679993df565d3c9e3da28030ee43","lessThan":"1712fd71a5aaf81e47c747f180535fa963ad7830","versionType":"git","status":"affected"},{"version":"10132ccf99f49b43aeb7470df50d72344a601ad6","lessThan":"0b3073f40cc9f95d5ff0037eb0a06f5c1725a7ea","versionType":"git","status":"affected"},{"version":"3295f1b866bfbcabd625511968e8a5c541f9ab32","lessThan":"5e62d7857fd51b908b8371062ee839739a086bbe","versionType":"git","status":"affected"},{"version":"3295f1b866bfbcabd625511968e8a5c541f9ab32","lessThan":"729b68a5bad71220ae0914c8bdab9488ad5be6c8","versionType":"git","status":"affected"},{"version":"3295f1b866bfbcabd625511968e8a5c541f9ab32","lessThan":"48dd0b2ec9f2e97c486eb68cd0a64b25c1c3df3e","versionType":"git","status":"affected"},{"version":"3295f1b866bfbcabd625511968e8a5c541f9ab32","lessThan":"b4ecbdc4f8830f5586c4a5cfc384c00f20f8f8b3","versionType":"git","status":"affected"},{"version":"02d13616ca30014ed96302e51a5b0e17664e58bc","versionType":"git","status":"affected"},{"version":"dff3b01e91a3df93063b03d0f8dd5c40546687ec","versionType":"git","status":"affected"},{"version":"489d77fbd66375972a380d207f7eb39b00c4a67b","versionType":"git","status":"affected"},{"version":"5.10.221","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.15.162","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.96","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.36","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"4.19.317","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.4.279","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"6.9.7","lessThan":"6.10","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/misc/uss720.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0b3073f40cc9f95d5ff0037eb0a06f5c1725a7ea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1712fd71a5aaf81e47c747f180535fa963ad7830","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/48dd0b2ec9f2e97c486eb68cd0a64b25c1c3df3e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5e62d7857fd51b908b8371062ee839739a086bbe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6bbb98bec71b577fda4f4b48f7aea5874b04a576","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/729b68a5bad71220ae0914c8bdab9488ad5be6c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/93563243377f8e9b46cc94d9c4f06533dd31b141","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b4ecbdc4f8830f5586c4a5cfc384c00f20f8f8b3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64339","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:15.870","lastModified":"2026-07-25T10:17:15.870","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: misc: usbio: bound bulk IN response length to the received transfer\n\nusbio_bulk_msg() copies bpkt_len = le16_to_cpu(bpkt->len) bytes out of\nthe bulk IN buffer (usbio->rxbuf, allocated with size usbio->rxbuf_len)\ninto the caller's buffer.  bpkt_len is fully controlled by the device\nand is only checked against ibuf_len; ibuf_len in turn is checked\nagainst usbio->txbuf_len, not against rxbuf_len:\n\n\tif ((obuf_len > (usbio->txbuf_len - sizeof(*bpkt))) ||\n\t    (ibuf_len > (usbio->txbuf_len - sizeof(*bpkt))))\n\t\treturn -EMSGSIZE;\n\ntxbuf_len and rxbuf_len are taken independently from the bulk OUT and\nbulk IN endpoint wMaxPacketSize in usbio_probe().  A malicious or\nmalfunctioning device that advertises a large bulk OUT endpoint and a\nsmall bulk IN endpoint (e.g. by claiming one of the quirk-free IDs such\nas the Lattice NX33U, 0x2ac1:0x20cb) therefore makes ibuf_len, and\nhence the device-supplied bpkt_len, exceed rxbuf_len.  memcpy() then\nreads up to txbuf_len - rxbuf_len bytes past the end of the rxbuf slab\nobject.  The over-read bytes are handed back to the i2c layer and on to\nuser space through i2c-dev, disclosing adjacent slab memory; with KASAN\nthis is reported as a slab-out-of-bounds read.\n\nThe number of bytes actually received is already known: act equals the\nURB actual_length and is bounded by rxbuf_len.  Reject any response\nthat claims more payload than was received, mirroring the existing\n\"act < sizeof(*bpkt)\" check just above.\n\nThe control path (usbio_ctrl_msg()) is not affected: it uses a single\nbuffer (ctrlbuf) for both directions, so its analogous copy can never\nleave the allocation.\n\nFound by code review.  The out-of-bounds read was confirmed under\nAddressSanitizer with a faithful userspace model of usbio_bulk_msg()'s\nreceive path (an rxbuf_len-sized buffer, the same act/ibuf_len/bpkt_len\nchecks and the memcpy).  A USB raw-gadget + dummy_hcd reproducer is\nalso available."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/misc/usbio.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"121a0f839dbb397af5fabb701cea3e9983223e50","lessThan":"48394f94211cf8fe0ea8604fc441633abf90fc94","versionType":"git","status":"affected"},{"version":"121a0f839dbb397af5fabb701cea3e9983223e50","lessThan":"fc1b546973c1442d5b947fcdd03581f20ecc5bd2","versionType":"git","status":"affected"},{"version":"121a0f839dbb397af5fabb701cea3e9983223e50","lessThan":"8c6314489550fa81d41723a0ff33f655b5b6c7b6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/misc/usbio.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/48394f94211cf8fe0ea8604fc441633abf90fc94","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8c6314489550fa81d41723a0ff33f655b5b6c7b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc1b546973c1442d5b947fcdd03581f20ecc5bd2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64340","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:15.983","lastModified":"2026-07-25T10:17:15.983","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: legousbtower: fix use-after-free on disconnect race\n\nmutex_unlock() may access the mutex structure after releasing the lock\nand therefore cannot be used to manage lifetime of objects directly\n(unlike spinlocks and refcounts). [1][2]\n\nUse a kref to release the driver data to avoid use-after-free in\nmutex_unlock() when release() races with disconnect().\n\n[1] a51749ab34d9 (\"locking/mutex: Document that mutex_unlock() is\n                   non-atomic\")\n[2] 2b9d9e0a9ba0 (\"locking/mutex: Clarify that mutex_unlock(), and most\n                   other sleeping locks, can still use the lock object\n                   after it's unlocked\")"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/misc/legousbtower.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"18bcbcfe9ca2308ebffb40068b51803da9315d97","lessThan":"11d069f85851997b4ea0adf242ed9672dc749b8f","versionType":"git","status":"affected"},{"version":"18bcbcfe9ca2308ebffb40068b51803da9315d97","lessThan":"b4222c05066b252b451f9c8c4730b5b60824ea66","versionType":"git","status":"affected"},{"version":"18bcbcfe9ca2308ebffb40068b51803da9315d97","lessThan":"6462de75d2e370c7e74dcfb7b4ae79eb5a6a55ee","versionType":"git","status":"affected"},{"version":"18bcbcfe9ca2308ebffb40068b51803da9315d97","lessThan":"0b57e5ddbd89df3bc367463de3d2ca66f99a1a5e","versionType":"git","status":"affected"},{"version":"18bcbcfe9ca2308ebffb40068b51803da9315d97","lessThan":"ab2bfd7bec4f134b377ec42f513e90c35db94160","versionType":"git","status":"affected"},{"version":"18bcbcfe9ca2308ebffb40068b51803da9315d97","lessThan":"766738ecf2b819e54d38763c8d1c8ae6cff14b39","versionType":"git","status":"affected"},{"version":"18bcbcfe9ca2308ebffb40068b51803da9315d97","lessThan":"9ba62966461a8e3cc593b62c56ec62eb2d80436d","versionType":"git","status":"affected"},{"version":"18bcbcfe9ca2308ebffb40068b51803da9315d97","lessThan":"62fc8eb1b1481051f7bab4aa93d79809053dd09f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/misc/legousbtower.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.25","status":"affected"},{"version":"0","lessThan":"2.6.25","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0b57e5ddbd89df3bc367463de3d2ca66f99a1a5e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/11d069f85851997b4ea0adf242ed9672dc749b8f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/62fc8eb1b1481051f7bab4aa93d79809053dd09f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6462de75d2e370c7e74dcfb7b4ae79eb5a6a55ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/766738ecf2b819e54d38763c8d1c8ae6cff14b39","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ba62966461a8e3cc593b62c56ec62eb2d80436d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ab2bfd7bec4f134b377ec42f513e90c35db94160","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b4222c05066b252b451f9c8c4730b5b60824ea66","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64341","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:16.117","lastModified":"2026-07-25T10:17:16.117","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: iowarrior: fix use-after-free on disconnect race\n\nmutex_unlock() may access the mutex structure after releasing the lock\nand therefore cannot be used to manage lifetime of objects directly\n(unlike spinlocks and refcounts). [1][2]\n\nUse a kref to release the driver data to avoid use-after-free in\nmutex_unlock() when release() races with disconnect().\n\n[1] a51749ab34d9 (\"locking/mutex: Document that mutex_unlock() is non-atomic\")\n[2] 2b9d9e0a9ba0 (\"locking/mutex: Clarify that mutex_unlock(), and most\n                   other sleeping locks, can still use the lock object\n                   after it's unlocked\")"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/misc/iowarrior.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"946b960d13c15f050a3b848987aaca79f6a459b7","lessThan":"3c0a7b29ebb391d5f50b115e86f842b709195b08","versionType":"git","status":"affected"},{"version":"946b960d13c15f050a3b848987aaca79f6a459b7","lessThan":"71590982700fdeb39a37a500c877228b0140978e","versionType":"git","status":"affected"},{"version":"946b960d13c15f050a3b848987aaca79f6a459b7","lessThan":"c602254ba4c10f60a73cd99d147874f86a3f485c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/misc/iowarrior.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.21","status":"affected"},{"version":"0","lessThan":"2.6.21","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3c0a7b29ebb391d5f50b115e86f842b709195b08","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/71590982700fdeb39a37a500c877228b0140978e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c602254ba4c10f60a73cd99d147874f86a3f485c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64342","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:16.227","lastModified":"2026-07-25T10:17:16.227","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: iowarrior: fix use-after-free on disconnect\n\nSubmitted write URBs are not stopped on close() and therefore need to be\nstopped unconditionally on disconnect() to avoid use-after-free in the\ncompletion handler."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/misc/iowarrior.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"946b960d13c15f050a3b848987aaca79f6a459b7","lessThan":"d058d377291567b72aea33b017215cbfb383b0ad","versionType":"git","status":"affected"},{"version":"946b960d13c15f050a3b848987aaca79f6a459b7","lessThan":"a7bbe946ca3a6eeb6f364d5e84b05e02c7c0d595","versionType":"git","status":"affected"},{"version":"946b960d13c15f050a3b848987aaca79f6a459b7","lessThan":"97ad9337127be04ca0b027c2b01e69302353f404","versionType":"git","status":"affected"},{"version":"946b960d13c15f050a3b848987aaca79f6a459b7","lessThan":"164398601a7f160bc3df1efa454f983302cef03f","versionType":"git","status":"affected"},{"version":"946b960d13c15f050a3b848987aaca79f6a459b7","lessThan":"f328b0e9a0dbd162f5db1b83026b689f2fea2241","versionType":"git","status":"affected"},{"version":"946b960d13c15f050a3b848987aaca79f6a459b7","lessThan":"b748f97aff339e7f08dca9cf38a05b980fb66fea","versionType":"git","status":"affected"},{"version":"946b960d13c15f050a3b848987aaca79f6a459b7","lessThan":"e4596816984efc537e7c04c1af0c639394f967f7","versionType":"git","status":"affected"},{"version":"946b960d13c15f050a3b848987aaca79f6a459b7","lessThan":"bc0e4f16c44e50daa0b1ea729934baa3b4815dee","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/misc/iowarrior.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.21","status":"affected"},{"version":"0","lessThan":"2.6.21","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/164398601a7f160bc3df1efa454f983302cef03f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/97ad9337127be04ca0b027c2b01e69302353f404","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a7bbe946ca3a6eeb6f364d5e84b05e02c7c0d595","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b748f97aff339e7f08dca9cf38a05b980fb66fea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bc0e4f16c44e50daa0b1ea729934baa3b4815dee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d058d377291567b72aea33b017215cbfb383b0ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e4596816984efc537e7c04c1af0c639394f967f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f328b0e9a0dbd162f5db1b83026b689f2fea2241","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64343","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:16.353","lastModified":"2026-07-25T10:17:16.353","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: ldusb: fix use-after-free on disconnect race\n\nmutex_unlock() may access the mutex structure after releasing the lock\nand therefore cannot be used to manage lifetime of objects directly\n(unlike spinlocks and refcounts). [1][2]\n\nUse a kref to release the driver data to avoid use-after-free in\nmutex_unlock() when release() races with disconnect().\n\n[1] a51749ab34d9 (\"locking/mutex: Document that mutex_unlock() is\n                   non-atomic\")\n[2] 2b9d9e0a9ba0 (\"locking/mutex: Clarify that mutex_unlock(), and most\n                   other sleeping locks, can still use the lock object\n                   after it's unlocked\")"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/misc/ldusb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ce0d7d3f575fc1ba6a89c3c651e710355590daff","lessThan":"fc55923a972e715f9a27187b47d4920709e23d85","versionType":"git","status":"affected"},{"version":"ce0d7d3f575fc1ba6a89c3c651e710355590daff","lessThan":"e5a9bdce4bfd3e2226b5f3df5fb8385d6935ee69","versionType":"git","status":"affected"},{"version":"ce0d7d3f575fc1ba6a89c3c651e710355590daff","lessThan":"af59829e67e11ba2511a9f8e4b9111afc7d1f550","versionType":"git","status":"affected"},{"version":"ce0d7d3f575fc1ba6a89c3c651e710355590daff","lessThan":"02ca08fff74cf9b0a3c4d2cacde1c6edeeb95bb4","versionType":"git","status":"affected"},{"version":"ce0d7d3f575fc1ba6a89c3c651e710355590daff","lessThan":"d8f69404e1d671326f86d378b9f5bfbd56490e9d","versionType":"git","status":"affected"},{"version":"ce0d7d3f575fc1ba6a89c3c651e710355590daff","lessThan":"2107a4fc8ff1cf1d52f416c1e5cc8e97413a5915","versionType":"git","status":"affected"},{"version":"ce0d7d3f575fc1ba6a89c3c651e710355590daff","lessThan":"a3e794136ab5e3ad1e7019175a4b837aec86db4b","versionType":"git","status":"affected"},{"version":"ce0d7d3f575fc1ba6a89c3c651e710355590daff","lessThan":"19bdfc7b3c179331eafa423d87e1336f43bbfeb8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/misc/ldusb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.26","status":"affected"},{"version":"0","lessThan":"2.6.26","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/02ca08fff74cf9b0a3c4d2cacde1c6edeeb95bb4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/19bdfc7b3c179331eafa423d87e1336f43bbfeb8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2107a4fc8ff1cf1d52f416c1e5cc8e97413a5915","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3e794136ab5e3ad1e7019175a4b837aec86db4b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af59829e67e11ba2511a9f8e4b9111afc7d1f550","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8f69404e1d671326f86d378b9f5bfbd56490e9d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5a9bdce4bfd3e2226b5f3df5fb8385d6935ee69","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc55923a972e715f9a27187b47d4920709e23d85","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64344","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:16.487","lastModified":"2026-07-25T10:17:16.487","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: idmouse: fix use-after-free on disconnect race\n\nmutex_unlock() may access the mutex structure after releasing the lock\nand therefore cannot be used to manage lifetime of objects directly\n(unlike spinlocks and refcounts). [1][2]\n\nUse a kref to release the driver data to avoid use-after-free in\nmutex_unlock() when release() races with disconnect().\n\n[1] a51749ab34d9 (\"locking/mutex: Document that mutex_unlock() is\n                   non-atomic\")\n[2] 2b9d9e0a9ba0 (\"locking/mutex: Clarify that mutex_unlock(), and most\n                   other sleeping locks, can still use the lock object\n                   after it's unlocked\")"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/misc/idmouse.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"54d2bc068fd21bcb096660938bce7c7265613a24","lessThan":"31e75fed8f90cfea9f8285e7ed135b0e452bf872","versionType":"git","status":"affected"},{"version":"54d2bc068fd21bcb096660938bce7c7265613a24","lessThan":"8d53b14ad4ccbff6d306b3a39c812303f4a87d41","versionType":"git","status":"affected"},{"version":"54d2bc068fd21bcb096660938bce7c7265613a24","lessThan":"f62622e947f82a3854a8502d09492ffbdeb252b4","versionType":"git","status":"affected"},{"version":"54d2bc068fd21bcb096660938bce7c7265613a24","lessThan":"60fc5ef4ecea3e3d1fe556cecf53ddd13096ef09","versionType":"git","status":"affected"},{"version":"54d2bc068fd21bcb096660938bce7c7265613a24","lessThan":"d0f61acb51a8c8f3fd41c303ddb7770cd83e7ed4","versionType":"git","status":"affected"},{"version":"54d2bc068fd21bcb096660938bce7c7265613a24","lessThan":"54c2b7356b4aeea467f9fb13b85e9e036bc428cb","versionType":"git","status":"affected"},{"version":"54d2bc068fd21bcb096660938bce7c7265613a24","lessThan":"e88cff5fbaa629f3cab45c8b46f395d62c2eb515","versionType":"git","status":"affected"},{"version":"54d2bc068fd21bcb096660938bce7c7265613a24","lessThan":"ff002c153f9722caece3983cc23dc4d9d4652cb4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/misc/idmouse.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.24","status":"affected"},{"version":"0","lessThan":"2.6.24","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/31e75fed8f90cfea9f8285e7ed135b0e452bf872","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/54c2b7356b4aeea467f9fb13b85e9e036bc428cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/60fc5ef4ecea3e3d1fe556cecf53ddd13096ef09","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8d53b14ad4ccbff6d306b3a39c812303f4a87d41","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d0f61acb51a8c8f3fd41c303ddb7770cd83e7ed4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e88cff5fbaa629f3cab45c8b46f395d62c2eb515","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f62622e947f82a3854a8502d09492ffbdeb252b4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff002c153f9722caece3983cc23dc4d9d4652cb4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64345","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:16.623","lastModified":"2026-07-25T10:17:16.623","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_printer: take kref only for successful open\n\nprinter_open() returns -EBUSY when the character device is already\nopen, but it increments dev->kref regardless of the return value. VFS\ndoes not call ->release() for a failed open, so every rejected second\nopen permanently leaks one reference.\n\nMove kref_get() into the successful-open branch."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/gadget/function/f_printer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e8d5f92b8d30bb4ade76494490c3c065e12411b1","lessThan":"94ec20d97aa51547965a539f660a1fe79c6929a3","versionType":"git","status":"affected"},{"version":"e8d5f92b8d30bb4ade76494490c3c065e12411b1","lessThan":"75c0ad13e136961328253742501b4efc3988a587","versionType":"git","status":"affected"},{"version":"e8d5f92b8d30bb4ade76494490c3c065e12411b1","lessThan":"bf20c94fa6aaff945f0ae3a23f3212cd299f28d9","versionType":"git","status":"affected"},{"version":"e8d5f92b8d30bb4ade76494490c3c065e12411b1","lessThan":"8a5eba992c862b0c94411eecf9b7121e8636db38","versionType":"git","status":"affected"},{"version":"e8d5f92b8d30bb4ade76494490c3c065e12411b1","lessThan":"7f1f24c367938c5537e2308bf9a965f051d14774","versionType":"git","status":"affected"},{"version":"e8d5f92b8d30bb4ade76494490c3c065e12411b1","lessThan":"30adce93d5c4a5a1ec29d9249e3fdfcc391d406b","versionType":"git","status":"affected"},{"version":"25c95c6bd4dc50a3c20de0fa7f450ea02b2320fc","versionType":"git","status":"affected"},{"version":"4a47581cf010dc351d8069978080fdb000c0776d","versionType":"git","status":"affected"},{"version":"d9fe88b2a38dc700bf5bd3a09c7cd11bbc248367","versionType":"git","status":"affected"},{"version":"cedb0187b8ba929c3f76f28e6bc25804d65f8a54","versionType":"git","status":"affected"},{"version":"e9e791f5c39ab30e374a3b1a9c25ca7ff24988f3","versionType":"git","status":"affected"},{"version":"34f026263889e2827e04acdc3a0eb9ecbd191ef0","versionType":"git","status":"affected"},{"version":"5f845e5d18d151230476cf90aa46449f69ba2ef1","versionType":"git","status":"affected"},{"version":"4.4.241","lessThan":"4.5","versionType":"semver","status":"affected"},{"version":"4.9.241","lessThan":"4.10","versionType":"semver","status":"affected"},{"version":"4.14.203","lessThan":"4.15","versionType":"semver","status":"affected"},{"version":"4.19.154","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.4.73","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"5.8.17","lessThan":"5.9","versionType":"semver","status":"affected"},{"version":"5.9.2","lessThan":"5.10","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/gadget/function/f_printer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/30adce93d5c4a5a1ec29d9249e3fdfcc391d406b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/75c0ad13e136961328253742501b4efc3988a587","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f1f24c367938c5537e2308bf9a965f051d14774","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8a5eba992c862b0c94411eecf9b7121e8636db38","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/94ec20d97aa51547965a539f660a1fe79c6929a3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf20c94fa6aaff945f0ae3a23f3212cd299f28d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64346","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:16.757","lastModified":"2026-07-25T10:17:16.757","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: udc: Fix use-after-free in gadget_match_driver\n\nThe udc structure acts as the management structure for the gadget,\nbut their lifecycles are decoupled. A race condition exists where\nusb_del_gadget() frees the udc memory (e.g., via mode-switch work)\nwhile gadget_match_driver() concurrently accesses the freed udc memory\n(e.g., via configfs), causing a Use-After-Free (UAF) that triggers a\nNULL pointer dereference when the freed memory is zeroed:\n\n[39430.908615][ T1171] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n[39430.911397][ T1171] pc : __pi_strcmp+0x20/0x140\n[39430.911441][ T1171] lr : gadget_match_driver+0x34/0x60\n...\n[39430.911890][ T1171]  usb_gadget_register_driver_owner+0x50/0xf8\n[39430.911910][ T1171]  gadget_dev_desc_UDC_store+0xf4/0x140\n[39430.931308][ T1171]  configfs_write_iter+0xec/0x134\n\n[39430.957058][ T1171] Workqueue: events_freezable __dwc3_set_mode\n[39430.957287][ T1171]  dwc3_gadget_exit+0x34/0x8c\n[39430.957304][ T1171]  __dwc3_set_mode+0xc0/0x664\n\nFix this by ensuring the udc structure remains allocated until the\ngadget is released. To achieve this, introduce a new\nusb_gadget_release() routine to the core. When the gadget is added,\nusb_add_gadget() stores the gadget's release routine in the udc\nstructure and takes a reference to the udc. When the gadget is\nreleased, usb_gadget_release() drops the reference to the udc and\nthen calls the gadget's release routine."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/gadget/udc/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f845852a5a8914277031f47d8de0f350fef52405","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"50eeb8e8a4f389efc91b93cff14a683e714ec194","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7a5214dae906d9f58e07bc4995e8181ee74439f4","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d026f71df141c9b064ff32a78af5391a31ef75c2","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b52476a83d9e12df00765359d728a875b128bef1","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"54fa390aae393eb130f307a85562e3001cc39a52","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"67e511d2989eb1c8c588b599ce2fcc6bb8e6f7ea","versionType":"git","status":"affected"},{"version":"0","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.39","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/gadget/udc/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/50eeb8e8a4f389efc91b93cff14a683e714ec194","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/54fa390aae393eb130f307a85562e3001cc39a52","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/67e511d2989eb1c8c588b599ce2fcc6bb8e6f7ea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7a5214dae906d9f58e07bc4995e8181ee74439f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b52476a83d9e12df00765359d728a875b128bef1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d026f71df141c9b064ff32a78af5391a31ef75c2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f845852a5a8914277031f47d8de0f350fef52405","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64347","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:16.893","lastModified":"2026-07-25T10:17:16.893","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: composite: fix dead empty check in the USB_DT_OTG handler\n\nThe OTG branch of composite_setup() falls back to the first\nconfiguration when none is selected:\n\n\tif (cdev->config)\n\t\tconfig = cdev->config;\n\telse\n\t\tconfig = list_first_entry(&cdev->configs,\n\t\t\t\t\t  struct usb_configuration, list);\n\tif (!config)\n\t\tgoto done;\n\t...\n\tmemcpy(req->buf, config->descriptors[0], value);\n\nlist_first_entry() never returns NULL. On an empty list it returns\ncontainer_of() of the list head. So the \"if (!config)\" check is dead.\n\nWhen cdev->configs is empty, config points at the head inside struct\nusb_composite_dev. config->descriptors[0] reads whatever sits at that\noffset. The memcpy copies up to w_length bytes of it into the response\nbuffer.\n\ncdev->configs can be empty in two cases. One is a teardown race on\ngadget unbind with a control transfer in flight. The other is a driver\nthat sets is_otg before it adds a config. A reproducer that holds\ncdev->configs empty triggers a KASAN fault in this branch.\n\nUse list_first_entry_or_null() so the existing check does its job."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/gadget/composite.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"53e6242db8d60da0587d36951cc9434d1a1c21dd","lessThan":"2454264b2ab4cf0055c0bfd39e79f830452bd0db","versionType":"git","status":"affected"},{"version":"53e6242db8d60da0587d36951cc9434d1a1c21dd","lessThan":"d3e72cfef2e38bd588055739a8100d14f9773b17","versionType":"git","status":"affected"},{"version":"53e6242db8d60da0587d36951cc9434d1a1c21dd","lessThan":"8ac463fe6c0f85bdb1ce8c30e8c9e060802e4483","versionType":"git","status":"affected"},{"version":"53e6242db8d60da0587d36951cc9434d1a1c21dd","lessThan":"56add2b9b2e89ec61c0761165d758f73004fdfdf","versionType":"git","status":"affected"},{"version":"53e6242db8d60da0587d36951cc9434d1a1c21dd","lessThan":"91b3ecd34b60f950c50c560974945b6596a6f207","versionType":"git","status":"affected"},{"version":"53e6242db8d60da0587d36951cc9434d1a1c21dd","lessThan":"01feaf024f29618d5ffa7ab0fd858e0579dcbf7b","versionType":"git","status":"affected"},{"version":"53e6242db8d60da0587d36951cc9434d1a1c21dd","lessThan":"fcb21bf747640c9d6bd1eda9da85420f076d59c1","versionType":"git","status":"affected"},{"version":"53e6242db8d60da0587d36951cc9434d1a1c21dd","lessThan":"f8f680609c2b3ab795ffcd6f21585b6dfc46d395","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/gadget/composite.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.3","status":"affected"},{"version":"0","lessThan":"4.3","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/01feaf024f29618d5ffa7ab0fd858e0579dcbf7b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2454264b2ab4cf0055c0bfd39e79f830452bd0db","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/56add2b9b2e89ec61c0761165d758f73004fdfdf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8ac463fe6c0f85bdb1ce8c30e8c9e060802e4483","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/91b3ecd34b60f950c50c560974945b6596a6f207","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3e72cfef2e38bd588055739a8100d14f9773b17","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f8f680609c2b3ab795ffcd6f21585b6dfc46d395","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fcb21bf747640c9d6bd1eda9da85420f076d59c1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64348","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:17.040","lastModified":"2026-07-25T10:17:17.040","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: free iso schedules on failed submit\n\nEHCI and FOTG210 isochronous submits build an ehci_iso_sched before\nlinking the URB to the endpoint queue, and keep the staged schedule in\nurb->hcpriv until iso_stream_schedule() and the link helpers consume it.\nIf the controller is no longer accessible, or usb_hcd_link_urb_to_ep()\nfails, submit jumps to done_not_linked before that handoff happens and\nleaks the staged schedule still attached to urb->hcpriv.\n\nFree the staged schedule from done_not_linked when submit fails before\nthe URB is linked and clear urb->hcpriv after the free.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1.1.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have an\nEHCI host controller with a USB isochronous device to test with, no\nruntime testing was able to be performed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/fotg210/fotg210-hcd.c","drivers/usb/host/ehci-sched.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8de98402652c01839ae321be6cb3054cf5735d83","lessThan":"b0d00d077f9738d215af9b50c74dffab7a1de19f","versionType":"git","status":"affected"},{"version":"8de98402652c01839ae321be6cb3054cf5735d83","lessThan":"be5004395dfd0b6ec310db359f887fa396fd0dd2","versionType":"git","status":"affected"},{"version":"8de98402652c01839ae321be6cb3054cf5735d83","lessThan":"8890699eea19027ef6e4f9cbcf27cba5e789793f","versionType":"git","status":"affected"},{"version":"8de98402652c01839ae321be6cb3054cf5735d83","lessThan":"6bc17a78a05671d303820224fb37ca339c1dc2cb","versionType":"git","status":"affected"},{"version":"8de98402652c01839ae321be6cb3054cf5735d83","lessThan":"4bb88aee6b868cbf73bf453f62497802f5fe4769","versionType":"git","status":"affected"},{"version":"8de98402652c01839ae321be6cb3054cf5735d83","lessThan":"b9399d25fbb34a05bbe76eeedd730f62ff2670e9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/fotg210/fotg210-hcd.c","drivers/usb/host/ehci-sched.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.15","status":"affected"},{"version":"0","lessThan":"2.6.15","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4bb88aee6b868cbf73bf453f62497802f5fe4769","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6bc17a78a05671d303820224fb37ca339c1dc2cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8890699eea19027ef6e4f9cbcf27cba5e789793f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b0d00d077f9738d215af9b50c74dffab7a1de19f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b9399d25fbb34a05bbe76eeedd730f62ff2670e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be5004395dfd0b6ec310db359f887fa396fd0dd2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64349","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:17.170","lastModified":"2026-07-25T10:17:17.170","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup()\n\nThe dwc3_ulpi_setup() calls the register read and write calls with\ndwc3->regs when both these calls take the dwc3 structure directly.\n\nChnage these two calls to fix the following sparse warning, and\npossibly a nasty bug in the dwc3_ulpi_setup() code:\n\ndrivers/usb/dwc3/core.c:796:45: warning: incorrect type in argument 1 (different address spaces)\ndrivers/usb/dwc3/core.c:796:45:    expected struct dwc3 *dwc\ndrivers/usb/dwc3/core.c:796:45:    got void [noderef] __iomem *regs\ndrivers/usb/dwc3/core.c:798:40: warning: incorrect type in argument 1 (different address spaces)\ndrivers/usb/dwc3/core.c:798:40:    expected struct dwc3 *dwc\ndrivers/usb/dwc3/core.c:798:40:    got void [noderef] __iomem *regs"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/dwc3/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"476ee6389120e1900290b46081b3a12b54e05672","lessThan":"41a4e80d5af04855e68ac88f5e2cd07fa67287f8","versionType":"git","status":"affected"},{"version":"9accc68b1cf0a2b220f51d53641128bb32598070","lessThan":"4349e487a1149ff33b65d53427b8aca57f2e4578","versionType":"git","status":"affected"},{"version":"9accc68b1cf0a2b220f51d53641128bb32598070","lessThan":"e0f844d9d74200d311c6438a0f04270834ba5365","versionType":"git","status":"affected"},{"version":"6.18.32","lessThan":"6.18.40","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/dwc3/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/41a4e80d5af04855e68ac88f5e2cd07fa67287f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4349e487a1149ff33b65d53427b8aca57f2e4578","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e0f844d9d74200d311c6438a0f04270834ba5365","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64350","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:17.280","lastModified":"2026-07-25T10:17:17.280","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()\n\ncdnsp_alloc_stream_info() allocates stream_info->stream_ctx_array with\ncdnsp_alloc_stream_ctx(). If a later stream ring allocation or stream\nmapping update fails, the error path frees the allocated stream rings\nand stream_rings array, but leaves stream_ctx_array allocated.\n\nFree the stream context array before falling through to the stream_rings\ncleanup path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/cdns3/cdnsp-mem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3d82904559f4f5a2622db1b21de3edf2eded7664","lessThan":"37283f5a47127fbdea567749a2110766af53d18d","versionType":"git","status":"affected"},{"version":"3d82904559f4f5a2622db1b21de3edf2eded7664","lessThan":"cb8e9391b7f4f77d112c51910cd7c355a337ef76","versionType":"git","status":"affected"},{"version":"3d82904559f4f5a2622db1b21de3edf2eded7664","lessThan":"fde3c095e1d48e0ac3ab8bc32905da42fe58a36a","versionType":"git","status":"affected"},{"version":"3d82904559f4f5a2622db1b21de3edf2eded7664","lessThan":"d9643bbe93a6aee24edee1a86e0303aa74bcd320","versionType":"git","status":"affected"},{"version":"3d82904559f4f5a2622db1b21de3edf2eded7664","lessThan":"c00826e87bb75e14e0381b05da5f18ffd0241ab6","versionType":"git","status":"affected"},{"version":"3d82904559f4f5a2622db1b21de3edf2eded7664","lessThan":"963075c4da0cd43b3d17b107c355e1eb0ee64a58","versionType":"git","status":"affected"},{"version":"3d82904559f4f5a2622db1b21de3edf2eded7664","lessThan":"3348f444a4ce43dd5c2d1aa41634cb6eff33aa64","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/cdns3/cdnsp-mem.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.12","status":"affected"},{"version":"0","lessThan":"5.12","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3348f444a4ce43dd5c2d1aa41634cb6eff33aa64","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/37283f5a47127fbdea567749a2110766af53d18d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/963075c4da0cd43b3d17b107c355e1eb0ee64a58","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c00826e87bb75e14e0381b05da5f18ffd0241ab6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb8e9391b7f4f77d112c51910cd7c355a337ef76","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d9643bbe93a6aee24edee1a86e0303aa74bcd320","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fde3c095e1d48e0ac3ab8bc32905da42fe58a36a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64351","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:17.407","lastModified":"2026-07-25T10:17:17.407","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: kalmia: bound RX frame length in kalmia_rx_fixup()\n\nkalmia_rx_fixup() computes usb_packet_length = skb->len - (2 *\nKALMIA_HEADER_LENGTH) as a u16, guarded only by a pre-loop check that\nskb->len is at least KALMIA_HEADER_LENGTH, which is 6. A device can\ndeliver a short bulk-IN frame with skb->len in the 6 to 11 range, or\nleave a short trailing remainder on a later loop iteration. Either case\nunderflows usb_packet_length to about 65530.\n\nThat bypasses the usb_packet_length < ether_packet_length truncation path.\nThe device-supplied ether_packet_length, a le16 up to 65535 read from\nheader_start[2], then drives a memcmp() and the following skb_trim() and\nskb_pull() past the end of the rx buffer. The rx buffer is hard_mtu * 10,\nwhich is 14000 bytes. That is an out of bounds read.\n\nRequire both the start and end framing headers to be present before\nsubtracting them, on every loop iteration."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/usb/kalmia.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d40261236e8e278cb1936cb5e934262971692b10","lessThan":"391706889a5112feafdc0c68db3ecc7ed325d09c","versionType":"git","status":"affected"},{"version":"d40261236e8e278cb1936cb5e934262971692b10","lessThan":"aa4eef2cbb66ea3dfcfc24bdce798dd78a81b54b","versionType":"git","status":"affected"},{"version":"d40261236e8e278cb1936cb5e934262971692b10","lessThan":"2d04c37ed4e1d0f733ad39ec35b5a5d8818b4f4a","versionType":"git","status":"affected"},{"version":"d40261236e8e278cb1936cb5e934262971692b10","lessThan":"46ab32870d010e9a057bc5659cea22b7e728ca88","versionType":"git","status":"affected"},{"version":"d40261236e8e278cb1936cb5e934262971692b10","lessThan":"c466097d85d52f3aa200736cb4759e66d4bbf6e3","versionType":"git","status":"affected"},{"version":"d40261236e8e278cb1936cb5e934262971692b10","lessThan":"e24eb271061db384a3c3ef6f107fe515e68ef222","versionType":"git","status":"affected"},{"version":"d40261236e8e278cb1936cb5e934262971692b10","lessThan":"51e65f1d78457ea4f9513d90ab22c9dccbb35110","versionType":"git","status":"affected"},{"version":"d40261236e8e278cb1936cb5e934262971692b10","lessThan":"47b6bcef6e679593d2e86e04ee72c46a4e2f7139","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/usb/kalmia.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.0","status":"affected"},{"version":"0","lessThan":"3.0","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2d04c37ed4e1d0f733ad39ec35b5a5d8818b4f4a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/391706889a5112feafdc0c68db3ecc7ed325d09c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/46ab32870d010e9a057bc5659cea22b7e728ca88","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/47b6bcef6e679593d2e86e04ee72c46a4e2f7139","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/51e65f1d78457ea4f9513d90ab22c9dccbb35110","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aa4eef2cbb66ea3dfcfc24bdce798dd78a81b54b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c466097d85d52f3aa200736cb4759e66d4bbf6e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e24eb271061db384a3c3ef6f107fe515e68ef222","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64352","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:17.547","lastModified":"2026-07-25T10:17:17.547","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Allow LPM map access from sleepable BPF programs\n\ntrie_lookup_elem() annotates its rcu_dereference_check() walks with\nonly rcu_read_lock_bh_held().  Because rcu_dereference_check(p, c)\nresolves to \"c || rcu_read_lock_held()\", this passes for XDP/NAPI and\nclassic RCU readers but fails for sleepable BPF programs, which enter\nvia __bpf_prog_enter_sleepable() and hold only rcu_read_lock_trace().\n\ntrie_update_elem() and trie_delete_elem() have the same problem in a\ndifferent form: they walk the trie with plain rcu_dereference(), which\nasserts rcu_read_lock_held() unconditionally.  Both are reachable from\nsleepable BPF programs via the bpf_map_update_elem / bpf_map_delete_elem\nhelpers, and from the syscall path under classic rcu_read_lock().  In\nthe writer paths the trie is actually protected by trie->lock (an\nrqspinlock taken across the walk); we never relied on the RCU read-side\nlock to keep nodes alive there.\n\nA sleepable LSM hook that ends up touching an LPM trie therefore\ntriggers lockdep on debug kernels:\n\n  =============================\n  WARNING: suspicious RCU usage\n  7.1.0-... Tainted: G            E\n  -----------------------------\n  kernel/bpf/lpm_trie.c:249 suspicious rcu_dereference_check() usage!\n  1 lock held by net_tests/540:\n   #0: (rcu_tasks_trace_srcu_struct){....}-{0:0},\n       at: __bpf_prog_enter_sleepable+0x26/0x280\n  Call Trace:\n   dump_stack_lvl\n   lockdep_rcu_suspicious\n   trie_lookup_elem\n   bpf_prog_..._enforce_security_socket_connect\n   bpf_trampoline_...\n   security_socket_connect\n   __sys_connect\n   do_syscall_64\n\nThis is lockdep-only -- no UAF, since Tasks Trace RCU does serialize\nagainst the trie's reclaim path -- but it spams the console once per\ndistinct callsite on every debug kernel running a sleepable BPF LSM\nthat touches an LPM trie, which is increasingly common.\n\nFor the lookup path, switch the rcu_dereference_check() annotation\nfrom rcu_read_lock_bh_held() to bpf_rcu_lock_held(), which accepts all\nthree contexts (classic, BH, Tasks Trace).  Other map types already\nfollow this convention.\n\nFor trie_update_elem() and trie_delete_elem(), annotate the walks as\nrcu_dereference_protected(*p, 1) -- matching trie_free() in the same\nfile -- since trie->lock is held across the walk.  rqspinlock has no\nlockdep_map, so the predicate degenerates to '1' rather than\nlockdep_is_held(&trie->lock); the protection is real but not\nmachine-verifiable.  trie_get_next_key() also uses bare\nrcu_dereference() but is reachable only from the BPF syscall, which\nholds classic rcu_read_lock() before dispatching, so it is left\nuntouched."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/lpm_trie.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"694cea395fded425008e93cd90cfdf7a451674af","lessThan":"f0967d4f1ba4323a3cb7dc8fdba74dd3a8caaf04","versionType":"git","status":"affected"},{"version":"694cea395fded425008e93cd90cfdf7a451674af","lessThan":"304ca50582f0c047370f85e13caec456f78c9fcc","versionType":"git","status":"affected"},{"version":"694cea395fded425008e93cd90cfdf7a451674af","lessThan":"ec662a8b2cde01e76b37ccd4b992d0342299e69c","versionType":"git","status":"affected"},{"version":"694cea395fded425008e93cd90cfdf7a451674af","lessThan":"9bfdf4b81b0e56d47bc6c46c34a46638be716695","versionType":"git","status":"affected"},{"version":"694cea395fded425008e93cd90cfdf7a451674af","lessThan":"57454944737f3ad9a8703aecbbb79713b513a94b","versionType":"git","status":"affected"},{"version":"694cea395fded425008e93cd90cfdf7a451674af","lessThan":"bd6ad9a6b30498d845413e863fb95c6fab3babe3","versionType":"git","status":"affected"},{"version":"694cea395fded425008e93cd90cfdf7a451674af","lessThan":"2f884d371fafea137afea504d49ee4a7c8d7985b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/lpm_trie.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2f884d371fafea137afea504d49ee4a7c8d7985b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/304ca50582f0c047370f85e13caec456f78c9fcc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/57454944737f3ad9a8703aecbbb79713b513a94b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9bfdf4b81b0e56d47bc6c46c34a46638be716695","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd6ad9a6b30498d845413e863fb95c6fab3babe3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ec662a8b2cde01e76b37ccd4b992d0342299e69c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f0967d4f1ba4323a3cb7dc8fdba74dd3a8caaf04","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64353","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:17.700","lastModified":"2026-07-25T10:17:17.700","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Keep dynamic inner array lookups nullable\n\nAn ARRAY_OF_MAPS can use an array created with BPF_F_INNER_MAP as its\ninner map template. A concrete inner array with a different max_entries\nvalue can then replace the template.\n\nAfter a successful outer map lookup, the verifier represents the\nresulting map pointer using the inner map template. Const-key lookup\nnullness elision consequently uses the template max_entries even though\nthe runtime helper uses the concrete inner map max_entries.\n\nDo not elide lookup result nullness for maps marked with BPF_F_INNER_MAP,\nbecause the template max_entries does not prove that the key is in bounds\nfor the concrete runtime map."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/verifier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d2102f2f5d75a84dbab6ff890359f0bd4a18ca22","lessThan":"0b92ad64d6e4bde85e6b9888404f9a7a2b65d269","versionType":"git","status":"affected"},{"version":"d2102f2f5d75a84dbab6ff890359f0bd4a18ca22","lessThan":"d57db0d975053e01410c54e708a85b6d32ef2ebd","versionType":"git","status":"affected"},{"version":"d2102f2f5d75a84dbab6ff890359f0bd4a18ca22","lessThan":"53040a81ae57cdca8af8ac36fe4e661730cf7c6b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/verifier.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0b92ad64d6e4bde85e6b9888404f9a7a2b65d269","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/53040a81ae57cdca8af8ac36fe4e661730cf7c6b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d57db0d975053e01410c54e708a85b6d32ef2ebd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64354","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:17.810","lastModified":"2026-07-25T10:17:17.810","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Validate BTF repeated field counts before expansion\n\nbtf_parse_struct_metas() walks user-supplied BTF during BPF_BTF_LOAD,\nand btf_repeat_fields() expands repeatable fields from array elements\ninto the fixed BTF_FIELDS_MAX scratch array used by btf_parse_fields().\n\nThe remaining-capacity check performs the expanded field count calculation\nin u32. A malformed BTF can wrap that calculation, causing the check to\npass even when the expanded field count exceeds the scratch array\ncapacity. The following memcpy() can then write past the end of the\narray.\n\nUse checked addition and multiplication before copying repeated fields\nand reject impossible counts."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/btf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"797d73ee232dd1833dec4824bc53a22032e97c1c","lessThan":"c5ff816d5f13900c3f1f3298cfcc61339e056e56","versionType":"git","status":"affected"},{"version":"797d73ee232dd1833dec4824bc53a22032e97c1c","lessThan":"cd407de2ef5dc70f1970b343ffaa16186340fdfd","versionType":"git","status":"affected"},{"version":"797d73ee232dd1833dec4824bc53a22032e97c1c","lessThan":"ff77d013b737c0f77d925e2f2c59f0cf3d76bd35","versionType":"git","status":"affected"},{"version":"797d73ee232dd1833dec4824bc53a22032e97c1c","lessThan":"b9452b594fd3aecbfd4aa0a6a1f741330a37dab7","versionType":"git","status":"affected"},{"version":"6f957d972feee9b385ea3ae6530310a84e55ba71","versionType":"git","status":"affected"},{"version":"6.11.6","lessThan":"6.12","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/btf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/b9452b594fd3aecbfd4aa0a6a1f741330a37dab7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c5ff816d5f13900c3f1f3298cfcc61339e056e56","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd407de2ef5dc70f1970b343ffaa16186340fdfd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff77d013b737c0f77d925e2f2c59f0cf3d76bd35","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64355","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:17.920","lastModified":"2026-07-25T10:17:17.920","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject fragmented frames in devmap\n\nDevmap broadcast redirects clone the packet for all but the last\ndestination.\n\nFor native XDP, that clone path copies only the linear xdp_frame data,\nwhile fragmented frames keep skb_shared_info in tailroom outside the\nlinear area. Cloning such a frame leaves XDP_FLAGS_HAS_FRAGS set but\nwithout valid frag metadata, and the later free path can interpret\nuninitialized tail data as skb_shared_info, leading to an out-of-bounds\naccess during frame return.\n\nReject fragmented native XDP frames in dev_map_enqueue_clone().\n\nAdd the same restriction to the generic XDP clone path in\ndev_map_redirect_clone(). Generic XDP represents fragmented packets as\nnonlinear skbs, and rejecting them here keeps clone-based broadcast\nsupport aligned between native and generic XDP."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/bpf/devmap.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e624d4ed4aa8cc3c69d1359b0aaea539203ed266","lessThan":"47baddc856ae7e93a565dd9deeb797999b179466","versionType":"git","status":"affected"},{"version":"e624d4ed4aa8cc3c69d1359b0aaea539203ed266","lessThan":"07a4c11ee8ef4abcb39d922e9e410ae269671cdf","versionType":"git","status":"affected"},{"version":"e624d4ed4aa8cc3c69d1359b0aaea539203ed266","lessThan":"bccbab36ff228e0825eb85d9b0f9b8434cd0a399","versionType":"git","status":"affected"},{"version":"e624d4ed4aa8cc3c69d1359b0aaea539203ed266","lessThan":"c5b4f5efcb55c1af3fe44ff712d31b7fb098a831","versionType":"git","status":"affected"},{"version":"e624d4ed4aa8cc3c69d1359b0aaea539203ed266","lessThan":"a9bb2d9c798cb62a4050a991c27b752770c33afe","versionType":"git","status":"affected"},{"version":"e624d4ed4aa8cc3c69d1359b0aaea539203ed266","lessThan":"51d07c12ca411e692c424ecdabf077f1e61a61be","versionType":"git","status":"affected"},{"version":"e624d4ed4aa8cc3c69d1359b0aaea539203ed266","lessThan":"aa496720618f1a6054f1c870bf10b4f6c99bf656","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/bpf/devmap.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/07a4c11ee8ef4abcb39d922e9e410ae269671cdf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/47baddc856ae7e93a565dd9deeb797999b179466","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/51d07c12ca411e692c424ecdabf077f1e61a61be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a9bb2d9c798cb62a4050a991c27b752770c33afe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aa496720618f1a6054f1c870bf10b4f6c99bf656","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bccbab36ff228e0825eb85d9b0f9b8434cd0a399","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c5b4f5efcb55c1af3fe44ff712d31b7fb098a831","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64356","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:18.040","lastModified":"2026-07-25T10:17:18.040","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: fix memory leak in xfs_dqinode_metadir_create()\n\nIf xfs_metadir_create() fails in xfs_dqinode_metadir_create(), the current\ncode returns directly, leaking the allocated update and transaction state.\nIf the subsequent commit fails, the caller-owned inode reference is left\nbehind.\n\nFix this memory leak by routing the create failure path through\nxfs_metadir_cancel().  For both create and commit failures, finish and\nrelease any inode returned to the caller, mirroring the unwind pattern in\nxfs_metadir_mkdir().\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1.1.\n\nAn x86_64 allyesconfig build showed no new warnings. Runtime validation\nused kprobe fault injection during `mount -o uquota` on a metadir XFS\nimage. Injecting xfs_metadir_create() reproduced the old active-update path\nthat left mount stuck later in mount setup; after this change, the same\ninjection reported cancel_hits=1 and irele_hits=1. Injecting\nxfs_metadir_commit() exercised the old inode-reference leak path; after\nthis change, it reported irele_hits=1."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/xfs/libxfs/xfs_dquot_buf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e80fbe1ad8eff7d7d1363e14f1e493d84dd37c84","lessThan":"c3d3d2212c2966973dd7d603c6c6e6ed6fc7fbe1","versionType":"git","status":"affected"},{"version":"e80fbe1ad8eff7d7d1363e14f1e493d84dd37c84","lessThan":"06a2e6dbaa26c0740ac76dfa66b0aedc78d05820","versionType":"git","status":"affected"},{"version":"e80fbe1ad8eff7d7d1363e14f1e493d84dd37c84","lessThan":"45de375b25060edf46e20abb36521ba530336ceb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/xfs/libxfs/xfs_dquot_buf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/06a2e6dbaa26c0740ac76dfa66b0aedc78d05820","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/45de375b25060edf46e20abb36521ba530336ceb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c3d3d2212c2966973dd7d603c6c6e6ed6fc7fbe1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64357","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:18.150","lastModified":"2026-07-25T10:17:18.150","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: fix exchmaps reservation limit check\n\nxfs_exchmaps_estimate_overhead() adds the bmbt and rmapbt\noverhead to a local resblks variable, but the final UINT_MAX\ncheck still tests req->resblks.  That is the reservation value\nfrom before the overhead was added.\n\nThe computed value is stored back in req->resblks and later passed\nto xfs_trans_alloc(), whose block reservation argument is unsigned\nint.  Check the computed reservation so the existing limit applies\nto the value that will be used."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/xfs/libxfs/xfs_exchmaps.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"966ceafc7a437105ecfe1cadb3747b2965a260ca","lessThan":"c597c8580d50127fc1221b5a5b653a94d49e23e3","versionType":"git","status":"affected"},{"version":"966ceafc7a437105ecfe1cadb3747b2965a260ca","lessThan":"a62ef2d13d6e7270dd5e88c6082bf2d0edcd5112","versionType":"git","status":"affected"},{"version":"966ceafc7a437105ecfe1cadb3747b2965a260ca","lessThan":"4707344b0d36d1012c8a1716e20167cd3afdd5f1","versionType":"git","status":"affected"},{"version":"966ceafc7a437105ecfe1cadb3747b2965a260ca","lessThan":"0a5213bbff62b51c7d4999ac8c7e11ea57d00d45","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/xfs/libxfs/xfs_exchmaps.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0a5213bbff62b51c7d4999ac8c7e11ea57d00d45","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4707344b0d36d1012c8a1716e20167cd3afdd5f1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a62ef2d13d6e7270dd5e88c6082bf2d0edcd5112","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c597c8580d50127fc1221b5a5b653a94d49e23e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64358","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:18.253","lastModified":"2026-07-25T10:17:18.253","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mtk-jpeg: cancel workqueue on release for supported platforms only\n\nSince a recent fix the mtk_jpeg_release function cancels any pending\nor running work present in the driver workqueue using\ncancel_work_sync function.\nCurrently, only the multicore based variants use this workqueue and they\nhave the jpeg_worker platform data field initialized with a workqueue\ncallback function. For the others, this field value remain NULL by\ndefault.\nThe cancel_work_sync function is unconditionally called in\nmtk_jpeg_release function, even for the variants that do not use the\nworkqueue. This call generates a WARN_ON print in __flush_work because\nthe workqueue callback function presence check fails in __flush_work\nfunction (used by cancel_work_sync).\n\nSo, to avoid these warnings, call cancel_work_sync only if a workqueue\ncallback is defined in platform data."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2209fdae5c2f615930c9af1379c1cfca199ec5d8","lessThan":"0fed0fc34ce734b4b8c2f6a467d38bddcb21dda9","versionType":"git","status":"affected"},{"version":"0498b27a1542021d90269d58347501d4c3ccd84e","lessThan":"ac0774961a6ea174a71d4ffa39966edafbf7662d","versionType":"git","status":"affected"},{"version":"26506a30e0e26d612f82a7bf0e395626968a44e6","lessThan":"973408ceab14555a8548b97c8cc7b54208c3f251","versionType":"git","status":"affected"},{"version":"34c519feef3e4fcff1078dc8bdb25fbbbd10303f","lessThan":"4c4b4af4a9f278da096f0dbdb6b59594701d29bf","versionType":"git","status":"affected"},{"version":"34c519feef3e4fcff1078dc8bdb25fbbbd10303f","lessThan":"b1845a227fda37b2fe5327df3ca0015d7e290235","versionType":"git","status":"affected"},{"version":"e78c39f720679fcf3a2eacd82725ec3ea2648301","versionType":"git","status":"affected"},{"version":"6.6.140","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.86","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"6.18.27","lessThan":"6.18.39","versionType":"semver","status":"affected"},{"version":"7.0.4","lessThan":"7.1","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0fed0fc34ce734b4b8c2f6a467d38bddcb21dda9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4c4b4af4a9f278da096f0dbdb6b59594701d29bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/973408ceab14555a8548b97c8cc7b54208c3f251","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ac0774961a6ea174a71d4ffa39966edafbf7662d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b1845a227fda37b2fe5327df3ca0015d7e290235","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64359","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:18.377","lastModified":"2026-07-25T10:17:18.377","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers\n\nSyzbot reported a hung task in nilfs_transaction_begin() where multiple\ntasks performing chmod() on a nilfs2 mount blocked for over 143 seconds\nwaiting to acquire ns_segctor_sem for read:\n\n  INFO: task syz.0.17:5918 blocked for more than 143 seconds.\n  Call Trace:\n   schedule+0x164/0x360\n   rwsem_down_read_slowpath+0x6d9/0x940\n   down_read+0x99/0x2e0\n   nilfs_transaction_begin+0x364/0x710 fs/nilfs2/segment.c:221\n   nilfs_setattr+0x124/0x2c0 fs/nilfs2/inode.c:921\n   notify_change+0xc1a/0xf40\n   chmod_common+0x273/0x4a0\n   do_fchmodat+0x12d/0x230\n\nThe writer holding ns_segctor_sem was a concurrent\nNILFS_IOCTL_CLEAN_SEGMENTS caller, stuck inside printk while emitting\nper-element warnings from nilfs_sufile_updatev():\n\n   __nilfs_msg+0x373/0x450 fs/nilfs2/super.c:78\n   nilfs_sufile_updatev+0x21c/0x6d0 fs/nilfs2/sufile.c:186\n   nilfs_sufile_freev fs/nilfs2/sufile.h:93 [inline]\n   nilfs_free_segments fs/nilfs2/segment.c:1140 [inline]\n   nilfs_segctor_collect_blocks fs/nilfs2/segment.c:1261 [inline]\n   nilfs_segctor_do_construct+0x1f55/0x76c0\n   nilfs_clean_segments+0x3bd/0xa50\n   nilfs_ioctl_clean_segments fs/nilfs2/ioctl.c:922 [inline]\n   nilfs_ioctl+0x261f/0x2780\n\nThe root cause is that user-supplied segment numbers are not validated\nbefore nilfs_clean_segments() begins doing work; the range check on\neach segnum is performed deep inside the call chain by\nnilfs_sufile_updatev(), which emits a nilfs_warn() per invalid entry\nwhile still holding the segctor lock and the sufile mi_sem.  Under load\n(repeated invocations across multiple mounts saturating the global\nprintk path), the cumulative printk latency keeps ns_segctor_sem held\nlong enough to trip the hung_task watchdog, blocking concurrent\noperations such as chmod() that need ns_segctor_sem for read.\n\nFix by validating the contents of kbufs[4] in nilfs_clean_segments()\nimmediately after acquiring ns_segctor_sem via nilfs_transaction_lock().\nHolding ns_segctor_sem serializes the check against\nnilfs_ioctl_resize(), which can modify ns_nsegments, so the validation\nuses a consistent value.  Out-of-range segment numbers are rejected\nwith -EINVAL before any segment-cleaning work begins, so the bad\nentries never reach the per-element diagnostic path inside\nnilfs_sufile_updatev()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/nilfs2/segment.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"071cb4b81987a28c7ac2702003cff3e61684a630","lessThan":"3ed388ec3b8922383d1e2d4432d7bd4cbbf8364e","versionType":"git","status":"affected"},{"version":"071cb4b81987a28c7ac2702003cff3e61684a630","lessThan":"876c98e0fc65f071680c03c2e2ee3ef7ff9ca078","versionType":"git","status":"affected"},{"version":"071cb4b81987a28c7ac2702003cff3e61684a630","lessThan":"39607452b1400c7bf748f15122df4d058b768c5b","versionType":"git","status":"affected"},{"version":"071cb4b81987a28c7ac2702003cff3e61684a630","lessThan":"286f77d002a337735c0846d7480a82d9cda2aa31","versionType":"git","status":"affected"},{"version":"071cb4b81987a28c7ac2702003cff3e61684a630","lessThan":"0789f0a6710713254a08f3a7d2ecbb6d1cbcf0aa","versionType":"git","status":"affected"},{"version":"071cb4b81987a28c7ac2702003cff3e61684a630","lessThan":"223463c488b0554212a94de971ea538eb2805fc7","versionType":"git","status":"affected"},{"version":"071cb4b81987a28c7ac2702003cff3e61684a630","lessThan":"d26aef771b4f6923da9f89d6d5b70d8def5853de","versionType":"git","status":"affected"},{"version":"071cb4b81987a28c7ac2702003cff3e61684a630","lessThan":"0e7a690fe435f8d5ea3feb7c1d8d73ba7e8b8aa9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/nilfs2/segment.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.31","status":"affected"},{"version":"0","lessThan":"2.6.31","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0789f0a6710713254a08f3a7d2ecbb6d1cbcf0aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0e7a690fe435f8d5ea3feb7c1d8d73ba7e8b8aa9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/223463c488b0554212a94de971ea538eb2805fc7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/286f77d002a337735c0846d7480a82d9cda2aa31","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/39607452b1400c7bf748f15122df4d058b768c5b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3ed388ec3b8922383d1e2d4432d7bd4cbbf8364e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/876c98e0fc65f071680c03c2e2ee3ef7ff9ca078","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d26aef771b4f6923da9f89d6d5b70d8def5853de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64360","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:18.530","lastModified":"2026-07-25T10:17:18.530","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhfs/hfsplus: zero-initialize buffer in hfs_bnode_read\n\nhfs_bnode_read() can return early without writing to the output buffer\nwhen is_bnode_offset_valid() fails or when check_and_correct_requested_\nlength() corrects the length to zero.  Callers such as hfs_bnode_read_\nu16() and hfs_bnode_read_u8() pass stack-allocated buffers and use the\nresult unconditionally, leading to KMSAN uninit-value reports.\n\nRather than initializing at each individual call site, zero the buffer\nat the start of hfs_bnode_read() before any validation checks.  This\nensures all callers in both hfs and hfsplus get a deterministic zero\nvalue regardless of which early-return path is taken."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/hfs/bnode.c","fs/hfsplus/bnode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"67ecc81f6492275c9c54280532f558483c99c90e","lessThan":"34684a04777358b2b40ac729e54c8e45359e46b3","versionType":"git","status":"affected"},{"version":"a1a60e79502279f996e55052f50cc14919020475","lessThan":"0b189b2204f1a2612dc68f8d139fb5b80539e710","versionType":"git","status":"affected"},{"version":"fe2891a9c43ab87d1a210d61e6438ca6936e2f62","lessThan":"8f72fd25a57a457866350359ddd27a43caa62c95","versionType":"git","status":"affected"},{"version":"384a66b89f9540a9a8cb0f48807697dfabaece4c","lessThan":"16ca053c2be5f4f3044dccf7fc19237dc820d394","versionType":"git","status":"affected"},{"version":"efc095b35b23297e419c2ab4fc1ed1a8f0781a29","lessThan":"d2afc7ecee476f9251dd87444f7fb6a424410922","versionType":"git","status":"affected"},{"version":"a431930c9bac518bf99d6b1da526a7f37ddee8d8","lessThan":"f3461b84a4865d9b5e70fbb71da72ae044a3bcd2","versionType":"git","status":"affected"},{"version":"a431930c9bac518bf99d6b1da526a7f37ddee8d8","lessThan":"d5b45bad75cd2730b8452aed4d3b20a2b2a12576","versionType":"git","status":"affected"},{"version":"a431930c9bac518bf99d6b1da526a7f37ddee8d8","lessThan":"d67aadee19ffdf3cc8520c5a4f4d5b2916d30baf","versionType":"git","status":"affected"},{"version":"e7d2dc2421e821e4045775e6dc226378328de6f6","versionType":"git","status":"affected"},{"version":"fc7f732984ec91f30be3e574e0644066d07f2b78","versionType":"git","status":"affected"},{"version":"eec522fd0d28106b14a59ab2d658605febe4a3bb","versionType":"git","status":"affected"},{"version":"5.10.241","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.15.190","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.149","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.103","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.43","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"5.4.297","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"6.15.11","lessThan":"6.16","versionType":"semver","status":"affected"},{"version":"6.16.2","lessThan":"6.17","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/hfs/bnode.c","fs/hfsplus/bnode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0b189b2204f1a2612dc68f8d139fb5b80539e710","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/16ca053c2be5f4f3044dccf7fc19237dc820d394","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/34684a04777358b2b40ac729e54c8e45359e46b3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f72fd25a57a457866350359ddd27a43caa62c95","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2afc7ecee476f9251dd87444f7fb6a424410922","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d5b45bad75cd2730b8452aed4d3b20a2b2a12576","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d67aadee19ffdf3cc8520c5a4f4d5b2916d30baf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f3461b84a4865d9b5e70fbb71da72ae044a3bcd2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64361","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:18.677","lastModified":"2026-07-25T10:17:18.677","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhfs/hfsplus: fix u32 overflow in check_and_correct_requested_length\n\ncheck_and_correct_requested_length() compares (off + len) against\nnode_size using u32 arithmetic.  When the caller passes a large len\nvalue (e.g. from an underflowed subtraction in hfs_brec_remove()),\noff + len can wrap past 2^32 and produce a small result, causing the\nbounds check to pass when it should fail.\n\nFor example, with off=14 and len=0xFFFFFFF2 (underflowed from\ndata_off - keyoffset - size in hfs_brec_remove), off + len wraps to 6,\nwhich is less than a typical node_size of 512, so the check passes and\nthe subsequent memmove reads ~4GB past the node buffer.\n\nFix this by widening the addition to u64 before comparing against\nnode_size.  This prevents the u32 wrap while keeping the logic\nstraightforward."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/hfs/bnode.c","fs/hfsplus/hfsplus_fs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"67ecc81f6492275c9c54280532f558483c99c90e","lessThan":"c8dd112173c02adf539fe2ad34a45f5e0068780d","versionType":"git","status":"affected"},{"version":"a1a60e79502279f996e55052f50cc14919020475","lessThan":"fc9d1447ca3cdc78d2e4ace1ce1f3a7c77ca08b1","versionType":"git","status":"affected"},{"version":"fe2891a9c43ab87d1a210d61e6438ca6936e2f62","lessThan":"671c3fcc2ad31c1311ea6414382a2d95104ae1b9","versionType":"git","status":"affected"},{"version":"384a66b89f9540a9a8cb0f48807697dfabaece4c","lessThan":"b6a481642ea1977be2f84dc08c5affd742c177e7","versionType":"git","status":"affected"},{"version":"efc095b35b23297e419c2ab4fc1ed1a8f0781a29","lessThan":"7399c3baee7bb622a92f0b895cd4d3009a693f2b","versionType":"git","status":"affected"},{"version":"a431930c9bac518bf99d6b1da526a7f37ddee8d8","lessThan":"607217f7ad419b53926f71e3f75001813bbc08ad","versionType":"git","status":"affected"},{"version":"a431930c9bac518bf99d6b1da526a7f37ddee8d8","lessThan":"c25d3c931a63e762fcaa9cb125b901c53b62403f","versionType":"git","status":"affected"},{"version":"a431930c9bac518bf99d6b1da526a7f37ddee8d8","lessThan":"966cb76fb2857a4242cab6ea2ea17acf818a3da7","versionType":"git","status":"affected"},{"version":"e7d2dc2421e821e4045775e6dc226378328de6f6","versionType":"git","status":"affected"},{"version":"fc7f732984ec91f30be3e574e0644066d07f2b78","versionType":"git","status":"affected"},{"version":"eec522fd0d28106b14a59ab2d658605febe4a3bb","versionType":"git","status":"affected"},{"version":"5.10.241","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.15.190","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.149","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.103","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.43","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"5.4.297","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"6.15.11","lessThan":"6.16","versionType":"semver","status":"affected"},{"version":"6.16.2","lessThan":"6.17","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/hfs/bnode.c","fs/hfsplus/hfsplus_fs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/607217f7ad419b53926f71e3f75001813bbc08ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/671c3fcc2ad31c1311ea6414382a2d95104ae1b9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7399c3baee7bb622a92f0b895cd4d3009a693f2b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/966cb76fb2857a4242cab6ea2ea17acf818a3da7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6a481642ea1977be2f84dc08c5affd742c177e7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c25d3c931a63e762fcaa9cb125b901c53b62403f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c8dd112173c02adf539fe2ad34a45f5e0068780d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc9d1447ca3cdc78d2e4ace1ce1f3a7c77ca08b1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64362","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:18.820","lastModified":"2026-07-25T10:17:18.820","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: lg-g15: cancel pending work on remove to fix a use-after-free\n\nlg_g15_data is allocated with devm and holds a work item. The report\nhandlers schedule that work straight from device input.\nlg_g15_event() and lg_g15_v2_event() do it on the backlight cycle key,\nand lg_g510_leds_event() does it too. The worker dereferences the\nlg_g15_data back through container_of.\n\nThe driver had no remove callback and never cancelled the work. So if a\nreport scheduled the work and the keyboard was then unplugged, devres\nfreed lg_g15_data while the work was still pending or running, and the\nworker touched freed memory. This is a use-after-free. It is reachable\nas a race on device unplug.\n\nAdd a remove callback that cancels the work before devres frees the\nstate. g15->work is only initialized for the models that schedule it\n(G15, G15 v2, G510). The G13 and Z-10 leave it zeroed, so guard the\ncancel on g15->work.func to avoid cancelling a work that was never set\nup. The g15 NULL test mirrors the one already in lg_g15_raw_event()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/hid-lg-g15.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"97b741aba918c4143f4208d2421d08ff215c1b49","lessThan":"3b9a3919aac6977262f04d5365c0456877522a44","versionType":"git","status":"affected"},{"version":"97b741aba918c4143f4208d2421d08ff215c1b49","lessThan":"4aef9676c26dff8723b56834951cfc6b618f0986","versionType":"git","status":"affected"},{"version":"97b741aba918c4143f4208d2421d08ff215c1b49","lessThan":"acce9dee807f21184fff19ad17c8ed464247e7f7","versionType":"git","status":"affected"},{"version":"97b741aba918c4143f4208d2421d08ff215c1b49","lessThan":"33cd1a000daf929356aacf2b191d31714ff0615e","versionType":"git","status":"affected"},{"version":"97b741aba918c4143f4208d2421d08ff215c1b49","lessThan":"dfc6e61f83113cc18346b6988f07271c0063357d","versionType":"git","status":"affected"},{"version":"97b741aba918c4143f4208d2421d08ff215c1b49","lessThan":"4d0d51bc12d246accbfbb94de05d729c68c9b8fb","versionType":"git","status":"affected"},{"version":"97b741aba918c4143f4208d2421d08ff215c1b49","lessThan":"8131f4226688c4be5f30874d167e44dab838eb09","versionType":"git","status":"affected"},{"version":"97b741aba918c4143f4208d2421d08ff215c1b49","lessThan":"7705b4140d188ce22656f6e541ae7ef834c7e11a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/hid-lg-g15.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.5","status":"affected"},{"version":"0","lessThan":"5.5","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/33cd1a000daf929356aacf2b191d31714ff0615e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3b9a3919aac6977262f04d5365c0456877522a44","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4aef9676c26dff8723b56834951cfc6b618f0986","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4d0d51bc12d246accbfbb94de05d729c68c9b8fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7705b4140d188ce22656f6e541ae7ef834c7e11a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8131f4226688c4be5f30874d167e44dab838eb09","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/acce9dee807f21184fff19ad17c8ed464247e7f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dfc6e61f83113cc18346b6988f07271c0063357d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64363","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:18.960","lastModified":"2026-07-25T10:17:18.960","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: appleir: fix UAF on pending key_up_timer in remove()\n\nappleir_remove() runs hid_hw_stop() before timer_delete_sync().\nhid_hw_stop() synchronously unregisters the HID input device via\nhid_disconnect() -> hidinput_disconnect() -> input_unregister_device(),\nwhich drops the last reference and frees the underlying input_dev when\nno userspace handle holds it open.\n\nkey_up_tick() reads appleir->input_dev and calls input_report_key() /\ninput_sync() on it.  The timer is armed from appleir_raw_event() with\na HZ/8 (~125 ms) timeout on every keydown and key-repeat report.  If a\nkey was pressed shortly before the device is disconnected, the timer\ncan fire after hid_hw_stop() has freed input_dev but before the\nteardown drains it.\n\nA simple reorder is not sufficient.  Putting the timer drain first\nstill leaves a window where a USB URB completion (raw_event) running\nduring hid_hw_stop() can call mod_timer() and re-arm the timer, which\nthen fires after hidinput_disconnect() has freed input_dev.  The same\nURB-completion window also lets raw_event() reach key_up(), key_down()\nand battery_flat() directly, all of which dereference\nappleir->input_dev.\n\nIntroduce a 'removing' flag on struct appleir, gated by the existing\nspinlock.  appleir_remove() sets the flag under the lock and then\nshuts down the timer with timer_shutdown_sync(), which both drains any\nin-flight callback and permanently disables further mod_timer() calls.\nappleir_raw_event() and key_up_tick() bail out early if the flag is\nset, so no path can arm or run the timer, or dereference\nappleir->input_dev, after remove() has started tearing down.\n\nThe keyrepeat and flatbattery branches of appleir_raw_event()\npreviously called into the input layer without holding the spinlock;\ntake it now so the flag check is well-defined.  This incidentally\ncloses a pre-existing read-side race on appleir->current_key in the\nkeyrepeat branch.\n\nThis bug is structurally a sibling of commit 4db2af929279 (\"HID:\nappletb-kbd: fix UAF in inactivity-timer cleanup path\") and has been\npresent since the driver was introduced."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/hid-appleir.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9a4a5574ce427c364d81746fc7fb82d86b5f1a7e","lessThan":"89ef67359672bf4cd6921524e39f61648fe38c0f","versionType":"git","status":"affected"},{"version":"9a4a5574ce427c364d81746fc7fb82d86b5f1a7e","lessThan":"3d30a0bb0e79621ae921b487835c56198adfafa3","versionType":"git","status":"affected"},{"version":"9a4a5574ce427c364d81746fc7fb82d86b5f1a7e","lessThan":"37a52c61d4f78153c38ae1f7491dfcc8ac828dcf","versionType":"git","status":"affected"},{"version":"9a4a5574ce427c364d81746fc7fb82d86b5f1a7e","lessThan":"05e3decc55d1deca9410e0eb36466651fcbe57a5","versionType":"git","status":"affected"},{"version":"9a4a5574ce427c364d81746fc7fb82d86b5f1a7e","lessThan":"3755f6e25776b8b12ddf062f9b573f05090e4034","versionType":"git","status":"affected"},{"version":"9a4a5574ce427c364d81746fc7fb82d86b5f1a7e","lessThan":"b363d964ca829c1761c9f04188dfa28f90b0f2d4","versionType":"git","status":"affected"},{"version":"9a4a5574ce427c364d81746fc7fb82d86b5f1a7e","lessThan":"6b0838e86da88b1d3bff86f19761ff25af73eaca","versionType":"git","status":"affected"},{"version":"9a4a5574ce427c364d81746fc7fb82d86b5f1a7e","lessThan":"75fe87e19d8aff81eb2c64d15d244ab8da4de945","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/hid-appleir.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.10","status":"affected"},{"version":"0","lessThan":"3.10","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/05e3decc55d1deca9410e0eb36466651fcbe57a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3755f6e25776b8b12ddf062f9b573f05090e4034","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/37a52c61d4f78153c38ae1f7491dfcc8ac828dcf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3d30a0bb0e79621ae921b487835c56198adfafa3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b0838e86da88b1d3bff86f19761ff25af73eaca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/75fe87e19d8aff81eb2c64d15d244ab8da4de945","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/89ef67359672bf4cd6921524e39f61648fe38c0f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b363d964ca829c1761c9f04188dfa28f90b0f2d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64364","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:19.110","lastModified":"2026-07-25T10:17:19.110","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: multitouch: fix out-of-bounds bit access on mt_io_flags\n\nmt_io_flags is a single unsigned long, but mt_process_slot(),\nmt_release_pending_palms() and mt_release_contacts() use it as a\nper-slot bitmap indexed by the slot number. That slot number is only\nbounded by td->maxcontacts, which is taken from the device's\nContactCountMaximum feature report and can be up to 255, not by\nBITS_PER_LONG.\n\nAs a result, a multitouch device that advertises a large contact count\nmakes set_bit()/clear_bit() operate past the mt_io_flags word and\ncorrupt the adjacent members of struct mt_device. The sticky-fingers\nrelease timer is the easiest way to reach this. mt_release_contacts()\nruns\n\n\tfor (i = 0; i < mt->num_slots; i++)\n\t\tclear_bit(i, &td->mt_io_flags);\n\nwith num_slots == maxcontacts. For maxcontacts around 250 the loop\nclears the bits that overlap td->applications.next, zeroing that list\nhead, and the list_for_each_entry() that immediately follows then\ndereferences NULL. The kernel panics from timer (softirq) context. On a\nKASAN build this shows up as a general protection fault in\nmt_release_contacts() with a null-ptr-deref at offset 0x58, which is\noffsetof(struct mt_application, num_received).\n\nThe state is reachable from an untrusted USB or Bluetooth HID\nmultitouch device; no local privileges are required.\n\nStore the per-slot active state in a separately allocated bitmap sized\nfor maxcontacts, the same pattern already used for pending_palm_slots,\nand keep only MT_IO_FLAGS_RUNNING in mt_io_flags. The two\n\"mt_io_flags & MT_IO_SLOTS_MASK\" arming checks become\nbitmap_empty(td->active_slots, td->maxcontacts).\n\nMove MT_IO_FLAGS_RUNNING back to bit 0. It was bumped to bit 32 by the\nsame commit to leave the low byte for the slot bits; with the slot bits\ngone it fits in bit 0 again, which also keeps it within the unsigned\nlong on 32-bit."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/hid-multitouch.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fc488f675344931ffab6a51c43691065ec006567","lessThan":"12e90656e330ff8bbaf2f29c535fdb8a11cc6f55","versionType":"git","status":"affected"},{"version":"77711d850bed75ae7142c3d1f22c1a8b4d049c33","lessThan":"152983d87387f6a8ae72b73474cfa55fbcf1ec75","versionType":"git","status":"affected"},{"version":"6acfe25968913788d30ec0eedd80178c4ea3f1d0","lessThan":"b5c037d6b807017e74a115288f81bc9cd5a5aab8","versionType":"git","status":"affected"},{"version":"d280c138e66be87d1fccfed42593f02fdb893905","lessThan":"a6d5ce2e1a2d7bf189bde8a659d04b65f0b0725d","versionType":"git","status":"affected"},{"version":"f32fea4c0234c971c12e46d76612cdc2dd4bb046","lessThan":"e24918ee67c4dc3d20d4670750e46e9b160365f4","versionType":"git","status":"affected"},{"version":"46f781e0d151844589dc2125c8cce3300546f92a","lessThan":"37daa8c96bd563d03150e23f094cb60703594a6d","versionType":"git","status":"affected"},{"version":"46f781e0d151844589dc2125c8cce3300546f92a","lessThan":"6493ebf9489efef0105078377b973ab33d51af22","versionType":"git","status":"affected"},{"version":"46f781e0d151844589dc2125c8cce3300546f92a","lessThan":"8813b0612275cc61fe9e6603d0ee019247ade6be","versionType":"git","status":"affected"},{"version":"59bd04163e6451b9c7275277882ed9f4abfa2051","versionType":"git","status":"affected"},{"version":"5.10.246","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.15.196","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.158","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.114","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.55","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.17.5","lessThan":"6.18","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/hid-multitouch.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/12e90656e330ff8bbaf2f29c535fdb8a11cc6f55","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/152983d87387f6a8ae72b73474cfa55fbcf1ec75","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/37daa8c96bd563d03150e23f094cb60703594a6d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6493ebf9489efef0105078377b973ab33d51af22","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8813b0612275cc61fe9e6603d0ee019247ade6be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a6d5ce2e1a2d7bf189bde8a659d04b65f0b0725d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5c037d6b807017e74a115288f81bc9cd5a5aab8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e24918ee67c4dc3d20d4670750e46e9b160365f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64365","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:19.280","lastModified":"2026-07-25T10:17:19.280","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: letsketch: fix UAF on inrange_timer at driver unbind\n\nletsketch_driver does not provide a .remove callback, but\nletsketch_probe() arms a per-device timer:\n\n    timer_setup(&data->inrange_timer, letsketch_inrange_timeout, 0);\n\nThe timer is re-armed from letsketch_raw_event() with a 100 ms\ntimeout on every pen-in-range report, and its callback dereferences\ndata->input_tablet to deliver a synthetic BTN_TOOL_PEN release.\n\nletsketch_data is allocated with devm_kzalloc(), and its input_dev\nfields are devm-allocated via letsketch_setup_input_tablet().  On\ndevice unbind (USB unplug or rmmod), the HID core runs its default\nteardown and devm cleanup frees both letsketch_data and the input\ndevices.  Because no .remove callback exists, nothing drains the\ntimer first: if raw_event armed it within ~100 ms of the unbind,\nthe pending timer fires on freed memory.  This is a UAF read of\ndata and of data->input_tablet, followed by input_report_key() /\ninput_sync() into the freed input_dev.\n\nThe same problem can occur on the probe error path: if\nhid_hw_start() enabled I/O on an always-poll-quirk device and then\nfailed, raw_event may have armed the timer before devm releases\ndata.\n\nFix by adding a .remove callback that calls hid_hw_stop() first.\nhid_hw_stop() synchronously kills the URBs that deliver raw_event(),\nso once it returns no path can re-arm the timer.  timer_shutdown_sync()\nthen drains any in-flight callback and permanently disables further\nmod_timer() calls.  Apply the same timer_shutdown_sync() in the probe\nerror path so the timer is guaranteed not to outlive data."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/hid-letsketch.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"33a5c2793451770cb6dcf0cc35c76cfd4b045513","lessThan":"2bb6e7143cf70ed281822d26c1848b2897ac36e9","versionType":"git","status":"affected"},{"version":"33a5c2793451770cb6dcf0cc35c76cfd4b045513","lessThan":"523db788c0f84612707638e266e8957ca7e3a756","versionType":"git","status":"affected"},{"version":"33a5c2793451770cb6dcf0cc35c76cfd4b045513","lessThan":"17f5928d7010bc9e002930326b59e60e40c09ee3","versionType":"git","status":"affected"},{"version":"33a5c2793451770cb6dcf0cc35c76cfd4b045513","lessThan":"3eca1a8165b5e7996e699e9df76cb4645e184d42","versionType":"git","status":"affected"},{"version":"33a5c2793451770cb6dcf0cc35c76cfd4b045513","lessThan":"df3d8aa1a9392da3de66398e7a03422463806b21","versionType":"git","status":"affected"},{"version":"33a5c2793451770cb6dcf0cc35c76cfd4b045513","lessThan":"46c8beeccd8ab2c863827254a85ea877654a3534","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/hid-letsketch.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/17f5928d7010bc9e002930326b59e60e40c09ee3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2bb6e7143cf70ed281822d26c1848b2897ac36e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3eca1a8165b5e7996e699e9df76cb4645e184d42","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/46c8beeccd8ab2c863827254a85ea877654a3534","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/523db788c0f84612707638e266e8957ca7e3a756","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/df3d8aa1a9392da3de66398e7a03422463806b21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64366","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:19.403","lastModified":"2026-07-25T10:17:19.403","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert\n\nwacom_wac_queue_insert() calls kfifo_skip() in a loop when the kfifo\ndoesn't have enough space for the incoming report. If the kfifo is\nempty, kfifo_skip() reads stale data left in the kmalloc'd buffer\nvia __kfifo_peek_n() and interprets it as a record length, advancing\nfifo->out by that garbage value. This corrupts the internal kfifo\nstate, causing kfifo_unused() to return a value much larger than the\nactual buffer size, which bypasses __kfifo_in_r()'s guard:\n\n  if (len + recsize > kfifo_unused(fifo))\n      return 0;\n\nkfifo_copy_in() then performs an out-of-bounds memcpy, writing up to\n3842 bytes past the 256-byte buffer.\n\nAdd a !kfifo_is_empty() condition to the while loop so kfifo_skip()\nis never called on an empty fifo, and check the return value of\nkfifo_in() to reject reports that are too large for the fifo."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/wacom_sys.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5e013ad206895e72d7da41bc1ae89d8cb499c3aa","lessThan":"ca899a926c11a59211b764b0155d9a1cdcc32b81","versionType":"git","status":"affected"},{"version":"5e013ad206895e72d7da41bc1ae89d8cb499c3aa","lessThan":"57bdd10ad50d68341f500a7b330f0d8949e510ec","versionType":"git","status":"affected"},{"version":"5e013ad206895e72d7da41bc1ae89d8cb499c3aa","lessThan":"6b3014ec0e9a390ca563030b2d7689921f0daef5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/wacom_sys.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/57bdd10ad50d68341f500a7b330f0d8949e510ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b3014ec0e9a390ca563030b2d7689921f0daef5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca899a926c11a59211b764b0155d9a1cdcc32b81","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64367","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:19.510","lastModified":"2026-07-25T10:17:19.510","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: hid-goodix-spi: validate report size to prevent stack buffer overflow\n\ngoodix_hid_set_raw_report() builds a protocol frame in a 128-byte stack\nbuffer (tmp_buf), writing an 11-12 byte header followed by the\ncaller-supplied report data.  The HID core caps report size at\nHID_MAX_BUFFER_SIZE (16384) by default, while the driver does not set\nhid_ll_driver.max_buffer_size and performs no bounds checking before\ncopying the payload:\n\n    memcpy(tmp_buf + tx_len, buf, len);\n\nA hidraw SET_REPORT ioctl with a report larger than ~116 bytes\noverflows the stack buffer.\n\nAdd a size check after constructing the header, rejecting reports that\nwould exceed the buffer capacity.\n\nDiscovered by Atuin - Automated Vulnerability Discovery Engine."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/hid-goodix-spi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"75e16c8ce283bb88e77704dc8fa041c577caac0f","lessThan":"ad47ad624f2fce0bc44bbadb664242461a97d774","versionType":"git","status":"affected"},{"version":"75e16c8ce283bb88e77704dc8fa041c577caac0f","lessThan":"dae1d000ddfd5c2140b036e47fff0c497ae9c64b","versionType":"git","status":"affected"},{"version":"75e16c8ce283bb88e77704dc8fa041c577caac0f","lessThan":"835fcc8655569737e3f057d42875a96259db74c2","versionType":"git","status":"affected"},{"version":"75e16c8ce283bb88e77704dc8fa041c577caac0f","lessThan":"db0a0768d09273aadadeb76730cd658d720333a4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/hid-goodix-spi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/835fcc8655569737e3f057d42875a96259db74c2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ad47ad624f2fce0bc44bbadb664242461a97d774","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dae1d000ddfd5c2140b036e47fff0c497ae9c64b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/db0a0768d09273aadadeb76730cd658d720333a4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64368","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:19.613","lastModified":"2026-07-25T10:17:19.613","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/slab: do not limit zeroing to orig_size when only red zoning is enabled\n\nWhen init (zeroing) on allocation is requested, for kmalloc() we\ngenerally have to zero the full object size even if a smaller size is\nrequested, in order to provide krealloc()'s __GFP_ZERO guarantees.\n\nBut if we track the requested size, krealloc() uses that information to\ndo the right thing, so we can zero only the requested size. With red\nzoning also enabled, any extra size became part of the red zone, so it\nmust not be zeroed and thus we must zero only the requested size.\n\nHowever the current check is imprecise, and will trigger also when only\nSLAB_RED_ZONE is enabled without SLAB_STORE_USER (which enables tracking\nthe requested size). This means enabling red zoning alone can compromise\nkrealloc()'s __GFP_ZERO contract.\n\nFix this by using slub_debug_orig_size() instead, which is the exact\ncheck for whether the requested size is tracked. We don't need to care\nif red zoning is also enabled or not. Also update and expand the\ncomment accordingly."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/slub.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9ce67395f5a0cdec6ce152d26bfda13b98b25c01","lessThan":"6256899c3a34674bba6076884aedbba49fc695e4","versionType":"git","status":"affected"},{"version":"9ce67395f5a0cdec6ce152d26bfda13b98b25c01","lessThan":"7e706d50fa119eead6376bf0ef973e8d73a96030","versionType":"git","status":"affected"},{"version":"9ce67395f5a0cdec6ce152d26bfda13b98b25c01","lessThan":"2382971aaaef5bf85a651234c64906f59580b8be","versionType":"git","status":"affected"},{"version":"9ce67395f5a0cdec6ce152d26bfda13b98b25c01","lessThan":"0d18ccef142f04433dfb2a0c120cf223d2b8a42c","versionType":"git","status":"affected"},{"version":"9ce67395f5a0cdec6ce152d26bfda13b98b25c01","lessThan":"648927ceb84021a25a0fbd5673740956f318d534","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/slub.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.2","status":"affected"},{"version":"0","lessThan":"6.2","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0d18ccef142f04433dfb2a0c120cf223d2b8a42c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2382971aaaef5bf85a651234c64906f59580b8be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6256899c3a34674bba6076884aedbba49fc695e4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/648927ceb84021a25a0fbd5673740956f318d534","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7e706d50fa119eead6376bf0ef973e8d73a96030","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64369","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:19.743","lastModified":"2026-07-25T10:17:19.743","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390: Revert support for DCACHE_WORD_ACCESS\n\nload_unaligned_zeropad() reads eight bytes from unaligned addresses and may\ncross page boundaries. It handles exceptions which may happen if reading\nfrom the second page results in an exception.\n\nFor pages which are donated to the Ultravisor for secure execution purposes\nthe do_secure_storage_access() exception handler however does not handle\nsuch exceptions correctly. Such an exception may result in an endless\nexception loop which will never be resolved.\n\nAn attempt to fix this [1] turned out to be not sufficient. For now revert\nload_unaligned_zeropad() until this problem has been resolved in a proper\nway.\n\nNote that the implementation of load_unaligned_zeropad() itself is\ncorrect. The revert is just a temporary workaround until there is complete\nfix for secure storage access exceptions.\n\n[1] commit b00be77302d7 (\"s390/mm: Add missing secure storage access fixups for donated memory\")"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/s390/Kconfig","arch/s390/include/asm/asm-extable.h","arch/s390/include/asm/word-at-a-time.h","arch/s390/mm/extable.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"802ba53eefc592a6a82231f74e19bafe3256f172","lessThan":"c9e0f1517631ac08987f8385817119bccf2f1f12","versionType":"git","status":"affected"},{"version":"802ba53eefc592a6a82231f74e19bafe3256f172","lessThan":"be79d285bea70d0edd5015bd487311bfa8cbebc9","versionType":"git","status":"affected"},{"version":"802ba53eefc592a6a82231f74e19bafe3256f172","lessThan":"c94806905e02cc8e17a69c822d93c41743b7ffc5","versionType":"git","status":"affected"},{"version":"802ba53eefc592a6a82231f74e19bafe3256f172","lessThan":"37540b8c287fc817bdbd0c62bb75ad6eab0e5d03","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/s390/Kconfig","arch/s390/include/asm/asm-extable.h","arch/s390/include/asm/word-at-a-time.h","arch/s390/mm/extable.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/37540b8c287fc817bdbd0c62bb75ad6eab0e5d03","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be79d285bea70d0edd5015bd487311bfa8cbebc9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c94806905e02cc8e17a69c822d93c41743b7ffc5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9e0f1517631ac08987f8385817119bccf2f1f12","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64370","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:19.880","lastModified":"2026-07-25T10:17:19.880","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nposix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path\n\nIn do_cpu_nanosleep(), posix_cpu_timer_create() takes a pid reference\nvia get_pid() and stores it in timer.it.cpu.pid. If the subsequent\nposix_cpu_timer_set() call fails, the function returns immediately\nwithout calling posix_cpu_timer_del() to release the pid reference,\ncausing a leak.\n\nFix it by calling posix_cpu_timer_del() before the unlock-and-return\non the error path, consistent with the other exit paths in the same\nfunction."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/time/posix-cpu-timers.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"afed3cdc1cca133f804fcf57ff228974f424b23a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"8a270b1258797f61b61da44f8bfd41a581b5c85b","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d605d00085adc3fddf67de01dc2a44aebf1a3fb5","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e5ffc638faf5dc7d9dc85c9a95e10bf97442e0c0","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"eb4cec29a78334d09bcfb41c0660cdd62ba05843","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7776f9226e99eb49d97492b0b445027cfcb189da","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"8f06363446c5d043c9a7c008b250040e9de98cf9","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"87bd2ad568e15b90d5f7d4bcd70342d05dad649c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/time/posix-cpu-timers.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/7776f9226e99eb49d97492b0b445027cfcb189da","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/87bd2ad568e15b90d5f7d4bcd70342d05dad649c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8a270b1258797f61b61da44f8bfd41a581b5c85b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f06363446c5d043c9a7c008b250040e9de98cf9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/afed3cdc1cca133f804fcf57ff228974f424b23a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d605d00085adc3fddf67de01dc2a44aebf1a3fb5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5ffc638faf5dc7d9dc85c9a95e10bf97442e0c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eb4cec29a78334d09bcfb41c0660cdd62ba05843","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64371","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:20.010","lastModified":"2026-07-25T10:17:20.010","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nproc: protect ptrace_may_access() with exec_update_lock (part 1)\n\nFix the easy cases where procfs currently calls ptrace_may_access() without\nexec_update_lock protection, where the fix is to simply add the extra lock\nor use mm_access():\n\n - do_task_stat(): grab exec_update_lock\n - proc_pid_wchan(): grab exec_update_lock\n - proc_map_files_lookup(): use mm_access() instead of get_task_mm()\n - proc_map_files_readdir(): use mm_access() instead of get_task_mm()\n - proc_ns_get_link(): grab exec_update_lock\n - proc_ns_readlink(): grab exec_update_lock"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/proc/array.c","fs/proc/base.c","fs/proc/namespaces.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f83ce3e6b02d5e48b3a43b001390e2b58820389d","lessThan":"ae1e630bcaac739f625822078edbaea98366930d","versionType":"git","status":"affected"},{"version":"f83ce3e6b02d5e48b3a43b001390e2b58820389d","lessThan":"d54f14655fd7d7b293698a8b6918563c4c0465e7","versionType":"git","status":"affected"},{"version":"f83ce3e6b02d5e48b3a43b001390e2b58820389d","lessThan":"bb43679356f1f2a4c6b1c88aec4f021e5b5c74e9","versionType":"git","status":"affected"},{"version":"f83ce3e6b02d5e48b3a43b001390e2b58820389d","lessThan":"7456ae990a9738962b33146916fabca62ae3d4e0","versionType":"git","status":"affected"},{"version":"f83ce3e6b02d5e48b3a43b001390e2b58820389d","lessThan":"4bfe8c481846cee52473a2f7d7b30ee8e6749fc4","versionType":"git","status":"affected"},{"version":"f83ce3e6b02d5e48b3a43b001390e2b58820389d","lessThan":"f9b4b03ccc9c69bf7f7298d4559906ebea7143b3","versionType":"git","status":"affected"},{"version":"f83ce3e6b02d5e48b3a43b001390e2b58820389d","lessThan":"c1cfd63326f5d09999134e9052c353faf738286e","versionType":"git","status":"affected"},{"version":"f83ce3e6b02d5e48b3a43b001390e2b58820389d","lessThan":"6650527444dadc63d84aa939d14ecba4fadb2f69","versionType":"git","status":"affected"},{"version":"6b06d6282100dd5aacf7d45443d651a1995bd9c4","versionType":"git","status":"affected"},{"version":"334ed22054b2ec8477e4409e214fc139cf937ef6","versionType":"git","status":"affected"},{"version":"2.6.27.23","lessThan":"2.6.28","versionType":"semver","status":"affected"},{"version":"2.6.29.3","lessThan":"2.6.30","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/proc/array.c","fs/proc/base.c","fs/proc/namespaces.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.30","status":"affected"},{"version":"0","lessThan":"2.6.30","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4bfe8c481846cee52473a2f7d7b30ee8e6749fc4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6650527444dadc63d84aa939d14ecba4fadb2f69","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7456ae990a9738962b33146916fabca62ae3d4e0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae1e630bcaac739f625822078edbaea98366930d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb43679356f1f2a4c6b1c88aec4f021e5b5c74e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c1cfd63326f5d09999134e9052c353faf738286e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d54f14655fd7d7b293698a8b6918563c4c0465e7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f9b4b03ccc9c69bf7f7298d4559906ebea7143b3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64372","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:20.147","lastModified":"2026-07-25T10:17:20.147","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: pcc: fix use-after-free and double free in _OSC evaluation\n\npcc_cpufreq_do_osc() calls acpi_evaluate_object() twice for the\ntwo-phase _OSC negotiation. Between the two calls it freed\noutput.pointer but left output.length unchanged. Since\nacpi_evaluate_object() treats a non-zero length with a non-NULL\npointer as an existing buffer to write into, the second call wrote\ninto freed memory (use-after-free). The subsequent kfree(output.pointer)\nat out_free then freed the same pointer a second time (double free).\n\nReset output.pointer to NULL and output.length to ACPI_ALLOCATE_BUFFER\nafter freeing the first result, so ACPICA allocates a fresh buffer for\neach phase independently."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/cpufreq/pcc-cpufreq.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0f1d683fb35d6c6f49ef696c95757f3970682a0e","lessThan":"8e454e9d0bc03446d610ee49abec9dfd424f6541","versionType":"git","status":"affected"},{"version":"0f1d683fb35d6c6f49ef696c95757f3970682a0e","lessThan":"632666a63116d8061c62a988d1ca39dcd6d27c9b","versionType":"git","status":"affected"},{"version":"0f1d683fb35d6c6f49ef696c95757f3970682a0e","lessThan":"5cdb25f144b101083d8bf3fd023ad87fbe6850d7","versionType":"git","status":"affected"},{"version":"0f1d683fb35d6c6f49ef696c95757f3970682a0e","lessThan":"982c9f92d57bda2b769851ff6d90d43dcf5f3734","versionType":"git","status":"affected"},{"version":"0f1d683fb35d6c6f49ef696c95757f3970682a0e","lessThan":"a36ca93a8ba57464e521d70a337d37f069064111","versionType":"git","status":"affected"},{"version":"0f1d683fb35d6c6f49ef696c95757f3970682a0e","lessThan":"6ba6f6783be2ffeb2cbcdc9321c4b9f708f796f7","versionType":"git","status":"affected"},{"version":"0f1d683fb35d6c6f49ef696c95757f3970682a0e","lessThan":"0e3c739a2f6fc1de5b19a8839ab80696b9cb2a29","versionType":"git","status":"affected"},{"version":"0f1d683fb35d6c6f49ef696c95757f3970682a0e","lessThan":"266d3dd8b757b48a576e90f018b51f7b7563cc32","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/cpufreq/pcc-cpufreq.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.34","status":"affected"},{"version":"0","lessThan":"2.6.34","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0e3c739a2f6fc1de5b19a8839ab80696b9cb2a29","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/266d3dd8b757b48a576e90f018b51f7b7563cc32","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5cdb25f144b101083d8bf3fd023ad87fbe6850d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/632666a63116d8061c62a988d1ca39dcd6d27c9b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6ba6f6783be2ffeb2cbcdc9321c4b9f708f796f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8e454e9d0bc03446d610ee49abec9dfd424f6541","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/982c9f92d57bda2b769851ff6d90d43dcf5f3734","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a36ca93a8ba57464e521d70a337d37f069064111","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64373","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:20.283","lastModified":"2026-07-25T10:17:20.283","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: Fix hotplug-suspend race during reboot\n\nDuring system reboot, cpufreq_suspend() is called via the\nkernel_restart() -> device_shutdown() path. Unlike the normal system\nsuspend path, the reboot path does not call freeze_processes(), so\nuserspace processes and kernel threads remain active.\n\nThis allows CPU hotplug operations to run concurrently with\ncpufreq_suspend(). The original code has no synchronization with CPU\nhotplug, leading to a race condition where governor_data can be freed\nby the hotplug path while cpufreq_suspend() is still accessing it,\nresulting in a null pointer dereference:\n\n  Unable to handle kernel NULL pointer dereference\n  Call Trace:\n   do_kernel_fault+0x28/0x3c\n   cpufreq_suspend+0xdc/0x160\n   device_shutdown+0x18/0x200\n   kernel_restart+0x40/0x80\n   arm64_sys_reboot+0x1b0/0x200\n\nFix this by adding cpus_read_lock()/cpus_read_unlock() to\ncpufreq_suspend() to block CPU hotplug operations while suspend is in\nprogress.\n\n[ rjw: Changelog edits ]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/cpufreq/cpufreq.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"65650b35133ff20f0c9ef0abd5c3c66dbce3ae57","lessThan":"6d5dd354c37abaf4d60400c55c71f23ba2b33639","versionType":"git","status":"affected"},{"version":"65650b35133ff20f0c9ef0abd5c3c66dbce3ae57","lessThan":"9103078c7b3091a2fbb52af176f95982ee7dd7f8","versionType":"git","status":"affected"},{"version":"65650b35133ff20f0c9ef0abd5c3c66dbce3ae57","lessThan":"cd4524ff6567fa4458a5bec4b017105e671d393e","versionType":"git","status":"affected"},{"version":"65650b35133ff20f0c9ef0abd5c3c66dbce3ae57","lessThan":"73255d702c7560185fd5951aadcf7eb057c2f453","versionType":"git","status":"affected"},{"version":"65650b35133ff20f0c9ef0abd5c3c66dbce3ae57","lessThan":"a0ef2fc89d28ca62923376c4b8ffaa57136a36be","versionType":"git","status":"affected"},{"version":"65650b35133ff20f0c9ef0abd5c3c66dbce3ae57","lessThan":"6e175c00c62dca3d91b987015808b5d52e8db2b4","versionType":"git","status":"affected"},{"version":"65650b35133ff20f0c9ef0abd5c3c66dbce3ae57","lessThan":"a0106b41f9a724868d390b8b3b4ea5ca0e04ea53","versionType":"git","status":"affected"},{"version":"65650b35133ff20f0c9ef0abd5c3c66dbce3ae57","lessThan":"a9029dd55696c651ee46912afa2a166fa456bb3e","versionType":"git","status":"affected"},{"version":"8bfa06ea6e81bf08d2132d7e70c2b5313b34caf8","versionType":"git","status":"affected"},{"version":"7ccf3b8b7a12dc9da158c2e699c36d04b2496944","versionType":"git","status":"affected"},{"version":"5f466713989250938624afa79dc33bae20920700","versionType":"git","status":"affected"},{"version":"89ab39da1452d272007acc5912d4008047b86706","versionType":"git","status":"affected"},{"version":"cb4b4601f910c78d2b49f637a12ef98b41cb76a9","versionType":"git","status":"affected"},{"version":"4.4.198","lessThan":"4.5","versionType":"semver","status":"affected"},{"version":"4.9.198","lessThan":"4.10","versionType":"semver","status":"affected"},{"version":"4.14.151","lessThan":"4.15","versionType":"semver","status":"affected"},{"version":"4.19.81","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.3.8","lessThan":"5.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/cpufreq/cpufreq.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.4","status":"affected"},{"version":"0","lessThan":"5.4","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6d5dd354c37abaf4d60400c55c71f23ba2b33639","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e175c00c62dca3d91b987015808b5d52e8db2b4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/73255d702c7560185fd5951aadcf7eb057c2f453","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9103078c7b3091a2fbb52af176f95982ee7dd7f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a0106b41f9a724868d390b8b3b4ea5ca0e04ea53","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a0ef2fc89d28ca62923376c4b8ffaa57136a36be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a9029dd55696c651ee46912afa2a166fa456bb3e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd4524ff6567fa4458a5bec4b017105e671d393e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64374","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:20.433","lastModified":"2026-07-25T10:17:20.433","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT\n\nRT migration is done aggressively. When a CPU schedules out a high\npriority RT task for a lower priority task, it will look to see if there's\nany RT tasks that are waiting to run on another CPU that is of higher\npriority than the task this CPU is about to run. If it finds one, it will\npull that task over to the CPU and allow it to run there instead.\n\nNormally, this pulling is done by looking at the RT overloaded mask (rto)\nwhich contains all the CPUs in the scheduler domain with RT tasks that are\nwaiting to run due to a higher priority RT task currently running on their\nCPU. The CPU that is about to schedule a lower priority task will grab the\nrq lock of the overloaded CPU and move the RT task from that CPU's runqueue\nto the local one and schedule the higher priority RT task.\n\nThis caused issues when a lot of CPUs would schedule a lower priority task\nat the same time. They would all try to grab the same runqueue lock of\nthe CPU with the overloaded RT tasks. Only the first CPU that got in will\nget that task. All the others would wait until they got the runqueue lock\nand see there's nothing to pull and do nothing. On systems with lots of\nCPUs, this caused a large latency (up to 500us) which is beyond what\nPREEMPT_RT is to allow.\n\nThe solution to that was to create an RT_PUSH_IPI logic. When any CPU\nwanted to pull a task, instead of grabbing the runqueue lock of the\noverloaded CPU, it would start by sending an IPI to the overloaded CPU,\nand that IPI handler would have the CPU with the waiting RT task do a push\ninstead. Then that handler would send an IPI to the next CPU with\noverloaded RT tasks, and so on. Note, after the first CPU starts this\nprocess, if another CPU wanted to do a pull, it would see that the process\nhas already begun and would only increment a counter to have the IPIs\ncontinue again.\n\nThe RT_PUSH_IPI solved the latency problem with PREEMPT_RT but could cause\na new issue with non PREEMPT_RT. Namely, softirqs run in a threaded\ncontext on PREEMPT_RT but they can run in an interrupt context in non-RT.\n\nIf an IPI lands on a CPU that has just woken up multiple RT tasks and the\ncurrent CPU is running a non RT or a low priority RT task, instead of\ndoing a push, it would simply do a schedule on that CPU. But if a softirq\nwas also executing on this CPU, the schedule would need to wait until the\nsoftirq finished. Until then, the CPU would still be considered overloaded\nas there are RT tasks still waiting to run on it.\n\nA live lock occurred on a workload that was doing heavy networking traffic\non a large machine where the softirqs would run 500us out of 750us. And it\nwould also be waking up RT tasks, causing the RT pull logic to be\nconstantly executed.\n\nWhen a softirq triggered on a CPU with RT tasks queued but not running\nyet, and the other CPUs would see this CPU as being overloaded, they would\nsend an IPI over to it. The CPU would notice that the waiting RT tasks are\nof higher priority than the currently running task and simply schedule\nthat CPU instead. But because the softirq was executing, before it could\nschedule, it would receive another IPI to do the same. The amount of IPIs\nwould slow down the currently running softirq so much that before it could\nreturn back to task context, it would execute another softirq never\nallowing the CPU to schedule. This live locked that CPU.\n\nAs RT_PUSH_IPI was created to help PREEMPT_RT, make it default off if\nPREEMPT_RT is not enabled."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/sched/features.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b6366f048e0caff28af5335b7af2031266e1b06b","lessThan":"b99f04ae3d200d2f8844aa29145bd18eccbeecde","versionType":"git","status":"affected"},{"version":"b6366f048e0caff28af5335b7af2031266e1b06b","lessThan":"d8312a56d9a162e3ec76476aa487e7d20bc602e9","versionType":"git","status":"affected"},{"version":"b6366f048e0caff28af5335b7af2031266e1b06b","lessThan":"44aae426dbfd51286f7eb601cfa14bc32164812a","versionType":"git","status":"affected"},{"version":"b6366f048e0caff28af5335b7af2031266e1b06b","lessThan":"860aaff72c8446fed5e576249e19952883a18885","versionType":"git","status":"affected"},{"version":"b6366f048e0caff28af5335b7af2031266e1b06b","lessThan":"89237c8fc15d8016a194076e648ccb57d75e65ae","versionType":"git","status":"affected"},{"version":"b6366f048e0caff28af5335b7af2031266e1b06b","lessThan":"4bd0da48fbc1dbef6774175129107fbbdd353e26","versionType":"git","status":"affected"},{"version":"b6366f048e0caff28af5335b7af2031266e1b06b","lessThan":"a18f80bf5359238c4f067d691b96af00286fdd89","versionType":"git","status":"affected"},{"version":"b6366f048e0caff28af5335b7af2031266e1b06b","lessThan":"dd29c017aed628076e915fe4cdfb5392fd4c5cab","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/sched/features.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.1","status":"affected"},{"version":"0","lessThan":"4.1","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/44aae426dbfd51286f7eb601cfa14bc32164812a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4bd0da48fbc1dbef6774175129107fbbdd353e26","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/860aaff72c8446fed5e576249e19952883a18885","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/89237c8fc15d8016a194076e648ccb57d75e65ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a18f80bf5359238c4f067d691b96af00286fdd89","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b99f04ae3d200d2f8844aa29145bd18eccbeecde","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8312a56d9a162e3ec76476aa487e7d20bc602e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd29c017aed628076e915fe4cdfb5392fd4c5cab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64375","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:20.593","lastModified":"2026-07-25T10:17:20.593","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nproc: protect ptrace_may_access() with exec_update_lock (FD links)\n\nproc_pid_get_link() and proc_pid_readlink() currently look up the task from\nthe pid once, then do the ptrace access check on that task, then look up\nthe task from the pid a second time to do the actual access.\nThat's racy in several ways.\n\nTo fix it, pass the task to the ->proc_get_link() handler, and instead of\nproc_fd_access_allowed(), introduce a new helper call_proc_get_link() that\nlooks up and locks the task, does the access check, and calls\n->proc_get_link()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/proc/base.c","fs/proc/fd.c","fs/proc/internal.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"778c1144771f0064b6f51bee865cceb0d996f2f9","lessThan":"6253dfee5afba536bb54fc6fe6c091c3758fafe1","versionType":"git","status":"affected"},{"version":"778c1144771f0064b6f51bee865cceb0d996f2f9","lessThan":"65bf0d2b6e914f1448d6a2fde193dcf60936a651","versionType":"git","status":"affected"},{"version":"778c1144771f0064b6f51bee865cceb0d996f2f9","lessThan":"de497d7aa2fae453a7e7c8f7d3e8682e565e3aaf","versionType":"git","status":"affected"},{"version":"778c1144771f0064b6f51bee865cceb0d996f2f9","lessThan":"138c692d2b2d63d26f2eb957d0e4fcc5d61f9ff2","versionType":"git","status":"affected"},{"version":"778c1144771f0064b6f51bee865cceb0d996f2f9","lessThan":"83b17872e3166c295c599279fc9562ac3840c638","versionType":"git","status":"affected"},{"version":"778c1144771f0064b6f51bee865cceb0d996f2f9","lessThan":"497c6bae5167428596575f20af6613ff5671f383","versionType":"git","status":"affected"},{"version":"778c1144771f0064b6f51bee865cceb0d996f2f9","lessThan":"dfd1894cb64cbd8758b461ed713800fe73db4f82","versionType":"git","status":"affected"},{"version":"778c1144771f0064b6f51bee865cceb0d996f2f9","lessThan":"6255da28d4bb5349fe18e84cb043ccd394eba75d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/proc/base.c","fs/proc/fd.c","fs/proc/internal.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.18","status":"affected"},{"version":"0","lessThan":"2.6.18","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/138c692d2b2d63d26f2eb957d0e4fcc5d61f9ff2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/497c6bae5167428596575f20af6613ff5671f383","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6253dfee5afba536bb54fc6fe6c091c3758fafe1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6255da28d4bb5349fe18e84cb043ccd394eba75d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/65bf0d2b6e914f1448d6a2fde193dcf60936a651","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/83b17872e3166c295c599279fc9562ac3840c638","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/de497d7aa2fae453a7e7c8f7d3e8682e565e3aaf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dfd1894cb64cbd8758b461ed713800fe73db4f82","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64376","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:20.717","lastModified":"2026-07-25T10:17:20.717","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware_loader: fix device reference leak in firmware_upload_register()\n\nfirmware_upload_register()\n  -> fw_create_instance()\n     -> device_initialize()\n\nAfter fw_create_instance() succeeds, the lifetime of the embedded struct\ndevice is expected to be managed through the device core reference\ncounting, since fw_create_instance() has already called\ndevice_initialize().\n\nIn firmware_upload_register(), if alloc_lookup_fw_priv() fails after\nfw_create_instance() succeeds, the code reaches free_fw_sysfs and frees\nfw_sysfs directly instead of releasing the device reference with\nput_device(). This may leave the reference count of the embedded struct\ndevice unbalanced, resulting in a refcount leak.\n\nThe issue was identified by a static analysis tool I developed and\nconfirmed by manual review. Fix this by using put_device(fw_dev) in the\nfailure path and letting fw_dev_release() handle the final cleanup,\ninstead of freeing the instance directly from the error path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/base/firmware_loader/sysfs_upload.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"97730bbb242cde22b7140acd202ffd88823886c9","lessThan":"517676ec7dfca064e08f94007a4abd21969de0a0","versionType":"git","status":"affected"},{"version":"97730bbb242cde22b7140acd202ffd88823886c9","lessThan":"46d403da376a8b7c1187193294953816e1a8d7fe","versionType":"git","status":"affected"},{"version":"97730bbb242cde22b7140acd202ffd88823886c9","lessThan":"2619b47a0c8114eef980a56ade7e3ef4b58eb384","versionType":"git","status":"affected"},{"version":"97730bbb242cde22b7140acd202ffd88823886c9","lessThan":"92f41769e5fd16bcd9ba97500d0517332e0a5b45","versionType":"git","status":"affected"},{"version":"97730bbb242cde22b7140acd202ffd88823886c9","lessThan":"15432f19562fdb9199cce6d9fc24db12c71ed574","versionType":"git","status":"affected"},{"version":"97730bbb242cde22b7140acd202ffd88823886c9","lessThan":"896df22ee57648b0c505bd76ddbc6b2341834696","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/base/firmware_loader/sysfs_upload.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/15432f19562fdb9199cce6d9fc24db12c71ed574","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2619b47a0c8114eef980a56ade7e3ef4b58eb384","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/46d403da376a8b7c1187193294953816e1a8d7fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/517676ec7dfca064e08f94007a4abd21969de0a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/896df22ee57648b0c505bd76ddbc6b2341834696","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/92f41769e5fd16bcd9ba97500d0517332e0a5b45","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64377","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:20.837","lastModified":"2026-07-25T10:17:20.837","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: qcom-cpufreq-hw: Fix possible double free\n\nqcom_cpufreq.data is allocated with devm_kzalloc() in probe() as an\narray of per-domain data. qcom_cpufreq_hw_cpu_init() stores a pointer to\none element of this array in policy->driver_data.\n\nqcom_cpufreq_hw_cpu_exit() currently calls kfree() on policy->driver_data.\nThis is not valid because the memory is devm-managed. For the first\ndomain, this can free the devm-managed allocation while the devres entry\nis still active, leading to a possible double free when the platform\ndevice is later detached. For other domains, the pointer may refer to an\nelement inside the array rather than the allocation base.\n\nRemove the kfree(data) call and let devres release qcom_cpufreq.data.\n\nThis issue was found by a static analysis tool I am developing."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/cpufreq/qcom-cpufreq-hw.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"054a3ef683a176a509cc9b37f762029aae942495","lessThan":"28a03a3f6e6cda0b0da3b43761d175dec5d14d13","versionType":"git","status":"affected"},{"version":"054a3ef683a176a509cc9b37f762029aae942495","lessThan":"e904961332801c87355f5d11c65bb433e717c489","versionType":"git","status":"affected"},{"version":"054a3ef683a176a509cc9b37f762029aae942495","lessThan":"9de568ef6cdfc7912d5ea8db02843c0e4ef0c75d","versionType":"git","status":"affected"},{"version":"054a3ef683a176a509cc9b37f762029aae942495","lessThan":"bcb8889c4981fdde42d4fd2c29a77d510fe21da2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/cpufreq/qcom-cpufreq-hw.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.2","status":"affected"},{"version":"0","lessThan":"6.2","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/28a03a3f6e6cda0b0da3b43761d175dec5d14d13","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9de568ef6cdfc7912d5ea8db02843c0e4ef0c75d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bcb8889c4981fdde42d4fd2c29a77d510fe21da2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e904961332801c87355f5d11c65bb433e717c489","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64378","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:20.940","lastModified":"2026-07-25T10:17:20.940","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwriteback: fix race between cgroup_writeback_umount() and inode_switch_wbs()\n\nWhen a container exits, the following BUG_ON() is occasionally triggered:\n\n==================================================================\n VFS: Busy inodes after unmount of sdb (ext4)\n ------------[ cut here ]------------\n kernel BUG at fs/super.c:695!\n CPU: 3 PID: 6 Comm: containerd-shim Tainted: G OE K 6.6 #1\n pstate: 63400009 (nZCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\n pc : generic_shutdown_super+0xf0/0x100\n lr : generic_shutdown_super+0xf0/0x100\n Call trace:\n  generic_shutdown_super+0xf0/0x100\n  kill_block_super+0x20/0x48\n  ext4_kill_sb+0x28/0x60\n  deactivate_locked_super+0x54/0x130\n  deactivate_super+0x84/0xa0\n  cleanup_mnt+0xa4/0x140\n  __cleanup_mnt+0x18/0x28\n  task_work_run+0x78/0xe0\n  do_notify_resume+0x204/0x240\n==================================================================\n\nThe root cause is a race between cgroup_writeback_umount() and\ninode_switch_wbs()/cleanup_offline_cgwb(). There is a window between\ninode_prepare_wbs_switch() returning true and the subsequent\nwb_queue_isw() call. Following is the process that triggers the issue:\n\n      CPU A (umount)           |          CPU B (writeback)\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n                                 inode_switch_wbs/cleanup_offline_cgwb\n                                  atomic_inc(&isw_nr_in_flight)\n                                  inode_prepare_wbs_switch\n                                   -> passes SB_ACTIVE check\n                                   __iget(inode)\n generic_shutdown_super\n  sb->s_flags &= ~SB_ACTIVE\n  cgroup_writeback_umount(sb)\n   smp_mb()\n   atomic_read(&isw_nr_in_flight)\n   rcu_barrier()\n    -> no pending RCU callbacks\n   flush_workqueue(isw_wq)\n    -> nothing queued, returns\n  evict_inodes(sb)\n   -> Inode skipped as isw still holds a ref.\n  sop->put_super(sb)\n   /* destroys percpu counters */\n  -> VFS: Busy inodes after unmount!\n                                  wb_queue_isw()\n                                   queue_work(isw_wq, ...)\n                                  /* later in work function */\n                                  inode_switch_wbs_work_fn\n                                   process_inode_switch_wbs\n                                    iput() -> evict\n                                     percpu_counter_dec() // UAF!\n\nFix this by extending the RCU read-side critical section in\ninode_switch_wbs() and cleanup_offline_cgwb() to cover from\ninode_prepare_wbs_switch() through wb_queue_isw().  Since there is\nno sleep in this window, rcu_read_lock() can be used.  Then add a\nsynchronize_rcu() in cgroup_writeback_umount() before the existing\nrcu_barrier(), so that all in-flight switchers that have passed the\nSB_ACTIVE check have completed queue_work() before flush_workqueue()\nis called.\n\nThe existing rcu_barrier() is intentionally retained so this fix can\nbe backported unchanged to stable kernels (5.10.y, 6.6.y, ...) that\nstill queue switches via queue_rcu_work(). It is a no-op on current\nmainline (since commit e1b849cfa6b6 (\"writeback: Avoid contention on\nwb->list_lock when switching inodes\")) and is removed in a follow-up\npatch."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/fs-writeback.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a1a0e23e49037c23ea84bc8cc146a03584d13577","lessThan":"087d5b8b501c570f84bf655164e6698c3ce146e0","versionType":"git","status":"affected"},{"version":"a1a0e23e49037c23ea84bc8cc146a03584d13577","lessThan":"3c9c9648f77e4d14e50676bc51c2174ba9c8d361","versionType":"git","status":"affected"},{"version":"a1a0e23e49037c23ea84bc8cc146a03584d13577","lessThan":"5c3265f3252b2ee50707adaaa3f9bd0df3df72de","versionType":"git","status":"affected"},{"version":"a1a0e23e49037c23ea84bc8cc146a03584d13577","lessThan":"c923cc3cb5cd8945ceaf08252754110643446593","versionType":"git","status":"affected"},{"version":"a1a0e23e49037c23ea84bc8cc146a03584d13577","lessThan":"685fc15a410885b6d4dee64de0dce721b9428b12","versionType":"git","status":"affected"},{"version":"a1a0e23e49037c23ea84bc8cc146a03584d13577","lessThan":"53eeaf4d63068dbc7708b0c7adb20151c812feca","versionType":"git","status":"affected"},{"version":"a1a0e23e49037c23ea84bc8cc146a03584d13577","lessThan":"cba38ec4cbd3a7b8b942a8d52531a05be8a9ff0d","versionType":"git","status":"affected"},{"version":"c5cbbec54fe71c4de2d34f8c0ec8fbfdd7f17339","versionType":"git","status":"affected"},{"version":"4.4.5","lessThan":"4.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/fs-writeback.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.5","status":"affected"},{"version":"0","lessThan":"4.5","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/087d5b8b501c570f84bf655164e6698c3ce146e0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3c9c9648f77e4d14e50676bc51c2174ba9c8d361","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/53eeaf4d63068dbc7708b0c7adb20151c812feca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5c3265f3252b2ee50707adaaa3f9bd0df3df72de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/685fc15a410885b6d4dee64de0dce721b9428b12","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c923cc3cb5cd8945ceaf08252754110643446593","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cba38ec4cbd3a7b8b942a8d52531a05be8a9ff0d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64379","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:21.090","lastModified":"2026-07-25T10:17:21.090","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: mask server-provided mode to 07777 in modefromsid\n\nWhen modefromsid is active, parse_dacl() applies the server-provided\nsub_auth[2] value from the NFS mode SID to cf_mode without masking to\n07777. Apply the correct masking, same as in the read path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/client/cifsacl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e2f8fbfb8d09c06decde162090fac3ee220aa280","lessThan":"5f6f2241034f189c69d4d0b5f8fe24a0c25b0c14","versionType":"git","status":"affected"},{"version":"e2f8fbfb8d09c06decde162090fac3ee220aa280","lessThan":"ee2216dbdf0c677e89bb43e03247dba590ed00ef","versionType":"git","status":"affected"},{"version":"e2f8fbfb8d09c06decde162090fac3ee220aa280","lessThan":"f511807feee7cb29b61bdfa86472c7e9e2e5df94","versionType":"git","status":"affected"},{"version":"e2f8fbfb8d09c06decde162090fac3ee220aa280","lessThan":"08c600b7e1818539ba5efee4cdb06215c245ca78","versionType":"git","status":"affected"},{"version":"e2f8fbfb8d09c06decde162090fac3ee220aa280","lessThan":"b84e002e0df26bbc6cbd3ca01b8212601fe0ae7d","versionType":"git","status":"affected"},{"version":"e2f8fbfb8d09c06decde162090fac3ee220aa280","lessThan":"c6c484a7d5bff6b929a86d7ed5130f29834c6a0d","versionType":"git","status":"affected"},{"version":"e2f8fbfb8d09c06decde162090fac3ee220aa280","lessThan":"f80add1bfb3425100a325b14f19648e75669a954","versionType":"git","status":"affected"},{"version":"e2f8fbfb8d09c06decde162090fac3ee220aa280","lessThan":"e3d9c7160d483fc8f9e225aafad8ecbbc43f3151","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/client/cifsacl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.4","status":"affected"},{"version":"0","lessThan":"5.4","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/08c600b7e1818539ba5efee4cdb06215c245ca78","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5f6f2241034f189c69d4d0b5f8fe24a0c25b0c14","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b84e002e0df26bbc6cbd3ca01b8212601fe0ae7d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c6c484a7d5bff6b929a86d7ed5130f29834c6a0d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e3d9c7160d483fc8f9e225aafad8ecbbc43f3151","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ee2216dbdf0c677e89bb43e03247dba590ed00ef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f511807feee7cb29b61bdfa86472c7e9e2e5df94","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f80add1bfb3425100a325b14f19648e75669a954","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64380","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:21.220","lastModified":"2026-07-25T10:17:21.220","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: harden POSIX SID length parsing\n\nposix_info_sid_size() reads sid[1] to obtain the subauthority count,\nbut its existing boundary check still accepts buffers with only one\nremaining byte. Require two bytes before reading sid[1] so all client\npaths that reuse the helper reject truncated POSIX SIDs safely."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/client/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"349e13ad30b45998bb9937cfe0b32be6f951976d","lessThan":"171605aed68380c2fa75dff9b3a1ed427c50065b","versionType":"git","status":"affected"},{"version":"349e13ad30b45998bb9937cfe0b32be6f951976d","lessThan":"4213c1208978483021d7d125c131de3985d38f61","versionType":"git","status":"affected"},{"version":"349e13ad30b45998bb9937cfe0b32be6f951976d","lessThan":"96e889bc1e759c83f25093e8c2f3da31b4973f30","versionType":"git","status":"affected"},{"version":"349e13ad30b45998bb9937cfe0b32be6f951976d","lessThan":"0de5b8e76847f5de26f364a82c6602c4881c30da","versionType":"git","status":"affected"},{"version":"349e13ad30b45998bb9937cfe0b32be6f951976d","lessThan":"427eb7eb46425fec845a43e861f3d6e2899cae59","versionType":"git","status":"affected"},{"version":"349e13ad30b45998bb9937cfe0b32be6f951976d","lessThan":"86c5d470f5d42e61123b2f4b4f0b91f4eee5b980","versionType":"git","status":"affected"},{"version":"349e13ad30b45998bb9937cfe0b32be6f951976d","lessThan":"46a84715a015cb48e1b9c219dc88c03d8a541ea4","versionType":"git","status":"affected"},{"version":"349e13ad30b45998bb9937cfe0b32be6f951976d","lessThan":"7ad2bcf2441430bb2e918fb3ef9a90d775a6e422","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/client/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.7","status":"affected"},{"version":"0","lessThan":"5.7","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0de5b8e76847f5de26f364a82c6602c4881c30da","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/171605aed68380c2fa75dff9b3a1ed427c50065b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4213c1208978483021d7d125c131de3985d38f61","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/427eb7eb46425fec845a43e861f3d6e2899cae59","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/46a84715a015cb48e1b9c219dc88c03d8a541ea4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7ad2bcf2441430bb2e918fb3ef9a90d775a6e422","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/86c5d470f5d42e61123b2f4b4f0b91f4eee5b980","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/96e889bc1e759c83f25093e8c2f3da31b4973f30","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64381","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:21.347","lastModified":"2026-07-25T10:17:21.347","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Fix next buffer leak in receive_encrypted_standard()\n\nreceive_encrypted_standard() allocates next_buffer before checking\nwhether the number of compound PDUs already reached MAX_COMPOUND. If\nthe limit check fails, the function returns immediately and the newly\nallocated next_buffer is not assigned to server->smallbuf/server->bigbuf,\nmaking it leaked.\n\nMove the MAX_COMPOUND check before allocating next_buffer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/client/smb2ops.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b24df3e30cbf48255db866720fb71f14bf9d2f39","lessThan":"94e4f672db029414b9888b5137a7559f1febf2d8","versionType":"git","status":"affected"},{"version":"b24df3e30cbf48255db866720fb71f14bf9d2f39","lessThan":"68fc0b6cc03ca58060c0f36454e169f5fe258974","versionType":"git","status":"affected"},{"version":"b24df3e30cbf48255db866720fb71f14bf9d2f39","lessThan":"07e0ab81df1790afa35732a4e8e07ff831b29008","versionType":"git","status":"affected"},{"version":"b24df3e30cbf48255db866720fb71f14bf9d2f39","lessThan":"9136a08dc29328edd9867f2545e73906ac9df93b","versionType":"git","status":"affected"},{"version":"b24df3e30cbf48255db866720fb71f14bf9d2f39","lessThan":"67097772df7791c53d608f04bd31c676ccf79b83","versionType":"git","status":"affected"},{"version":"b24df3e30cbf48255db866720fb71f14bf9d2f39","lessThan":"297243e365fc9fe2f8e9b7dd535a65d922cd108b","versionType":"git","status":"affected"},{"version":"b24df3e30cbf48255db866720fb71f14bf9d2f39","lessThan":"927d4805aea0a287d36dd4f826ee24d69a2afee3","versionType":"git","status":"affected"},{"version":"b24df3e30cbf48255db866720fb71f14bf9d2f39","lessThan":"1c6267a1d5cf4c73b656f8181b310cbbb3e4767b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/client/smb2ops.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.19","status":"affected"},{"version":"0","lessThan":"4.19","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/07e0ab81df1790afa35732a4e8e07ff831b29008","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1c6267a1d5cf4c73b656f8181b310cbbb3e4767b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/297243e365fc9fe2f8e9b7dd535a65d922cd108b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/67097772df7791c53d608f04bd31c676ccf79b83","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/68fc0b6cc03ca58060c0f36454e169f5fe258974","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9136a08dc29328edd9867f2545e73906ac9df93b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/927d4805aea0a287d36dd4f826ee24d69a2afee3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/94e4f672db029414b9888b5137a7559f1febf2d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64382","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:21.477","lastModified":"2026-07-25T10:17:21.477","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix double-free in SMB2_open() replay\n\nA response-bearing attempt can return a replayable error and free its\nresponse buffer. If SMB2_open_init() fails before the next send, cleanup\nretains the previous buffer type and frees that response again.\n\nReset response bookkeeping before each attempt to prevent the stale free."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/client/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"433042a91f9373241307725b52de573933ffedbf","lessThan":"02bc2896bdc3e29362d6e40d404006944a159c25","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"3196b5192f246df4272072f61a2f4a3e9967f55d","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"14498ff5ce0f272ce0ef988721413e06b7038972","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"ff2d30927bc3bf3c629f0768d2068096e64ef5ce","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"b55e182f2324bc6a604c21a47aa6c448f719a532","versionType":"git","status":"affected"},{"version":"6.6.32","lessThan":"6.6.145","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/client/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/02bc2896bdc3e29362d6e40d404006944a159c25","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/14498ff5ce0f272ce0ef988721413e06b7038972","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3196b5192f246df4272072f61a2f4a3e9967f55d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b55e182f2324bc6a604c21a47aa6c448f719a532","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff2d30927bc3bf3c629f0768d2068096e64ef5ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64383","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:21.587","lastModified":"2026-07-25T10:17:21.587","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix double-free in SMB2_flush() replay\n\nSMB2_flush() keeps its response buffer bookkeeping across replay\nattempts. If a replayable flush response is received and the retry then\nfails before cifs_send_recv() stores a replacement response, flush_exit\nwill free the stale response pointer a second time.\n\nReinitialize resp_buftype and rsp_iov at the top of the replay loop so\ncleanup only acts on response state produced by the current attempt.\nThis fixes a double-free without changing replay handling for successful\nrequests."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/client/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"433042a91f9373241307725b52de573933ffedbf","lessThan":"6e27f40b682a5e42a2daae3ce6d96f0e0e16dedb","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"878757163eea684750107a31ea134c103863515d","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"3407240cde132a4b72d6429a2625a09a2f78adaf","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"013a9a3da46c5dabcf18f65ea6a47874ba12a15d","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"4be31c943a3a27a5a0251dbb8f5cb89059ec3d5a","versionType":"git","status":"affected"},{"version":"6.6.32","lessThan":"6.6.145","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/client/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/013a9a3da46c5dabcf18f65ea6a47874ba12a15d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3407240cde132a4b72d6429a2625a09a2f78adaf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4be31c943a3a27a5a0251dbb8f5cb89059ec3d5a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e27f40b682a5e42a2daae3ce6d96f0e0e16dedb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/878757163eea684750107a31ea134c103863515d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64384","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:21.700","lastModified":"2026-07-25T10:17:21.700","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix change notify replay double-free\n\nA response-bearing attempt can return a replayable error and free its\nresponse buffer. If SMB2_notify_init() fails before the next send, cleanup\nretains the previous buffer type and frees that response again.\n\nReset response bookkeeping before each attempt to prevent the stale free."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/client/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"433042a91f9373241307725b52de573933ffedbf","lessThan":"5821f9dbb8b5b24391850a13418e633edd0fb003","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"d684f4134998085702009b94c35c2003fc9e72d3","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"52af1975f0dfae990c5a0e85872cc41be0e88a68","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"901891513951bc8322ece754863909ea45af95c6","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"145f820dcbb2cced374f2532f8a61a44dce4a615","versionType":"git","status":"affected"},{"version":"6.6.32","lessThan":"6.6.145","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/client/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/145f820dcbb2cced374f2532f8a61a44dce4a615","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/52af1975f0dfae990c5a0e85872cc41be0e88a68","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5821f9dbb8b5b24391850a13418e633edd0fb003","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/901891513951bc8322ece754863909ea45af95c6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d684f4134998085702009b94c35c2003fc9e72d3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64385","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:21.810","lastModified":"2026-07-25T10:17:21.810","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix double-free in SMB2_ioctl() replay\n\nA response-bearing attempt can return a replayable error and free its\nresponse buffer. If SMB2_ioctl_init() fails before the next send, cleanup\nretains the previous buffer type and frees that response again.\n\nReset response bookkeeping before each attempt to prevent the stale free."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/client/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"433042a91f9373241307725b52de573933ffedbf","lessThan":"0be4bc64882edaefaaee8d1e27d083643eb778e6","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"96fcfc8ae7359346156e492ca610e830d2649ad6","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"276c8efbc49f9303ac76d0d4deab7128581b0f3b","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"fc65ffb4ef1bf540da16b17c225ae51091e07d72","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"f9bbadb6c94583e3b4af1afc449bfceb1d1ddec9","versionType":"git","status":"affected"},{"version":"6.6.32","lessThan":"6.6.145","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/client/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0be4bc64882edaefaaee8d1e27d083643eb778e6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/276c8efbc49f9303ac76d0d4deab7128581b0f3b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/96fcfc8ae7359346156e492ca610e830d2649ad6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f9bbadb6c94583e3b4af1afc449bfceb1d1ddec9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc65ffb4ef1bf540da16b17c225ae51091e07d72","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64386","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:21.917","lastModified":"2026-07-25T10:17:21.917","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix query_info() replay double-free\n\nA response-bearing attempt can return a replayable error and free its\nresponse buffer. If SMB2_query_info_init() fails before the next send,\ncleanup retains the previous buffer type and frees that response again.\n\nReset response bookkeeping before each attempt to prevent the stale free."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/client/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"433042a91f9373241307725b52de573933ffedbf","lessThan":"100fb7c455fa86d248b8bd7bb9de757c192870b4","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"3c81dda84799f76b42aec598564316e2964440db","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"f1add4acb656f5a82806a1ab0e63fed3d8b1bfca","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"89234773e8348918111aa15f6922b58cf3843364","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"2a88561d66eb855813cf004a0abe648bbb17de5e","versionType":"git","status":"affected"},{"version":"6.6.32","lessThan":"6.6.145","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/client/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/100fb7c455fa86d248b8bd7bb9de757c192870b4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2a88561d66eb855813cf004a0abe648bbb17de5e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3c81dda84799f76b42aec598564316e2964440db","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/89234773e8348918111aa15f6922b58cf3843364","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1add4acb656f5a82806a1ab0e63fed3d8b1bfca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64387","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:22.020","lastModified":"2026-07-25T10:17:22.020","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix query directory replay double-free\n\nA response-bearing attempt can return a replayable error and free its\nresponse buffer. If SMB2_query_directory_init() fails before the next send,\ncleanup retains the previous buffer type and frees that response again.\n\nReset response bookkeeping before each attempt to prevent the stale free."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/client/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"433042a91f9373241307725b52de573933ffedbf","lessThan":"3409aedf3c81a810243da94164f6621c9d205c98","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"1665f25b1dea30bf2d02e16245d203a944c9d994","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"00b0fa425941438b664950a8ee65dfba2def4336","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"3317a5d015fca976475aa71df224056777316fde","versionType":"git","status":"affected"},{"version":"4f1fffa2376922f3d1d506e49c0fd445b023a28e","lessThan":"9647492b5e41954be59d5157eddbcd4cdc1656f7","versionType":"git","status":"affected"},{"version":"6.6.32","lessThan":"6.6.145","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/client/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/00b0fa425941438b664950a8ee65dfba2def4336","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1665f25b1dea30bf2d02e16245d203a944c9d994","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3317a5d015fca976475aa71df224056777316fde","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3409aedf3c81a810243da94164f6621c9d205c98","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9647492b5e41954be59d5157eddbcd4cdc1656f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64388","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:22.127","lastModified":"2026-07-25T10:17:22.127","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb/client: fix chown/chgrp with SMB3 POSIX Extensions\n\nOwnership (chown) and group (chgrp) modifications were being ignored when\nmounting with SMB3 POSIX Extensions unless CIFS_MOUNT_CIFS_ACL or\nCIFS_MOUNT_MODE_FROM_SID were also explicitly set.\n\nFix this by checking for posix_extensions in cifs_setattr_nounix() when\nupdating UID and GID, ensuring that id_mode_to_cifs_acl() is called to map\nand set the ownership/group information on the server."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/client/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"550cfb8a81181331d4d0f76ab75ee58a0bf41e3e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"760ef2c579c2609cf17fb1cd5392f64d42d43d33","versionType":"git","status":"affected"},{"version":"0","lessThan":"7.1.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/client/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/550cfb8a81181331d4d0f76ab75ee58a0bf41e3e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/760ef2c579c2609cf17fb1cd5392f64d42d43d33","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64389","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:22.227","lastModified":"2026-07-25T10:17:22.227","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate NTLMv2 response before updating session key\n\nksmbd_auth_ntlmv2() derives the NTLMv2 session key into\nsess->sess_key before it verifies the NTLMv2 response.\nksmbd_decode_ntlmssp_auth_blob() then continues into KEY_XCH even\nwhen ksmbd_auth_ntlmv2() failed.\n\nWith SMB3 multichannel binding, the failed authentication operates on\nan existing session and the session setup error path does not expire\nbinding sessions. A client can send a binding session setup with a\nbad NT proof and KEY_XCH and still modify sess->sess_key before\nSTATUS_LOGON_FAILURE is returned.\n\nRelevant path:\n\n  smb2_sess_setup()\n    -> conn->binding = true\n    -> ntlm_authenticate()\n       -> session_user()\n       -> ksmbd_decode_ntlmssp_auth_blob()\n          -> ksmbd_auth_ntlmv2()\n             -> calc_ntlmv2_hash()\n             -> hmac_md5_usingrawkey(..., sess->sess_key)\n             -> crypto_memneq() returns mismatch\n          -> KEY_XCH arc4_crypt(..., sess->sess_key, ...)\n    -> out_err without expiring the binding session\n\nDerive the base session key into a local buffer and copy it to\nsess->sess_key only after the proof matches. Return immediately on\nauthentication failure so KEY_XCH is only processed after successful\nauthentication."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/auth.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"b56400364aed5c34d6e1a0b493081290a5328a9c","versionType":"git","status":"affected"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"89ca7756d5566ba636bb9092cdbe57dab095e136","versionType":"git","status":"affected"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"954d196bebb2b50151cb96454c72dc113b2af1ac","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/auth.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/89ca7756d5566ba636bb9092cdbe57dab095e136","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/954d196bebb2b50151cb96454c72dc113b2af1ac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b56400364aed5c34d6e1a0b493081290a5328a9c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64390","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:22.330","lastModified":"2026-07-25T10:17:22.330","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: track the connection owning a byte-range lock\n\nSMB2_LOCK adds each granted byte-range lock to both the file lock list\nand the lock list of the connection which handled the request.  The\nfinal close and durable handle paths, however, remove the connection\nlist entry while holding fp->conn->llist_lock.\n\nWith SMB3 multichannel, the connection handling the LOCK request can be\ndifferent from the connection which opened the file.  The entry can\ntherefore be removed under a different spinlock from the one protecting\nthe list it belongs to.  A concurrent traversal can then access freed\nstruct ksmbd_lock and struct file_lock objects.\n\nRecord the connection owning each lock's clist entry and hold a\nreference to it while the entry is linked.  Use that connection and its\nllist_lock for unlock, rollback, close, and durable preserve.  Durable\nreconnect assigns the new connection as the owner when publishing the\nlocks again."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/smb2pdu.c","fs/smb/server/vfs_cache.c","fs/smb/server/vfs_cache.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f5a544e3bab78142207e0242d22442db85ba1eff","lessThan":"22d38cf75b556c20b039743bdf3654d535b858be","versionType":"git","status":"affected"},{"version":"f5a544e3bab78142207e0242d22442db85ba1eff","lessThan":"66eb3643164e5e1029907793926c132f8b5c6148","versionType":"git","status":"affected"},{"version":"f5a544e3bab78142207e0242d22442db85ba1eff","lessThan":"ea5c9bf99f626a15cc59f645dc895f2b3f01992e","versionType":"git","status":"affected"},{"version":"f5a544e3bab78142207e0242d22442db85ba1eff","lessThan":"fe20d492a69a6f79e637f438072b212e21ed3b78","versionType":"git","status":"affected"},{"version":"f5a544e3bab78142207e0242d22442db85ba1eff","lessThan":"427faaa52b0b399940c1a88065a5c310d10dad15","versionType":"git","status":"affected"},{"version":"f5a544e3bab78142207e0242d22442db85ba1eff","lessThan":"5fecc15a30cb9ebd310f7b52c1ab607edcea78f6","versionType":"git","status":"affected"},{"version":"f5a544e3bab78142207e0242d22442db85ba1eff","lessThan":"c1016dd1d8b2bcd1158bbaabe94a31bb7e7431fb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/smb2pdu.c","fs/smb/server/vfs_cache.c","fs/smb/server/vfs_cache.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/22d38cf75b556c20b039743bdf3654d535b858be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/427faaa52b0b399940c1a88065a5c310d10dad15","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5fecc15a30cb9ebd310f7b52c1ab607edcea78f6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/66eb3643164e5e1029907793926c132f8b5c6148","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c1016dd1d8b2bcd1158bbaabe94a31bb7e7431fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea5c9bf99f626a15cc59f645dc895f2b3f01992e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe20d492a69a6f79e637f438072b212e21ed3b78","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64391","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:22.453","lastModified":"2026-07-25T10:17:22.453","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use opener credentials for ADS I/O\n\nAlternate data streams are stored as xattrs. Unlike regular file I/O,\ntheir read and write paths therefore call VFS xattr helpers which recheck\ninode permissions and LSM policy using the current task credentials.\n\nRun ADS I/O with the credentials captured when the SMB handle was opened."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/vfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a8f5d39971bbad9340d49cd41b0e2da9452a649d","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2b4592cea214683de0f2ce6f8c22c097fb0ea1ab","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"52a56cf53ec834c44ac1b4d16d585f26613ee5ce","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"baa5e094886fffa7e6272edcb5e08be5ce28262c","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.39","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/vfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2b4592cea214683de0f2ce6f8c22c097fb0ea1ab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/52a56cf53ec834c44ac1b4d16d585f26613ee5ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a8f5d39971bbad9340d49cd41b0e2da9452a649d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/baa5e094886fffa7e6272edcb5e08be5ce28262c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64392","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:22.557","lastModified":"2026-07-25T10:17:22.557","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: use opener credentials for delete-on-close\n\nDelete-on-close can be completed by deferred or durable handle teardown,\nwhere no request work is available. Both the base-file unlink and the ADS\nxattr removal consequently run with the ksmbd worker credentials and can\nbypass filesystem permission checks.\n\nRun both operations with the credentials captured in struct file when the\nhandle was opened. This preserves the authenticated user's fsuid, fsgid,\nsupplementary groups and capability restrictions at final close."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/vfs.c","fs/smb/server/vfs_cache.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f08b3f451f12eee4abd8a5981803bc36db84458b","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"18c59109bb6fb816d5102171666f87cf1e29901d","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e72c15085b6d86f45d224d98aa75b5cace4aaab9","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"4b7059974549d278e30fe70e2a4e421f9839817d","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"52e2f21911158ec961cd5aae19c56460db382af0","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.39","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/vfs.c","fs/smb/server/vfs_cache.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/18c59109bb6fb816d5102171666f87cf1e29901d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4b7059974549d278e30fe70e2a4e421f9839817d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/52e2f21911158ec961cd5aae19c56460db382af0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e72c15085b6d86f45d224d98aa75b5cace4aaab9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f08b3f451f12eee4abd8a5981803bc36db84458b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64393","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:22.663","lastModified":"2026-07-25T10:17:22.663","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: run set info with opener credentials\n\nSMB2 SET_INFO handlers call path-based VFS helpers after checking the\naccess mask granted to the SMB handle. Those helpers perform their owner,\ninode permission and LSM checks using the current ksmbd worker credentials.\n\nRun the complete SET_INFO dispatch with the credentials captured when the\nhandle was opened. This also removes the separate security information\ncredential setup and keeps all SET_INFO classes under one credential scope.\n\nDirect override_creds() is used because it can nest with the request\ncredential overrides already used by rename and link helpers."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5cbabf3a71575cd31bc7785d92d4ab42338a654b","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b35afd5cf8fab236ef21117e42ee45691d4ffa7b","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"0ce682867fd506f61f40c76bde7e4205bde34e87","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"20ee516a62989a8d505ee432f9e59525ea23984e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"8cc9ec711f5255167247a9ab6a7179b787426ed7","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b383bcad3d2fe634b26efbce53e22bbb5753a520","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.39","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0ce682867fd506f61f40c76bde7e4205bde34e87","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/20ee516a62989a8d505ee432f9e59525ea23984e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5cbabf3a71575cd31bc7785d92d4ab42338a654b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8cc9ec711f5255167247a9ab6a7179b787426ed7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b35afd5cf8fab236ef21117e42ee45691d4ffa7b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b383bcad3d2fe634b26efbce53e22bbb5753a520","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64394","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:22.790","lastModified":"2026-07-25T10:17:22.790","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY\n\ncommit cc57232cae23 (\"ksmbd: fix FSCTL permission bypass by adding a\npermission check for FSCTL_SET_SPARSE\") added a fp->daccess gate to\nfsctl_set_sparse and noted that \"similar handle-level checks exist in other\nfunctions but are missing here.\" The SMB2 SET_INFO SECURITY arm is one of\nthe missing ones, and the most security-relevant: smb2_set_info_sec() calls\nset_info_sec() with no per-handle access check.\n\nset_info_sec() (fs/smb/server/smbacl.c) re-permissions the file: it\nrewrites owner/group/mode via notify_change(), rewrites the POSIX ACL via\nset_posix_acl(), and on KSMBD_SHARE_FLAG_ACL_XATTR shares removes and\nrewrites the Windows security descriptor via ksmbd_vfs_set_sd_xattr().\nEvery other persistent-mutation arm of the sibling handler\nsmb2_set_info_file() checks fp->daccess first (FILE_WRITE_DATA /\nFILE_DELETE / FILE_WRITE_EA / FILE_WRITE_ATTRIBUTES); the SECURITY arm —\nwhich mutates the access control itself — is the only one with no gate.\n\nA client can therefore open a handle with FILE_WRITE_ATTRIBUTES only (no\nFILE_WRITE_DAC / FILE_WRITE_OWNER) and use SMB2_SET_INFO with InfoType\nSMB2_O_INFO_SECURITY to rewrite the file's DACL and owner, granting itself\naccess the handle's daccess never carried. Unlike the FSCTL data arms this\nis a metadata/xattr operation, so there is no FMODE_WRITE VFS backstop —\nthe missing fp->daccess check is the entire gate.\n\nSetting a security descriptor is the WRITE_DAC / WRITE_OWNER operation, so\nrequire at least one of those on the handle before re-permissioning the\nfile. -EACCES is mapped to STATUS_ACCESS_DENIED by smb2_set_info()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"0848b1d8b403f530878195dcbe241a2fddb9d0e1","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e6aa731f1b4b3e08caebf66a99f04b22bdab2e99","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9ab2ffd3ed3d4ca1667c52de27026ddabc11e537","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f56535db508ead8dec1c481ad93d7d8acd8f8f1e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"aae600cdaffc6d9ce97645f129799a103a97d06d","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"44df157a1183a7f746caa970c169255da5ac61f8","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.39","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0848b1d8b403f530878195dcbe241a2fddb9d0e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/44df157a1183a7f746caa970c169255da5ac61f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ab2ffd3ed3d4ca1667c52de27026ddabc11e537","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aae600cdaffc6d9ce97645f129799a103a97d06d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e6aa731f1b4b3e08caebf66a99f04b22bdab2e99","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f56535db508ead8dec1c481ad93d7d8acd8f8f1e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64395","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:22.923","lastModified":"2026-07-25T10:17:22.923","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: require source read access for duplicate extents\n\nFSCTL_DUPLICATE_EXTENTS_TO_FILE passes the source file directly to\nvfs_clone_file_range() or vfs_copy_file_range() without checking the SMB\naccess mask granted to the source handle. A handle opened with attribute\naccess can consequently be used to copy file contents into an\nattacker-readable destination.\n\nRequire FILE_READ_DATA on the source handle before either VFS operation,\nmatching other ksmbd data-copy paths."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2d2ab6983620c2d60ce7db72133984ca3873b929","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"67bdad9cf01b25030e3bf00bbce6c309319d6663","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b0d4d5cb846a1ddb7aaab9adfb5986e4540e6e5f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"db231af842868268839f9f9619c68cb27830d8be","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a10942af27832c2761d020863a46e79bebe0567d","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"cedff600f1642aa982178503552f0d007bc829c8","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.39","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2d2ab6983620c2d60ce7db72133984ca3873b929","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/67bdad9cf01b25030e3bf00bbce6c309319d6663","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a10942af27832c2761d020863a46e79bebe0567d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b0d4d5cb846a1ddb7aaab9adfb5986e4540e6e5f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cedff600f1642aa982178503552f0d007bc829c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/db231af842868268839f9f9619c68cb27830d8be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64396","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:23.040","lastModified":"2026-07-25T10:17:23.040","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation\n\nWhen a blocking byte-range lock request is deferred in the\nFILE_LOCK_DEFERRED path, ksmbd registers the asynchronous work into\nthe connection's async_requests list via setup_async_work(). The cancel\ncallback smb2_remove_blocked_lock() holds a reference to the flock.\n\nIf the lock waiter is subsequently woken up but the work state is no\nlonger KSMBD_WORK_ACTIVE (e.g., due to a concurrent cancellation), the\ncleanup path calls locks_free_lock(flock) without dequeuing the work from\nthe async_requests list. Concurrently, smb2_cancel() walks the list\nunder conn->request_lock and invokes the cancel callback, which then\ndereferences the already freed 'flock'. This leads to a slab-use-after-free\ninside __wake_up_common.\n\nFix this by restructuring the cleanup logic after the worker returns\nfrom ksmbd_vfs_posix_lock_wait(). Move list_del(&smb_lock->llist) and\nrelease_async_work(work) to the top of the cleanup block. This guarantees\nthat the async work is completely dequeued and serialized under\nconn->request_lock before locks_free_lock(flock) is called, rendering\nthe flock unreachable for any concurrent smb2_cancel()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"367c42a611fe488b7b03f1f6737f4dee0e8b20a2","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7703fd9aba1f2483c8e55f9ff73b7663e0761ed9","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"463bbd79698513af4dad50fe1c573825f297ca2e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5aa1cb01155f96824003baf7997cdf1f150caba3","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5c75275c0fc9a2deb0d8f5604edcb16f288171c8","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d20d1c8ba5765d1d12eefc0aee6385ab3f240e1e","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.39","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/367c42a611fe488b7b03f1f6737f4dee0e8b20a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/463bbd79698513af4dad50fe1c573825f297ca2e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5aa1cb01155f96824003baf7997cdf1f150caba3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5c75275c0fc9a2deb0d8f5604edcb16f288171c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7703fd9aba1f2483c8e55f9ff73b7663e0761ed9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d20d1c8ba5765d1d12eefc0aee6385ab3f240e1e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64397","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:23.160","lastModified":"2026-07-25T10:17:23.160","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: serialize QUERY_DIRECTORY requests per file\n\nsmb2_query_dir() stores a pointer to its stack-allocated private data in\nthe ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY requests using the\nsame file handle can overwrite this pointer while an iterate_dir() callback\nis still using it, resulting in a stack use-after-free.\n\nAdd a per-file mutex and hold it while accessing the shared directory\nenumeration state. The lock covers scan restart, dot entry state,\nreaddir_data setup and iteration, and response construction. This prevents\nanother request from replacing readdir_data.private before the current\nrequest has finished using it and also serializes the shared file position."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/smb2pdu.c","fs/smb/server/vfs_cache.c","fs/smb/server/vfs_cache.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1426fd79102539bc0ab5c8fced047ad4313b9908","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2a64dbf9c739ddf7a25a066507597bf89f8f73d2","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"64dac2d486ec1eb18dc00968b16a230b6b75ec24","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a1d5d31cad593ea5e1b637f2f39c9ef6d09d1199","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"fd22b039a5a05bc1d6818e9dcd1001fb432a829d","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"be6d26bf27499977c746abc163659915082348d8","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.39","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/smb2pdu.c","fs/smb/server/vfs_cache.c","fs/smb/server/vfs_cache.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1426fd79102539bc0ab5c8fced047ad4313b9908","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2a64dbf9c739ddf7a25a066507597bf89f8f73d2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/64dac2d486ec1eb18dc00968b16a230b6b75ec24","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a1d5d31cad593ea5e1b637f2f39c9ef6d09d1199","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be6d26bf27499977c746abc163659915082348d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fd22b039a5a05bc1d6818e9dcd1001fb432a829d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64398","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:23.280","lastModified":"2026-07-25T10:17:23.280","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: add a permission check for FSCTL_SET_ZERO_DATA\n\nFSCTL_SET_ZERO_DATA in smb2_ioctl() destroys file data via\nksmbd_vfs_zero_data() -> vfs_fallocate(PUNCH_HOLE/ZERO_RANGE) after\nchecking only the share-level KSMBD_TREE_CONN_FLAG_WRITABLE, with no\nper-handle access check. A handle opened with only FILE_WRITE_ATTRIBUTES\nstill yields an FMODE_WRITE filp (FILE_WRITE_ATTRIBUTES is part of\nFILE_WRITE_DESIRE_ACCESS_LE, so smb2_create_open_flags() opens it\nO_WRONLY), so the vfs_fallocate FMODE_WRITE check does not stop it; only\nthe missing fp->daccess gate would. Reproduced on mainline 7.1-rc7 with\nKASAN by an authenticated SMB client: a FILE_WRITE_ATTRIBUTES-only handle\nzeroed 4096 bytes of file data it had no FILE_WRITE_DATA right to\n(6/6; a FILE_READ_DATA-only handle was correctly denied).\n\nThis is the unfixed sibling of commit cc57232cae23 (\"ksmbd: fix FSCTL\npermission bypass by adding a permission check for FSCTL_SET_SPARSE\").\nBecause SET_ZERO_DATA writes data (not an attribute), require\nFILE_WRITE_DATA."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"25377f369688dd0bd814dc8965ed26d44238ecaa","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3072d82461f498c85daea8766e9d8bfbada31605","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ca53bb17f4e8232cfaece3953d3cef62c559b039","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"57f2042fd87d7ce8fc3ac8b6c176e554df68b1a7","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"deffa929086d7902e30918adf3dd27ccfe9c08b1","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3320ba068198adc144c89d6661b805acce01735b","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.39","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/25377f369688dd0bd814dc8965ed26d44238ecaa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3072d82461f498c85daea8766e9d8bfbada31605","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3320ba068198adc144c89d6661b805acce01735b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/57f2042fd87d7ce8fc3ac8b6c176e554df68b1a7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca53bb17f4e8232cfaece3953d3cef62c559b039","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/deffa929086d7902e30918adf3dd27ccfe9c08b1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64399","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:23.397","lastModified":"2026-07-25T10:17:23.397","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE\n\nThe FSCTL_DUPLICATE_EXTENTS_TO_FILE arm of smb2_ioctl() overwrites the\ndestination file's data via vfs_clone_file_range() with neither the\nshare-level KSMBD_TREE_CONN_FLAG_WRITABLE check nor a per-handle\nfp->daccess check that the other write-bearing arms carry. A client can\noverwrite destination data on a read-only share, or from a handle opened\nwith only FILE_WRITE_ATTRIBUTES (which still yields an FMODE_WRITE filp).\nFILE_WRITE_ATTRIBUTES-only destination handle overwrote the file's data via\nthe clone. Add both checks, matching the FSCTL_SET_SPARSE permission fix;\nrequire FILE_WRITE_DATA since this writes data."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"bf460ad5958d506492de4524a656439da3f99c51","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"620d133d469295ee7c017ca6aafac335f65c4a5a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9b9cf7e65cbeaae1b6636144bacee611cdd7a5d6","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"baae7b39673ec21073a25e3d14f8feaada01d5df","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c917e4522d251071dde9871b9142d8ea1186ebfe","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"388e4139db27a9e3612c9d356b826f5b1ff6a9e3","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.39","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/388e4139db27a9e3612c9d356b826f5b1ff6a9e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/620d133d469295ee7c017ca6aafac335f65c4a5a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b9cf7e65cbeaae1b6636144bacee611cdd7a5d6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/baae7b39673ec21073a25e3d14f8feaada01d5df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf460ad5958d506492de4524a656439da3f99c51","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c917e4522d251071dde9871b9142d8ea1186ebfe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64400","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:23.510","lastModified":"2026-07-25T10:17:23.510","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: prevent path traversal bypass by restricting caseless retry\n\nksmbd_vfs_path_lookup() enforces LOOKUP_BENEATH to restrict path\nresolution within the share root. When a crafted path attempts to\nescape the share boundary using parent-directory components ('..'),\nvfs_path_parent_lookup() detects this and immediately fails,\nreturning -EXDEV.\n\nHowever, a bug exists in __ksmbd_vfs_kern_path() under caseless mode.\nThe function fails to intercept the -EXDEV error and erroneously\nfalls through to the caseless retry logic, which is intended only\nfor genuinely missing files. During this retry process, the path\nis reconstructed, leading to an unintended LOOKUP_BENEATH bypass\nthat allows write-capable users to create zero-length files or\ndirectories outside the exported share.\n\nFix this by ensuring that the execution only proceeds to the caseless\nlookup retry when the error is specifically -ENOENT. Any other errors,\nsuch as -EXDEV from a path traversal attempt, must be returned immediately."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/vfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"8c9a4f1327eb71efbf14842e7b8a6d965077eb67","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"54bab9ba5a9f156ffa9324fcbe5a356fd0242f95","versionType":"git","status":"affected"},{"version":"0","lessThan":"7.1.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/vfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/54bab9ba5a9f156ffa9324fcbe5a356fd0242f95","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8c9a4f1327eb71efbf14842e7b8a6d965077eb67","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64401","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:23.610","lastModified":"2026-07-25T10:17:23.610","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: resolve SWN tcon from live registrations\n\ncifs_swn_notify() looks up a witness registration by id under\ncifs_swnreg_idr_mutex, drops the mutex, and then uses the registration's\ncached tcon pointer.  That pointer is not a lifetime reference, and it is\nnot a stable representative once cifs_get_swn_reg() lets multiple tcons\nfor the same net/share name share one registration id.\n\nA same-share second mount can keep the cifs_swn_reg alive after the first\ntcon unregisters and is freed.  The registration then still points at the\nfreed first tcon, so taking tc_lock or incrementing tc_count through\nswnreg->tcon only moves the use-after-free earlier.  Taking tc_lock while\nholding cifs_swnreg_idr_mutex also violates the documented CIFS lock\norder.\n\nFix this by making the registration store only the stable witness\nidentity: id, net name, share name, and notify flags.  When a notify\narrives, copy that identity under cifs_swnreg_idr_mutex, drop the mutex,\nthen find and pin a live witness tcon that currently matches the net/share\npair under the normal cifs_tcp_ses_lock -> tc_lock order.  The notification\npath uses that pinned tcon directly and drops the reference when done.\n\nRegistration and unregister messages now use the live tcon passed by the\ncaller instead of a cached tcon in the registration.  The final unregister\nsend is folded into cifs_swn_unregister() while the registration is still\nprotected by cifs_swnreg_idr_mutex.  This removes the previous\nfind/drop/reacquire raw-pointer window.  The release path only removes the\nidr entry and frees the stable identity strings.\n\nThis preserves the intended one-registration/many-tcon behavior: a\nregistration id represents a net/share pair, and notify handling acts on a\nlive representative selected at use time.  It also preserves CLIENT_MOVE\nordering for the representative tcon because the old-IP unregister is sent\nbefore cifs_swn_register() sends the new-IP register."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/client/cifs_swn.c","fs/smb/client/trace.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fed979a7e082bd9f25f9002c3c4f8740dacd0bc8","lessThan":"51d18db392e5386a7bb9e816d611f14e600cca3c","versionType":"git","status":"affected"},{"version":"fed979a7e082bd9f25f9002c3c4f8740dacd0bc8","lessThan":"aa3c0cab4b28c5007ec570c63e1d6ad6943ed0fd","versionType":"git","status":"affected"},{"version":"fed979a7e082bd9f25f9002c3c4f8740dacd0bc8","lessThan":"945b4a4a54497db1dcb2f20ef801a84e884dac21","versionType":"git","status":"affected"},{"version":"fed979a7e082bd9f25f9002c3c4f8740dacd0bc8","lessThan":"91b8a58c6ac15c7db6518f696389933282f88da7","versionType":"git","status":"affected"},{"version":"fed979a7e082bd9f25f9002c3c4f8740dacd0bc8","lessThan":"0700f946659d0ab2352ec8a9b1c6fc74b13a27d7","versionType":"git","status":"affected"},{"version":"fed979a7e082bd9f25f9002c3c4f8740dacd0bc8","lessThan":"ec457f9afe5ae9538bdcd58fd4cb442b9787e183","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/client/cifs_swn.c","fs/smb/client/trace.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.11","status":"affected"},{"version":"0","lessThan":"5.11","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0700f946659d0ab2352ec8a9b1c6fc74b13a27d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/51d18db392e5386a7bb9e816d611f14e600cca3c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/91b8a58c6ac15c7db6518f696389933282f88da7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/945b4a4a54497db1dcb2f20ef801a84e884dac21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aa3c0cab4b28c5007ec570c63e1d6ad6943ed0fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ec457f9afe5ae9538bdcd58fd4cb442b9787e183","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64402","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:23.737","lastModified":"2026-07-25T10:17:23.737","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncoresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()\n\nWhen the SMB sink is used as a perf AUX sink, smb_update_buffer() calls\nsmb_sync_perf_buffer() to copy hardware trace data into the perf AUX ring\nbuffer pages. It derives pg_idx = head >> PAGE_SHIFT from @head, which is\nhandle->head, and indexes dst_pages[pg_idx]. The pg_idx %= nr_pages\nnormalization is only applied after the first loop iteration.\n\nThis leaves the initial page index underived from the buffer size, which\ncan result in an out-of-bounds write past dst_pages[] when head exceeds\nthe AUX buffer size.\n\nNormalize head modulo the AUX buffer size before deriving the page index\nand offset, mirroring tmc_etr_sync_perf_buffer()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hwtracing/coresight/ultrasoc-smb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"06f5c2926aaa0fba7f99678da6ef77cbbbda1441","lessThan":"38dbc8db8341ccdf8e1e1a067453d33ad751864b","versionType":"git","status":"affected"},{"version":"06f5c2926aaa0fba7f99678da6ef77cbbbda1441","lessThan":"4c5a0a946373da99a80398289b28845b5ae40cd1","versionType":"git","status":"affected"},{"version":"06f5c2926aaa0fba7f99678da6ef77cbbbda1441","lessThan":"661a019ac0413ecec9e5d1dfcc12fbca8e78d5fb","versionType":"git","status":"affected"},{"version":"06f5c2926aaa0fba7f99678da6ef77cbbbda1441","lessThan":"daf6246ab988fc8bdc82ad7c8d0b1c182d11b15f","versionType":"git","status":"affected"},{"version":"06f5c2926aaa0fba7f99678da6ef77cbbbda1441","lessThan":"98495b5a4d77dd22e106f462b76e1093a55b29a7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hwtracing/coresight/ultrasoc-smb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.3","status":"affected"},{"version":"0","lessThan":"6.3","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/38dbc8db8341ccdf8e1e1a067453d33ad751864b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4c5a0a946373da99a80398289b28845b5ae40cd1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/661a019ac0413ecec9e5d1dfcc12fbca8e78d5fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/98495b5a4d77dd22e106f462b76e1093a55b29a7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/daf6246ab988fc8bdc82ad7c8d0b1c182d11b15f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64403","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:23.850","lastModified":"2026-07-25T10:17:23.850","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: validate option length before reading conf opt value\n\nl2cap_get_conf_opt() derives the option length from the\nattacker-controlled opt->len field and immediately dereferences\nopt->val (as u8, get_unaligned_le16() or get_unaligned_le32(), or a\nraw pointer for the default case) before any caller has confirmed\nthat opt->len bytes are present in the buffer. The callers\n(l2cap_parse_conf_req(), l2cap_parse_conf_rsp() and\nl2cap_conf_rfc_get()) only detect a malformed option afterwards, once\nthe running length has gone negative, by which point the\nout-of-bounds read has already executed.\n\nAn existing post-hoc length check keeps the garbage value from being\nconsumed, so this is not a data leak in the current control flow. It\nis still a validate-after-use ordering bug: up to 4 bytes are read\npast the end of the buffer before it is known to contain them, and it\nis fragile to future changes in the callers.\n\nFix it at the source. Pass the end of the buffer into\nl2cap_get_conf_opt() and refuse to touch opt->val unless the full\noption (header + value) fits. Each caller computes an end pointer\nonce before the loop and checks the return value directly instead of\ninferring the error from a negative length."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/l2cap_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7c9cbd0b5e38a1672fcd137894ace3b042dfbf69","lessThan":"cca81b4bc672604a84f6d224a55cc77ec7dee619","versionType":"git","status":"affected"},{"version":"7c9cbd0b5e38a1672fcd137894ace3b042dfbf69","lessThan":"f70d4aa88068096f35d73e3a05eff33c0a16b9cd","versionType":"git","status":"affected"},{"version":"7c9cbd0b5e38a1672fcd137894ace3b042dfbf69","lessThan":"7d871e969b941ce25653f7716203a0ea4d07ad4b","versionType":"git","status":"affected"},{"version":"7c9cbd0b5e38a1672fcd137894ace3b042dfbf69","lessThan":"98d93c226bdfaa79bbdd86981921d7f106374225","versionType":"git","status":"affected"},{"version":"7c9cbd0b5e38a1672fcd137894ace3b042dfbf69","lessThan":"996d3da39899aceb8f4910911a3f19a45a7d9d1b","versionType":"git","status":"affected"},{"version":"7c9cbd0b5e38a1672fcd137894ace3b042dfbf69","lessThan":"73abbaf91aa33da87c008fb62c148ade561bb606","versionType":"git","status":"affected"},{"version":"7c9cbd0b5e38a1672fcd137894ace3b042dfbf69","lessThan":"6b47bdaacfd0045687880177e0987055d8f4765a","versionType":"git","status":"affected"},{"version":"7c9cbd0b5e38a1672fcd137894ace3b042dfbf69","lessThan":"687617555cedfb74c9e3cb85d759b908dcb17856","versionType":"git","status":"affected"},{"version":"78c2887130f1a7d1883195732be1b6cdab667487","versionType":"git","status":"affected"},{"version":"ac7c597c465eb09391e40febbe088bdad601080b","versionType":"git","status":"affected"},{"version":"ade4560e4fea198866e033fe1c02f063d6d7db2e","versionType":"git","status":"affected"},{"version":"99665dcf6ff803351b5e658f3a929cb498561e36","versionType":"git","status":"affected"},{"version":"2b59d36f22622c92c0b06aee7571f0a86a217188","versionType":"git","status":"affected"},{"version":"15d6538a0d6e0f6de5116081a948cba7cc3e1d3d","versionType":"git","status":"affected"},{"version":"a556547bae00528f24b42786b41a14047db14b84","versionType":"git","status":"affected"},{"version":"3.16.66","lessThan":"3.17","versionType":"semver","status":"affected"},{"version":"3.18.138","lessThan":"3.19","versionType":"semver","status":"affected"},{"version":"4.4.178","lessThan":"4.5","versionType":"semver","status":"affected"},{"version":"4.9.167","lessThan":"4.10","versionType":"semver","status":"affected"},{"version":"4.14.110","lessThan":"4.15","versionType":"semver","status":"affected"},{"version":"4.19.33","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.0.6","lessThan":"5.1","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/l2cap_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.1","status":"affected"},{"version":"0","lessThan":"5.1","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/687617555cedfb74c9e3cb85d759b908dcb17856","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b47bdaacfd0045687880177e0987055d8f4765a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/73abbaf91aa33da87c008fb62c148ade561bb606","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d871e969b941ce25653f7716203a0ea4d07ad4b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/98d93c226bdfaa79bbdd86981921d7f106374225","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/996d3da39899aceb8f4910911a3f19a45a7d9d1b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cca81b4bc672604a84f6d224a55cc77ec7dee619","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f70d4aa88068096f35d73e3a05eff33c0a16b9cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64404","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:24.003","lastModified":"2026-07-25T10:17:24.003","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync()\n\niso_conn_big_sync() drops the socket lock to call hci_get_route() and\nthen re-acquires it, but dereferences iso_pi(sk)->conn->hcon afterwards\nwithout re-checking that conn is still valid.\n\nWhile the lock is dropped, the connection can be torn down under the\nsame socket lock: iso_disconn_cfm() -> iso_conn_del() -> iso_chan_del()\nsets iso_pi(sk)->conn to NULL (and the broadcast teardown path can also\nclear conn->hcon on its own). When iso_conn_big_sync() re-acquires the\nlock and reads conn->hcon, conn may be NULL, causing a NULL pointer\ndereference (hcon is the first member of struct iso_conn).\n\nThis path is reached from iso_sock_recvmsg() for a PA-sync broadcast\nsink socket (BT_SK_DEFER_SETUP | BT_SK_PA_SYNC), so the dropped-lock\nwindow can race with connection teardown driven by controller events.\n\nRe-validate iso_pi(sk)->conn and its hcon after re-acquiring the socket\nlock and bail out if the connection went away, as already done in the\nsibling iso_sock_rebind_bc()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/iso.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cbe640d6cae590b9a7d81ce86fe9a90e83eec1d5","lessThan":"b3e647a4aa4d2d054f86a783f5c426035e1dc237","versionType":"git","status":"affected"},{"version":"7a17308c17880d259105f6e591eb1bc77b9612f0","lessThan":"b84eeb7636d6962dd882d5e0b31475e4f404313c","versionType":"git","status":"affected"},{"version":"7a17308c17880d259105f6e591eb1bc77b9612f0","lessThan":"01afd198c2c286cd3b81f44d4e33a2e638711550","versionType":"git","status":"affected"},{"version":"7a17308c17880d259105f6e591eb1bc77b9612f0","lessThan":"d5541eb148da72d5e0a1bca8ecd171f9fc8b366f","versionType":"git","status":"affected"},{"version":"6.12.6","lessThan":"6.12.96","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/iso.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/01afd198c2c286cd3b81f44d4e33a2e638711550","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b3e647a4aa4d2d054f86a783f5c426035e1dc237","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b84eeb7636d6962dd882d5e0b31475e4f404313c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d5541eb148da72d5e0a1bca8ecd171f9fc8b366f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64405","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:24.110","lastModified":"2026-07-25T10:17:24.110","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()\n\nhci_abort_conn() read hci_skb_event(hdev->sent_cmd) when a connection\nwas pending, but hdev->sent_cmd can be NULL while req_status is still\nHCI_REQ_PEND, leading to a NULL pointer dereference and a general\nprotection fault from the hci_rx_work() receive path.\n\nInstead of inspecting hdev->sent_cmd, track the in-flight create\nconnection command with a new per-connection HCI_CONN_CREATE flag and\nroute all cancellation through hci_cancel_connect_sync(), which\ndispatches to a dedicated per-type cancel function. The create command\nis in exactly one of two states: still queued, or in flight. The cancel\nfunction holds cmd_sync_work_lock across the whole decision: the worker\ntakes this lock to dequeue every entry, so while it is held a queued\ncommand cannot start running and an in-flight command cannot complete\nand let the next command become pending. This keeps the flag test and\nhci_cmd_sync_cancel() atomic with respect to the worker, so a queued\ncommand is simply dequeued, and an in-flight command owned by this\nconnection is cancelled without the risk of cancelling an unrelated\ncommand that became pending in the meantime. CIS uses the same flag\nmechanism via HCI_CONN_CREATE_CIS but cannot be dequeued per-connection.\n\nhci_acl_create_conn_sync() and hci_le_create_conn_sync() clear\nHCI_CONN_CREATE after the create command completes, but the command\nstatus handler can free conn via hci_conn_del() (for example when the\ncontroller rejects the connection) while the worker is still blocked on\nthe connection complete event. Hold a reference on conn across the\ncreate command so the flag can be cleared without a use-after-free."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/bluetooth/hci_core.h","net/bluetooth/hci_conn.c","net/bluetooth/hci_sync.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6083089ab00631617f9eac678df3ab050a9d837a","lessThan":"903227b6168bb99fd57d4e3c9c1b5014986198e0","versionType":"git","status":"affected"},{"version":"a13f316e90fdb1fb6df6582e845aa9b3270f3581","lessThan":"83b22d7f7c384564fa42c3cf19bec715c693d7a2","versionType":"git","status":"affected"},{"version":"a13f316e90fdb1fb6df6582e845aa9b3270f3581","lessThan":"70c397b62ee015e19b3924d9da741c8dda017819","versionType":"git","status":"affected"},{"version":"a13f316e90fdb1fb6df6582e845aa9b3270f3581","lessThan":"61701912c58a05f6a043f097cc177a964abef348","versionType":"git","status":"affected"},{"version":"a13f316e90fdb1fb6df6582e845aa9b3270f3581","lessThan":"b42cb640a0493d16b61ddd267420274be15efdc1","versionType":"git","status":"affected"},{"version":"a13f316e90fdb1fb6df6582e845aa9b3270f3581","lessThan":"12917f591cea1af36087dba5b9ec888652f0b42a","versionType":"git","status":"affected"},{"version":"e4511a67fcdba9729d1c7cfc6d2e645c765ce801","versionType":"git","status":"affected"},{"version":"4ab81f16c68a602b2b69e333ae08d8748a9398de","versionType":"git","status":"affected"},{"version":"6.1.83","lessThan":"6.1.118","versionType":"semver","status":"affected"},{"version":"6.4.16","lessThan":"6.5","versionType":"semver","status":"affected"},{"version":"6.5.3","lessThan":"6.6","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/bluetooth/hci_core.h","net/bluetooth/hci_conn.c","net/bluetooth/hci_sync.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","versionType":"semver","status":"unaffected"},{"version":"6.1.118","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/12917f591cea1af36087dba5b9ec888652f0b42a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/61701912c58a05f6a043f097cc177a964abef348","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/70c397b62ee015e19b3924d9da741c8dda017819","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/83b22d7f7c384564fa42c3cf19bec715c693d7a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/903227b6168bb99fd57d4e3c9c1b5014986198e0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b42cb640a0493d16b61ddd267420274be15efdc1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64406","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:24.243","lastModified":"2026-07-25T10:17:24.243","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: fix UAF in bt_accept_dequeue()\n\nbt_accept_get() takes a temporary reference before dropping the accept\nqueue lock. bt_accept_dequeue() currently drops that reference before\nbt_accept_unlink(), leaving only the queue reference.\n\nbt_accept_unlink() drops the queue reference. The subsequent\nsock_hold() therefore accesses freed memory if it was the final\nreference, as observed by KASAN during listening L2CAP socket cleanup.\n\nRetain the temporary queue-walk reference through unlink and hand it to\nthe caller on success. Drop it explicitly on the closed and\nnot-yet-connected paths."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/af_bluetooth.c","net/bluetooth/l2cap_sock.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"751de6ec671fe75ad9cf65a0638d2a06b6a5984d","lessThan":"c0577c55219be42b6ea2ea8db11e85bfab6f4e8d","versionType":"git","status":"affected"},{"version":"407217734835d21d4e0105ebf347860dc1806f88","lessThan":"96ad400d5132eb333f28f6f1e2d58f0728ca9547","versionType":"git","status":"affected"},{"version":"7eebd4c2c86f573af87ff165d08a83432eb0b919","lessThan":"0a98ff4e7b867f72fbb4e1237d81e9fa02ded0a0","versionType":"git","status":"affected"},{"version":"5d86d2f1b4d9a508c441d3e45277ae1a73cfed57","lessThan":"c66a95e60b65d876a927123b0ed36bd6177d9ca6","versionType":"git","status":"affected"},{"version":"87c543e2f78d0871f271df92dab98901bbd5b6f5","lessThan":"6303ed4bbe0095f4cc195225479bf506e010d1db","versionType":"git","status":"affected"},{"version":"added1213395071470a900cc845a042fb51882a6","lessThan":"26168db1ce5a9766cde021b18e590a101c056614","versionType":"git","status":"affected"},{"version":"ab1513597c6cf17cd1ad2a21e3b045421b48e022","lessThan":"50c662bdcd51b03033a0abed6716bfd377ba1049","versionType":"git","status":"affected"},{"version":"ab1513597c6cf17cd1ad2a21e3b045421b48e022","lessThan":"4bd0b274054f2679f28b70222b607bb0afc3ab9a","versionType":"git","status":"affected"},{"version":"a5ca86a6097a8b030ca3226cd300b17ed330f966","versionType":"git","status":"affected"},{"version":"5.10.259","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.15.210","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.175","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.142","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.92","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"6.18.34","lessThan":"6.18.39","versionType":"semver","status":"affected"},{"version":"7.0.11","lessThan":"7.1","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/af_bluetooth.c","net/bluetooth/l2cap_sock.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0a98ff4e7b867f72fbb4e1237d81e9fa02ded0a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/26168db1ce5a9766cde021b18e590a101c056614","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4bd0b274054f2679f28b70222b607bb0afc3ab9a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/50c662bdcd51b03033a0abed6716bfd377ba1049","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6303ed4bbe0095f4cc195225479bf506e010d1db","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/96ad400d5132eb333f28f6f1e2d58f0728ca9547","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c0577c55219be42b6ea2ea8db11e85bfab6f4e8d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c66a95e60b65d876a927123b0ed36bd6177d9ca6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64407","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:24.407","lastModified":"2026-07-25T10:17:24.407","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3()\n\nDuring the v3 firmware download the controller sends a v3_data_req with a\n32 bit offset and a 16 bit len. nxp_recv_fw_req_v3() checks only the lower\nbound of the offset and then sends firmware from that offset.\n\n  nxpdev->fw_dnld_v3_offset = offset - nxpdev->fw_v3_offset_correction;\n  serdev_device_write_buf(nxpdev->serdev, nxpdev->fw->data +\n                          nxpdev->fw_dnld_v3_offset, len);\n\nNothing checks that fw_dnld_v3_offset + len stays within nxpdev->fw->size,\nso a controller that asks for an offset or length past the firmware image\nmakes the driver read past the end of nxpdev->fw->data and send that\nmemory back over UART.\n\nnxp_recv_fw_req_v1() already bounds the same write. Add the equivalent\ncheck to the v3 path, reject the request when it falls outside the firmware\nimage, and zero len on the error path so the fw_v3_prev_sent bookkeeping at\nfree_skb stays consistent."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/bluetooth/btnxpuart.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"689ca16e523278470c38832a3010645a78c544d8","lessThan":"21e60eb4d95854196e7c0e77383f35e7ac95df61","versionType":"git","status":"affected"},{"version":"689ca16e523278470c38832a3010645a78c544d8","lessThan":"441088792ffec3ca01f4efe2934060570eb11eb8","versionType":"git","status":"affected"},{"version":"689ca16e523278470c38832a3010645a78c544d8","lessThan":"2a68a773089204af1c8581dc79668b775418c5ee","versionType":"git","status":"affected"},{"version":"689ca16e523278470c38832a3010645a78c544d8","lessThan":"49bcb39e3a041ce26021f77971eaccb49a275118","versionType":"git","status":"affected"},{"version":"689ca16e523278470c38832a3010645a78c544d8","lessThan":"badff6c3bed8923a1257a853f137d447976eec30","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/bluetooth/btnxpuart.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/21e60eb4d95854196e7c0e77383f35e7ac95df61","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2a68a773089204af1c8581dc79668b775418c5ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/441088792ffec3ca01f4efe2934060570eb11eb8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/49bcb39e3a041ce26021f77971eaccb49a275118","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/badff6c3bed8923a1257a853f137d447976eec30","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64408","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:24.517","lastModified":"2026-07-25T10:17:24.517","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: bnep: pin L2CAP connection during netdev registration\n\nbnep_add_connection() reads the L2CAP connection without holding the\nchannel lock, then passes its HCI device to register_netdev(). Controller\nteardown can clear and release that connection concurrently, leaving the\nnetwork device registration path to dereference a freed parent device.\n\nTake a reference to the L2CAP connection while holding the channel lock.\nRetain it until register_netdev() has taken the parent device reference."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/bnep/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"65f53e9802dbfae0e5758a91793c3f5f8bece49b","lessThan":"390b5db3ff8745187f094c4e915663b7b1f98944","versionType":"git","status":"affected"},{"version":"65f53e9802dbfae0e5758a91793c3f5f8bece49b","lessThan":"46a88784c4c9b96954dd86f747ce93f65efa1302","versionType":"git","status":"affected"},{"version":"65f53e9802dbfae0e5758a91793c3f5f8bece49b","lessThan":"551ae773ec64045b4e72099132654887e0270bcc","versionType":"git","status":"affected"},{"version":"65f53e9802dbfae0e5758a91793c3f5f8bece49b","lessThan":"ae215c5b6422d8eda443b861b124bd1be6969c31","versionType":"git","status":"affected"},{"version":"65f53e9802dbfae0e5758a91793c3f5f8bece49b","lessThan":"df22adc7eafc22e651561813c11dc51a796b12ee","versionType":"git","status":"affected"},{"version":"65f53e9802dbfae0e5758a91793c3f5f8bece49b","lessThan":"a6b22dbd80926556290ad2243be25218d6956a19","versionType":"git","status":"affected"},{"version":"65f53e9802dbfae0e5758a91793c3f5f8bece49b","lessThan":"563a8573047182f550b1e1e030615755cd8c41da","versionType":"git","status":"affected"},{"version":"65f53e9802dbfae0e5758a91793c3f5f8bece49b","lessThan":"bb067a99a0356196c0b89a95721985485ebce5a5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/bnep/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.13","status":"affected"},{"version":"0","lessThan":"3.13","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/390b5db3ff8745187f094c4e915663b7b1f98944","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/46a88784c4c9b96954dd86f747ce93f65efa1302","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/551ae773ec64045b4e72099132654887e0270bcc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/563a8573047182f550b1e1e030615755cd8c41da","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a6b22dbd80926556290ad2243be25218d6956a19","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae215c5b6422d8eda443b861b124bd1be6969c31","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb067a99a0356196c0b89a95721985485ebce5a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/df22adc7eafc22e651561813c11dc51a796b12ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64409","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:24.633","lastModified":"2026-07-25T10:17:24.633","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()\n\nEvery once in a while we see a hung btmtksdio_flush() task:\n\n INFO: task kworker/u17:0:189 blocked for more than 122 seconds.\n __cancel_work_timer+0x3f4/0x460\n cancel_work_sync+0x1c/0x2c\n btmtksdio_flush+0x2c/0x40\n hci_dev_open_sync+0x10c4/0x2190\n [..]\n\nIt all boils down to incorrect time_is_before_jiffies() usage in\nbtmtksdio_txrx_work().  The btmtksdio_txrx_work() loop is expected\nto be terminated if running for longer than 5*HZ.  However the\ntimeout check is twisted:  time_is_before_jiffies(old_jiffies + 5*HZ)\nevaluates to true when old_jiffies + 5*HZ is in the past i.e. when a\ntimeout has occurred.  Using OR with time_is_before_jiffies(txrx_timeout)\nmeans that:\n- before the 5-second timeout: the condition is `int_status || false`,\n  so it loops as long as there are pending interrupts.\n- after the 5-second timeout: the condition becomes `int_status || true`,\n  which is always true.\n\nWhen the loop becomes infinite btmtksdio_txrx_work() loop never\nterminates and never releases the SDIO host.\n\nFix loop termination condition to actually enforce a 5*HZ timeout."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/bluetooth/btmtksdio.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"26270bc189ea4b5a8356ec99561357fc87f00b32","lessThan":"f6682c23b6fac4780d297ae4662053d17e58fd52","versionType":"git","status":"affected"},{"version":"26270bc189ea4b5a8356ec99561357fc87f00b32","lessThan":"466540e045d01fcacf383a5beb8a2dad2fc53a26","versionType":"git","status":"affected"},{"version":"26270bc189ea4b5a8356ec99561357fc87f00b32","lessThan":"7b429d611060e87752e848851815537963726493","versionType":"git","status":"affected"},{"version":"26270bc189ea4b5a8356ec99561357fc87f00b32","lessThan":"0039bdde36b23ccf1196635f1d52c5490481544d","versionType":"git","status":"affected"},{"version":"26270bc189ea4b5a8356ec99561357fc87f00b32","lessThan":"0f0a83e26a9c7fd4b243c315ce07161d2496d83d","versionType":"git","status":"affected"},{"version":"26270bc189ea4b5a8356ec99561357fc87f00b32","lessThan":"a257407e2bbbb099ed427719a50563f67fa366d8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/bluetooth/btmtksdio.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0039bdde36b23ccf1196635f1d52c5490481544d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0f0a83e26a9c7fd4b243c315ce07161d2496d83d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/466540e045d01fcacf383a5beb8a2dad2fc53a26","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7b429d611060e87752e848851815537963726493","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a257407e2bbbb099ed427719a50563f67fa366d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f6682c23b6fac4780d297ae4662053d17e58fd52","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64410","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:24.753","lastModified":"2026-07-25T10:17:24.753","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: IPIP tunnel hardware offload is not yet support\n\nNo driver supports for IPIP tunnels yet, give up early on setting up the\nhardware offload for this scenario.\n\nThis patch adds a stub that can be enhanced to add more configuration\nthat are currently not supported. As of now, the offload work is\nenqueued to the worker, then ignored if the hardware offload\nconfiguration is not supported.\n\nCheck the NF_FLOW_HW flag to know if this entry was already tried once\nto be offloaded so this is not retried on refresh when unsupported. Move\nNF_FLOW_HW flag check to nf_flow_offload_add(). If this NF_FLOW_HW flag\nis unset the _del and _stats variants are never called.\n\nThis can be updated later on to skip hardware offload work to be queued\nin case hardware offload does not support it."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/netfilter/nf_flow_table.h","net/netfilter/nf_flow_table_core.c","net/netfilter/nf_flow_table_offload.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ab427db17885814069bae891834f20842f0ac3a4","lessThan":"9efe838c13133acb70c78d04c49e8362fe533566","versionType":"git","status":"affected"},{"version":"ab427db17885814069bae891834f20842f0ac3a4","lessThan":"6c5dcab95f4cd42a1648739ec9300fbb4b1a021f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/netfilter/nf_flow_table.h","net/netfilter/nf_flow_table_core.c","net/netfilter/nf_flow_table_offload.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6c5dcab95f4cd42a1648739ec9300fbb4b1a021f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9efe838c13133acb70c78d04c49e8362fe533566","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64411","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:24.853","lastModified":"2026-07-25T10:17:24.853","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ebtables: terminate table name before find_table_lock()\n\nupdate_counters() and compat_update_counters() forward a user-supplied\n32-byte table name to find_table_lock() without NUL-terminating it. On a\nlookup miss, find_inlist_lock() calls try_then_request_module(..., \"%s%s\",\n\"ebtable_\", name), and vsnprintf() reads past the name field and the\nstack object until it hits a zero byte.\n\n  BUG: KASAN: stack-out-of-bounds in string (lib/vsprintf.c:648 lib/vsprintf.c:730)\n  Read of size 1 at addr ffff8880119dfb20 by task exploit/147\n  Call Trace:\n  ...\n   string (lib/vsprintf.c:648 lib/vsprintf.c:730)\n   vsnprintf (lib/vsprintf.c:2945)\n   __request_module (kernel/module/kmod.c:150)\n   do_update_counters.isra.0 (net/bridge/netfilter/ebtables.c:371 net/bridge/netfilter/ebtables.c:380)\n   update_counters (net/bridge/netfilter/ebtables.c:1440)\n   do_ebt_set_ctl (net/bridge/netfilter/ebtables.c:2573)\n   nf_setsockopt (net/netfilter/nf_sockopt.c:101)\n   ip_setsockopt (net/ipv4/ip_sockglue.c:1424)\n   raw_setsockopt (net/ipv4/raw.c:847)\n   __sys_setsockopt (net/socket.c:2393)\n  ...\n\ncompat_do_replace() shares the same unterminated name via\ncompat_copy_ebt_replace_from_user(); terminate it there too so all\nfind_table_lock() callers behave alike. The other callers already\nterminate the name after the copy."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bridge/netfilter/ebtables.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"4c046ca4e35a83ea32f6e748f54139f5fe2a1d01","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ab63ccefb9c71627f957a0724c2b9ebc869c6f20","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c6f539311e58e76aa96feef0f1572b13a564f8a2","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2664f537ca5bcb2ef3fac2683dcca602e51fad24","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7436da6c1bc44654b7f11a17e746f6999fd37250","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6fe8d3cecd20bfaaaf440db3a06ba674d2f2e322","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b6183b1b88a722b6d8ea0cecc99eba168a15e0be","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a622d2e9608c9dff47fc2e5759ac7aa3a836b45d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bridge/netfilter/ebtables.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2664f537ca5bcb2ef3fac2683dcca602e51fad24","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4c046ca4e35a83ea32f6e748f54139f5fe2a1d01","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6fe8d3cecd20bfaaaf440db3a06ba674d2f2e322","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7436da6c1bc44654b7f11a17e746f6999fd37250","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a622d2e9608c9dff47fc2e5759ac7aa3a836b45d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ab63ccefb9c71627f957a0724c2b9ebc869c6f20","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6183b1b88a722b6d8ea0cecc99eba168a15e0be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c6f539311e58e76aa96feef0f1572b13a564f8a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64412","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:24.990","lastModified":"2026-07-25T10:17:24.990","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ebtables: module names must be null-terminated\n\nWe need to explicitly check the length, else we may pass non-null\nterminated string to request_module()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bridge/netfilter/ebtables.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bcf4934288402be3464110109a4dae3bd6fb3e93","lessThan":"43dd2332b8a27b3ac5108791680cade654ab0f96","versionType":"git","status":"affected"},{"version":"bcf4934288402be3464110109a4dae3bd6fb3e93","lessThan":"5777c8f1c3610786d8482b8f620f40fccaf1542b","versionType":"git","status":"affected"},{"version":"bcf4934288402be3464110109a4dae3bd6fb3e93","lessThan":"0ddca0f90fa3395111d078ae4399615cf3ea94aa","versionType":"git","status":"affected"},{"version":"bcf4934288402be3464110109a4dae3bd6fb3e93","lessThan":"d2367d99f2455f373996d9ddbe833dbe9f942213","versionType":"git","status":"affected"},{"version":"bcf4934288402be3464110109a4dae3bd6fb3e93","lessThan":"da32e78bbb187ed7b137e0007034185570a3a172","versionType":"git","status":"affected"},{"version":"bcf4934288402be3464110109a4dae3bd6fb3e93","lessThan":"13a5f532e3a4fc75c33060a026def1572c208643","versionType":"git","status":"affected"},{"version":"bcf4934288402be3464110109a4dae3bd6fb3e93","lessThan":"7b217960e88b5d2d1e8cdcbcaf3bdf6fe199a0c8","versionType":"git","status":"affected"},{"version":"bcf4934288402be3464110109a4dae3bd6fb3e93","lessThan":"084d23f818321390509e9738a0b08bbf46df6425","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bridge/netfilter/ebtables.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.6","status":"affected"},{"version":"0","lessThan":"4.6","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/084d23f818321390509e9738a0b08bbf46df6425","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0ddca0f90fa3395111d078ae4399615cf3ea94aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/13a5f532e3a4fc75c33060a026def1572c208643","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/43dd2332b8a27b3ac5108791680cade654ab0f96","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5777c8f1c3610786d8482b8f620f40fccaf1542b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7b217960e88b5d2d1e8cdcbcaf3bdf6fe199a0c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2367d99f2455f373996d9ddbe833dbe9f942213","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/da32e78bbb187ed7b137e0007034185570a3a172","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64413","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:25.110","lastModified":"2026-07-25T10:17:25.110","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ebtables: zero chainstack array\n\nsashiko reports:\n looking at ebtables table\n translation, could a sparse cpu_possible_mask lead to an uninitialized pointer\n free?\n\n If cpu_possible_mask is sparse (for example, CPU 0 and CPU 2 are possible,\n but CPU 1 is not), the allocation loop skips CPU 1. If vmalloc_node() fails at\n CPU 2, the cleanup loop will blindly decrement and call vfree() on\n newinfo->chainstack[1].\n\nNot a real-world bug, such allocation isn't expected to fail\nin the first place."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bridge/netfilter/ebtables.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2ade612967e2cdfb9290ebcb773f302c82f311fa","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"42bef500d07b5769d916e9122a3e3fa3fd2245ef","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"fc7f105451044501a50cfd530cfa3b472c54acbc","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9e6c5169db423e51dcc66a73fd15409c0d38e088","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"29bf41a9b59aff9f6197df58641a00037d567ca8","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9f74d28e903fa4fdf82f870d0aeadddc8196e41c","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5ee856e4208acafaaaf7b84824d39b78c21345d6","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"cbfe53599eebffd188938ab6774cc41794f6f9d5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bridge/netfilter/ebtables.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/29bf41a9b59aff9f6197df58641a00037d567ca8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2ade612967e2cdfb9290ebcb773f302c82f311fa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/42bef500d07b5769d916e9122a3e3fa3fd2245ef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5ee856e4208acafaaaf7b84824d39b78c21345d6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9e6c5169db423e51dcc66a73fd15409c0d38e088","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f74d28e903fa4fdf82f870d0aeadddc8196e41c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cbfe53599eebffd188938ab6774cc41794f6f9d5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc7f105451044501a50cfd530cfa3b472c54acbc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64414","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:25.237","lastModified":"2026-07-25T10:17:25.237","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: handle unreadable frags\n\nsashiko reports:\n When an skb with unreadable fragments (such as from devmem TCP, where\n skb_frags_readable(skb) returns false) is processed by the u32 module,\n skb_copy_bits() will safely return a negative error code [..]\n\nxt_u32: bail out with hotdrop in this case.\ngather_frags: return -1, just as if we had no fragment header.\nnfnetlink_queue: restrict to the linear part.\nnfnetlink_log: restrict to the linear part.\n\nv2:\n - skb_zerocopy helpers don't copy readable flag, i.e. nfnetlink_queue\n is broken too\n xt_u32 shouldn't return true if hotdrop was set."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/netfilter/nf_conntrack_reasm.c","net/netfilter/nfnetlink_log.c","net/netfilter/nfnetlink_queue.c","net/netfilter/xt_u32.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"65249feb6b3df9e17bab5911ee56fa7b0971e231","lessThan":"3b13e7635795394705920cca1e1db7e4ca2e334b","versionType":"git","status":"affected"},{"version":"65249feb6b3df9e17bab5911ee56fa7b0971e231","lessThan":"fc5bfe63bacf8a3ae307b62b34206406ca733354","versionType":"git","status":"affected"},{"version":"65249feb6b3df9e17bab5911ee56fa7b0971e231","lessThan":"57056be3ec12e7d9ecd20a60d4060f510e4f284c","versionType":"git","status":"affected"},{"version":"65249feb6b3df9e17bab5911ee56fa7b0971e231","lessThan":"da5b58478a9c1b85608c9e40a3b8432d071b409e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/netfilter/nf_conntrack_reasm.c","net/netfilter/nfnetlink_log.c","net/netfilter/nfnetlink_queue.c","net/netfilter/xt_u32.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3b13e7635795394705920cca1e1db7e4ca2e334b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/57056be3ec12e7d9ecd20a60d4060f510e4f284c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/da5b58478a9c1b85608c9e40a3b8432d071b409e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc5bfe63bacf8a3ae307b62b34206406ca733354","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64415","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:25.343","lastModified":"2026-07-25T10:17:25.343","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup\n\nWe hit a real softlockup in an internal stress test environment.  The\nworkload was LTP memory/swap stress on a large arm64 machine, with 320\nCPUs, about 1TB memory and an 8.6GB swap device.  The system was under\nheavy load and the swap device had a large number of full clusters.  The\nsoftlockup was triggered during a stress test after about 3 days.\n\nSo, add periodic cond_resched() calls during large full_clusters\nreclaim operations to prevent softlockup issues.\n\nDetailed call trace as follow:\n\nPID: 3817773  TASK: ffff0883bb28b780  CPU: 48   COMMAND: \"kworker/48:7\"\n   #0 [ffff800080183d10] __crash_kexec at ffffa4c1361e5de4\n   #1 [ffff800080183d90] panic at ffffa4c1360d5e9c\n   #2 [ffff800080183e20] watchdog_timer_fn at ffffa4c136231fa8\n   ...\n  #16 [ffff8000c4ad3cb0] swap_cache_del_folio at ffffa4c1363e1614\n  #17 [ffff8000c4ad3ce0] __try_to_reclaim_swap at ffffa4c1363e4bfc\n  #18 [ffff8000c4ad3d40] swap_reclaim_full_clusters at ffffa4c1363e5474\n  #19 [ffff8000c4ad3da0] swap_reclaim_work at ffffa4c1363e550c\n  #20 [ffff8000c4ad3dc0] process_one_work at ffffa4c136102edc\n  #21 [ffff8000c4ad3e10] worker_thread at ffffa4c136103398\n  #22 [ffff8000c4ad3e70] kthread at ffffa4c13610d95c"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/swapfile.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5168a68eb78fa1c67a8b2d31d0642c7fd866cc12","lessThan":"60cbe67d1342f34b66df1c2ee328e3cd333767d7","versionType":"git","status":"affected"},{"version":"5168a68eb78fa1c67a8b2d31d0642c7fd866cc12","lessThan":"69c0e6246575b780ae0d3f411c749bcf13c221f3","versionType":"git","status":"affected"},{"version":"5168a68eb78fa1c67a8b2d31d0642c7fd866cc12","lessThan":"2a55fdf9f746a1a6ced7fd62ea1080b8a917e0b0","versionType":"git","status":"affected"},{"version":"5168a68eb78fa1c67a8b2d31d0642c7fd866cc12","lessThan":"66366d291f666ddeda5f8c84f253e308de3e6b55","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/swapfile.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2a55fdf9f746a1a6ced7fd62ea1080b8a917e0b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/60cbe67d1342f34b66df1c2ee328e3cd333767d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/66366d291f666ddeda5f8c84f253e308de3e6b55","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/69c0e6246575b780ae0d3f411c749bcf13c221f3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64416","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:25.453","lastModified":"2026-07-25T10:17:25.453","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host\n\nlookup_swap_cgroup_id() passes swap_cgroup_ctrl[type].map to\n__swap_cgroup_id_lookup() without checking that the type was ever\nregistered via swap_cgroup_swapon().  On a swapless host every ctrl->map\nis NULL, so __swap_cgroup_id_lookup() dereferences NULL + a scaled\nswp_offset().\n\nSince commit bea67dcc5eea (\"mm: attempt to batch free swap entries for\nzap_pte_range()\"), zap_pte_range() -> swap_pte_batch() calls\nlookup_swap_cgroup_id() on any non-present, non-none PTE that decodes as a\nreal swap entry, without first validating it against swap_info[].  A\nsingle PTE corrupted into a type-0 swap entry takes the host down at\nprocess exit.\n\nWe hit this in production on a swapless 6.12.58 host: ~1s of\n\"get_swap_device: Bad swap file entry 3f800204222bb\" (do_swap_page() being\ncorrectly defensive about the same entry) followed by\n\n  BUG: unable to handle page fault for address: 000003f800204220\n  RIP: 0010:lookup_swap_cgroup_id+0x2b/0x60\n  Call Trace:\n   swap_pte_batch+0xbf/0x230\n   zap_pte_range+0x4c8/0x780\n   unmap_page_range+0x190/0x3e0\n   exit_mmap+0xd9/0x3c0\n   do_exit+0x20c/0x4b0\n\nsyzbot has reported the identical stack.\n\nThe source of the PTE corruption is a separate bug; this change makes the\nteardown path as robust as the fault path already is.  Every other caller\nof lookup_swap_cgroup_id() is downstream of a get_swap_device() that has\nalready validated the entry, so the new branch is cold."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/swap_cgroup.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bea67dcc5eea0f6a213897a59b9e644977cd07e6","lessThan":"818416fef38759f23210de449663cd9d7e293d39","versionType":"git","status":"affected"},{"version":"bea67dcc5eea0f6a213897a59b9e644977cd07e6","lessThan":"b415c00bf23df577a4a95673d00ae76687bcc1d4","versionType":"git","status":"affected"},{"version":"bea67dcc5eea0f6a213897a59b9e644977cd07e6","lessThan":"6a4196d19f477524d2f92adca90fc1fbe9a0420a","versionType":"git","status":"affected"},{"version":"bea67dcc5eea0f6a213897a59b9e644977cd07e6","lessThan":"63b02a9409cb5180398491b093e48bcb5315f5fb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/swap_cgroup.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/63b02a9409cb5180398491b093e48bcb5315f5fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6a4196d19f477524d2f92adca90fc1fbe9a0420a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/818416fef38759f23210de449663cd9d7e293d39","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b415c00bf23df577a4a95673d00ae76687bcc1d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64417","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:25.567","lastModified":"2026-07-25T10:17:25.567","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm: shrinker: fix NULL pointer dereference in debugfs\n\nshrinker_debugfs_add() creates both \"count\" and \"scan\" debugfs files\nunconditionally.\n\nThat assumes every shrinker implements both count_objects() and\nscan_objects(), which is not guaranteed.  For example, the xen-backend\nshrinker sets count_objects() but leaves scan_objects() NULL, so writing\nto its scan file calls through a NULL function pointer and panics the\nkernel:\n\nBUG: kernel NULL pointer dereference, address: 0000000000000000\nRIP: 0010:0x0\nCode: Unable to access opcode bytes at 0xffffffffffffffd6.\nCall Trace:\n <TASK>\n shrinker_debugfs_scan_write+0x12e/0x270\n full_proxy_write+0x5f/0x90\n vfs_write+0xde/0x420\n ? filp_flush+0x75/0x90\n ? filp_close+0x1d/0x30\n ? do_dup2+0xb8/0x120\n ksys_write+0x68/0xf0\n ? filp_flush+0x75/0x90\n do_syscall_64+0xb3/0x5b0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThe count path has the same issue in principle if a shrinker omits\ncount_objects().\n\nTo fix it, only create \"count\" and \"scan\" debugfs files when the\ncorresponding callbacks are present."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/shrinker_debug.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bbf535fd6f06b94b9d07ed6f09397a936d4a58d8","lessThan":"ebb45c2648b1f60715fd283700f651e05e431231","versionType":"git","status":"affected"},{"version":"bbf535fd6f06b94b9d07ed6f09397a936d4a58d8","lessThan":"09d2407985b8ce3e831f9d4310fe7ac06a6b3ae9","versionType":"git","status":"affected"},{"version":"bbf535fd6f06b94b9d07ed6f09397a936d4a58d8","lessThan":"36f8534f461222291a74156ab91f3ba9f09b6f93","versionType":"git","status":"affected"},{"version":"bbf535fd6f06b94b9d07ed6f09397a936d4a58d8","lessThan":"006467ab932698612398f853344a7405164541f4","versionType":"git","status":"affected"},{"version":"bbf535fd6f06b94b9d07ed6f09397a936d4a58d8","lessThan":"b9beed2322f3538b0d2d53307062da4102b8d8d8","versionType":"git","status":"affected"},{"version":"bbf535fd6f06b94b9d07ed6f09397a936d4a58d8","lessThan":"e30453c61e185e914fde83c650e268067b140218","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/shrinker_debug.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/006467ab932698612398f853344a7405164541f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/09d2407985b8ce3e831f9d4310fe7ac06a6b3ae9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/36f8534f461222291a74156ab91f3ba9f09b6f93","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b9beed2322f3538b0d2d53307062da4102b8d8d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e30453c61e185e914fde83c650e268067b140218","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ebb45c2648b1f60715fd283700f651e05e431231","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64418","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:25.727","lastModified":"2026-07-25T10:17:25.727","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm: shrinker: fix shrinker_info teardown race with expansion\n\nexpand_shrinker_info() iterates all visible memcgs under shrinker_mutex,\nincluding memcgs that have not finished ->css_online() yet.\n\nOnce pn->shrinker_info has been published, teardown must stay serialized\nwith expand_shrinker_info() until that memcg is either fully online or no\nlonger visible to iteration.  Today alloc_shrinker_info() breaks that rule\nby dropping shrinker_mutex before freeing a partially initialized\nshrinker_info array, which may cause the following race:\n\nCPU0                   CPU1\n====                   ====\n\ncss_create\n--> list_add_tail_rcu(&css->sibling, &parent_css->children);\n    online_css\n    --> mem_cgroup_css_online\n        --> alloc_shrinker_info\n            --> alloc node0 info\n                rcu_assign_pointer(C->node0->shrinker_info, old0)\n                alloc node1 info -> FAIL -> goto err\n                mutex_unlock(shrinker_mutex)\n\n                       shrinker_alloc()\n                       --> shrinker_memcg_alloc\n                           --> mutex_lock(shrinker_mutex)\n                               expand_shrinker_info\n                               --> mem_cgroup_iter see the memcg\n                                   expand_one_shrinker_info\n                                   --> old0 = C->node0->shrinker_info\n                                       memcpy(new->unit, old0->unit, ...);\n\n                free_shrinker_info\n                --> kvfree(old0);\n\n                                       /* double free !! */\n                                       kvfree_rcu(old0, rcu);\n\nThe same problem exists later in mem_cgroup_css_online().  If\nalloc_shrinker_info() succeeds but a subsequent objcg allocation fails,\nthe free_objcg -> free_shrinker_info() unwind path tears down the already\npublished pn->shrinker_info arrays without shrinker_mutex.  The\nexpand_one_shrinker_info() can race with that teardown in the same way,\nleading to use-after-free or double-free of the old shrinker_info.\n\nFix this by serializing shrinker_info teardown with shrinker_mutex, and by\nkeeping alloc_shrinker_info() error cleanup inside the locked section."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/shrinker.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"307bececcd1205bcb67a3c0d53a69db237ccc9d4","lessThan":"b9a280a9a454ed514636351d53fe2a233dc5054b","versionType":"git","status":"affected"},{"version":"307bececcd1205bcb67a3c0d53a69db237ccc9d4","lessThan":"6465ff3ce65131c774a312d450abe10f4b9f3875","versionType":"git","status":"affected"},{"version":"307bececcd1205bcb67a3c0d53a69db237ccc9d4","lessThan":"284c267f013e45d8c89d9fb9373105dc8e6c0947","versionType":"git","status":"affected"},{"version":"307bececcd1205bcb67a3c0d53a69db237ccc9d4","lessThan":"65476d31d8056e859c48580f82295ce159196ffe","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/shrinker.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/284c267f013e45d8c89d9fb9373105dc8e6c0947","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6465ff3ce65131c774a312d450abe10f4b9f3875","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/65476d31d8056e859c48580f82295ce159196ffe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b9a280a9a454ed514636351d53fe2a233dc5054b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64419","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:25.847","lastModified":"2026-07-25T10:17:25.847","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()\n\nReading the debugfs \"count\" file of a memcg-aware shrinker can sleep\ninside an RCU read-side critical section:\n\n  BUG: sleeping function called from invalid context at kernel/cgroup/rstat.c:421\n  RCU nest depth: 1, expected: 0\n   css_rstat_flush\n   mem_cgroup_flush_stats\n   zswap_shrinker_count\n   shrinker_debugfs_count_show\n\nshrinker_debugfs_count_show() invokes the ->count_objects() callback under\nrcu_read_lock().  The zswap callback flushes memcg stats via\ncss_rstat_flush(), which may sleep, so it must not run under RCU.\n\nThe RCU lock is not needed here.  mem_cgroup_iter() takes RCU internally\nand returns a memcg holding a css reference (dropped on the next iteration\nor by mem_cgroup_iter_break()), so the memcg stays alive without it.  The\nshrinker is kept alive by the open debugfs file: shrinker_free() removes\nthe debugfs entries via debugfs_remove_recursive(), which waits for\nin-flight readers to drain, before call_rcu(..., shrinker_free_rcu_cb). \nThe sibling \"scan\" handler already invokes the sleeping ->scan_objects()\ncallback with no RCU section.\n\nDrop the rcu_read_lock()/rcu_read_unlock()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/shrinker_debug.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5035ebc644aec92d55d1bbfe042f35341e4bffb5","lessThan":"de5f69b8dae8698ac5e48dfcd30017887cdf4e5a","versionType":"git","status":"affected"},{"version":"5035ebc644aec92d55d1bbfe042f35341e4bffb5","lessThan":"e441cbfbd0eaa6404278e985033c33caba4db767","versionType":"git","status":"affected"},{"version":"5035ebc644aec92d55d1bbfe042f35341e4bffb5","lessThan":"2fed79f0fe8c8d28a972c290dbfd693c3546c8c4","versionType":"git","status":"affected"},{"version":"5035ebc644aec92d55d1bbfe042f35341e4bffb5","lessThan":"560e21e8ccff813e84d05f6500907c549a3d6985","versionType":"git","status":"affected"},{"version":"5035ebc644aec92d55d1bbfe042f35341e4bffb5","lessThan":"86237e56091e70f09c0fbf217f9d9c0e08f556c4","versionType":"git","status":"affected"},{"version":"5035ebc644aec92d55d1bbfe042f35341e4bffb5","lessThan":"b902890c62d200b3509cb5e09cf1e0a66553c128","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/shrinker_debug.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2fed79f0fe8c8d28a972c290dbfd693c3546c8c4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/560e21e8ccff813e84d05f6500907c549a3d6985","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/86237e56091e70f09c0fbf217f9d9c0e08f556c4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b902890c62d200b3509cb5e09cf1e0a66553c128","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/de5f69b8dae8698ac5e48dfcd30017887cdf4e5a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e441cbfbd0eaa6404278e985033c33caba4db767","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64420","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:25.963","lastModified":"2026-07-25T10:17:25.963","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmfd: cros_ec: Delay dev_set_drvdata() until probe success\n\nIf ec_device_probe() fails, cros_ec_class_release releases memory for the\ncros_ec_dev structure. However, because the drvdata was already set,\nsub-drivers like cros_ec_typec can still retrieve the stale pointer via the\nplatform device. This leads to a use-after-free when cros_ec_typec attempts\nto access &typec->ec->ec->dev on a device that has already been released.\nMove dev_set_drvdata() to ensure that the pointer is only made available\nonce all initialization steps have succeeded.\n\n sysfs: cannot create duplicate filename '/class/chromeos/cros_ec'\n Call trace:\n  sysfs_do_create_link_sd+0x94/0xdc\n  sysfs_create_link+0x30/0x44\n  device_add_class_symlinks+0x90/0x13c\n  device_add+0xf0/0x50c\n  ec_device_probe+0x150/0x4f0\n  platform_probe+0xa0/0xe0\n ...\n BUG: KASAN: invalid-access in __memcpy+0x44/0x230\n Write at addr f5ffff809e2d33ac by task kworker/u32:5/125\n Pointer tag: [f5], memory tag: [fe]\n Tainted : [W]=WARN, [O]=OOT_MODULE\n Hardware name: Google Navi unprovisioned 0x7FFFFFFF/sku0 board/sku3\n Workqueue: events_unbound deferred_probe_work_func\n Call trace:\n  __memcpy+0x44/0x230\n  cros_ec_check_features+0x60/0xcc [cros_ec_proto]\n  cros_typec_probe+0xe8/0x6e0 [cros_ec_typec]\n  platform_probe+0xa0/0xe0"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/mfd/cros_ec_dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b","lessThan":"24522713034d521ea4b5f5f36342e2b2f7e73bd6","versionType":"git","status":"affected"},{"version":"1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b","lessThan":"f7e81dc181d9fe8ab977158042cd193e8cc12091","versionType":"git","status":"affected"},{"version":"1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b","lessThan":"257203d83204b192d1265a916b42ca0d499bb117","versionType":"git","status":"affected"},{"version":"1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b","lessThan":"729ae27dc2503a7c1f92da1859efb45da03e4fa0","versionType":"git","status":"affected"},{"version":"1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b","lessThan":"ed2941e5db016a0c600b25f1972620e6e223d9fa","versionType":"git","status":"affected"},{"version":"1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b","lessThan":"b5f41d5bf08e7b1b14fa0bd640975e6d78dc006d","versionType":"git","status":"affected"},{"version":"1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b","lessThan":"fc030c5b116f668d4ca86dca63742ddbc98d1665","versionType":"git","status":"affected"},{"version":"1c1d152cc5ac3a67d199728a9ba0b4f54a498f8b","lessThan":"8b2c1d41bc36c100b38ce5ee6def246c527eaf8a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/mfd/cros_ec_dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/24522713034d521ea4b5f5f36342e2b2f7e73bd6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/257203d83204b192d1265a916b42ca0d499bb117","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/729ae27dc2503a7c1f92da1859efb45da03e4fa0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b2c1d41bc36c100b38ce5ee6def246c527eaf8a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5f41d5bf08e7b1b14fa0bd640975e6d78dc006d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed2941e5db016a0c600b25f1972620e6e223d9fa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7e81dc181d9fe8ab977158042cd193e8cc12091","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc030c5b116f668d4ca86dca63742ddbc98d1665","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64421","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:26.097","lastModified":"2026-07-25T10:17:26.097","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: nxp: imx8-isi: Fix use-after-free on remove\n\nKASAN reports a slab-use-after-free in __media_entity_remove_link()\nduring rmmod of imx8_isi:\n\n  BUG: KASAN: slab-use-after-free in __media_entity_remove_link+0x608/0x650\n  Read of size 2 at addr ffff0000d47cb02a by task rmmod/724\n\n  Call trace:\n   __media_entity_remove_link+0x608/0x650\n   __media_entity_remove_links+0x78/0x144\n   __media_device_unregister_entity+0x150/0x280\n   media_device_unregister_entity+0x48/0x68\n   v4l2_device_unregister_subdev+0x158/0x300\n   v4l2_async_unbind_subdev_one+0x22c/0x358\n   v4l2_async_nf_unbind_all_subdevs+0xfc/0x1c0\n   v4l2_async_nf_unregister+0x5c/0x14c\n   mxc_isi_remove+0x124/0x2a0 [imx8_isi]\n\n  Allocated by task 249:\n   __kmalloc_noprof+0x27c/0x690\n   mxc_isi_crossbar_init+0x22c/0x560 [imx8_isi]\n\n  Freed by task 724:\n   kfree+0x1e4/0x5b0\n   mxc_isi_crossbar_cleanup+0x34/0x80 [imx8_isi]\n   mxc_isi_remove+0x11c/0x2a0 [imx8_isi]\n\nThe problem is that mxc_isi_remove() calls mxc_isi_crossbar_cleanup()\nbefore mxc_isi_v4l2_cleanup(). The crossbar cleanup frees the media\nentity pads, but the subsequent v4l2 cleanup still tries to remove\nmedia links that reference those pads.\n\nFix this by calling mxc_isi_v4l2_cleanup() before\nmxc_isi_crossbar_cleanup() to ensure all media entities are properly\nunregistered while the pads are still valid."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/media/platform/nxp/imx8-isi/imx8-isi-core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cf21f328fcafacf4f96e7a30ef9dceede1076378","lessThan":"d22fb719654bfde6f682c9f14629f5f9534175b7","versionType":"git","status":"affected"},{"version":"cf21f328fcafacf4f96e7a30ef9dceede1076378","lessThan":"ba2aa5d325270cd965c44458c5ff5ab555e6af51","versionType":"git","status":"affected"},{"version":"cf21f328fcafacf4f96e7a30ef9dceede1076378","lessThan":"ef382a6baf0a95cf199fdf6bba2fd08e58b0a249","versionType":"git","status":"affected"},{"version":"cf21f328fcafacf4f96e7a30ef9dceede1076378","lessThan":"c12a5b2261351cd3b03921ce4720332ff5184b50","versionType":"git","status":"affected"},{"version":"cf21f328fcafacf4f96e7a30ef9dceede1076378","lessThan":"b670bf89824ede5d07d20bb9bfbafb754846081d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/media/platform/nxp/imx8-isi/imx8-isi-core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/b670bf89824ede5d07d20bb9bfbafb754846081d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba2aa5d325270cd965c44458c5ff5ab555e6af51","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c12a5b2261351cd3b03921ce4720332ff5184b50","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d22fb719654bfde6f682c9f14629f5f9534175b7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef382a6baf0a95cf199fdf6bba2fd08e58b0a249","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64422","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:26.213","lastModified":"2026-07-25T10:17:26.213","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ipv4: bound TCP reordering sysctl writes and MTU probe sizes\n\nReject invalid `net.ipv4.tcp_reordering` values before they reach TCP\nsocket state. The sysctl is stored as an `int` but copied into the\n`u32` `tp->reordering` field for new sockets, so negative writes wrap\nto large values.\n\nWith `tcp_mtu_probing=2`, the wrapped value can overflow the\n`tcp_mtu_probe()` size calculation and drive the MTU probing path into\nan out-of-bounds read. Route `tcp_reordering` writes through\n`proc_dointvec_minmax()` and require it to be at least 1. Also require\n`tcp_max_reordering` to be at least 1 so the configured maximum cannot\nbecome negative either.\n\nWhen registering the table for a non-init network namespace, relocate\n`extra2` pointers that refer into `init_net.ipv4` so the\n`tcp_reordering` upper bound follows that namespace's\n`tcp_max_reordering`.\n\nHarden `tcp_mtu_probe()` itself by computing `size_needed` as `u64`.\nThis keeps the send queue and window checks from being bypassed through\nsigned integer overflow."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/sysctl_net_ipv4.c","net/ipv4/tcp_output.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"91cc17c0e5e5ada156a8d5787a2509d263ea6bbf","lessThan":"f0d88a4cd03affff6c08adf6c63964e235aede43","versionType":"git","status":"affected"},{"version":"91cc17c0e5e5ada156a8d5787a2509d263ea6bbf","lessThan":"27ddf4486c7dbf5bdd393fa8bef6b67179796d98","versionType":"git","status":"affected"},{"version":"91cc17c0e5e5ada156a8d5787a2509d263ea6bbf","lessThan":"782708ca1ea1f68b8cbb5ea3a7f5f18d0000efae","versionType":"git","status":"affected"},{"version":"91cc17c0e5e5ada156a8d5787a2509d263ea6bbf","lessThan":"e81f805824a8109504fce090641b17d135b48cd1","versionType":"git","status":"affected"},{"version":"91cc17c0e5e5ada156a8d5787a2509d263ea6bbf","lessThan":"99206ce2244f8a3ed64298d0667c9055845a5dc7","versionType":"git","status":"affected"},{"version":"91cc17c0e5e5ada156a8d5787a2509d263ea6bbf","lessThan":"bbae351c0f32f7c200249e4aa6561b2b419dcf69","versionType":"git","status":"affected"},{"version":"91cc17c0e5e5ada156a8d5787a2509d263ea6bbf","lessThan":"a094ac95d3b69adfa1676eb9c8eae6835d4f1671","versionType":"git","status":"affected"},{"version":"91cc17c0e5e5ada156a8d5787a2509d263ea6bbf","lessThan":"efb8763d7bbb40cff4cc55a6b62c3095a038149c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/sysctl_net_ipv4.c","net/ipv4/tcp_output.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.24","status":"affected"},{"version":"0","lessThan":"2.6.24","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/27ddf4486c7dbf5bdd393fa8bef6b67179796d98","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/782708ca1ea1f68b8cbb5ea3a7f5f18d0000efae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/99206ce2244f8a3ed64298d0667c9055845a5dc7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a094ac95d3b69adfa1676eb9c8eae6835d4f1671","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bbae351c0f32f7c200249e4aa6561b2b419dcf69","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e81f805824a8109504fce090641b17d135b48cd1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/efb8763d7bbb40cff4cc55a6b62c3095a038149c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f0d88a4cd03affff6c08adf6c63964e235aede43","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64423","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:26.350","lastModified":"2026-07-25T10:17:26.350","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: igmp: remove multicast group from hash table on device destruction\n\nWhen a device is destroyed under RTNL, ip_mc_destroy_dev() iterates through\nthe multicast list and calls ip_ma_put() on each membership, scheduling\nthem for RCU reclamation. However, they are not unlinked from the device's\nmulticast hash table (mc_hash).\n\nSince the device remains published in dev->ip_ptr until after\nip_mc_destroy_dev() completes, concurrent RCU readers traversing mc_hash\ncan still locate and access the multicast group after its refcount is\ndecremented. If the RCU callback runs and frees the group while a reader is\naccessing it, a use-after-free occurs.\n\nFix this by unlinking the multicast group from mc_hash using\nip_mc_hash_remove() before scheduling it for reclamation.\n\nBUG: KASAN: slab-use-after-free in ip_check_mc_rcu+0x149/0x3f0\nRead of size 4 at addr ffff888009bf1408 by task mausezahn/2276\n\nCall Trace:\n <IRQ>\n dump_stack_lvl+0x67/0x90\n print_report+0x175/0x7c0\n kasan_report+0x147/0x180\n ip_check_mc_rcu+0x149/0x3f0\n udp_v4_early_demux+0x36d/0x12d0\n ip_rcv_finish_core+0xb8b/0x1390\n ip_rcv_finish+0x54/0x120\n NF_HOOK+0x213/0x2b0\n __netif_receive_skb+0x126/0x340\n process_backlog+0x4f2/0xf00\n __napi_poll+0x92/0x2c0\n net_rx_action+0x583/0xc60\n handle_softirqs+0x236/0x7f0\n do_softirq+0x57/0x80\n </IRQ>\n\nAllocated by task 2239:\n kasan_save_track+0x3e/0x80\n __kasan_kmalloc+0x72/0x90\n ____ip_mc_inc_group+0x31a/0xa40\n __ip_mc_join_group+0x334/0x3f0\n do_ip_setsockopt+0x16fa/0x2010\n ip_setsockopt+0x3f/0x90\n do_sock_setsockopt+0x1ad/0x300\n\nFreed by task 0:\n kasan_save_track+0x3e/0x80\n kasan_save_free_info+0x40/0x50\n __kasan_slab_free+0x3a/0x60\n __rcu_free_sheaf_prepare+0xd4/0x220\n rcu_free_sheaf+0x36/0x190\n rcu_core+0x8d9/0x12f0\n handle_softirqs+0x236/0x7f0"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/igmp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e9897071350bd9d94a56b5b6f79c85b1a98fc7e7","lessThan":"412ba7def06ffe974ba9a1d862b022362c54ffa5","versionType":"git","status":"affected"},{"version":"e9897071350bd9d94a56b5b6f79c85b1a98fc7e7","lessThan":"c6cb5f8ebe1c1a78710c19f102db9fe48b9e6ba9","versionType":"git","status":"affected"},{"version":"e9897071350bd9d94a56b5b6f79c85b1a98fc7e7","lessThan":"5f42729d74bd6c61306d864423290d92962de4e1","versionType":"git","status":"affected"},{"version":"e9897071350bd9d94a56b5b6f79c85b1a98fc7e7","lessThan":"76d030ac95e17f91d69a595f17ebc5979700cf9a","versionType":"git","status":"affected"},{"version":"e9897071350bd9d94a56b5b6f79c85b1a98fc7e7","lessThan":"8820b530cb2388503d7418228d03ba074bf7a03e","versionType":"git","status":"affected"},{"version":"e9897071350bd9d94a56b5b6f79c85b1a98fc7e7","lessThan":"2ca18df1c2611f70eb3eb487e02ae85eb703b284","versionType":"git","status":"affected"},{"version":"e9897071350bd9d94a56b5b6f79c85b1a98fc7e7","lessThan":"f91883031e5a62877a29ce139442973cbea769f1","versionType":"git","status":"affected"},{"version":"e9897071350bd9d94a56b5b6f79c85b1a98fc7e7","lessThan":"7993211bde166471dffac074dc965489f86531f8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/igmp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.11","status":"affected"},{"version":"0","lessThan":"3.11","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2ca18df1c2611f70eb3eb487e02ae85eb703b284","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/412ba7def06ffe974ba9a1d862b022362c54ffa5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5f42729d74bd6c61306d864423290d92962de4e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/76d030ac95e17f91d69a595f17ebc5979700cf9a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7993211bde166471dffac074dc965489f86531f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8820b530cb2388503d7418228d03ba074bf7a03e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c6cb5f8ebe1c1a78710c19f102db9fe48b9e6ba9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f91883031e5a62877a29ce139442973cbea769f1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64424","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:26.483","lastModified":"2026-07-25T10:17:26.483","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetpoll: fix a use-after-free on shutdown path\n\nThere is a use-after-free error on netpoll, which is clearly detected by\nKASAN.\n\n      BUG: KASAN: slab-use-after-free in _raw_spin_lock_irqsave+0x3b/0x80\n      Read of size 1 at addr ... by task kworker/9:1\n      Workqueue: events queue_process\n      Call Trace:\n       skb_dequeue+0x1e/0xb0\n       queue_process+0x2c/0x600\n       process_scheduled_works+0x4b6/0x850\n       worker_thread+0x414/0x5a0\n      Allocated by task 242:\n       __netpoll_setup+0x201/0x4a0\n       netpoll_setup+0x249/0x550\n       enabled_store+0x32f/0x380\n      Freed by task 0:\n       kfree+0x1b7/0x540\n       rcu_core+0x3f8/0x7a0\n\nThe problem happens when there is a pending TX worker running in\nparallel with the cleanup path.\n\nThis is what happens on netpoll shutdown path:\n\n1) __netpoll_cleanup() is called\n2) set dev->npinfo to NULL\n3) call_rcu() with rcu_cleanup_netpoll_info()\n  3.1) rcu_cleanup_netpoll_info() tries to cancel all workers with\n       cancel_delayed_work(), but doesn't wait for the worker to finish\n4) and kfree(npinfo);\n\nBecause 3.1) doesn't really cancel the work, as the comment says \"we\ncan't call cancel_delayed_work_sync here, as we are in softirq\", the TX\nworker can run after 4).\n\nTl;DR: queue_process() is not an RCU reader, it reaches npinfo through\nthe work item via container_of().\n\nUse disable_delayed_work_sync() to ensure the worker is completely\nstopped and prevent any future re-arming attempts. Once npinfo is set\nto NULL, senders will bail out and not queue new work. The disable flag\nensures any in-flight re-arming attempts also fail silently.\n\nIn the future, we can do the cleanup inline here without needing the\nnpinfo->rcu rcu_head, but that is net-next material."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/core/netpoll.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"38e6bc185d9544dfad1774b3f8902a0b061aea25","lessThan":"95ecc5b58042f6b6743b589e6588f1cd7ba336aa","versionType":"git","status":"affected"},{"version":"38e6bc185d9544dfad1774b3f8902a0b061aea25","lessThan":"a33f37f8d079da7236ed7b7e2aed2a34ab81e7cf","versionType":"git","status":"affected"},{"version":"38e6bc185d9544dfad1774b3f8902a0b061aea25","lessThan":"5ed09a108d93a3b002cc79823d9455b50c4a8be7","versionType":"git","status":"affected"},{"version":"38e6bc185d9544dfad1774b3f8902a0b061aea25","lessThan":"45f1458a85017a023f138b22ac5c76abd477db42","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/core/netpoll.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.6","status":"affected"},{"version":"0","lessThan":"3.6","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/45f1458a85017a023f138b22ac5c76abd477db42","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5ed09a108d93a3b002cc79823d9455b50c4a8be7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/95ecc5b58042f6b6743b589e6588f1cd7ba336aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a33f37f8d079da7236ed7b7e2aed2a34ab81e7cf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64425","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:26.600","lastModified":"2026-07-25T10:17:26.600","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item\n\ncommit 10dc95939817 (\"io_uring/io-wq: check IO_WQ_BIT_EXIT inside work\nrun loop\") fixed the obvious case where io_worker_handle_work() took one\nexit-bit snapshot before draining pending work, but the fix stops one\nlevel too early.\n\nio_worker_handle_work() now re-checks IO_WQ_BIT_EXIT in its outer work\nrun loop, yet it still snapshots that bit once before processing a whole\ndependent linked-work chain. If io_wq_exit_start() sets IO_WQ_BIT_EXIT\nafter the first linked item has started, the remaining linked items can\nstill reuse stale do_kill = false, skip IO_WQ_WORK_CANCEL, and continue\nrunning after exit has begun.\n\nMove the check further inside, so it covers linked items too. Note: this\nis a syzbot special as it loves setting up tons of slow linked work on\nweird devices like msr that take forever to read, and immediately close\nthe ring. Exit then takes a long time."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["io_uring/io-wq.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"065dd936195a3466b8ebe5f9287400987ee3c063","lessThan":"14b7ecad2ec56699325180a744f4b19f046401bb","versionType":"git","status":"affected"},{"version":"27e47500fac23d15b7dc93ff650bc4844d2581bd","lessThan":"d179533c610e1b4c6aa436e3c1fd1b719d2c727c","versionType":"git","status":"affected"},{"version":"d05d99573f81a091547b1778b9a50120f5d6c68a","lessThan":"6e2f51f3e06773c2ee98ad09738f0908b48f76f9","versionType":"git","status":"affected"},{"version":"85eb83694a91c89d9abe615d717c0053c3efa714","lessThan":"ea61b04e1d7242cb37f5ed2cc91cf21a493f6597","versionType":"git","status":"affected"},{"version":"2e8ca1078b14142db2ce51cbd18ff9971560046b","lessThan":"b6f179a653a934736c88d820fe0098c3c2532549","versionType":"git","status":"affected"},{"version":"bdf0bf73006ea8af9327cdb85cfdff4c23a5f966","lessThan":"1636d85dc139b07c0449308f2bb5e0c7a2e0da99","versionType":"git","status":"affected"},{"version":"10dc959398175736e495f71c771f8641e1ca1907","lessThan":"ab85765cbe3258b43dc6729af0e6ce3a87a133d8","versionType":"git","status":"affected"},{"version":"10dc959398175736e495f71c771f8641e1ca1907","lessThan":"29bef9934b2521f787bb15dd1985d4c0d12ae02a","versionType":"git","status":"affected"},{"version":"5.10.253","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.15.203","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.167","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.122","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.68","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"6.18.8","lessThan":"6.18.39","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["io_uring/io-wq.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/14b7ecad2ec56699325180a744f4b19f046401bb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1636d85dc139b07c0449308f2bb5e0c7a2e0da99","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/29bef9934b2521f787bb15dd1985d4c0d12ae02a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e2f51f3e06773c2ee98ad09738f0908b48f76f9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ab85765cbe3258b43dc6729af0e6ce3a87a133d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6f179a653a934736c88d820fe0098c3c2532549","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d179533c610e1b4c6aa436e3c1fd1b719d2c727c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea61b04e1d7242cb37f5ed2cc91cf21a493f6597","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64426","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:26.737","lastModified":"2026-07-25T10:17:26.737","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/nop: fix file reference leak with IOSQE_FIXED_FILE\n\nNOP file-acquisition support choses between a fixed (registered) file and\na normal fget()'d file based on its own IORING_NOP_FIXED_FILE flag in\nsqe->nop_flags. However, a request's REQ_F_FIXED_FILE is set\nindependently from the generic IOSQE_FIXED_FILE sqe flag during request\ninit, before the issue handler runs.\n\nIf a NOP is submitted with IOSQE_FIXED_FILE set (so REQ_F_FIXED_FILE is\nset) but without IORING_NOP_FIXED_FILE, io_nop() takes the normal path\nand grabs a real reference via io_file_get_normal(). On completion,\nio_put_file() only drops the reference when REQ_F_FIXED_FILE is clear,\nso the fget()'d file is never released and leaks:\n\n  BUG: memory leak\n  unreferenced object 0xffff88800f42c240 (size 176):\n    kmem_cache_alloc_noprof+0x358/0x440\n    alloc_empty_file+0x57/0x180\n    path_openat+0x44/0x1e50\n    do_file_open+0x121/0x200\n    do_sys_openat2+0xa7/0x150\n    __x64_sys_openat+0x82/0xf0\n\nDecide between fixed and normal file acquisition from REQ_F_FIXED_FILE,\nthe same way io_assign_file() does for every other opcode, and fold\nIORING_NOP_FIXED_FILE into REQ_F_FIXED_FILE at prep time."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["io_uring/nop.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a85f31052bce52111b4e9d5a536003481d0421d0","lessThan":"722869fcff598fad20d5ab79c305897a7534708b","versionType":"git","status":"affected"},{"version":"a85f31052bce52111b4e9d5a536003481d0421d0","lessThan":"7267717f35787167fcce4bc14f6ef3fa06682dcf","versionType":"git","status":"affected"},{"version":"a85f31052bce52111b4e9d5a536003481d0421d0","lessThan":"2564ca2e31bd8ee8348362941af2ee4671e487ca","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["io_uring/nop.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2564ca2e31bd8ee8348362941af2ee4671e487ca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/722869fcff598fad20d5ab79c305897a7534708b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7267717f35787167fcce4bc14f6ef3fa06682dcf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64427","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:26.843","lastModified":"2026-07-25T10:17:26.843","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: logitech-dj: Fix maxfield check in DJ short report validation\n\nCommit b6a57912854e (\"HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT\nrelated user initiated OOB write\") added validation for the DJ short\noutput report, but the error path dereferences rep->field[0] even when\nrep->maxfield is zero.\n\nCommit 8b9a097eb2fc (\"HID: logitech-dj: fix wrong detection of bad\nDJ_SHORT output report\") made the check conditional on rep being present,\nbut a crafted descriptor can still create report ID 0x20 with only padding\noutput items. hid-core registers the report, ignores the padding field,\nand leaves rep->maxfield as zero.\n\nIn that case the validation enters the rep->maxfield < 1 branch and then\ndereferences rep->field[0]->report_count while printing the error message,\ncausing a NULL pointer dereference during probe. This is reproducible with\nuhid by emulating a Logitech receiver with a padding-only DJ short output\nreport:\n\n  BUG: KASAN: null-ptr-deref in logi_dj_probe+0xb1/0x754 [hid_logitech_dj]\n  Read of size 4 at addr 0000000000000028 by task kworker/4:1/129\n  ...\n  Call Trace:\n   logi_dj_probe+0xb1/0x754 [hid_logitech_dj]\n   hid_device_probe+0x329/0x3f0 [hid]\n   really_probe+0x162/0x570\n   __device_attach+0x137/0x2c0\n   bus_probe_device+0x38/0xc0\n   device_add+0xa56/0xce0\n   hid_add_device+0x19c/0x280 [hid]\n   uhid_device_add_worker+0x2c/0xb0 [uhid]\n\nReject the zero-field report before printing the field report_count."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/hid-logitech-dj.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b6a57912854e7ea36f3b270032661140cc4209cd","lessThan":"7a89ad762fad53d56b7002d7ffc923a4b7f4006f","versionType":"git","status":"affected"},{"version":"b6a57912854e7ea36f3b270032661140cc4209cd","lessThan":"590cc4d782487632a52f37c2171bee1eeea29627","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/hid-logitech-dj.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/590cc4d782487632a52f37c2171bee1eeea29627","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7a89ad762fad53d56b7002d7ffc923a4b7f4006f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64428","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:26.947","lastModified":"2026-07-25T10:17:26.947","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: sch: use raw_spinlock_t in the irq startup path\n\nsch_irq_unmask() enables the GPIO IRQ and then updates the controller\nstate through sch_irq_mask_unmask(), which takes sch->lock with\nspin_lock_irqsave().  The callback can be reached from irq_startup()\nwhile setting up a requested IRQ.  That path is not sleepable, but on\nPREEMPT_RT a regular spinlock_t becomes a sleeping lock.\n\nThis issue was found by our static analysis tool and then manually\nreviewed against the current tree.\n\nThe grounded PoC kept the request_threaded_irq() -> __setup_irq() ->\nirq_startup() -> sch_irq_unmask() -> sch_irq_mask_unmask() carrier and\nused the original spin_lock_irqsave(&sch->lock) edge.  Lockdep reported:\n\n  BUG: sleeping function called from invalid context\n  hardirqs last disabled at ... __setup_irq.constprop.0 ... [vuln_msv]\n  sch_rt_spin_lock_irqsave+0x1c/0x30 [vuln_msv]\n  sch_irq_mask_unmask.constprop.0+0x31/0x70 [vuln_msv]\n  __setup_irq.constprop.0+0xd/0x30 [vuln_msv]\n\nConvert the SCH controller lock to raw_spinlock_t.  The same lock is\nalso used by the GPIO direction and value callbacks, but those critical\nsections only update MMIO-backed GPIO registers and do not contain\nsleepable operations.  Keeping this register lock non-sleeping is\ntherefore appropriate for the irqchip callbacks and does not change the\nGPIO-side locking contract."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpio/gpio-sch.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7a81638485c1a62a87b4c391ecc9c651a4a9dc19","lessThan":"3b1aa05ec27eeccc889ecaa3f2d9baa9f453e50d","versionType":"git","status":"affected"},{"version":"7a81638485c1a62a87b4c391ecc9c651a4a9dc19","lessThan":"4f03a15cc73c83740fc355ee22b336492d17b4da","versionType":"git","status":"affected"},{"version":"7a81638485c1a62a87b4c391ecc9c651a4a9dc19","lessThan":"7a550256d68bbdfa0903ab1c4595c04a6815493a","versionType":"git","status":"affected"},{"version":"7a81638485c1a62a87b4c391ecc9c651a4a9dc19","lessThan":"a235cec779bb39ec8f961a935b28a2ce278c6c64","versionType":"git","status":"affected"},{"version":"7a81638485c1a62a87b4c391ecc9c651a4a9dc19","lessThan":"4508366ab7dd0c2917a51a9c2e23cc1b9d35157a","versionType":"git","status":"affected"},{"version":"7a81638485c1a62a87b4c391ecc9c651a4a9dc19","lessThan":"41cad91a09d69e8fff4e936db29b1054b4e9f9f7","versionType":"git","status":"affected"},{"version":"7a81638485c1a62a87b4c391ecc9c651a4a9dc19","lessThan":"286533cb14a3c8a8bd39ff64ea2fc8e1aa0f638b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpio/gpio-sch.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/286533cb14a3c8a8bd39ff64ea2fc8e1aa0f638b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3b1aa05ec27eeccc889ecaa3f2d9baa9f453e50d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/41cad91a09d69e8fff4e936db29b1054b4e9f9f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4508366ab7dd0c2917a51a9c2e23cc1b9d35157a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4f03a15cc73c83740fc355ee22b336492d17b4da","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7a550256d68bbdfa0903ab1c4595c04a6815493a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a235cec779bb39ec8f961a935b28a2ce278c6c64","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64429","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:27.070","lastModified":"2026-07-25T10:17:27.070","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: eic-sprd: use raw_spinlock_t in the irq startup path\n\nsprd_eic_irq_unmask() enables the GPIO IRQ and then updates controller\nstate through sprd_eic_update(), which takes sprd_eic->lock with\nspin_lock_irqsave().  The callback can be reached from irq_startup()\nwhile setting up a requested IRQ.  That path is not sleepable, but on\nPREEMPT_RT a regular spinlock_t becomes a sleeping lock.\n\nThis issue was found by our static analysis tool and then manually\nreviewed against the current tree.\n\nThe grounded PoC kept the request_threaded_irq() -> __setup_irq() ->\nirq_startup() -> sprd_eic_irq_unmask() -> sprd_eic_update() carrier and\nused the original spin_lock_irqsave(&sprd_eic->lock) edge.  Lockdep\n\n  BUG: sleeping function called from invalid context\n  hardirqs last disabled at ... __setup_irq.constprop.0 ... [vuln_msv]\n  sprd_rt_spin_lock_irqsave+0x1c/0x30 [vuln_msv]\n  sprd_eic_update.constprop.0+0x48/0x90 [vuln_msv]\n  sprd_eic_irq_unmask.constprop.0+0x35/0x50 [vuln_msv]\n  __setup_irq.constprop.0+0xd/0x30 [vuln_msv]\n\nConvert the Spreadtrum EIC controller lock to raw_spinlock_t.  The\nlocked section only serializes MMIO register updates and does not contain\nsleepable operations, so keeping it non-sleeping is appropriate for the\nirqchip callbacks."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpio/gpio-eic-sprd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"25518e024e3a6e5715d672f1daa91e1d100f7436","lessThan":"96612bf2712cd961dbd9b52f3a9b4ab668f57628","versionType":"git","status":"affected"},{"version":"25518e024e3a6e5715d672f1daa91e1d100f7436","lessThan":"581ac2ad001ff1128931191f249a7f2074672b7a","versionType":"git","status":"affected"},{"version":"25518e024e3a6e5715d672f1daa91e1d100f7436","lessThan":"e244cd8b51001ba480f274c44dba9002813a4739","versionType":"git","status":"affected"},{"version":"25518e024e3a6e5715d672f1daa91e1d100f7436","lessThan":"19d63fd528719ce7d06d9aeb88d25b7d6478198a","versionType":"git","status":"affected"},{"version":"25518e024e3a6e5715d672f1daa91e1d100f7436","lessThan":"6112fba4150039ccd90e29f2d1b788c73ad7b3dd","versionType":"git","status":"affected"},{"version":"25518e024e3a6e5715d672f1daa91e1d100f7436","lessThan":"4750909a40da9016185e0ac991510a278cecb1e7","versionType":"git","status":"affected"},{"version":"25518e024e3a6e5715d672f1daa91e1d100f7436","lessThan":"5c3c9ec1172a4c3384b8b800b3a8896cc2c1b20e","versionType":"git","status":"affected"},{"version":"25518e024e3a6e5715d672f1daa91e1d100f7436","lessThan":"90f0109019e6817eb40a486671b7722d1544ae29","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpio/gpio-eic-sprd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.17","status":"affected"},{"version":"0","lessThan":"4.17","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/19d63fd528719ce7d06d9aeb88d25b7d6478198a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4750909a40da9016185e0ac991510a278cecb1e7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/581ac2ad001ff1128931191f249a7f2074672b7a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5c3c9ec1172a4c3384b8b800b3a8896cc2c1b20e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6112fba4150039ccd90e29f2d1b788c73ad7b3dd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/90f0109019e6817eb40a486671b7722d1544ae29","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/96612bf2712cd961dbd9b52f3a9b4ab668f57628","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e244cd8b51001ba480f274c44dba9002813a4739","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64430","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:27.203","lastModified":"2026-07-25T10:17:27.203","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNTB: epf: Avoid calling pci_irq_vector() from hardirq context\n\nntb_epf_vec_isr() calls pci_irq_vector() in hardirq context to derive\nthe vector number. pci_irq_vector() calls msi_get_virq() that takes a\nmutex and can therefore trigger \"scheduling while atomic\" splats:\n\n  BUG: scheduling while atomic: kworker/u33:0/55/0x00010001\n  ...\n  Call trace:\n   ...\n   schedule+0x38/0x110\n   schedule_preempt_disabled+0x28/0x50\n   __mutex_lock.constprop.0+0x848/0x908\n   __mutex_lock_slowpath+0x18/0x30\n   mutex_lock+0x4c/0x60\n   msi_domain_get_virq+0xe8/0x138\n   pci_irq_vector+0x2c/0x60\n   ntb_epf_vec_isr+0x28/0x120 [ntb_hw_epf]\n   __handle_irq_event_percpu+0x70/0x3a8\n   handle_irq_event+0x48/0x100\n   handle_edge_irq+0x100/0x1c8\n   ...\n\nCache the Linux IRQ number for vector 0 when vectors are allocated and\nuse it as a base in the ISR. Running the ISR in a threaded IRQ handler\nwould also avoid the problem, but that would be unnecessary here."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/ntb/hw/epf/ntb_hw_epf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"812ce2f8d14ea791edd88c36ebcc9017bf4c88cb","lessThan":"33bba331a4a5fee8b6026fe72eca13cceeec1b7b","versionType":"git","status":"affected"},{"version":"812ce2f8d14ea791edd88c36ebcc9017bf4c88cb","lessThan":"aff271b12a1eb8c8b3da19223ae1a6abe1e8168b","versionType":"git","status":"affected"},{"version":"812ce2f8d14ea791edd88c36ebcc9017bf4c88cb","lessThan":"1dba8444ac0100133d72374634f6d7451fff1ccc","versionType":"git","status":"affected"},{"version":"812ce2f8d14ea791edd88c36ebcc9017bf4c88cb","lessThan":"174a97f21bf9c54fa37ec0f321692e862ea130a3","versionType":"git","status":"affected"},{"version":"812ce2f8d14ea791edd88c36ebcc9017bf4c88cb","lessThan":"f71e8d9875069fa73e335f63f02ec6e52e3aaa51","versionType":"git","status":"affected"},{"version":"812ce2f8d14ea791edd88c36ebcc9017bf4c88cb","lessThan":"6350df503897d57c5634f71b0767d48c3b837583","versionType":"git","status":"affected"},{"version":"812ce2f8d14ea791edd88c36ebcc9017bf4c88cb","lessThan":"4dcddc1c794d1c65eda68f1f8dd04a0fecc0870f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/ntb/hw/epf/ntb_hw_epf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.12","status":"affected"},{"version":"0","lessThan":"5.12","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/174a97f21bf9c54fa37ec0f321692e862ea130a3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1dba8444ac0100133d72374634f6d7451fff1ccc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/33bba331a4a5fee8b6026fe72eca13cceeec1b7b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4dcddc1c794d1c65eda68f1f8dd04a0fecc0870f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6350df503897d57c5634f71b0767d48c3b837583","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aff271b12a1eb8c8b3da19223ae1a6abe1e8168b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f71e8d9875069fa73e335f63f02ec6e52e3aaa51","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64431","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:27.327","lastModified":"2026-07-25T10:17:27.327","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: avoid calling post_write_mst_fixup() for invalid index_block\n\nntfs_icx_ib_sync_write() calls post_write_mst_fixup() when ntfs_ib_write()\nreturns an error, intending to restore the buffer after a failed write.\n\nHowever, ntfs_ib_write() returns an error immediately if\npre_write_mst_fixup() validation fails. The caller,\nntfs_icx_ib_sync_write(), interprets any error as a write failure\nrequiring rollback. It does not differentiate between I/O errors and\nvalidation failures, and calls post_write_mst_fixup() anyway.\n\nSince post_write_mst_fixup() assumes that the index_block contents is\ncorrect, it doesn't perform the boundary checks, which results in\nout-of-bounds memory access.\n\nAn attacker can craft a malicious NTFS image with:\n  - large index_block.usa_ofs offset, pointing outside the ntfs_record\n  - index_block.usa_count = 0, causing integer underflow\n  - or index_block.usa_count larger than actual number of sectors in the\n    ntfs_record, causing out-of-bounds access\n\nKASAN reports describing the memory corruption:\n  ==================================================================\n  BUG: KASAN: slab-out-of-bounds in post_write_mst_fixup+0x19c/0x1d0\n  Read of size 2 at addr ffff8881586c9018 by task p/9428\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0x100/0x190\n   print_report+0x139/0x4ad\n   ? post_write_mst_fixup+0x19c/0x1d0\n   ? __virt_addr_valid+0x262/0x500\n   ? post_write_mst_fixup+0x19c/0x1d0\n   kasan_report+0xe4/0x1d0\n   ? post_write_mst_fixup+0x19c/0x1d0\n   post_write_mst_fixup+0x19c/0x1d0\n   ntfs_icx_ib_sync_write+0x179/0x220\n   ntfs_inode_sync_filename+0x83d/0x1080\n   __ntfs_write_inode+0x1049/0x1480\n   ntfs_file_fsync+0x131/0x9b0\n  ==================================================================\n  BUG: KASAN: slab-out-of-bounds in post_write_mst_fixup+0x1aa/0x1d0\n  Write of size 2 at addr ffff8881586c91fe by task p/9428\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0x100/0x190\n   print_report+0x139/0x4ad\n   ? post_write_mst_fixup+0x1aa/0x1d0\n   ? __virt_addr_valid+0x262/0x500\n   ? post_write_mst_fixup+0x1aa/0x1d0\n   kasan_report+0xe4/0x1d0\n   ? post_write_mst_fixup+0x1aa/0x1d0\n   post_write_mst_fixup+0x1aa/0x1d0\n   ntfs_icx_ib_sync_write+0x179/0x220\n   ntfs_inode_sync_filename+0x83d/0x1080\n   __ntfs_write_inode+0x1049/0x1480\n   ntfs_file_fsync+0x131/0x9b0\n  ==================================================================\n\nLet's move the post_write_mst_fixup() call to ntfs_ib_write().\nThe ntfs_ib_write() function calls pre_write_mst_fixup() at the beginning.\nIf the index_block contents is invalid, pre_write_mst_fixup() fails and\nntfs_ib_write() returns early without calling post_write_mst_fixup() on\nbad index_block."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/index.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0a8ac0c1fa0b99a5b29002bc7f232ed7eafddef0","lessThan":"e2018628301a6d9f54e34b0cb417f1688c66df1d","versionType":"git","status":"affected"},{"version":"0a8ac0c1fa0b99a5b29002bc7f232ed7eafddef0","lessThan":"5b6eedd7cc2936f9238e852b553a1b326105bde8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/index.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5b6eedd7cc2936f9238e852b553a1b326105bde8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2018628301a6d9f54e34b0cb417f1688c66df1d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64432","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:27.437","lastModified":"2026-07-25T10:17:27.437","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns\n\nIn the analysis pass of $LogFile journal replay, log_replay() copies\nLCNs from each action log record into an existing Dirty Page Table\n(DPT) entry without bounding the destination index. A crafted NTFS\nimage with DPT entry lcns_follow=1 and an action log record with\nlcns_follow=2 produces a kernel slab out-of-bounds write at mount\ntime:\n\n  BUG: KASAN: slab-out-of-bounds in log_replay+0x654c/0xdb60\n  Write of size 8 at addr ffff8880095e1040 by task mount\n\nTwo attacker-controlled fields can drive j+i past the allocated\npage_lcns[] array:\n\n  1. dp->lcns_follow (capacity) can be smaller than lrh->lcns_follow.\n  2. lrh->target_vcn may be smaller than dp->vcn, making the u64\n     subtraction wrap to a huge size_t.\n\nValidate target VCN delta and per-record LCN count against the\nDPT entry capacity, bail via the existing out: cleanup label with\n-EINVAL.\n\nThis mirrors the bounds-check pattern added in commit b2bc7c44ed17\n(\"fs/ntfs3: Fix slab-out-of-bounds read in DeleteIndexEntryRoot\")\nand commit 0ca0485e4b2e (\"fs/ntfs3: validate rec->used in\njournal-replay file record check\")."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs3/fslog.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"964c3fae1dfc49dde5468eace940f199cda234e9","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"3aa96956ca2200674e2a8f9c23ec6ecd45e5010f","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"946046841013ebac8492ef49651c53638d7a9a6a","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"c6f9e804f73ef809529865fbc7256dd189ff8c33","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"cf28fc1658463d768657cf1c27a83980d4ba7ef2","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"f433acc85b86f327d03ba8b03a33c105c51053de","versionType":"git","status":"affected"},{"version":"b46acd6a6a627d876898e1c84d3f84902264b445","lessThan":"57382ec6ac63b63dce2789e835fded28b698ae79","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs3/fslog.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3aa96956ca2200674e2a8f9c23ec6ecd45e5010f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/57382ec6ac63b63dce2789e835fded28b698ae79","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/946046841013ebac8492ef49651c53638d7a9a6a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/964c3fae1dfc49dde5468eace940f199cda234e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c6f9e804f73ef809529865fbc7256dd189ff8c33","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf28fc1658463d768657cf1c27a83980d4ba7ef2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f433acc85b86f327d03ba8b03a33c105c51053de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64433","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:27.567","lastModified":"2026-07-25T10:17:27.567","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete\n\nadd_device_complete() runs from the hci_cmd_sync_work kworker, which\nholds only hci_req_sync_lock and *not* hci_dev_lock.  It calls\nhci_conn_params_lookup() and then dereferences the returned object\n(params->flags) without taking hci_dev_lock:\n\n\tparams = hci_conn_params_lookup(hdev, &cp->addr.bdaddr,\n\t\t\t\t\tle_addr_type(cp->addr.type));\n\t...\n\tdevice_flags_changed(NULL, hdev, &cp->addr.bdaddr,\n\t\t\t     cp->addr.type, hdev->conn_flags,\n\t\t\t     params ? params->flags : 0);\n\nhci_conn_params_lookup() walks hdev->le_conn_params and is documented to\nrequire hdev->lock.  A concurrent MGMT_OP_REMOVE_DEVICE\n(remove_device()), which does run under hci_dev_lock, can call\nhci_conn_params_free() to list_del() and kfree() the very object the\nlookup returned, so the subsequent params->flags read touches freed\nmemory [0].\n\nHold hci_dev_lock() across the hci_conn_params_lookup() and the read of\nparams->flags (and the matching event emission) so the lookup result\ncannot be freed by a concurrent remove_device() before it is used,\nhonouring the locking contract of hci_conn_params_lookup().\n\n[0]: (trailing page/memory-state dump trimmed)\nBUG: KASAN: slab-use-after-free in add_device_complete+0x358/0x3d8 net/bluetooth/mgmt.c:7671\nRead of size 1 at addr ffff000017ab26c1 by task kworker/u9:8/388\n\nCPU: 1 UID: 0 PID: 388 Comm: kworker/u9:8 Not tainted 7.0.11 #20 PREEMPT\nHardware name: linux,dummy-virt (DT)\nWorkqueue: hci0 hci_cmd_sync_work\nCall trace:\n show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:499 (C)\n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0xb4/0xd4 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0x118/0x5d8 mm/kasan/report.c:482\n kasan_report+0xb0/0xf4 mm/kasan/report.c:595\n __asan_report_load1_noabort+0x20/0x2c mm/kasan/report_generic.c:378\n add_device_complete+0x358/0x3d8 net/bluetooth/mgmt.c:7671\n hci_cmd_sync_work+0x14c/0x240 net/bluetooth/hci_sync.c:334\n process_one_work+0x628/0xd38 kernel/workqueue.c:3289\n process_scheduled_works kernel/workqueue.c:3372 [inline]\n worker_thread+0x7a8/0xac0 kernel/workqueue.c:3453\n kthread+0x39c/0x444 kernel/kthread.c:436\n ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:860\n\nAllocated by task 3401:\n kasan_save_stack+0x3c/0x64 mm/kasan/common.c:57\n kasan_save_track+0x20/0x3c mm/kasan/common.c:78\n kasan_save_alloc_info+0x40/0x54 mm/kasan/generic.c:570\n poison_kmalloc_redzone mm/kasan/common.c:398 [inline]\n __kasan_kmalloc+0xd4/0xd8 mm/kasan/common.c:415\n kasan_kmalloc include/linux/kasan.h:263 [inline]\n __kmalloc_cache_noprof+0x1b0/0x458 mm/slub.c:5385\n kmalloc_noprof include/linux/slab.h:950 [inline]\n kzalloc_noprof include/linux/slab.h:1188 [inline]\n hci_conn_params_add+0x10c/0x4b0 net/bluetooth/hci_core.c:2279\n hci_conn_params_set net/bluetooth/mgmt.c:5162 [inline]\n add_device+0x5b4/0xa54 net/bluetooth/mgmt.c:7755\n hci_mgmt_cmd net/bluetooth/hci_sock.c:1721 [inline]\n hci_sock_sendmsg+0x10b4/0x1dd0 net/bluetooth/hci_sock.c:1841\n sock_sendmsg_nosec net/socket.c:727 [inline]\n __sock_sendmsg+0xe0/0x128 net/socket.c:742\n sock_write_iter+0x250/0x390 net/socket.c:1195\n new_sync_write fs/read_write.c:595 [inline]\n vfs_write+0x66c/0xab0 fs/read_write.c:688\n ksys_write+0x1fc/0x24c fs/read_write.c:740\n __do_sys_write fs/read_write.c:751 [inline]\n __se_sys_write fs/read_write.c:748 [inline]\n __arm64_sys_write+0x70/0xa4 fs/read_write.c:748\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x84/0x2a8 arch/arm64/kernel/syscall.c:49\n el0_svc_common.constprop.0+0xe4/0x294 arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x44/0x5c arch/arm64/kernel/syscall.c:151\n el0_svc+0x38/0xac arch/arm64/kernel/entry-common.c:724\n el0t_64_sync_handler+0xa0/0xe4 arch/arm64/kernel/entry-common.c:743\n el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:596\n\nFreed by task 3740:\n kasan_save_stack+0x3c/0x64 \n---truncated---"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/mgmt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"31492b8386e5a243df26ca4a9421f6b041f414d5","lessThan":"caed4a96d55757c139a899744657c032b6186665","versionType":"git","status":"affected"},{"version":"28826a89fdfd49f3291980c2e68b8a7c5d55e199","lessThan":"e4369e4e970f3fa4676b76be14c1d315c87f22b6","versionType":"git","status":"affected"},{"version":"1e2e3044c1bc64a64aa0eaf7c17f7832c26c9775","lessThan":"b346efa825b5e4386f19bc63f81141652d496ec4","versionType":"git","status":"affected"},{"version":"1e2e3044c1bc64a64aa0eaf7c17f7832c26c9775","lessThan":"9531014c60c804e16099885d4a98aedcf31bce8d","versionType":"git","status":"affected"},{"version":"1e2e3044c1bc64a64aa0eaf7c17f7832c26c9775","lessThan":"fa85d985f614bc3feb343000f14a1072e99b0df1","versionType":"git","status":"affected"},{"version":"7e370545b8bdb54ed7f1ae485d6d24d3b62a0b53","versionType":"git","status":"affected"},{"version":"6.6.92","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.30","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"6.14.8","lessThan":"6.15","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/mgmt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/9531014c60c804e16099885d4a98aedcf31bce8d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b346efa825b5e4386f19bc63f81141652d496ec4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/caed4a96d55757c139a899744657c032b6186665","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e4369e4e970f3fa4676b76be14c1d315c87f22b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fa85d985f614bc3feb343000f14a1072e99b0df1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64434","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:27.717","lastModified":"2026-07-25T10:17:27.717","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref\n\nl2cap_chan_timeout() runs asynchronously and accesses chan->conn. If\nthe connection is torn down while the timer is running or pending,\nchan->conn can be freed, leading to a use-after-free when the timer\nworker attempts to lock conn->lock:\n\n| BUG: KASAN: slab-use-after-free in instrument_atomic_read_write include/linux/instrumented.h:112 [inline]\n| BUG: KASAN: slab-use-after-free in atomic_long_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:4456 [inline]\n| BUG: KASAN: slab-use-after-free in __mutex_trylock_fast kernel/locking/mutex.c:161 [inline]\n| BUG: KASAN: slab-use-after-free in mutex_lock+0x4f/0xa0 kernel/locking/mutex.c:318\n| Write of size 8 at addr ffff8881298d9550 by task kworker/2:1/83\n|\n| CPU: 2 UID: 0 PID: 83 Comm: kworker/2:1 Not tainted 7.1.0-rc6-next-20260601-dirty #6 PREEMPT(full)\n| Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014\n| Workqueue: events l2cap_chan_timeout\n| Call Trace:\n|  <TASK>\n|  instrument_atomic_read_write include/linux/instrumented.h:112 [inline]\n|  atomic_long_try_cmpxchg_acquire include/linux/atomic/atomic-instrumented.h:4456 [inline]\n|  __mutex_trylock_fast kernel/locking/mutex.c:161 [inline]\n|  mutex_lock+0x4f/0xa0 kernel/locking/mutex.c:318\n|  l2cap_chan_timeout+0x5d/0x1b0 net/bluetooth/l2cap_core.c:422\n|  process_one_work kernel/workqueue.c:3326 [inline]\n|  process_scheduled_works+0x7c8/0xfb0 kernel/workqueue.c:3409\n|  worker_thread+0x8a9/0xcf0 kernel/workqueue.c:3490\n|  kthread+0x346/0x430 kernel/kthread.c:436\n|  ret_from_fork+0x1a3/0x470 arch/x86/kernel/process.c:158\n|  ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n|  </TASK>\n|\n| Allocated by task 320:\n|  l2cap_conn_add+0xa7/0x820 net/bluetooth/l2cap_core.c:7075\n|  l2cap_connect_cfm+0xdb/0xd70 net/bluetooth/l2cap_core.c:7452\n|  hci_connect_cfm include/net/bluetooth/hci_core.h:2139 [inline]\n|  hci_remote_features_evt+0x52f/0x9f0 net/bluetooth/hci_event.c:3760\n|  hci_event_func net/bluetooth/hci_event.c:7796 [inline]\n|  hci_event_packet+0x561/0xa70 net/bluetooth/hci_event.c:7847\n|  hci_rx_work+0x370/0x890 net/bluetooth/hci_core.c:4040\n|  process_one_work kernel/workqueue.c:3326 [inline]\n|  process_scheduled_works+0x7c8/0xfb0 kernel/workqueue.c:3409\n|  worker_thread+0x8a9/0xcf0 kernel/workqueue.c:3490\n|  kthread+0x346/0x430 kernel/kthread.c:436\n|  ret_from_fork+0x1a3/0x470 arch/x86/kernel/process.c:158\n|  ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n|\n| Freed by task 322:\n|  hci_disconn_cfm include/net/bluetooth/hci_core.h:2154 [inline]\n|  hci_conn_hash_flush+0x101/0x1f0 net/bluetooth/hci_conn.c:2736\n|  hci_dev_close_sync+0x889/0xde0 net/bluetooth/hci_sync.c:5405\n|  hci_dev_do_close net/bluetooth/hci_core.c:502 [inline]\n|  hci_unregister_dev+0x1f7/0x370 net/bluetooth/hci_core.c:2679\n|  vhci_release+0x12a/0x180 drivers/bluetooth/hci_vhci.c:690\n|  __fput+0x369/0x890 fs/file_table.c:510\n|  task_work_run+0x160/0x1d0 kernel/task_work.c:233\n|  get_signal+0xf5b/0x1120 kernel/signal.c:2810\n|  arch_do_signal_or_restart+0x4d/0x600 arch/x86/kernel/signal.c:337\n|  __exit_to_user_mode_loop kernel/entry/common.c:64 [inline]\n|  exit_to_user_mode_loop+0x85/0x510 kernel/entry/common.c:98\n|  do_syscall_64+0x263/0x3d0 arch/x86/entry/syscall_64.c:100\n|  entry_SYSCALL_64_after_hwframe+0x77/0x7f\n|\n| The buggy address belongs to the object at ffff8881298d9400\n|  which belongs to the cache kmalloc-512 of size 512\n| The buggy address is located 336 bytes inside of\n|  freed 512-byte region [ffff8881298d9400, ffff8881298d9600)\n\nFix it by having chan->conn hold a reference to l2cap_conn (via\nl2cap_conn_get) when the channel is added to the connection, and\nreleasing it in the channel destructor. This ensures the l2cap_conn\nremains alive as long as the channel exists.\n\nA new FLAG_DEL channel flag is introduced to indicate that the ch\n---truncated---"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/bluetooth/l2cap.h","net/bluetooth/l2cap_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"89dec92041717b027216e110599e4f6d6c921b79","lessThan":"91047a4396a8b1857a6f712a90cf33ec0012b189","versionType":"git","status":"affected"},{"version":"50dfec218808b148ab4247b1858031b7a32015c5","lessThan":"0b0e2bf39cf99e458d991b9df253727e036a7d7d","versionType":"git","status":"affected"},{"version":"859d3ace791ed878ae9ba5522c7844d960da8f88","lessThan":"d3b739db5dc6f688a60d56da872fabaf65246032","versionType":"git","status":"affected"},{"version":"8c8e620467a7b51562dbcefbd1f09f288d7d710d","lessThan":"50c38d9f42a529691e4e67ea9cedf4f0bfc8d277","versionType":"git","status":"affected"},{"version":"8c8e620467a7b51562dbcefbd1f09f288d7d710d","lessThan":"b66774b48dd98f07254951f74ea6f513efe7ff8b","versionType":"git","status":"affected"},{"version":"3634cbdc2eb414b69ffa752ddbe5e0458518e321","versionType":"git","status":"affected"},{"version":"e1c100e2d61bd8c718b7d91fe3e050780a9bf72d","versionType":"git","status":"affected"},{"version":"deb8493a8fa599f6c95e2465b12bfdfb7f94a1d9","versionType":"git","status":"affected"},{"version":"7555fd885a0603f50e49a655850a1f2bd8a25398","versionType":"git","status":"affected"},{"version":"6.6.143","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.93","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.18.35","lessThan":"6.18.39","versionType":"semver","status":"affected"},{"version":"5.10.259","lessThan":"5.11","versionType":"semver","status":"affected"},{"version":"5.15.210","lessThan":"5.16","versionType":"semver","status":"affected"},{"version":"6.1.176","lessThan":"6.2","versionType":"semver","status":"affected"},{"version":"7.0.12","lessThan":"7.1","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/bluetooth/l2cap.h","net/bluetooth/l2cap_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0b0e2bf39cf99e458d991b9df253727e036a7d7d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/50c38d9f42a529691e4e67ea9cedf4f0bfc8d277","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/91047a4396a8b1857a6f712a90cf33ec0012b189","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b66774b48dd98f07254951f74ea6f513efe7ff8b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3b739db5dc6f688a60d56da872fabaf65246032","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64435","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:27.873","lastModified":"2026-07-25T10:17:27.873","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\naudit: Fix data races of skb_queue_len() readers on audit_queue\n\nMultiple readers access audit_queue.qlen via skb_queue_len() without\nholding the queue lock or using READ_ONCE(), while kauditd writes to\nthis field via the skb_dequeue() → __skb_unlink() path with WRITE_ONCE()\nprotected by a spinlock. This constitutes data races.\n\nAll affected skb_queue_len(&audit_queue) call sites:\n  - kauditd_thread() wait_event_freezable() condition\n  - audit_receive_msg() AUDIT_GET handler (s.backlog assignment)\n  - audit_receive() backlog check\n  - audit_log_start() backlog check and pr_warn()\n\nKCSAN reports the following conflicting access pattern (one example):\n==================================================================\nBUG: KCSAN: data-race in audit_log_start / skb_dequeue\n\nwrite (marked) to 0xffffffff8512ee20 of 4 bytes by task 661 on cpu 57:\n skb_dequeue+0x70/0xf0\n kauditd_send_queue+0x71/0x220\n kauditd_thread+0x1cb/0x430\n kthread+0x1c2/0x210\n ret_from_fork+0x162/0x1a0\n ret_from_fork_asm+0x1a/0x30\n\nread to 0xffffffff8512ee20 of 4 bytes by task 36586 on cpu 1:\n audit_log_start+0x2a0/0x6b0\n audit_core_dumps+0x64/0xa0\n do_coredump+0x14b/0x1260\n get_signal+0xeb2/0xf70\n arch_do_signal_or_restart+0x41/0x170\n exit_to_user_mode_loop+0xa2/0x1c0\n do_syscall_64+0x1a3/0x1c0\n entry_SYSCALL_64_after_hwframe+0x76/0xe0\n\nvalue changed: 0x00000001 -> 0x00000000\n==================================================================\n\nResolve the race by switching to lockless helper skb_queue_len_lockless(),\nwhich internally uses READ_ONCE() and properly pairs with the WRITE_ONCE()\nwrite accesses already present on the writer side.\n\n[PM: line length tweak]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/audit.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3197542482df22c2a131d4a813280bd7c54cedf5","lessThan":"69f98fff30bdaa72b0cb0e7e078ab6456a0a59b0","versionType":"git","status":"affected"},{"version":"3197542482df22c2a131d4a813280bd7c54cedf5","lessThan":"b35597bdae1a5d8395da4b9baa993b9b71f74d68","versionType":"git","status":"affected"},{"version":"3197542482df22c2a131d4a813280bd7c54cedf5","lessThan":"e575dabb805252e3113fdc3f56f6ecacfde422d0","versionType":"git","status":"affected"},{"version":"3197542482df22c2a131d4a813280bd7c54cedf5","lessThan":"7ff42312ccde549f8c698723822c7db35107a39b","versionType":"git","status":"affected"},{"version":"3197542482df22c2a131d4a813280bd7c54cedf5","lessThan":"a3d85dec60bb0622360fc176b2a51abdbe2ff0ad","versionType":"git","status":"affected"},{"version":"3197542482df22c2a131d4a813280bd7c54cedf5","lessThan":"fe997a84a385f840b593ead92e575503a5046cee","versionType":"git","status":"affected"},{"version":"3197542482df22c2a131d4a813280bd7c54cedf5","lessThan":"c5186201fa7030289cc4fe23fae87a3fcb566856","versionType":"git","status":"affected"},{"version":"3197542482df22c2a131d4a813280bd7c54cedf5","lessThan":"c9a71daaecb2fb1d8c704545cc0b1c920b9bf5d7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/audit.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.10","status":"affected"},{"version":"0","lessThan":"4.10","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/69f98fff30bdaa72b0cb0e7e078ab6456a0a59b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7ff42312ccde549f8c698723822c7db35107a39b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3d85dec60bb0622360fc176b2a51abdbe2ff0ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b35597bdae1a5d8395da4b9baa993b9b71f74d68","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c5186201fa7030289cc4fe23fae87a3fcb566856","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9a71daaecb2fb1d8c704545cc0b1c920b9bf5d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e575dabb805252e3113fdc3f56f6ecacfde422d0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe997a84a385f840b593ead92e575503a5046cee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64436","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:28.010","lastModified":"2026-07-25T10:17:28.010","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: af_key: initialize alg_key_len for IPComp states\n\npfkey_msg2xfrm_state() handles the IPComp (SADB_X_SATYPE_IPCOMP) case by\nallocating x->calg and copying only the algorithm name:\n\n\tx->calg = kmalloc_obj(*x->calg);\n\tif (!x->calg) {\n\t\terr = -ENOMEM;\n\t\tgoto out;\n\t}\n\tstrcpy(x->calg->alg_name, a->name);\n\tx->props.calgo = sa->sadb_sa_encrypt;\n\nUnlike the authentication (x->aalg) and encryption (x->ealg) branches of\nthe same function, the compression branch never initializes\ncalg->alg_key_len.  IPComp carries no key and the allocation only\nreserves sizeof(struct xfrm_algo) (i.e. no room for a key), so the field\nis left containing uninitialized slab data.\n\ncalg->alg_key_len is later used as a length by xfrm_algo_clone() when an\nIPComp state is cloned during XFRM_MSG_MIGRATE:\n\n\txfrm_state_migrate()\n\t  xfrm_state_clone_and_setup()\n\t    x->calg = xfrm_algo_clone(orig->calg);\n\t      kmemdup(orig, xfrm_alg_len(orig));\n\nwhere xfrm_alg_len() returns sizeof(*alg) + (alg_key_len + 7) / 8.  With\na non-zero garbage alg_key_len, kmemdup() reads past the end of the\n68-byte calg object.  Adding an IPComp SA via PF_KEY and then migrating\nit triggers (net-next, KASAN, init_on_alloc=0):\n\n  BUG: KASAN: slab-out-of-bounds in kmemdup_noprof+0x44/0x60\n  Read of size 4164 at addr ff11000025a74980 by task diag2/9287\n  CPU: 3 UID: 0 PID: 9287 Comm: diag2 7.1.0-rc6-g903db046d557 #1\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0x10e/0x1f0\n   print_report+0xf7/0x600\n   kasan_report+0xe4/0x120\n   kasan_check_range+0x105/0x1b0\n   __asan_memcpy+0x23/0x60\n   kmemdup_noprof+0x44/0x60\n   xfrm_state_migrate+0x70a/0x1da0\n   xfrm_migrate+0x753/0x18a0\n   xfrm_do_migrate+0xb47/0xf10\n   xfrm_user_rcv_msg+0x411/0xb50\n   netlink_rcv_skb+0x158/0x420\n   xfrm_netlink_rcv+0x71/0x90\n   netlink_unicast+0x584/0x850\n   netlink_sendmsg+0x8b0/0xdc0\n   ____sys_sendmsg+0x9f7/0xb90\n   ___sys_sendmsg+0x134/0x1d0\n   __sys_sendmsg+0x16d/0x220\n   do_syscall_64+0x116/0x7d0\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n   </TASK>\n\n  Allocated by task 9287:\n   kasan_save_stack+0x33/0x60\n   kasan_save_track+0x14/0x30\n   __kasan_kmalloc+0xaa/0xb0\n   pfkey_add+0x2652/0x2ea0\n   pfkey_process+0x6d0/0x830\n   pfkey_sendmsg+0x42c/0x850\n   __sys_sendto+0x461/0x4b0\n   __x64_sys_sendto+0xe0/0x1c0\n   do_syscall_64+0x116/0x7d0\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n  The buggy address belongs to the object at ff11000025a74980\n   which belongs to the cache kmalloc-96 of size 96\n  The buggy address is located 0 bytes inside of\n   allocated 68-byte region [ff11000025a74980, ff11000025a749c4)\n\nDepending on the uninitialized value the same field can instead request\nan oversized kmemdup() allocation and make the migration clone fail.\n\nThe XFRM netlink path is not affected: verify_one_alg() rejects an\nXFRMA_ALG_COMP attribute shorter than xfrm_alg_len(), so a calg added via\nXFRM_MSG_NEWSA is always self-consistent.\n\nInitialize calg->alg_key_len to 0, matching the aalg/ealg branches."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/key/af_key.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","lessThan":"58e82fc3dedb57b1432292504415b224fd2d6acb","versionType":"git","status":"affected"},{"version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","lessThan":"01b9115b55018123ef2449ac4951f89147a8428e","versionType":"git","status":"affected"},{"version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","lessThan":"3f63d1752d90c0e28be931a48ab5d89bc97d637d","versionType":"git","status":"affected"},{"version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","lessThan":"273c06b81d2e902b21acc801ae18c8276c8a9b69","versionType":"git","status":"affected"},{"version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","lessThan":"6de2a650917bedaaefd65b17cede83c5e2c1dedd","versionType":"git","status":"affected"},{"version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","lessThan":"e8417353cbd078d10531ba3928e609c84ab09e6b","versionType":"git","status":"affected"},{"version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","lessThan":"cea34abc94b0a81e3a8b5cfb41cf45af37c2c67e","versionType":"git","status":"affected"},{"version":"80c9abaabf4283f7cf4a0b3597cd302506635b7f","lessThan":"d129c3177d7b1138fd5066fcc63a698b3ba415b0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/key/af_key.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.21","status":"affected"},{"version":"0","lessThan":"2.6.21","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/01b9115b55018123ef2449ac4951f89147a8428e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/273c06b81d2e902b21acc801ae18c8276c8a9b69","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3f63d1752d90c0e28be931a48ab5d89bc97d637d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/58e82fc3dedb57b1432292504415b224fd2d6acb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6de2a650917bedaaefd65b17cede83c5e2c1dedd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cea34abc94b0a81e3a8b5cfb41cf45af37c2c67e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d129c3177d7b1138fd5066fcc63a698b3ba415b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e8417353cbd078d10531ba3928e609c84ab09e6b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64437","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:28.160","lastModified":"2026-07-25T10:17:28.160","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL\n\nCommit f580d27e8928 (\"ksmbd: fix use-after-free of a deferred file_lock on\ndouble SMB2_CANCEL\") made smb2_cancel() skip a work whose state is\nKSMBD_WORK_CANCELLED, so its cancel_fn cannot be fired a second time. But\nKSMBD_WORK has three states (ACTIVE, CANCELLED, CLOSED), and the same\nfreeing producer path is reached for CLOSED too:\n\n  SMB2_CLOSE on the locking handle -> set_close_state_blocked_works() sets\n  the deferred work's state to KSMBD_WORK_CLOSED and wakes the smb2_lock()\n  worker. The worker takes the non-ACTIVE early-exit, locks_free_lock()s\n  the file_lock and, because the state is not KSMBD_WORK_CANCELLED, takes\n  the STATUS_RANGE_NOT_LOCKED branch with \"goto out2\" -- which, like the\n  cancelled branch, skips release_async_work(). The work stays on\n  conn->async_requests with a live cancel_fn = smb2_remove_blocked_lock\n  pointing at the freed file_lock.\n\nA subsequent SMB2_CANCEL for the same AsyncId then passes the\nKSMBD_WORK_CANCELLED-only guard (its state is KSMBD_WORK_CLOSED), so\nsmb2_cancel() fires cancel_fn again over the freed file_lock -- the same\nuse-after-free fixed, via SMB2_CLOSE instead of a first SMB2_CANCEL:\n\n  BUG: KASAN: slab-use-after-free in __locks_delete_block\n    __locks_delete_block\n    locks_delete_block\n    ksmbd_vfs_posix_lock_unblock\n    smb2_remove_blocked_lock\n    smb2_cancel                 <- 2nd SMB2_CANCEL fires cancel_fn\n    handle_ksmbd_work\n  Allocated by ...: locks_alloc_lock <- smb2_lock\n  Freed by ...:     locks_free_lock  <- smb2_lock (non-ACTIVE early-exit)\n  ... cache file_lock_cache of size 192\n\nReproduced on mainline 7.1-rc7 (which already contains f580d27e8928) with\nKASAN by an authenticated SMB client; the double-SMB2_CANCEL control is\nsilent on that kernel, so the splat is attributable to the CLOSE trigger.\n\nOnly an ACTIVE deferred work may have its cancel_fn fired: both terminal\nstates (CANCELLED and CLOSED) reach the smb2_lock() early-exit that frees\nthe file_lock and skips release_async_work(). Guard on KSMBD_WORK_ACTIVE\nso any non-active work is skipped."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b7063c7426ea5a4d15e01b60538718765392f49d","lessThan":"a796ba4e61d5e14e07b79a359faac69f8f9b22a3","versionType":"git","status":"affected"},{"version":"0da2e073f9cbf4985a0fd9acb71bc5ff599f8afd","lessThan":"b8e274e69ab09222c7a552c7c0c1eef9ce627fc1","versionType":"git","status":"affected"},{"version":"89ae9df09d2c1fb4a4eb495c113a7ce1dca34147","lessThan":"ddb9239828336b36d8a3ef5943fdffb2f55b6508","versionType":"git","status":"affected"},{"version":"14d2eee0193ac3cd1bf3d014373449f0b8d35d6d","lessThan":"94083db751930b1540ddff2b54d4677549c57f81","versionType":"git","status":"affected"},{"version":"f580d27e8928828693df44ba2db0fffdbe11dfea","lessThan":"12c36c99655f325befe50c26842f7deca414c381","versionType":"git","status":"affected"},{"version":"f580d27e8928828693df44ba2db0fffdbe11dfea","lessThan":"10f293a07f9e10e988b0ae44e2e99c631f5a68e0","versionType":"git","status":"affected"},{"version":"2b2eda2821cff1d1b5a423b6ee7d8fc6fbc8e694","versionType":"git","status":"affected"},{"version":"6.1.176","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.143","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.94","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"6.18.36","lessThan":"6.18.39","versionType":"semver","status":"affected"},{"version":"7.0.13","lessThan":"7.1","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/smb2pdu.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/10f293a07f9e10e988b0ae44e2e99c631f5a68e0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/12c36c99655f325befe50c26842f7deca414c381","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/94083db751930b1540ddff2b54d4677549c57f81","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a796ba4e61d5e14e07b79a359faac69f8f9b22a3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b8e274e69ab09222c7a552c7c0c1eef9ce627fc1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ddb9239828336b36d8a3ef5943fdffb2f55b6508","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64438","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:28.303","lastModified":"2026-07-25T10:17:28.303","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - fix VF2PF work teardown race in adf_disable_sriov()\n\nThe VF2PF interrupt handler queues PF-side response work that stores a\nraw pointer to per-VF state (struct adf_accel_vf_info). Currently,\nadf_disable_sriov() destroys per-VF mutexes and frees vf_info without\nstopping new VF2PF work or waiting for in-flight workers to complete. A\nconcurrently scheduled or already queued worker can then dereference\nfreed memory.\n\nThis manifests as a use-after-free when KASAN is enabled:\n\n  BUG: KASAN: null-ptr-deref in mutex_lock+0x76/0xe0\n  Write of size 8 at addr 0000000000000260 by task kworker/24:2/...\n  Workqueue: qat_pf2vf_resp_wq adf_iov_send_resp [intel_qat]\n  Call Trace:\n    kasan_report+0x119/0x140\n    mutex_lock+0x76/0xe0\n    adf_gen4_pfvf_send+0xd4/0x1f0 [intel_qat]\n    adf_recv_and_handle_vf2pf_msg+0x290/0x360 [intel_qat]\n    adf_iov_send_resp+0x8c/0xe0 [intel_qat]\n    process_one_work+0x6ac/0xfd0\n    worker_thread+0x4dd/0xd30\n    kthread+0x326/0x410\n    ret_from_fork+0x33b/0x670\n\nAdd a PF-local flag, vf2pf_disabled, that gates work queueing, worker\nprocessing, and interrupt re-enabling during teardown. Set this flag\natomically with the hardware interrupt mask inside\nadf_disable_all_vf2pf_interrupts(). After masking, synchronize the AE\ncluster MSI-X interrupt and flush the PF response workqueue before\ntearing down per-VF locks and state so all in-flight work completes\nbefore vf_info is destroyed.\n\nIntroduce adf_enable_all_vf2pf_interrupts() to clear the flag and\nunmask all VF2PF interrupts under the same lock when SR-IOV is\nre-enabled. This ensures the software flag and hardware state transition\natomically on both the enable and disable paths."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/intel/qat/qat_common/adf_accel_devices.h","drivers/crypto/intel/qat/qat_common/adf_common_drv.h","drivers/crypto/intel/qat/qat_common/adf_isr.c","drivers/crypto/intel/qat/qat_common/adf_sriov.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ed8ccaef52fa03fb03cff45b380f72c9f869f273","lessThan":"218c2836b3987f3fa1d9eac505462cded0821e4c","versionType":"git","status":"affected"},{"version":"ed8ccaef52fa03fb03cff45b380f72c9f869f273","lessThan":"446b4d77599cf1a168573f7fb32a4a6aa4f09219","versionType":"git","status":"affected"},{"version":"ed8ccaef52fa03fb03cff45b380f72c9f869f273","lessThan":"5d916c1eae1933511a69bffe243b4ee5d7da399c","versionType":"git","status":"affected"},{"version":"ed8ccaef52fa03fb03cff45b380f72c9f869f273","lessThan":"f344a369d0380d54c8d6c8d24734a78dd5a89817","versionType":"git","status":"affected"},{"version":"ed8ccaef52fa03fb03cff45b380f72c9f869f273","lessThan":"51144032248cc4ea22917370565650670b8b4e9b","versionType":"git","status":"affected"},{"version":"ed8ccaef52fa03fb03cff45b380f72c9f869f273","lessThan":"49cd5ac6de8de39a14ead609bb552d372d5602cd","versionType":"git","status":"affected"},{"version":"ed8ccaef52fa03fb03cff45b380f72c9f869f273","lessThan":"6e92b28cd74fa433658efeadf21b9d4b01023d7d","versionType":"git","status":"affected"},{"version":"ed8ccaef52fa03fb03cff45b380f72c9f869f273","lessThan":"277281c10c63791067d24d421f7c43a15faa9096","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/intel/qat/qat_common/adf_accel_devices.h","drivers/crypto/intel/qat/qat_common/adf_common_drv.h","drivers/crypto/intel/qat/qat_common/adf_isr.c","drivers/crypto/intel/qat/qat_common/adf_sriov.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.3","status":"affected"},{"version":"0","lessThan":"4.3","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/218c2836b3987f3fa1d9eac505462cded0821e4c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/277281c10c63791067d24d421f7c43a15faa9096","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/446b4d77599cf1a168573f7fb32a4a6aa4f09219","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/49cd5ac6de8de39a14ead609bb552d372d5602cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/51144032248cc4ea22917370565650670b8b4e9b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5d916c1eae1933511a69bffe243b4ee5d7da399c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e92b28cd74fa433658efeadf21b9d4b01023d7d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f344a369d0380d54c8d6c8d24734a78dd5a89817","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64439","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:28.447","lastModified":"2026-07-25T10:17:28.447","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: krb5 - filter out async aead implementations at alloc\n\nkrb5_aead_encrypt(), krb5_aead_decrypt() in rfc3961_simplified.c and\nrfc8009_encrypt(), rfc8009_decrypt() in rfc8009_aes2.c set a NULL\ncompletion callback and treat any negative return from\ncrypto_aead_{encrypt,decrypt}() as terminal, falling through to\nkfree_sensitive(buffer).  When the encrypt_name resolves to an\nasync AEAD instance the request returns -EINPROGRESS, the buffer\nis freed while the backend's worker still holds a pointer, and the\nworker dereferences the freed slab on completion.\n\nKASAN report under UML+SLUB with a synthetic async aead backend\nbound to krb5->encrypt_name:\n\n  BUG: KASAN: slab-use-after-free in t5_stub_complete+0x7d/0xc7\n\nThe helpers were written synchronously, so filter the async\ninstances out at allocation time instead of plumbing\ncrypto_wait_req() through every call site.\n\nReachable via net/rxrpc/rxgk.c, fs/afs/cm_security.c and\nnet/ceph/crypto.c on systems with an async AEAD provider bound to\nthe krb5 enctype name."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["crypto/krb5/krb5_api.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"00244da40f7821b242c4612428d4192230dba27f","lessThan":"ef6feb77e2d91761427c5b773edc9c97e1b706ad","versionType":"git","status":"affected"},{"version":"00244da40f7821b242c4612428d4192230dba27f","lessThan":"2b7bd6dccff14b8b632c5244f1fd506918077221","versionType":"git","status":"affected"},{"version":"00244da40f7821b242c4612428d4192230dba27f","lessThan":"6c9dddeb582fde005360f4fe02c760d45ca05fb5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["crypto/krb5/krb5_api.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2b7bd6dccff14b8b632c5244f1fd506918077221","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c9dddeb582fde005360f4fe02c760d45ca05fb5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef6feb77e2d91761427c5b773edc9c97e1b706ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64440","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:28.547","lastModified":"2026-07-25T10:17:28.547","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB write in HT_caps_handler()\n\nHT_caps_handler() iterates pIE->length bytes and writes into\nHT_caps.u.HT_cap[], which is a fixed 26-byte array (sizeof struct\nHT_caps_element). Because pIE->length is a raw u8 from an over-the-air\n802.11 AssocResponse frame and is never validated, a malicious AP can\nset it up to 255, causing up to 229 bytes of out-of-bounds writes into\nadjacent fields of struct mlme_ext_info.\n\nTruncate the iteration count to the size of HT_caps.u.HT_cap using\numin() so that data from a longer-than-expected IE is silently ignored\nrather than written out of bounds, preserving interoperability with APs\nthat pad the element. An early return on oversized IEs was considered\nbut rejected: it would bypass the pmlmeinfo->HT_caps_enable = 1\nassignment that precedes the loop, silently disabling HT mode for APs\nthat append extra bytes to the HT Capabilities IE."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/staging/rtl8723bs/core/rtw_wlan_util.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"37f642d47c3648a707df3ceb092eee1adffbfd28","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"8c872b47c7fc32e95e0da1db7512388794adcd69","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"bb3b942da4123b55d1cacf19d1a7d5ba15dbf83a","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"918537a0fbed85aab61fa28ad75e6279070610c9","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"6f91621fc45025ad3c0be796b70e6e4cee22fc69","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"225b6d3fc7e99ac3d20b6c861d1e47d24e7ea31d","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"f8001e1a516ba3b495728c65b61f799cbfad6bd0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/staging/rtl8723bs/core/rtw_wlan_util.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/225b6d3fc7e99ac3d20b6c861d1e47d24e7ea31d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/37f642d47c3648a707df3ceb092eee1adffbfd28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6f91621fc45025ad3c0be796b70e6e4cee22fc69","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8c872b47c7fc32e95e0da1db7512388794adcd69","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/918537a0fbed85aab61fa28ad75e6279070610c9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb3b942da4123b55d1cacf19d1a7d5ba15dbf83a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f8001e1a516ba3b495728c65b61f799cbfad6bd0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64441","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:28.670","lastModified":"2026-07-25T10:17:28.670","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()\n\nThree IE/attribute parsing functions have missing bounds checks.\n\nrtw_get_sec_ie() and rtw_get_wapi_ie() iterate over a raw IE buffer\nwithout verifying that the header bytes (tag + length) are within the\nremaining buffer before reading them.  Additionally, rtw_get_sec_ie()\ncompares the 4-byte WPA OUI at cnt+2 without checking that at least\n6 bytes remain, and rtw_get_wapi_ie() compares a 4-byte WAPI OUI at\ncnt+6 without checking that at least 10 bytes remain.\n\nrtw_get_wps_attr() reads wps_ie[0] and wps_ie+2 unconditionally at\nentry, before verifying that wps_ielen is large enough to contain\nthe 6-byte WPS IE header (element_id + length + 4-byte OUI).  Inside\nthe attribute loop, get_unaligned_be16() is called on attr_ptr and\nattr_ptr+2 without checking that 4 bytes remain in the buffer.\n\nAdd a cnt+2 bounds check before each loop body in rtw_get_sec_ie()\nand rtw_get_wapi_ie(), guard each multi-byte comparison with a minimum\nIE length requirement, add a wps_ielen < 6 early return in\nrtw_get_wps_attr(), and add a 4-byte bounds check in its inner loop."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/staging/rtl8723bs/core/rtw_ieee80211.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"efa27d487abcdec79669a60a6d94d5d6eceb7c1d","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"2ea1ce30ead61589214240e8d33d96310fd613e5","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"b27ecba3196f6c14e3809595ebd69c0c2392512a","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"6ab1161e539fb7a1c8b35ff5a6ced4702e855b9c","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"4b51ee8a40fe47864197d73cc02b191de7a6b072","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"729c4e72563bda0f1725db1db9ea08df06f41d9b","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"1463ca3ec6601cbb097d8d87dbf5dcf1cb86a344","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/staging/rtl8723bs/core/rtw_ieee80211.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1463ca3ec6601cbb097d8d87dbf5dcf1cb86a344","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2ea1ce30ead61589214240e8d33d96310fd613e5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4b51ee8a40fe47864197d73cc02b191de7a6b072","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6ab1161e539fb7a1c8b35ff5a6ced4702e855b9c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/729c4e72563bda0f1725db1db9ea08df06f41d9b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b27ecba3196f6c14e3809595ebd69c0c2392512a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/efa27d487abcdec79669a60a6d94d5d6eceb7c1d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64442","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:28.793","lastModified":"2026-07-25T10:17:28.793","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()\n\nTwo IE parsing loops are missing the header bounds checks before they\ndereference pIE->length:\n\n - issue_assocreq() walks pmlmeinfo->network.ies to build the\n   association request. If the stored IE data ends with only an\n   element_id byte and no length byte, pIE->length is read one byte\n   past the end of the buffer.\n\n - join_cmd_hdl() walks pnetwork->ies during station join and has\n   the same problem under the same conditions.\n\nBoth buffers are filled from AP beacon and probe-response frames, so a\nmalicious AP that sends a truncated final IE can trigger the issue.\n\nApply the two-guard pattern established in update_beacon_info():\n  1. Break if fewer than sizeof(*pIE) bytes remain.\n  2. Break if the IE's declared data extends past the buffer end."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/staging/rtl8723bs/core/rtw_mlme_ext.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"bc881c9915c4468747d0ca5fd1abd7b313cfb0f4","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"605ebd94d0f469204f3c9f2f84acc71e43e2780f","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"a830bdc82461353bf7b1f8a2ad2689bf5d2de444","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"4c21eec80cf502d9ea18e0b946246b2376452786","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"ad2637c46ef8b8ae0894372a2d39fdfcdc420a1e","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"c38d16b1ffac385c9e4b38447cd5c46af1114b58","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"402f13ec95945f34a210b28df1f8740d3d4a58c5","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"ef61d628dfad38fead1fd2e08979ae9126d011d5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/staging/rtl8723bs/core/rtw_mlme_ext.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/402f13ec95945f34a210b28df1f8740d3d4a58c5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4c21eec80cf502d9ea18e0b946246b2376452786","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/605ebd94d0f469204f3c9f2f84acc71e43e2780f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a830bdc82461353bf7b1f8a2ad2689bf5d2de444","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ad2637c46ef8b8ae0894372a2d39fdfcdc420a1e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bc881c9915c4468747d0ca5fd1abd7b313cfb0f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c38d16b1ffac385c9e4b38447cd5c46af1114b58","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef61d628dfad38fead1fd2e08979ae9126d011d5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64443","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:28.930","lastModified":"2026-07-25T10:17:28.930","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB read in update_beacon_info() IE loop\n\nThe IE parsing loop in update_beacon_info() advances by\n(pIE->length + 2) each iteration but only guards on i < len.\nWhen a malicious AP sends a Beacon whose last IE has only one byte\nremaining in the frame (the element_id byte lands at len-1), the loop\nreads pIE->length from one byte past the allocated receive buffer.\n\nAdditionally, even when the header bytes are in bounds, pIE->length\nitself can extend the data window beyond len, passing a truncated IE\nto the handler functions.\n\nAdd two guards at the top of the loop body:\n  1. Break if fewer than sizeof(*pIE) bytes remain (can't read header).\n  2. Break if the IE's declared data extends past len.\n\nAlso replace i += (pIE->length + 2) with i += sizeof(*pIE) + pIE->length\nfor consistency with the sizeof(*pIE) guards added above."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/staging/rtl8723bs/core/rtw_wlan_util.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"5e8db4cff5b45c7c4edc8ae3f302027c3bb32b25","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"6dd5e8c3011ebabf417257d7f07901a7c4311539","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"9193c34f75fd9e1ea8a590d7cced464c3380dc29","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"bd953d52d587d42365e399b96c52dbdb13032070","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"69f174a0673b6b7a29b851adb60bc450cdc0ecc4","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"b5cc2f999927f69723ca53f1f2a3aa37dbeda907","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"ed51de4a86e173c3b0ef78e039c2e49e08b11f16","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/staging/rtl8723bs/core/rtw_wlan_util.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5e8db4cff5b45c7c4edc8ae3f302027c3bb32b25","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/69f174a0673b6b7a29b851adb60bc450cdc0ecc4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6dd5e8c3011ebabf417257d7f07901a7c4311539","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9193c34f75fd9e1ea8a590d7cced464c3380dc29","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5cc2f999927f69723ca53f1f2a3aa37dbeda907","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd953d52d587d42365e399b96c52dbdb13032070","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed51de4a86e173c3b0ef78e039c2e49e08b11f16","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64444","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:29.053","lastModified":"2026-07-25T10:17:29.053","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop\n\nThe IE parsing loop in OnAssocRsp() advances by (pIE->length + 2) each\niteration but only guards on i < pkt_len. When a malicious AP sends an\nAssocResponse whose last IE has only one byte remaining in the frame\n(the element_id byte lands at pkt_len-1), the loop reads pIE->length\nfrom pframe[pkt_len], which is one byte past the allocated receive buffer.\n\nAdditionally, even when the header bytes are in bounds, pIE->length\nitself can extend the data window beyond pkt_len, silently passing a\ntruncated IE to the handler functions.\n\nAdd two guards at the top of the loop body:\n  1. Break if fewer than sizeof(*pIE) bytes remain (can't read header).\n  2. Break if the IE's declared data extends past pkt_len."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/staging/rtl8723bs/core/rtw_mlme_ext.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"889ca6000ac7fa73457b041848fcb08e0d51b809","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"1a52a05471494546f955a58e8c170c0c796c52d5","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"0406d746574e875d8778552eb674fcfbf5330bfb","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"0970dd47726a57e52013594e9fbf667586eb3673","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"04f612dc03427e0b1ac80a2611b5ac0ba93ac446","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"7e7741c8315e4160aead00a60cdd6f81ab880717","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"f9654207e92283e0acac5d64fe5f8835383b5a23","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/staging/rtl8723bs/core/rtw_mlme_ext.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0406d746574e875d8778552eb674fcfbf5330bfb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/04f612dc03427e0b1ac80a2611b5ac0ba93ac446","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0970dd47726a57e52013594e9fbf667586eb3673","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1a52a05471494546f955a58e8c170c0c796c52d5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7e7741c8315e4160aead00a60cdd6f81ab880717","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/889ca6000ac7fa73457b041848fcb08e0d51b809","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f9654207e92283e0acac5d64fe5f8835383b5a23","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64445","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:29.177","lastModified":"2026-07-25T10:17:29.177","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()\n\nOnAuth() has two bugs in the shared-key authentication path.\n\nWhen the Privacy bit is set, rtw_wep_decrypt() is called without\nverifying that the frame is long enough to contain a valid WEP IV and\nICV.  Inside rtw_wep_decrypt(), length is computed as:\n\n    length = len - WLAN_HDR_A3_LEN - iv_len\n\nand then passed as (length - 4) to crc32_le().  If len is less than\nWLAN_HDR_A3_LEN + iv_len + icv_len (32 bytes), length - 4 is negative\nand, after the implicit cast to size_t, causes crc32_le() to read far\nbeyond the frame buffer.  Add a minimum length check before accessing\nthe IV field and calling the decryption path.\n\nWhen processing a seq=3 response, rtw_get_ie() stores the Challenge\nText IE length in ie_len, but the subsequent memcmp() always reads 128\nbytes regardless of ie_len.  IEEE 802.11 mandates a challenge text of\nexactly 128 bytes; reject any IE whose length field differs, matching\nthe check already applied to OnAuthClient()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/staging/rtl8723bs/core/rtw_mlme_ext.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"665e1ecb68b4e8419604e70a33f02d1c8b0222c6","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"87cccc2a767f17dcab71e3b9fe5ae29b5516c5ce","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"c9000c93078e5c0a5a651b077c0ec92a4bc7d580","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"1f6c9d255bdda41216b6e34c96aa2b1abee0bb84","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"3e44a7665f3abd320a80d9c64ee4a93317041b8b","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"64ec4192d9c10e96922245d4a6747304cc76b19d","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"d90b9f39f375c9826ef145605dfe97765d0ecb91","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"a1fc19d61f661d47204f095b593de507884849f7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/staging/rtl8723bs/core/rtw_mlme_ext.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1f6c9d255bdda41216b6e34c96aa2b1abee0bb84","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3e44a7665f3abd320a80d9c64ee4a93317041b8b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/64ec4192d9c10e96922245d4a6747304cc76b19d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/665e1ecb68b4e8419604e70a33f02d1c8b0222c6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/87cccc2a767f17dcab71e3b9fe5ae29b5516c5ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a1fc19d61f661d47204f095b593de507884849f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9000c93078e5c0a5a651b077c0ec92a4bc7d580","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d90b9f39f375c9826ef145605dfe97765d0ecb91","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64446","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:29.310","lastModified":"2026-07-25T10:17:29.310","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()\n\nsupplicant_ie is a 256-byte array in struct security_priv. The WPA and\nWPA2 IE copy paths use:\n\n    memcpy(padapter->securitypriv.supplicant_ie, &pwpa[0], wpa_ielen + 2);\n\nwhere wpa_ielen is the raw IE length field (u8, 0-255). When a local user\nsupplies a connect request via nl80211 with a crafted WPA IE of length 255,\nwpa_ielen + 2 equals 257, overflowing the 256-byte buffer by one byte into\nthe adjacent last_mic_err_time field.\n\nrtw_parse_wpa_ie() does not prevent this: its length consistency check\ncompares *(wpa_ie+1) against (u8)(wpa_ie_len-2), which is (u8)(255) == 255\nwhen wpa_ie_len = 257, so the check passes silently.\n\nAdd explicit bounds checks for both the WPA and WPA2 paths before the\nmemcpy, rejecting any IE whose total size (wpa_ielen + 2) exceeds the\nsupplicant_ie buffer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"a94a643a80a84ceb8139061c3d6bf988d75e45a5","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"2131621986c62c86109ce4d84cf73a73757eb8a6","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"6f20d7b0ee47c470734a69379b0fc6647c519603","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"5d7812360abf3143afcbf5efe4ef242448fa1f28","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"46f66c16a95191d9aca07a72ae6b1252a244e26c","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"b9c4bf133c3c47e23baf4f5403b98a953bf58606","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"138cd190efd56ab36c9fdd8fef8749d06937f24b","versionType":"git","status":"affected"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"5a752a616e756844388a1a45404db9fc29fec655","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/138cd190efd56ab36c9fdd8fef8749d06937f24b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2131621986c62c86109ce4d84cf73a73757eb8a6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/46f66c16a95191d9aca07a72ae6b1252a244e26c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5a752a616e756844388a1a45404db9fc29fec655","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5d7812360abf3143afcbf5efe4ef242448fa1f28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6f20d7b0ee47c470734a69379b0fc6647c519603","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a94a643a80a84ceb8139061c3d6bf988d75e45a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b9c4bf133c3c47e23baf4f5403b98a953bf58606","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64447","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:29.437","lastModified":"2026-07-25T10:17:29.437","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: media: ipu7: fix double-free and use-after-free in error paths\n\nIn both ipu7_isys_init() and ipu7_psys_init(), pdata is allocated and\nthen passed to ipu7_bus_initialize_device(), which stores it in\nadev->pdata. The ipu7_bus_release() function frees adev->pdata when the\ndevice's reference count drops to zero.\n\nTwo error paths incorrectly call kfree(pdata) after the device teardown\nhas already freed it:\n\n1. When ipu7_mmu_init() fails: put_device() is called, which drops the\n   reference count to zero and triggers ipu7_bus_release() ->\n   kfree(pdata). The subsequent kfree(pdata) is a double-free.\n\n2. When ipu7_bus_add_device() fails: it calls auxiliary_device_uninit()\n   internally, which calls put_device() -> ipu7_bus_release() ->\n   kfree(pdata). The subsequent kfree(pdata) is again a double-free.\n\nNote that the kfree(pdata) when ipu7_bus_initialize_device() itself\nfails is correct, because in that case auxiliary_device_init() failed\nand the release function was never set up, so pdata must be freed\nmanually.\n\nAdditionally, the error code was not saved before calling put_device(),\ncausing ERR_CAST() to dereference the already-freed adev pointer when\nconstructing the return value. Fix this by saving the error from\ndev_err_probe() before put_device() and returning ERR_PTR() instead.\n\nRemove the redundant kfree(pdata) calls and fix the use-after-free in\nthe return values of the two affected error paths."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/staging/media/ipu7/ipu7.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b7fe4c0019b12d60ece3e99eeb0ccfd5a1d103e5","lessThan":"b5ddc7257bee71f5b8cf9083e2b0ac0427e9fbb3","versionType":"git","status":"affected"},{"version":"b7fe4c0019b12d60ece3e99eeb0ccfd5a1d103e5","lessThan":"837c1f9655421055f751ed34745e820a54a27642","versionType":"git","status":"affected"},{"version":"b7fe4c0019b12d60ece3e99eeb0ccfd5a1d103e5","lessThan":"d3a9a8cf2d7fd61a2f63df61f6cbc0a9bb007cc0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/staging/media/ipu7/ipu7.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/837c1f9655421055f751ed34745e820a54a27642","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5ddc7257bee71f5b8cf9083e2b0ac0427e9fbb3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3a9a8cf2d7fd61a2f63df61f6cbc0a9bb007cc0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64448","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:29.557","lastModified":"2026-07-25T10:17:29.557","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: restrict implied bcc[0] exemption to responses without data area\n\nsmb2_check_message() has a long-standing quirk that accepts a response\nwhose calculated length is one byte larger than the bytes actually\nreceived (\"server can return one byte more due to implied bcc[0]\").\nThis was introduced to accommodate servers that omit the trailing bcc[0]\noverlap byte when no data area is present.\n\nHowever, the exemption is applied unconditionally, regardless of whether\nthe command actually carries a data area (has_smb2_data_area[]).  When a\nresponse with a data area is subject to the +1 exemption, the reported\ndata can extend one byte beyond the bytes actually received, yet\nsmb2_check_message() still accepts it.  The subsequent decoder then reads\npast the end of the receive buffer.  This is reachable during NEGOTIATE\nand SESSION_SETUP, before the session is established.\n\nThe resulting out-of-bounds reads are visible under KASAN when mounting\nagainst a non-conforming server; both the SPNEGO/negTokenInit and the\nNTLMSSP challenge decoders are affected:\n\n  BUG: KASAN: slab-out-of-bounds in asn1_ber_decoder+0x16a7/0x1b00\n  Read of size 1 at addr ffff8880084d67c0 by task mount.cifs/81\n  CPU: 1 UID: 0 PID: 81 Comm: mount.cifs Not tainted 7.1.0-rc6 #1\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0x4e/0x70\n   print_report+0x157/0x4c9\n   kasan_report+0xce/0x100\n   asn1_ber_decoder+0x16a7/0x1b00\n   decode_negTokenInit+0x19/0x30\n   SMB2_negotiate+0x31d9/0x4c90\n   cifs_negotiate_protocol+0x1f2/0x3f0\n   cifs_get_smb_ses+0x93f/0x17e0\n   cifs_mount_get_session+0x7f/0x3a0\n   cifs_mount+0xb4/0xcf0\n   cifs_smb3_do_mount+0x23a/0x1500\n   smb3_get_tree+0x3b0/0x630\n   vfs_get_tree+0x82/0x2d0\n   fc_mount+0x10/0x1b0\n   path_mount+0x50d/0x1de0\n   __x64_sys_mount+0x20b/0x270\n   do_syscall_64+0xee/0x590\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n   </TASK>\n  Allocated by task 85:\n   kmem_cache_alloc_noprof+0x106/0x380\n   mempool_alloc_noprof+0x116/0x1e0\n   cifs_small_buf_get+0x31/0x80\n   allocate_buffers+0x10d/0x2b0\n   cifs_demultiplex_thread+0x1d5/0x1d50\n   kthread+0x2c6/0x390\n   ret_from_fork+0x36e/0x5a0\n   ret_from_fork_asm+0x1a/0x30\n  The buggy address is located 0 bytes to the right of\n   allocated 448-byte region [ffff8880084d6600, ffff8880084d67c0)\n   which belongs to the cache cifs_small_rq of size 448\n\n  BUG: KASAN: slab-out-of-bounds in kmemdup_noprof+0x36/0x50\n  Read of size 329 at addr ffff88800726c678 by task mount.cifs/89\n  CPU: 0 UID: 0 PID: 89 Comm: mount.cifs Tainted: G    B      7.1.0-rc6 #1\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0x4e/0x70\n   print_report+0x157/0x4c9\n   kasan_report+0xce/0x100\n   kasan_check_range+0x10f/0x1e0\n   __asan_memcpy+0x23/0x60\n   kmemdup_noprof+0x36/0x50\n   decode_ntlmssp_challenge+0x457/0x680\n   SMB2_sess_auth_rawntlmssp_negotiate+0x6f0/0xcb0\n   SMB2_sess_setup+0x219/0x4f0\n   cifs_setup_session+0x248/0xaf0\n   cifs_get_smb_ses+0xf79/0x17e0\n   cifs_mount_get_session+0x7f/0x3a0\n   cifs_mount+0xb4/0xcf0\n   cifs_smb3_do_mount+0x23a/0x1500\n   smb3_get_tree+0x3b0/0x630\n   vfs_get_tree+0x82/0x2d0\n   fc_mount+0x10/0x1b0\n   path_mount+0x50d/0x1de0\n   __x64_sys_mount+0x20b/0x270\n   do_syscall_64+0xee/0x590\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n   </TASK>\n  Allocated by task 93:\n   kmem_cache_alloc_noprof+0x106/0x380\n   mempool_alloc_noprof+0x116/0x1e0\n   cifs_small_buf_get+0x31/0x80\n   allocate_buffers+0x10d/0x2b0\n   cifs_demultiplex_thread+0x1d5/0x1d50\n   kthread+0x2c6/0x390\n   ret_from_fork+0x36e/0x5a0\n   ret_from_fork_asm+0x1a/0x30\n  The buggy address is located 120 bytes inside of\n   allocated 448-byte region [ffff88800726c600, ffff88800726c7c0)\n   which belongs to the cache cifs_small_rq of size 448\n\nRestrict the +1 exemption to responses that have no data area, so that\nit still covers the bcc[0] omission it was meant for.  When a data area\nis present, the +1 discrepancy instead means the reported data length\noverruns the\n---truncated---"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/client/smb2misc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"093b2bdad3221e3fae3c26d89387e7297a157664","lessThan":"8d0bbc78046d264bbf6a574ea6f9072258a43e35","versionType":"git","status":"affected"},{"version":"093b2bdad3221e3fae3c26d89387e7297a157664","lessThan":"b6a381c01e2ac98a48e32ac0f2a45bbadd9e26b0","versionType":"git","status":"affected"},{"version":"093b2bdad3221e3fae3c26d89387e7297a157664","lessThan":"31c6312608c60b72a1feb99a5afb680645a3e8a3","versionType":"git","status":"affected"},{"version":"093b2bdad3221e3fae3c26d89387e7297a157664","lessThan":"573e502d14714d2947e22e7eff40ec20a6a44a42","versionType":"git","status":"affected"},{"version":"093b2bdad3221e3fae3c26d89387e7297a157664","lessThan":"419ec1b604d7fb60c10aec2dc062371f9fcd4940","versionType":"git","status":"affected"},{"version":"093b2bdad3221e3fae3c26d89387e7297a157664","lessThan":"ceb875a375dedbf51c9425c1d13a2d7a8435c08c","versionType":"git","status":"affected"},{"version":"093b2bdad3221e3fae3c26d89387e7297a157664","lessThan":"6e9d10f62773b99bd927940fd9cbdfe7207e23ff","versionType":"git","status":"affected"},{"version":"093b2bdad3221e3fae3c26d89387e7297a157664","lessThan":"53b7c271f06be4dd5cfc8c6ef552a8355c891a7f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/client/smb2misc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.6","status":"affected"},{"version":"0","lessThan":"3.6","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/31c6312608c60b72a1feb99a5afb680645a3e8a3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/419ec1b604d7fb60c10aec2dc062371f9fcd4940","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/53b7c271f06be4dd5cfc8c6ef552a8355c891a7f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/573e502d14714d2947e22e7eff40ec20a6a44a42","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e9d10f62773b99bd927940fd9cbdfe7207e23ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8d0bbc78046d264bbf6a574ea6f9072258a43e35","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6a381c01e2ac98a48e32ac0f2a45bbadd9e26b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ceb875a375dedbf51c9425c1d13a2d7a8435c08c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64449","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:29.727","lastModified":"2026-07-25T10:17:29.727","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: vme_user: bound slave read/write to the kern_buf size\n\nThe SLAVE-path helpers buffer_to_user() and buffer_from_user() copy\n'count' bytes into/out of the fixed-size kern_buf (size_buf ==\nPCI_BUF_SIZE == 0x20000, 128 KiB) using *ppos as the offset, without\nbounding *ppos + count against size_buf.\n\nvme_user_write()/vme_user_read() only clamp count to the VME window size\n(image_size = vme_get_size(resource)), which VME_SET_SLAVE sets from the\nuser-supplied slave.size -- validated against the VME address space (up\nto VME_A32_MAX = 4 GiB), not against PCI_BUF_SIZE.  When the window\nexceeds 128 KiB, a write()/read() copies past the kern_buf allocation.\n\nClamp count against size_buf in both helpers, with an early return when\n*ppos is already at/after the buffer end.  *ppos is >= 0 here (the caller\nrejects negative offsets), so size_buf - *ppos cannot wrap.  This mirrors\nthe existing clamp in the MASTER-path helpers resource_to_user() /\nresource_from_user(), and matches the read()/write() convention of a\nshort transfer at end-of-buffer.\n\nFound by static analysis (CodeQL taint tracking + CBMC bounded model\nchecking) and confirmed dynamically under KASAN with the vme_fake bridge:\n\n  BUG: KASAN: slab-out-of-bounds in _copy_from_user+0x2d/0x80\n  Write of size 262144 at addr ffff888004100000 by task trigger/68\n    _copy_from_user+0x2d/0x80\n    vme_user_write+0x13e/0x240 [vme_user]\n    vfs_write+0x1b8/0x7a0\n    ksys_write+0xb8/0x150"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/staging/vme_user/vme_user.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f00a86d98a1ec3e99d352cda926fab767ba43b1f","lessThan":"65358d89dc9f1c25d9364b2b3ef0f3b47717f9ed","versionType":"git","status":"affected"},{"version":"f00a86d98a1ec3e99d352cda926fab767ba43b1f","lessThan":"adc8b9c30d716c362646edb45662aa1c641a154a","versionType":"git","status":"affected"},{"version":"f00a86d98a1ec3e99d352cda926fab767ba43b1f","lessThan":"8eff7cd4817e14dbe3b9952cce55ef52d1d38940","versionType":"git","status":"affected"},{"version":"f00a86d98a1ec3e99d352cda926fab767ba43b1f","lessThan":"e99f2df433c63c86c93de1e5f08f16e404388756","versionType":"git","status":"affected"},{"version":"f00a86d98a1ec3e99d352cda926fab767ba43b1f","lessThan":"1b495fa0d4927c88d88bf346bf311f2e26e860ed","versionType":"git","status":"affected"},{"version":"f00a86d98a1ec3e99d352cda926fab767ba43b1f","lessThan":"9f32f38265014fac7f5dc9490fb01a638ce6e121","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/staging/vme_user/vme_user.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.32","status":"affected"},{"version":"0","lessThan":"2.6.32","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1b495fa0d4927c88d88bf346bf311f2e26e860ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/65358d89dc9f1c25d9364b2b3ef0f3b47717f9ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8eff7cd4817e14dbe3b9952cce55ef52d1d38940","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f32f38265014fac7f5dc9490fb01a638ce6e121","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/adc8b9c30d716c362646edb45662aa1c641a154a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e99f2df433c63c86c93de1e5f08f16e404388756","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64450","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:29.850","lastModified":"2026-07-25T10:17:29.850","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix out-of-bounds read in broadcast Gap ACK blocks\n\nA broadcast PROTOCOL/STATE_MSG can carry a Gap ACK blocks record in its\ndata area. tipc_get_gap_ack_blks() only verifies that the record's len\nfield is self-consistent with its ugack_cnt/bgack_cnt counts\n(sz == struct_size(p, gacks, ugack_cnt + bgack_cnt)); it does not check\nthat the record actually fits in the message data area, msg_data_sz().\n\nThe unicast caller tipc_link_proto_rcv() bounds it (\"if (glen > dlen)\nbreak;\"), but the broadcast caller tipc_bcast_sync_rcv() discards the\nreturned size, so tipc_link_advance_transmq() copies the record off the\nreceive skb with an attacker-controlled count:\n\n\tthis_ga = kmemdup(ga, struct_size(ga, gacks, ga->bgack_cnt),\n\t\t\t  GFP_ATOMIC);\n\nA TIPC neighbour that negotiated TIPC_GAP_ACK_BLOCK triggers it with one\nordinary broadcast STATE_MSG (msg_bc_ack_invalid() clear), sized so its\ndata area is short, carrying a Gap ACK record with len = 0x400,\nbgack_cnt = 0xff and ugack_cnt = 0. len then equals\nstruct_size(p, gacks, 255), so the consistency check passes and ga is\nnon-NULL; kmemdup() reads struct_size(ga, gacks, 255) = 1024 bytes out\nof the much smaller skb:\n\n  BUG: KASAN: slab-out-of-bounds in kmemdup_noprof+0x48/0x60\n  Read of size 1024 at addr ffff0000c7030d38 by task poc864/69\n  Call trace:\n   kmemdup_noprof+0x48/0x60\n   tipc_link_advance_transmq+0x86c/0xb80\n   tipc_link_bc_ack_rcv+0x19c/0x1e0\n   tipc_bcast_sync_rcv+0x1c4/0x2c4\n   tipc_rcv+0x85c/0x1340\n   tipc_l2_rcv_msg+0xac/0x104\n  The buggy address belongs to the object at ffff0000c7030d00\n   which belongs to the cache skbuff_small_head of size 704\n  The buggy address is located 56 bytes inside of\n   allocated 704-byte region [ffff0000c7030d00, ffff0000c7030fc0)\n\nThe copied-out bytes are subsequently consumed as gap/ack values, but\nthe read is already out of bounds at the kmemdup() regardless of how\nthey are used.\n\nThe unicast STATE path drops such a message: \"if (glen > dlen) break;\"\nskips the rest of STATE_MSG handling and the skb is freed. Make the\nbroadcast path drop it too. tipc_bcast_sync_rcv() now bounds the record\nagainst msg_data_sz() and, when it does not fit, reports it back through\ntipc_node_bc_sync_rcv() to tipc_rcv() so the skb is discarded rather than\nprocessed. ga is not cleared on this path: ga == NULL already means\n\"legacy peer without Selective ACK\", a distinct legitimate state."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/tipc/bcast.c","net/tipc/bcast.h","net/tipc/node.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d7626b5acff9227e2a65da636a53e09bdafdc0aa","lessThan":"055663d21dc4336f67933ab26bef3c5934be6324","versionType":"git","status":"affected"},{"version":"d7626b5acff9227e2a65da636a53e09bdafdc0aa","lessThan":"016f5995c37a5a2c45198308f830f244517d70b7","versionType":"git","status":"affected"},{"version":"d7626b5acff9227e2a65da636a53e09bdafdc0aa","lessThan":"74b45af86a767594ba52330cd440ea84e24d700d","versionType":"git","status":"affected"},{"version":"d7626b5acff9227e2a65da636a53e09bdafdc0aa","lessThan":"9a51115fcdc78687c8852bf93a1db3951dbb223b","versionType":"git","status":"affected"},{"version":"d7626b5acff9227e2a65da636a53e09bdafdc0aa","lessThan":"a21ed5064217cc33726da6c7ef1a520eba43aea1","versionType":"git","status":"affected"},{"version":"d7626b5acff9227e2a65da636a53e09bdafdc0aa","lessThan":"2de42e268174766cb2e2b90721afdfdff70e0d8d","versionType":"git","status":"affected"},{"version":"d7626b5acff9227e2a65da636a53e09bdafdc0aa","lessThan":"f333b6851bdf326fd2134133272dbbed0c94d921","versionType":"git","status":"affected"},{"version":"d7626b5acff9227e2a65da636a53e09bdafdc0aa","lessThan":"2b66974a1b6134a4bbc3bfed181f7418f688eb54","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/tipc/bcast.c","net/tipc/bcast.h","net/tipc/node.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.8","status":"affected"},{"version":"0","lessThan":"5.8","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/016f5995c37a5a2c45198308f830f244517d70b7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/055663d21dc4336f67933ab26bef3c5934be6324","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2b66974a1b6134a4bbc3bfed181f7418f688eb54","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2de42e268174766cb2e2b90721afdfdff70e0d8d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/74b45af86a767594ba52330cd440ea84e24d700d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9a51115fcdc78687c8852bf93a1db3951dbb223b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a21ed5064217cc33726da6c7ef1a520eba43aea1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f333b6851bdf326fd2134133272dbbed0c94d921","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64451","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:30.013","lastModified":"2026-07-25T10:17:30.013","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix NULL pointer dereference in func_set_flag()\n\nfunc_set_flag() dereferences tr->current_trace_flags before verifying\nthat the current tracer is actually the function tracer. When the active\ntracer has been switched away from \"function\" (e.g., to \"wakeup_rt\"),\ntr->current_trace_flags can be NULL, leading to a NULL pointer\ndereference and kernel crash.\n\nThe call chain that triggers this is:\n\n  trace_options_write()\n    -> __set_tracer_option()\n      -> trace->set_flag()          /* func_set_flag */\n\nIn func_set_flag(), the first operation is:\n\n  if (!!set == !!(tr->current_trace_flags->val & bit))\n\nThis dereferences tr->current_trace_flags unconditionally. The safety\ncheck that guards against a non-function tracer:\n\n  if (tr->current_trace != &function_trace)\n      return 0;\n\nis placed *after* the dereference, which is too late.\n\nThis was observed with the following crash dump:\n\n  BUG: unable to handle page fault at 0000000000000000\n  RIP: func_set_flag+0xd\n\n  Call Trace:\n   __set_tracer_option+0x27\n   trace_options_write+0x75\n   vfs_write+0x12a\n   ksys_write+0x66\n   do_syscall_64+0x5b\n\n  RIP: ffffffff914c973d  RSP: ff67ec88b01dfdf0  RFLAGS: 00010202\n  RAX: 0000000000000000  RBX: ff3a826e80354580  RCX: 0000000000000001\n  RDX: 0000000000000001  RSI: 0000000000000000  RDI: ffffffff93918080\n\nThe disassembly confirms the fault:\n\n  func_set_flag+0:   mov 0x1f08(%rdi), %rax  ; RAX = tr->current_trace_flags = NULL\n  func_set_flag+13:  mov (%rax), %eax        ; page fault: dereference NULL\n\nAt the time of the crash:\n  tr->current_trace_flags = 0x0 (NULL)\n  tr->current_trace = wakeup_rt_tracer (not function_trace)\n\nThe scenario is that a process opens a function tracer option file (such\nas \"func_stack_trace\"), then the current tracer is switched to another\ntracer (e.g., \"wakeup_rt\"), which sets current_trace_flags to NULL. When\nthe process subsequently writes to the option file, func_set_flag() is\ninvoked and crashes on the NULL dereference.\n\nFix this by moving the current_trace check before the\ncurrent_trace_flags dereference, so that func_set_flag() returns early\nwhen the function tracer is not active."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/trace/trace_functions.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"76680d0d2825900f23bf35290ab2b80bdf3a8e4a","lessThan":"69f17ac132a38974cf1defb480cef6b79d1ab768","versionType":"git","status":"affected"},{"version":"76680d0d2825900f23bf35290ab2b80bdf3a8e4a","lessThan":"c3e94604675e3db186111b8942650d86577df9b0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/trace/trace_functions.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/69f17ac132a38974cf1defb480cef6b79d1ab768","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c3e94604675e3db186111b8942650d86577df9b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64452","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:30.140","lastModified":"2026-07-25T10:17:30.140","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\n6lowpan: fix NHC entry use-after-free on error path\n\nlowpan_nhc_do_uncompression() looks up an NHC descriptor while holding\nlowpan_nhc_lock.  If the descriptor has no uncompress callback, the error\npath drops the lock before printing nhc->name.\n\nlowpan_nhc_del() removes descriptors under the same lock and then relies\non synchronize_net() before the owning module can be unloaded.  That only\nwaits for net RX RCU readers.  lowpan_header_decompress() is also exported\nand can be reached from callers that are not necessarily covered by the net\ncore RX critical section, for example the Bluetooth 6LoWPAN L2CAP receive\npath.\n\nThis leaves a race where one task drops lowpan_nhc_lock in the error path,\nanother task unregisters and frees the matching descriptor after\nsynchronize_net() returns, and the first task then dereferences nhc->name\nfor the warning.\n\nWith the post-unlock window widened, KASAN reports:\n\n  BUG: KASAN: slab-use-after-free in lowpan_nhc_do_uncompression+0x1f4/0x220\n  Read of size 8\n  lowpan_nhc_do_uncompression\n  lowpan_header_decompress\n\nFix this by printing the warning before dropping lowpan_nhc_lock, so the\ndescriptor name is read while unregister is still excluded.  The malformed\npacket is still rejected with -ENOTSUPP."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/6lowpan/nhc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"92aa7c65d295f3cbb96904afe335f683e55584b8","lessThan":"9c2f5c0829a8c8b904dae36be6d8056b719ac605","versionType":"git","status":"affected"},{"version":"92aa7c65d295f3cbb96904afe335f683e55584b8","lessThan":"80b5c8779acee0550845394fb3e5176a398aa24c","versionType":"git","status":"affected"},{"version":"92aa7c65d295f3cbb96904afe335f683e55584b8","lessThan":"cc27aea4d454abfb385ee2c9499c78b96db9b728","versionType":"git","status":"affected"},{"version":"92aa7c65d295f3cbb96904afe335f683e55584b8","lessThan":"a8e3a94711134e898c6021a6b77374efa91b3639","versionType":"git","status":"affected"},{"version":"92aa7c65d295f3cbb96904afe335f683e55584b8","lessThan":"593b78bb3c7ef0c6e9ae6fdf5afa80a5f7573168","versionType":"git","status":"affected"},{"version":"92aa7c65d295f3cbb96904afe335f683e55584b8","lessThan":"0beccbcf50de125be5520d0ffc59af4bb8655482","versionType":"git","status":"affected"},{"version":"92aa7c65d295f3cbb96904afe335f683e55584b8","lessThan":"b713aa0cc344f10f7a9928a230b5f5e780d04078","versionType":"git","status":"affected"},{"version":"92aa7c65d295f3cbb96904afe335f683e55584b8","lessThan":"1720db928e5a58ca7d75ac1d514c3b73fd7061a7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/6lowpan/nhc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.1","status":"affected"},{"version":"0","lessThan":"4.1","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0beccbcf50de125be5520d0ffc59af4bb8655482","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1720db928e5a58ca7d75ac1d514c3b73fd7061a7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/593b78bb3c7ef0c6e9ae6fdf5afa80a5f7573168","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/80b5c8779acee0550845394fb3e5176a398aa24c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c2f5c0829a8c8b904dae36be6d8056b719ac605","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a8e3a94711134e898c6021a6b77374efa91b3639","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b713aa0cc344f10f7a9928a230b5f5e780d04078","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cc27aea4d454abfb385ee2c9499c78b96db9b728","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64453","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:30.273","lastModified":"2026-07-25T10:17:30.273","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: misc: usbio: fix disconnect UAF in client teardown\n\nusbio_disconnect() walks usbio->cli_list in reverse and uninitializes each\nauxiliary device. auxiliary_device_uninit() drops the device reference, and\nfor an unbound child that can run usbio_auxdev_release() and free the\ncontaining struct usbio_client.\n\nlist_for_each_entry_reverse() advances after the loop body by reading\nclient->link.prev. If the current client is freed by\nauxiliary_device_uninit(), the iterator dereferences freed memory.\n\nUse list_for_each_entry_safe_reverse() so the previous client is\ncached before the body can drop the final reference. This preserves\nreverse teardown order while keeping the next iterator cursor independent\nof the current client's lifetime.\n\nValidation reproduced this kernel report:\nBUG: KASAN: slab-use-after-free in usbio_disconnect+0x12e/0x150\n\nCall Trace:\n <TASK>\n dump_stack_lvl+0x66/0xa0\n print_report+0xce/0x630\n ? usbio_disconnect+0x12e/0x150\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? __virt_addr_valid+0x188/0x320\n ? usbio_disconnect+0x12e/0x150\n kasan_report+0xe0/0x110\n ? usbio_disconnect+0x12e/0x150\n usbio_disconnect+0x12e/0x150\n usb_unbind_interface+0xf3/0x400\n really_probe+0x316/0x660\n __driver_probe_device+0x106/0x240\n driver_probe_device+0x4a/0x110\n __device_attach_driver+0xf1/0x1a0\n ? __pfx___device_attach_driver+0x10/0x10\n bus_for_each_drv+0xf9/0x160\n ? __pfx_bus_for_each_drv+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? trace_hardirqs_on+0x18/0x130\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? _raw_spin_unlock_irqrestore+0x44/0x60\n __device_attach+0x133/0x2a0\n ? __pfx___device_attach+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? do_raw_spin_unlock+0x9a/0x100\n ? srso_alias_return_thunk+0x5/0xfbef5\n device_initial_probe+0x55/0x70\n bus_probe_device+0x4a/0xd0\n device_add+0x9b9/0xc10\n ? __pfx_device_add+0x10/0x10\n ? _raw_spin_unlock_irqrestore+0x44/0x60\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? lockdep_hardirqs_on_prepare+0xea/0x1a0\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? usb_enable_lpm+0x3c/0x260\n usb_set_configuration+0xb64/0xf20\n usb_generic_driver_probe+0x5f/0x90\n usb_probe_device+0x71/0x1b0\n really_probe+0x46b/0x660\n __driver_probe_device+0x106/0x240\n driver_probe_device+0x4a/0x110\n __device_attach_driver+0xf1/0x1a0\n ? __pfx___device_attach_driver+0x10/0x10\n bus_for_each_drv+0xf9/0x160\n ? __pfx_bus_for_each_drv+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? trace_hardirqs_on+0x18/0x130\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? _raw_spin_unlock_irqrestore+0x44/0x60\n __device_attach+0x133/0x2a0\n ? __pfx___device_attach+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? do_raw_spin_unlock+0x9a/0x100\n ? srso_alias_return_thunk+0x5/0xfbef5\n device_initial_probe+0x55/0x70\n bus_probe_device+0x4a/0xd0\n device_add+0x9b9/0xc10\n ? __pfx_device_add+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? add_device_randomness+0xb7/0xf0\n usb_new_device+0x492/0x870\n hub_event+0x1b10/0x29c0\n ? __pfx_hub_event+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? lock_acquire+0x187/0x300\n ? process_one_work+0x475/0xb90\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? lock_release+0xc8/0x290\n ? srso_alias_return_thunk+0x5/0xfbef5\n process_one_work+0x4d7/0xb90\n ? __pfx_process_one_work+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? __list_add_valid_or_report+0x37/0xf0\n ? __pfx_hub_event+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n worker_thread+0x2d8/0x570\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x1ad/0x1f0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x3c9/0x540\n ? __pfx_ret_from_fork+0x10/0x10\n ? srso_alias_return_thunk+0x5/0xfbef5\n ? __switch_to+0x2e9/0x730\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n </TASK>"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/misc/usbio.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"121a0f839dbb397af5fabb701cea3e9983223e50","lessThan":"c40090f8d19b415e2925b22be964b5d1f695666f","versionType":"git","status":"affected"},{"version":"121a0f839dbb397af5fabb701cea3e9983223e50","lessThan":"1947b6411460d68b54b13c536961933166937d05","versionType":"git","status":"affected"},{"version":"121a0f839dbb397af5fabb701cea3e9983223e50","lessThan":"0bfeec21984fedd32987f4e4c0cde34b445af404","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/misc/usbio.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0bfeec21984fedd32987f4e4c0cde34b445af404","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1947b6411460d68b54b13c536961933166937d05","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c40090f8d19b415e2925b22be964b5d1f695666f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64454","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:30.407","lastModified":"2026-07-25T10:17:30.407","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: run gadget disconnect from sleepable suspend context\n\ndwc3_gadget_suspend() takes dwc->lock with IRQs disabled and then calls\ndwc3_disconnect_gadget().  For async callbacks that helper only uses\nplain spin_unlock()/spin_lock(), so the gadget ->disconnect() callback\nstill runs with IRQs disabled and any sleepable callback trips Lockdep.\n\nThis issue was found by our static analysis tool and then manually\nreviewed against the current tree.\n\nThe grounded PoC kept the dwc3_gadget_suspend() ->\ndwc3_disconnect_gadget() -> gadget_driver->disconnect() chain, and\nLockdep reported:\n\n  BUG: sleeping function called from invalid context\n  gadget_disconnect+0x21/0x39 [vuln_msv]\n  dwc3_gadget_suspend.constprop.0+0x2b/0x42 [vuln_msv]\n\nKeep the disconnect callback selection in one common helper, but add a\nsleepable suspend-side wrapper which snapshots the callback under\ndwc->lock and then runs it after spin_unlock_irqrestore().  The regular\nevent path still uses the existing spin_unlock()/spin_lock() window."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/dwc3/gadget.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"20351ddb1f41cfb3ae20e105425ef43a28393d76","lessThan":"b399be2958456efe1b64b19c55a54a24e9035769","versionType":"git","status":"affected"},{"version":"ad43004fd5326bec4466ecc8a07fe0e570b553ca","lessThan":"48958478cb8dbc429a5b19f36e866b63d6297d1d","versionType":"git","status":"affected"},{"version":"c8540870af4ce6ddeb27a7bb5498b75fb29b643c","lessThan":"5e5798880eb1533a7de6fb68eb14b2d8202ebf76","versionType":"git","status":"affected"},{"version":"c8540870af4ce6ddeb27a7bb5498b75fb29b643c","lessThan":"e0e4f15d4225fb7156cc0e3c21eb8953114f9b89","versionType":"git","status":"affected"},{"version":"c8540870af4ce6ddeb27a7bb5498b75fb29b643c","lessThan":"c4e232bd07fe2b69a6e5c380db41dd36b95e0524","versionType":"git","status":"affected"},{"version":"c8540870af4ce6ddeb27a7bb5498b75fb29b643c","lessThan":"642e04f5c292d04070ae6e4374fbf14cc40a2465","versionType":"git","status":"affected"},{"version":"c8540870af4ce6ddeb27a7bb5498b75fb29b643c","lessThan":"010382937fb69892b3469ac4d30af072262f59e8","versionType":"git","status":"affected"},{"version":"06684c72b6b153dc434bb6ccebbb49f4cd812b5e","versionType":"git","status":"affected"},{"version":"5.15.128","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.30","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.3.4","lessThan":"6.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/dwc3/gadget.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/010382937fb69892b3469ac4d30af072262f59e8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/48958478cb8dbc429a5b19f36e866b63d6297d1d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5e5798880eb1533a7de6fb68eb14b2d8202ebf76","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/642e04f5c292d04070ae6e4374fbf14cc40a2465","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b399be2958456efe1b64b19c55a54a24e9035769","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c4e232bd07fe2b69a6e5c380db41dd36b95e0524","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e0e4f15d4225fb7156cc0e3c21eb8953114f9b89","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64455","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:30.537","lastModified":"2026-07-25T10:17:30.537","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: chaoskey: Fix slab-use-after-free in chaoskey_release()\n\nThe chaoskey driver has a use-after-free bug in its release routine.\nIf the user closes the device file after the USB device has been\nunplugged, a debugging log statement will try to access the\nusb_interface structure after it has been deallocated:\n\n\tBUG: KASAN: slab-use-after-free in dev_driver_string (drivers/base/core.c:2406)\n\tRead of size 8 at addr ffff888168e8a0b8 by task chaoskey_raw_re/10106\n\n\tHardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n\tCall Trace:\n\t <TASK>\n\t dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)\n\t print_report (mm/kasan/report.c:378 mm/kasan/report.c:482)\n\t kasan_report (mm/kasan/report.c:595)\n\t dev_driver_string (drivers/base/core.c:2406)\n\t __dynamic_dev_dbg (lib/dynamic_debug.c:906)\n\t chaoskey_release (drivers/usb/misc/chaoskey.c:323)\n\t __fput (fs/file_table.c:510)\n\t fput_close_sync (fs/file_table.c:615)\n\t __x64_sys_close (fs/open.c:1507 fs/open.c:1492 fs/open.c:1492)\n\t do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\n\t entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nThe driver's last reference to the interface structure is dropped in\nthe chaoskey_free() routine, so the code must not use the interface --\neven in a debugging statement -- after that routine returns.\n(Exception: If we know that another reference is held by someone else,\nsuch as the device core while the disconnect routine runs, there's no\nproblem.  Thanks to Johan Hovold for pointing this out.)\n\nSince the bad access is part of an unimportant debugging statement,\nwe can fix the problem simply by removing the whole statement."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/misc/chaoskey.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"66e3e591891da9899a8990792da080432531ffd4","lessThan":"fe7a0f4be283b40dd592540027279735120d0d6f","versionType":"git","status":"affected"},{"version":"66e3e591891da9899a8990792da080432531ffd4","lessThan":"5ec61fbef9ec5635c492ae63dfb5d13f2bdf1023","versionType":"git","status":"affected"},{"version":"66e3e591891da9899a8990792da080432531ffd4","lessThan":"f3e409476ad0703c54c14f245e4e143c8124e1bd","versionType":"git","status":"affected"},{"version":"66e3e591891da9899a8990792da080432531ffd4","lessThan":"6c82f88bc7a8458d5c60f9b354c4d32d233f0cac","versionType":"git","status":"affected"},{"version":"66e3e591891da9899a8990792da080432531ffd4","lessThan":"3ad5fbcced4e9c2b0fee3c1b76289a147fc35b89","versionType":"git","status":"affected"},{"version":"66e3e591891da9899a8990792da080432531ffd4","lessThan":"2a52d55c86a429dac47886b8424e67f90b001e67","versionType":"git","status":"affected"},{"version":"66e3e591891da9899a8990792da080432531ffd4","lessThan":"8f50613bff228272577893aa10a346a2f3063e49","versionType":"git","status":"affected"},{"version":"66e3e591891da9899a8990792da080432531ffd4","lessThan":"abf76d3239dee97b66e7241ad04811f1ce562e28","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/misc/chaoskey.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.1","status":"affected"},{"version":"0","lessThan":"4.1","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2a52d55c86a429dac47886b8424e67f90b001e67","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3ad5fbcced4e9c2b0fee3c1b76289a147fc35b89","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5ec61fbef9ec5635c492ae63dfb5d13f2bdf1023","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c82f88bc7a8458d5c60f9b354c4d32d233f0cac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f50613bff228272577893aa10a346a2f3063e49","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/abf76d3239dee97b66e7241ad04811f1ce562e28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f3e409476ad0703c54c14f245e4e143c8124e1bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe7a0f4be283b40dd592540027279735120d0d6f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64456","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:30.677","lastModified":"2026-07-25T10:17:30.677","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhwrng: virtio: clamp device-reported used.len at copy_data()\n\nrandom_recv_done() stores the device-reported used.len directly into\nvi->data_avail.  copy_data() then indexes vi->data[] using\nvi->data_idx (advanced by previous copy_data() calls) and issues a\nmemcpy() without re-validating either value against the posted\nbuffer size sizeof(vi->data) (SMP_CACHE_BYTES bytes, typically 32\nor 64).\n\nA malicious or buggy virtio-rng backend can set used.len beyond\nsizeof(vi->data), steering the memcpy() past the end of the inline\narray into adjacent kmalloc-1k slab bytes.  hwrng_fillfn() mixes\nthose bytes into the guest RNG, and guest root can also observe\nthem directly via /dev/hwrng.\n\nConcrete impact is inside the guest:\n\n - Memory-safety / hardening: any virtio-rng backend that\n   over-reports used.len causes the driver to read past vi->data\n   into unrelated slab contents.  hwrng_fillfn() is a kernel thread\n   that runs as soon as the device is probed; no guest userspace\n   interaction is required to first-trigger the OOB.\n\n - Cross-boundary leak (confidential-compute threat model): a\n   malicious hypervisor cooperating with a malicious or compromised\n   guest root userspace can use /dev/hwrng as a leak channel for\n   guest-kernel heap data.  The host sets a large used.len, guest\n   root reads /dev/hwrng, and the returned bytes contain guest\n   kernel slab contents that were adjacent to vi->data.  In\n   practice, confidential-compute guests (SEV-SNP, TDX) usually\n   disable virtio-rng entirely, so this path is narrow, but the\n   fix is still worth carrying because the underlying\n   memory-safety bug contaminates the guest RNG on any host.\n\nKASAN confirms the OOB on a 7.1-rc4 guest whose virtio-rng backend\nhas been patched to report used.len = 0x10000:\n\n  BUG: KASAN: slab-out-of-bounds in virtio_read+0x394/0x5d0\n  Read of size 64 at addr ffff88800ae0ba20 by task hwrng/52\n  Call Trace:\n   __asan_memcpy+0x23/0x60\n   virtio_read+0x394/0x5d0\n   hwrng_fillfn+0xb2/0x470\n   kthread+0x2cc/0x3a0\n  Allocated by task 1:\n   probe_common+0xa5/0x660\n   virtio_dev_probe+0x549/0xbc0\n  The buggy address belongs to the object at ffff88800ae0b800\n   which belongs to the cache kmalloc-1k of size 1024\n  The buggy address is located 0 bytes to the right of\n   allocated 544-byte region [ffff88800ae0b800, ffff88800ae0ba20)\n\nSame class of bug as commit c04db81cd028 (\"net/9p: Fix buffer\noverflow in USB transport layer\"), which hardened\nusb9pfs_rx_complete() against unchecked device-reported length in\nthe USB 9p transport.\n\nWith the clamp at point of use and array_index_nospec() in place,\nthe same harness boots cleanly: copy_data() returns zero for the\nbogus report, the device-supplied bytes after data_idx are\ndiscarded, and the driver issues a fresh request."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/char/hw_random/virtio-rng.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f7f510ec195781c857ab76366a3e1c59e1caae42","lessThan":"3aa3e89cf80721c8d382b4c1a2b70a0449dad4a5","versionType":"git","status":"affected"},{"version":"f7f510ec195781c857ab76366a3e1c59e1caae42","lessThan":"63335e7b638ae70028ae285bb95153874a8bc852","versionType":"git","status":"affected"},{"version":"f7f510ec195781c857ab76366a3e1c59e1caae42","lessThan":"2e788948ff2a13358a303af112497a63201c5739","versionType":"git","status":"affected"},{"version":"f7f510ec195781c857ab76366a3e1c59e1caae42","lessThan":"fde19b0d4eeabae042519313c843fe6f27d41e9d","versionType":"git","status":"affected"},{"version":"f7f510ec195781c857ab76366a3e1c59e1caae42","lessThan":"81dd21b5f0c299cc7b5bf84f04a61938559d20e6","versionType":"git","status":"affected"},{"version":"f7f510ec195781c857ab76366a3e1c59e1caae42","lessThan":"285e17c44e3873a73460f294acbd64018ff64385","versionType":"git","status":"affected"},{"version":"f7f510ec195781c857ab76366a3e1c59e1caae42","lessThan":"92d5736a62040ec1cfff23ea57e6599301690ad5","versionType":"git","status":"affected"},{"version":"f7f510ec195781c857ab76366a3e1c59e1caae42","lessThan":"e3046eeada299f917a8ad883af4434bfb86556b1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/char/hw_random/virtio-rng.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.26","status":"affected"},{"version":"0","lessThan":"2.6.26","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/285e17c44e3873a73460f294acbd64018ff64385","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2e788948ff2a13358a303af112497a63201c5739","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3aa3e89cf80721c8d382b4c1a2b70a0449dad4a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/63335e7b638ae70028ae285bb95153874a8bc852","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/81dd21b5f0c299cc7b5bf84f04a61938559d20e6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/92d5736a62040ec1cfff23ea57e6599301690ad5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e3046eeada299f917a8ad883af4434bfb86556b1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fde19b0d4eeabae042519313c843fe6f27d41e9d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64457","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:30.830","lastModified":"2026-07-25T10:17:30.830","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio_pci: fix vq info pointer lookup via wrong index\n\nUnbinding a virtio balloon device:\n\n    echo virtio0 > /sys/bus/virtio/drivers/virtio_balloon/unbind\n\ntriggers a NULL pointer dereference. The dmesg says:\n\n    BUG: kernel NULL pointer dereference, address: 0000000000000008\n    [...]\n    RIP: 0010:__list_del_entry_valid_or_report+0x5/0xf0\n    Call Trace:\n    <TASK>\n    vp_del_vqs+0x121/0x230\n    remove_common+0x135/0x150\n    virtballoon_remove+0xee/0x100\n    virtio_dev_remove+0x3b/0x80\n    device_release_driver_internal+0x187/0x2c0\n    unbind_store+0xb9/0xe0\n    kernfs_fop_write_iter.llvm.11660790530567441834+0xf6/0x180\n    vfs_write+0x2a9/0x3b0\n    ksys_write+0x5c/0xd0\n    do_syscall_64+0x54/0x230\n    entry_SYSCALL_64_after_hwframe+0x29/0x31\n    [...]\n    </TASK>\n\nThe virtio_balloon device registers 5 queues (inflate, deflate, stats,\nfree_page, reporting) but only the first two are unconditional. The\nstats, free_page and reporting queues are each conditional on their\nrespective feature bits. When any of these features are absent, the\ncorresponding vqs_info entry has name == NULL, creating holes in the\narray.\n\nThe root cause is an indexing mismatch introduced when vq info storage\nwas changed to be passed as an argument. vp_find_vqs_msix() and\nvp_find_vqs_intx() store the info pointer at vp_dev->vqs[i], where 'i'\nis the caller's sparse array index. However, the virtqueue itself gets\nvq->index assigned from queue_idx, a dense index that skips NULL\nentries. When holes exist, 'i' and queue_idx diverge. Later,\nvp_del_vqs() looks up info via vp_dev->vqs[vq->index] using the dense\nindex into the sparsely-populated array, and hits NULL.\n\nFix this by storing info at vp_dev->vqs[queue_idx] instead of\nvp_dev->vqs[i], so the store index matches the lookup index\n(vq->index). Apply the fix to both the MSIX and INTX paths."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/virtio/virtio_pci_common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"89a1c435aec269d109ed46ca7bbb10fa8edf7ace","lessThan":"41e6dc1a10036c9f47057033f19af7e52ec464b6","versionType":"git","status":"affected"},{"version":"89a1c435aec269d109ed46ca7bbb10fa8edf7ace","lessThan":"075bc3c779e1ea7294afabdcb7e0a49536959b28","versionType":"git","status":"affected"},{"version":"89a1c435aec269d109ed46ca7bbb10fa8edf7ace","lessThan":"64a4c0befa77bcc01076aec9f93863ffd4ed06b7","versionType":"git","status":"affected"},{"version":"89a1c435aec269d109ed46ca7bbb10fa8edf7ace","lessThan":"f7d380fb525c13bdd114369a1979c80c346e6abc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/virtio/virtio_pci_common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/075bc3c779e1ea7294afabdcb7e0a49536959b28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/41e6dc1a10036c9f47057033f19af7e52ec464b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/64a4c0befa77bcc01076aec9f93863ffd4ed06b7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7d380fb525c13bdd114369a1979c80c346e6abc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64458","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:30.943","lastModified":"2026-07-25T10:17:30.943","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/ops-common: handle extreme intervals in damon_hot_score()\n\nFix three issues in damon_hot_score() that comes from wrong handling of\nextreme (zero or too high) monitoring intervals user setup.\n\nWhen the user sets sampling interval zero, damon_max_nr_accesses(), which\nis called from damon_hot_score(), causes a divide-by-zero.  Needless to\nsay, it is a problem.\n\nWhen the user sets the aggregation interval zero, the function returns\nzero.  It is wrong, since the real maximum nr_acceses in the setup should\nbe one.  Worse yet, it can cause another divide-by-zero from its caller,\ndamon_hot_score(), since it uses damon_max_nr_accesses() return value as a\ndenominator.\n\nWhen the user sets the aggregation interval very high, damon_hot_score()\ncould return a value out of [0, DAMOS_MAX_SCORE] range.  Since the return\nvalue is used as an index to the regions_score_histogram array, which is\nDAMOS_MAX_SCORE+1 size, it causes out of bounds array access.\n\nThe issues can be relatively easily reproduced like below.  The sysfs\nwrite permission is required, though.\n\n    # ./damo start --damos_action lru_prio --damos_quota_space 100M \\\n            --damos_quota_interval 1s\n    # cd /sys/kernel/mm/damon/admin/kdamonds/0\n    # echo 0 > contexts/0/monitoring_attrs/intervals/sample_us\n    # echo 0 > contexts/0/monitoring_attrs/intervals/aggr_us\n    # echo commit > state\n    # dmesg\n    [...]\n    [  131.329762] Oops: divide error: 0000 [#1] SMP NOPTI\n    [...]\n    [  131.336089] RIP: 0010:damon_hot_score+0x27/0xd0\n    [...]\n\nFix the divide-by-zero intervals problems by explicitly handling the zero\nintervals in damon_max_nr_accesses().  Fix the out-of-bound array access\nby applying [0, DAMOS_MAX_SCORE] bounds before returning from\ndamon_hot_score().\n\nThe issue was discovered [1] by Sashiko."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/linux/damon.h","mm/damon/ops-common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"198f0f4c58b9f481e4e51c8c70a6ab9852bbab7f","lessThan":"58321b4e6e4f0f412069ab27ccdd56292757343a","versionType":"git","status":"affected"},{"version":"198f0f4c58b9f481e4e51c8c70a6ab9852bbab7f","lessThan":"74fef68d521150281e36cdaa20e9e1ee3e3aa146","versionType":"git","status":"affected"},{"version":"198f0f4c58b9f481e4e51c8c70a6ab9852bbab7f","lessThan":"ef2ae10a4582bc92b7e944181bbd2f87f3d30f3a","versionType":"git","status":"affected"},{"version":"198f0f4c58b9f481e4e51c8c70a6ab9852bbab7f","lessThan":"9c8f31eaae6140ecadec0c07320498a944556de2","versionType":"git","status":"affected"},{"version":"198f0f4c58b9f481e4e51c8c70a6ab9852bbab7f","lessThan":"76e415ea88d20f022ed5cfcf78c50e156a267e91","versionType":"git","status":"affected"},{"version":"198f0f4c58b9f481e4e51c8c70a6ab9852bbab7f","lessThan":"35d4a3cf70a855b50e53189ac2f8463e20a02046","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/linux/damon.h","mm/damon/ops-common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.16","status":"affected"},{"version":"0","lessThan":"5.16","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/35d4a3cf70a855b50e53189ac2f8463e20a02046","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/58321b4e6e4f0f412069ab27ccdd56292757343a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/74fef68d521150281e36cdaa20e9e1ee3e3aa146","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/76e415ea88d20f022ed5cfcf78c50e156a267e91","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c8f31eaae6140ecadec0c07320498a944556de2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef2ae10a4582bc92b7e944181bbd2f87f3d30f3a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64459","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:31.073","lastModified":"2026-07-25T10:17:31.073","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: restore RCU grace period in tcp_ao_destroy_sock\n\nCommit 51e547e8c89c (\"tcp: Free TCP-AO/TCP-MD5 info/keys without RCU\")\nremoved the call_rcu() callback from tcp_ao_destroy_sock(), arguing that\n\"the destruction of info/keys is delayed until the socket destructor\"\nand therefore \"no one can discover it anymore\".\n\nThat argument does not hold for the call site in tcp_connect()\n(net/ipv4/tcp_output.c:4327-4332). At that point the socket is in\nTCP_SYN_SENT, has already been inserted into the inet ehash by\ninet_hash_connect() in tcp_v4_connect(), and is therefore very much\ndiscoverable: any softirq running tcp_v4_rcv() on another CPU can take\nthe socket out of the ehash, walk into tcp_inbound_hash(), and load\ntp->ao_info via implicit RCU before bh_lock_sock_nested() is taken on\nthe destroying CPU.\n\nThe reader path then enters __tcp_ao_do_lookup() (net/ipv4/tcp_ao.c:208)\nwhich re-loads tp->ao_info via rcu_dereference_check(); the re-load can\nstill observe the (about-to-be-freed) pointer because there is no\nsynchronize_rcu() between rcu_assign_pointer(tp->ao_info, NULL) and\ntcp_ao_info_free() in tcp_ao_destroy_sock(). The captured pointer is\nthen walked at line 223:\n\n\thlist_for_each_entry_rcu(key, &ao->head, node, ...)\n\nThe writer's synchronous kfree() is free to complete between the line\n218 re-fetch and the line 223 hlist iteration. The slab is reused\n(or simply LIST_POISON1-stamped if not yet reused) and the iteration\nwalks attacker-controlled or poison memory in softirq context.\n\nReproducer (no debug shim, stock x86_64 v7.1-rc2 SMP+KASAN, QEMU+KVM):\nan unprivileged uid=1000 process inside CLONE_NEWUSER|CLONE_NEWNET\ninstalls TCP_MD5SIG + TCP_AO_ADD_KEY on a TCP socket, sprays forged\nTCP-AO segments toward its eventual 4-tuple via raw sockets, then\ncalls connect(). The md5-wins reconciliation in tcp_connect() fires\ntcp_ao_destroy_sock(); the softirq backlog reader on the loopback\nNAPI path crashes on the freed ao->head.first walk:\n\n  Oops: general protection fault, probably for non-canonical\n    address 0xfbd59c000000002f\n  KASAN: maybe wild-memory-access in range\n    [0xdead000000000178-0xdead00000000017f]\n  CPU: 0 UID: 1000 PID: 100 Comm: repro_userns\n  RIP: 0010:__tcp_ao_do_lookup+0x107/0x1c0\n  Call Trace: <IRQ>\n    __tcp_ao_do_lookup+0x107/0x1c0\n    tcp_ao_inbound_lookup.constprop.0+0x12a/0x200\n    tcp_inbound_ao_hash+0x5ea/0x1520\n    tcp_inbound_hash+0x7ce/0x1240\n    tcp_v4_rcv+0x1e7a/0x3e10\n    ...\n\nRestore the RCU grace period: re-add struct rcu_head to tcp_ao_info\nand replace the synchronous tcp_ao_info_free() with a call_rcu()\ncallback. Readers that captured tp->ao_info before rcu_assign_pointer\nNULLed it now see the object remain valid until rcu_read_unlock().\nWith the patch applied the reproducer runs cleanly for 2000 iterations\non the same kernel build."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/tcp_ao.h","net/ipv4/tcp_ao.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"51e547e8c89c661f6fbede4a28b1d33b13625683","lessThan":"657646c08c94ef7b9dbe468fe7828032216f9841","versionType":"git","status":"affected"},{"version":"51e547e8c89c661f6fbede4a28b1d33b13625683","lessThan":"4caf12c778fed3dc3824cf36263be5e2c491fbd0","versionType":"git","status":"affected"},{"version":"51e547e8c89c661f6fbede4a28b1d33b13625683","lessThan":"8bc4d43bccbd60efe85d0a44d5bf41762f2f0c30","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/tcp_ao.h","net/ipv4/tcp_ao.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4caf12c778fed3dc3824cf36263be5e2c491fbd0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/657646c08c94ef7b9dbe468fe7828032216f9841","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8bc4d43bccbd60efe85d0a44d5bf41762f2f0c30","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64460","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:31.193","lastModified":"2026-07-25T10:17:31.193","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nPCI/IOV: Skip VF Resizable BAR restore on read error\n\nsriov_restore_vf_rebar_state() uses the VF Resizable BAR Control register\nto decide how many VF BARs to restore (nbars) and which VF BAR each\niteration addresses (bar_idx). bar_idx indexes into dev->sriov->barsz[],\nwhich has only PCI_SRIOV_NUM_BARS (6) entries.\n\nWhen a device does not respond, config reads typically return\nPCI_ERROR_RESPONSE (~0).  Both fields are 3 bits wide, so nbars and bar_idx\nboth evaluate to 7. The barsz[] access then goes out of bounds.  UBSAN\nreports this as:\n\n  UBSAN: array-index-out-of-bounds in drivers/pci/iov.c:948:51 index 7 is out of range for type 'resource_size_t [6]'\n\nObserved on an NVIDIA RTX PRO 1000 GPU (GB207GLM) that stopped responding\nduring a failed GC6 power state exit. The subsequent pci_restore_state()\ninvoked sriov_restore_vf_rebar_state() while config reads returned\n0xffffffff, triggering the splat.\n\nBail out if any VF Resizable BAR Control read returns PCI_ERROR_RESPONSE.\nNo further VF BARs are touched, which is safe because a config read that\nreturns PCI_ERROR_RESPONSE indicates the device is unreachable and\nrestoration is pointless. This mirrors the guard in\npci_restore_rebar_state()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/pci/iov.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5a8f77e24a30bbce2fa57926f3dede84894fd10a","lessThan":"b77524621250407386f44c6eea7e5e4619ada1ce","versionType":"git","status":"affected"},{"version":"5a8f77e24a30bbce2fa57926f3dede84894fd10a","lessThan":"55fd485e66d0ad5c762c23dba1461fe9c741cd96","versionType":"git","status":"affected"},{"version":"5a8f77e24a30bbce2fa57926f3dede84894fd10a","lessThan":"f34f1712229d71ce4286440fef12526fd4590b37","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/pci/iov.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/55fd485e66d0ad5c762c23dba1461fe9c741cd96","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b77524621250407386f44c6eea7e5e4619ada1ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f34f1712229d71ce4286440fef12526fd4590b37","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64461","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:31.293","lastModified":"2026-07-25T10:17:31.293","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: mediatek: Fix IRQ domain leak when port fails to enable\n\nWhen mtk_pcie_enable_port() fails, mtk_pcie_port_free() removes the port\nfrom pcie->ports and frees the port structure. However, the IRQ domains set\nup earlier by mtk_pcie_init_irq_domain() are never freed.\n\nFix this by refactoring mtk_pcie_irq_teardown() into a per-port helper,\nmtk_pcie_irq_teardown_port(), and calling it from mtk_pcie_setup() when\nmtk_pcie_enable_port() fails. Since the IRQ teardown must only happen in\nthe probe error path (during resume, child devices may have active MSI\nmappings and the NOIRQ context prohibits sleeping locks),\nmtk_pcie_enable_port() is changed to return an error code so callers can\ndistinguish the two paths and act accordingly.\n\nThis issue was reported by Sashiko while reviewing the EcoNet EN7528 SoC\nsupport series."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/pci/controller/pcie-mediatek.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b099631df160ec608cd6147f4d20a8042567a5b8","lessThan":"e23da72ef202654a7d5269885c4fa39a8404db76","versionType":"git","status":"affected"},{"version":"b099631df160ec608cd6147f4d20a8042567a5b8","lessThan":"ec7c05eed47d8b15c45380aee7ca168a82e15035","versionType":"git","status":"affected"},{"version":"b099631df160ec608cd6147f4d20a8042567a5b8","lessThan":"1fbe8972a39548a633d06d7b03a01b7b119a2c12","versionType":"git","status":"affected"},{"version":"b099631df160ec608cd6147f4d20a8042567a5b8","lessThan":"fe8c701a53c2816cd82301f66c671d952003c1b0","versionType":"git","status":"affected"},{"version":"b099631df160ec608cd6147f4d20a8042567a5b8","lessThan":"ce52e494a7555bdae1d990a2654fd7547ef6d986","versionType":"git","status":"affected"},{"version":"b099631df160ec608cd6147f4d20a8042567a5b8","lessThan":"6e6a529d6f779413379b4404c9ef6a36c0337225","versionType":"git","status":"affected"},{"version":"b099631df160ec608cd6147f4d20a8042567a5b8","lessThan":"df77314b3bedbd9ad5d6f0682f98b99e3c5f7e2e","versionType":"git","status":"affected"},{"version":"b099631df160ec608cd6147f4d20a8042567a5b8","lessThan":"f865a57896bd92d7662eb2818d8f48872e2cbbc7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/pci/controller/pcie-mediatek.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.14","status":"affected"},{"version":"0","lessThan":"4.14","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1fbe8972a39548a633d06d7b03a01b7b119a2c12","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e6a529d6f779413379b4404c9ef6a36c0337225","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ce52e494a7555bdae1d990a2654fd7547ef6d986","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/df77314b3bedbd9ad5d6f0682f98b99e3c5f7e2e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e23da72ef202654a7d5269885c4fa39a8404db76","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ec7c05eed47d8b15c45380aee7ca168a82e15035","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f865a57896bd92d7662eb2818d8f48872e2cbbc7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe8c701a53c2816cd82301f66c671d952003c1b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64462","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:31.420","lastModified":"2026-07-25T10:17:31.420","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: altera: Fix resource leaks on probe failure\n\nThe chained IRQ handler is set during probe, but is only removed during the\ndriver remove(). If pci_host_probe() fails, the handler and INTx IRQ\ndomain remain set even though the devm-managed host bridge storage\ncontaining struct altera_pcie will be released, leaving the handler with\na stale data pointer.\n\nInterrupts are also enabled before pci_host_probe() is called. If probe\nfails after that point, the controller interrupt source should be disabled\nbefore the chained handler and INTx domain are removed.\n\nSo set the chained handler only after the INTx domain has been created.\nDisable controller interrupts during IRQ teardown, and tear the IRQ setup\ndown if pci_host_probe() fails.\n\n[mani: commit log]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/pci/controller/pcie-altera.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c63aed7334c21de8d626ff028ccad98cf5847a0e","lessThan":"af7cf5d56d7d57c4fbfdb7b5b693790f331b07b7","versionType":"git","status":"affected"},{"version":"c63aed7334c21de8d626ff028ccad98cf5847a0e","lessThan":"9cf0cc481e1645ec65e61486ae41c486c59781cb","versionType":"git","status":"affected"},{"version":"c63aed7334c21de8d626ff028ccad98cf5847a0e","lessThan":"99fc088d6cc6890ae35fa2f29c50ebe027844c20","versionType":"git","status":"affected"},{"version":"c63aed7334c21de8d626ff028ccad98cf5847a0e","lessThan":"a25bfa2a6665a1d77324d4a609e7513b87680227","versionType":"git","status":"affected"},{"version":"c63aed7334c21de8d626ff028ccad98cf5847a0e","lessThan":"0db9aa9ec51be0a0ffdcdfd9af2b7bf3aeb7911a","versionType":"git","status":"affected"},{"version":"c63aed7334c21de8d626ff028ccad98cf5847a0e","lessThan":"09c43b7b7d29c6fadb27f32cdf7f3bb6598befa9","versionType":"git","status":"affected"},{"version":"c63aed7334c21de8d626ff028ccad98cf5847a0e","lessThan":"6864c789b570e57f932847fa83f6b56917182d73","versionType":"git","status":"affected"},{"version":"c63aed7334c21de8d626ff028ccad98cf5847a0e","lessThan":"7a94138caeb27f3c49c1dbd93bf422098925bb28","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/pci/controller/pcie-altera.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.9","status":"affected"},{"version":"0","lessThan":"5.9","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/09c43b7b7d29c6fadb27f32cdf7f3bb6598befa9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0db9aa9ec51be0a0ffdcdfd9af2b7bf3aeb7911a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6864c789b570e57f932847fa83f6b56917182d73","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7a94138caeb27f3c49c1dbd93bf422098925bb28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/99fc088d6cc6890ae35fa2f29c50ebe027844c20","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9cf0cc481e1645ec65e61486ae41c486c59781cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a25bfa2a6665a1d77324d4a609e7513b87680227","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af7cf5d56d7d57c4fbfdb7b5b693790f331b07b7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64463","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:31.543","lastModified":"2026-07-25T10:17:31.543","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: tcpci_rt1711h: unregister TCPCI port with devres\n\nrt1711h_probe() registers the TCPCI port before requesting the interrupt\nand enabling alert interrupts. If either of those later steps fails, the\nprobe function returns without unregistering the TCPCI port. The explicit\nunregister currently only happens from the remove callback.\n\nRegister a devres action immediately after tcpci_register_port() succeeds,\nso tcpci_unregister_port() runs on later probe failures and on driver\ndetach. Drop the remove callback to avoid unregistering the same port\ntwice.\n\nThis issue was identified during our ongoing static-analysis research while\nreviewing kernel code."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/typec/tcpm/tcpci_rt1711h.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"302c570bf36e997d55ad0d60628a2feec76954a4","lessThan":"ce2e36e8759dfbfe546723810c306f42f484866d","versionType":"git","status":"affected"},{"version":"302c570bf36e997d55ad0d60628a2feec76954a4","lessThan":"94b1abf1af94aa5a355e9f03675e07bccfc41c4b","versionType":"git","status":"affected"},{"version":"302c570bf36e997d55ad0d60628a2feec76954a4","lessThan":"e5406c8fb71cd2f89a46300a746f6e7972e621e8","versionType":"git","status":"affected"},{"version":"302c570bf36e997d55ad0d60628a2feec76954a4","lessThan":"569f18a83eed0b0be4615f0c7bed40fb5c50e2e6","versionType":"git","status":"affected"},{"version":"302c570bf36e997d55ad0d60628a2feec76954a4","lessThan":"e8da46d99d3710106e7c44db14566bf9b57386b5","versionType":"git","status":"affected"},{"version":"4309ab96ab744703871e35d829177dd9347bf643","versionType":"git","status":"affected"},{"version":"895ec8c86e13f85b119c71d5f95491b48867955e","versionType":"git","status":"affected"},{"version":"745dcedb896a740825160228f98dbb5725a49f85","versionType":"git","status":"affected"},{"version":"4.19.131","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.4.50","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"5.7.7","lessThan":"5.8","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/typec/tcpm/tcpci_rt1711h.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.8","status":"affected"},{"version":"0","lessThan":"5.8","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/569f18a83eed0b0be4615f0c7bed40fb5c50e2e6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/94b1abf1af94aa5a355e9f03675e07bccfc41c4b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ce2e36e8759dfbfe546723810c306f42f484866d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5406c8fb71cd2f89a46300a746f6e7972e621e8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e8da46d99d3710106e7c44db14566bf9b57386b5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64464","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:31.660","lastModified":"2026-07-25T10:17:31.660","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxhci: sideband: fix ring sg table pages leak\n\nxhci_ring_to_sgtable() allocates a temporary pages array and\nuses it to build the returned sg_table with\nsg_alloc_table_from_pages().\n\nThe error paths free the pages array, but the success path\nreturns the sg_table without freeing it. This leaks the temporary\narray every time a sideband client gets an endpoint or event ring\nbuffer.\n\nFree the pages array after sg_alloc_table_from_pages() succeeds.\nThe returned sg_table has its own scatterlist entries and does not\ndepend on the temporary array after construction."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/host/xhci-sideband.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"de66754e9f8029f8ae955a588959b99cab56b506","lessThan":"99d00a9e35e311a91d258029d5bb584377296c34","versionType":"git","status":"affected"},{"version":"de66754e9f8029f8ae955a588959b99cab56b506","lessThan":"a3eaf82ff842d6ca95937ea584417e04828235a6","versionType":"git","status":"affected"},{"version":"de66754e9f8029f8ae955a588959b99cab56b506","lessThan":"49f6e3c3ef19f04f6657ed8dce550e36c763abb8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/host/xhci-sideband.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/49f6e3c3ef19f04f6657ed8dce550e36c763abb8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/99d00a9e35e311a91d258029d5bb584377296c34","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3eaf82ff842d6ca95937ea584417e04828235a6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64465","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:31.763","lastModified":"2026-07-25T10:17:31.763","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci: Fix sleep in atomic context in xhci_free_streams()\n\nWhen a USB device with active stream endpoints is disconnected,\nxhci_free_streams() is called from the hub_event workqueue to\nfree the stream resources.  It calls xhci_free_stream_info()\nwhile holding xhci->lock with irqs disabled.\n\nxhci_free_stream_info() invokes xhci_free_stream_ctx(), which\ncalls dma_free_coherent() for large stream context arrays.\n\ndma_free_coherent() can sleep (e.g. via vunmap), triggering\na BUG when called from atomic context.\n\nCall trace:\n dma_free_attrs+0x174/0x220\n xhci_free_stream_info+0xd0/0x11c\n xhci_free_streams+0x278/0x37c\n usb_free_streams+0x98/0xc0\n usb_unbind_interface+0x1b8/0x2f8\n device_release_driver_internal+0x1d4/0x2cc\n device_release_driver+0x18/0x28\n bus_remove_device+0x160/0x1a4\n device_del+0x1ec/0x350\n usb_disable_device+0x98/0x214\n usb_disconnect+0xf0/0x35c\n hub_event+0xab4/0x19ec\n process_one_work+0x278/0x63c\n\nFix this by saving the stream_info pointers and clearing the\nep references under the lock, then calling xhci_free_stream_info()\noutside the lock where sleeping is allowed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/host/xhci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8df75f42f8e67e2851cdcf6da91640fb881defd1","lessThan":"e623e4a203f56d5c57519a9a3cb29600551534ad","versionType":"git","status":"affected"},{"version":"8df75f42f8e67e2851cdcf6da91640fb881defd1","lessThan":"d107eb316144c5fb958486e7fe604cd7f1b35cda","versionType":"git","status":"affected"},{"version":"8df75f42f8e67e2851cdcf6da91640fb881defd1","lessThan":"1e45aa722c4ce5663e987102aac18c8ad6a83fdd","versionType":"git","status":"affected"},{"version":"8df75f42f8e67e2851cdcf6da91640fb881defd1","lessThan":"10666ac9c552990204e791af653abf8e9d9ff619","versionType":"git","status":"affected"},{"version":"8df75f42f8e67e2851cdcf6da91640fb881defd1","lessThan":"f7b022ae07685e7526fc39f387ce65b5d309dd3b","versionType":"git","status":"affected"},{"version":"8df75f42f8e67e2851cdcf6da91640fb881defd1","lessThan":"f90586129cf9e1fbdb718ef602eea3f15dc1c31c","versionType":"git","status":"affected"},{"version":"8df75f42f8e67e2851cdcf6da91640fb881defd1","lessThan":"93cd037da94fcb93183bfb2457e3a56d3eb4c8f4","versionType":"git","status":"affected"},{"version":"8df75f42f8e67e2851cdcf6da91640fb881defd1","lessThan":"42c37c4b75d38b51d84f31a8e29427f5e06a7c2a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/host/xhci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.35","status":"affected"},{"version":"0","lessThan":"2.6.35","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/10666ac9c552990204e791af653abf8e9d9ff619","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1e45aa722c4ce5663e987102aac18c8ad6a83fdd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/42c37c4b75d38b51d84f31a8e29427f5e06a7c2a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/93cd037da94fcb93183bfb2457e3a56d3eb4c8f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d107eb316144c5fb958486e7fe604cd7f1b35cda","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e623e4a203f56d5c57519a9a3cb29600551534ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7b022ae07685e7526fc39f387ce65b5d309dd3b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f90586129cf9e1fbdb718ef602eea3f15dc1c31c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64466","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:31.893","lastModified":"2026-07-25T10:17:31.893","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nrust_binder: clear freeze listener on node removal\n\nGenerally userspace is supposed to explicitly clear freeze listeners\nbefore they drop the refcount on the node ref to zero, but there's\nnothing forcing that. Currently, in this scenario the freeze listener\nremains in the freeze_listeners rbtree and in the remote node's freeze\nlistener list, even though the ref for which the listener is registered\nis gone. This could potentially lead to a memory leak due to a refcount\ncycle. Thus, remove the freeze listener in this scenario."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/android/binder/freeze.rs","drivers/android/binder/node.rs","drivers/android/binder/process.rs"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"eafedbc7c050c44744fbdf80bdf3315e860b7513","lessThan":"91b27f8172cdbf265240104772fd042a461a7767","versionType":"git","status":"affected"},{"version":"eafedbc7c050c44744fbdf80bdf3315e860b7513","lessThan":"0644da3621ddd8e146280675a2a31d1e06634a1d","versionType":"git","status":"affected"},{"version":"eafedbc7c050c44744fbdf80bdf3315e860b7513","lessThan":"bc4a9828897871ff3e5a1f8a1d346decbf4ee95e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/android/binder/freeze.rs","drivers/android/binder/node.rs","drivers/android/binder/process.rs"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0644da3621ddd8e146280675a2a31d1e06634a1d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/91b27f8172cdbf265240104772fd042a461a7767","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bc4a9828897871ff3e5a1f8a1d346decbf4ee95e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64467","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:32.003","lastModified":"2026-07-25T10:17:32.003","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nrust_binder: use a u64 stride when cleaning up the offsets array\n\nAllocation's Drop walks the offsets array (binder_size_t = u64 entries),\ncleaning up the objects, but it used usize instead of u64 for both the\nstride and the per-entry read.\n\nOn 64-bit kernels (usize == u64) this is harmless, but on 32-bit kernels\nit walks the 8-byte entries in 4-byte steps, iterating an N-entry array\n2N times, and reads the always-zero high word as offset 0, cleaning up\nthe object at offset 0 N extra times. As a result the referenced node or\nhandle ends up with a lower reference count than it actually has (a\nrefcount over-decrement), and binder's reference accounting is corrupted;\nfor example, the owner can be notified of a strong reference release\n(BR_RELEASE) even though references still remain.\n\nChange the stride to u64, and read each entry as a u64, narrowing it to\nusize with try_into().\n\nOn 32-bit ARM, when this over-decrement would drive a count below zero,\nthe driver's existing refcount guard refuses it and fires:\n\n  rust_binder: Failure: refcount underflow!"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/android/binder/allocation.rs"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"eafedbc7c050c44744fbdf80bdf3315e860b7513","lessThan":"89b8cc948dce661af87527623b3a41cdd115e2f9","versionType":"git","status":"affected"},{"version":"eafedbc7c050c44744fbdf80bdf3315e860b7513","lessThan":"74920b1b4e474ba7a4de4323c0458deec49d210b","versionType":"git","status":"affected"},{"version":"eafedbc7c050c44744fbdf80bdf3315e860b7513","lessThan":"803c8a9502e9b97cd6ae937618ef4a8fd6274343","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/android/binder/allocation.rs"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/74920b1b4e474ba7a4de4323c0458deec49d210b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/803c8a9502e9b97cd6ae937618ef4a8fd6274343","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/89b8cc948dce661af87527623b3a41cdd115e2f9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64468","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:32.103","lastModified":"2026-07-25T10:17:32.103","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: fix UAF in binder_free_transaction()\n\nIn binder_free_transaction(), the t->to_proc is read under the t->lock.\nHowever, once the t->lock is dropped, the to_proc can die in parallel.\nThis leads to a use-after-free error when we attempt to acquire its\ninner lock right afterwards:\n\n  ==================================================================\n  BUG: KASAN: slab-use-after-free in _raw_spin_lock+0xe4/0x1a0\n  Write of size 4 at addr ffff00001125da70 by task B/672\n\n  CPU: 20 UID: 0 PID: 672 Comm: B Not tainted 7.1.0-rc6-00284-g8e65320d91cd #4 PREEMPT\n  Hardware name: linux,dummy-virt (DT)\n  Call trace:\n   _raw_spin_lock+0xe4/0x1a0\n   binder_free_transaction+0x8c/0x320\n   binder_send_failed_reply+0x21c/0x2f8\n   binder_thread_release+0x488/0x7e0\n   binder_ioctl+0x12c0/0x29a0\n  [...]\n\n  Allocated by task 675:\n   __kmalloc_cache_noprof+0x174/0x444\n   binder_open+0x118/0xb70\n   do_dentry_open+0x374/0x1040\n   vfs_open+0x58/0x3bc\n  [...]\n\n  Freed by task 212:\n   __kasan_slab_free+0x58/0x80\n   kfree+0x1a0/0x4a4\n   binder_proc_dec_tmpref+0x32c/0x5e0\n   binder_deferred_func+0xc48/0x104c\n   process_one_work+0x53c/0xbc0\n  [...]\n  ==================================================================\n\nTo prevent this, pin the target thread (t->to_thread) to guarantee the\ntarget process remains alive. Undelivered transactions without a target\nthread are already safe, as the target process can only be the current\ncontext in those paths."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/android/binder.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a370003cc301d4361bae20c9ef615f89bf8d1e8a","lessThan":"5602a43f251c3d75312df91a422675fc00ca3dce","versionType":"git","status":"affected"},{"version":"a370003cc301d4361bae20c9ef615f89bf8d1e8a","lessThan":"0be901ab1dcc4af59b88f2e324493bb283850167","versionType":"git","status":"affected"},{"version":"a370003cc301d4361bae20c9ef615f89bf8d1e8a","lessThan":"48aeda9f8039e4a6971d1804578efde7f2c01eda","versionType":"git","status":"affected"},{"version":"a370003cc301d4361bae20c9ef615f89bf8d1e8a","lessThan":"45df558c543bb5543bacc8065fd7c567740781e5","versionType":"git","status":"affected"},{"version":"a370003cc301d4361bae20c9ef615f89bf8d1e8a","lessThan":"d45ef513eed1abebfec90c3cfb6ae50c2a4182db","versionType":"git","status":"affected"},{"version":"a370003cc301d4361bae20c9ef615f89bf8d1e8a","lessThan":"328ccf32acb87e8bbb1fe2b065068c574e4db2bf","versionType":"git","status":"affected"},{"version":"a370003cc301d4361bae20c9ef615f89bf8d1e8a","lessThan":"0f15f0f6ca5df566275ce517f257af2559528b41","versionType":"git","status":"affected"},{"version":"a370003cc301d4361bae20c9ef615f89bf8d1e8a","lessThan":"f223d27a546c1e1f48d38fd67760e78f068fe8c4","versionType":"git","status":"affected"},{"version":"a4a3c070b8760f71c8311399fa9bfe67c8629bca","versionType":"git","status":"affected"},{"version":"22068d49d09d2b3890e19d7b2048a33340f992da","versionType":"git","status":"affected"},{"version":"0e3b977a8f1be01dcfa0baae68851b1f55f2a0a9","versionType":"git","status":"affected"},{"version":"4.14.136","lessThan":"4.15","versionType":"semver","status":"affected"},{"version":"4.19.64","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.1.15","lessThan":"5.2","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/android/binder.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.2","status":"affected"},{"version":"0","lessThan":"5.2","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0be901ab1dcc4af59b88f2e324493bb283850167","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0f15f0f6ca5df566275ce517f257af2559528b41","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/328ccf32acb87e8bbb1fe2b065068c574e4db2bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/45df558c543bb5543bacc8065fd7c567740781e5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/48aeda9f8039e4a6971d1804578efde7f2c01eda","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5602a43f251c3d75312df91a422675fc00ca3dce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d45ef513eed1abebfec90c3cfb6ae50c2a4182db","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f223d27a546c1e1f48d38fd67760e78f068fe8c4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64469","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:32.247","lastModified":"2026-07-25T10:17:32.247","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: fix UAF in binder_thread_release()\n\nWhen a thread exits, binder_thread_release() walks its transaction stack\nto clear the t->from and t->to_proc that correspond with the exiting\nthread. However, a process dying in parallel might attempt to kfree some\nof these transactions. And if one of them has no associated t->to_proc,\nthe t->to_proc->inner_lock will not be acquired.\n\nThis means that transaction accesses in binder_thread_release() after\nt->to_proc has been cleared might race with binder_free_transaction()\nand cause a use-after-free error as reported by KASAN:\n\n  ==================================================================\n  BUG: KASAN: slab-use-after-free in binder_thread_release+0x5d0/0x798\n  Write of size 8 at addr ffff000016627500 by task X/715\n\n  CPU: 17 UID: 0 PID: 715 Comm: X Not tainted 7.1.0-rc5-00149-g8fde5d1d47f6 #30 PREEMPT\n  Hardware name: linux,dummy-virt (DT)\n  Call trace:\n   binder_thread_release+0x5d0/0x798\n   binder_ioctl+0x12c0/0x299c\n   [...]\n\n  Allocated by task 717 on cpu 18 at 67.267803s:\n   __kasan_kmalloc+0xa0/0xbc\n   __kmalloc_cache_noprof+0x174/0x444\n   binder_transaction+0x554/0x8150\n   binder_thread_write+0xa30/0x4354\n   binder_ioctl+0x20f0/0x299c\n   [...]\n\n  Freed by task 202 on cpu 18 at 90.416221s:\n   __kasan_slab_free+0x58/0x80\n   kfree+0x1a0/0x4a4\n   binder_free_transaction+0x150/0x294\n   binder_send_failed_reply+0x398/0x6d8\n   binder_release_work+0x3e4/0x4ec\n   binder_deferred_func+0xbd8/0x104c\n   [...]\n  ==================================================================\n\nIn order to avoid this, make sure that binder_free_transaction() reads\nthe t->to_proc under the transaction lock. This will serialize the\ntransaction release with the accesses in binder_thread_release(). Plus,\nit matches the documented locking rules for @to_proc."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/android/binder.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7a4408c6bd3eb1dafba67986259191be081e3efb","lessThan":"1f96f8c0a6ed4f6d01d3dd29ad0cbf08dde96082","versionType":"git","status":"affected"},{"version":"7a4408c6bd3eb1dafba67986259191be081e3efb","lessThan":"df1a17abba8d6fac5f965adcb8113ceace6e4949","versionType":"git","status":"affected"},{"version":"7a4408c6bd3eb1dafba67986259191be081e3efb","lessThan":"38e1a71728e5795b670cc159c18e286a40aeebb4","versionType":"git","status":"affected"},{"version":"7a4408c6bd3eb1dafba67986259191be081e3efb","lessThan":"faa070c7ad8ba25dcd0b12d7cdbb419e336f5391","versionType":"git","status":"affected"},{"version":"7a4408c6bd3eb1dafba67986259191be081e3efb","lessThan":"e63032dc715026a96bcaa13d375a8e15c91caa84","versionType":"git","status":"affected"},{"version":"7a4408c6bd3eb1dafba67986259191be081e3efb","lessThan":"ea02df466df60ecd758eb3b4df3f0cadc5c886ce","versionType":"git","status":"affected"},{"version":"7a4408c6bd3eb1dafba67986259191be081e3efb","lessThan":"ef5439ba5b9ac93349f5df12ef88b42a0ce26340","versionType":"git","status":"affected"},{"version":"7a4408c6bd3eb1dafba67986259191be081e3efb","lessThan":"114a116aaa5f0295376cdf12da743c5bce3b20ce","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/android/binder.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.14","status":"affected"},{"version":"0","lessThan":"4.14","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/114a116aaa5f0295376cdf12da743c5bce3b20ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1f96f8c0a6ed4f6d01d3dd29ad0cbf08dde96082","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/38e1a71728e5795b670cc159c18e286a40aeebb4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/df1a17abba8d6fac5f965adcb8113ceace6e4949","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e63032dc715026a96bcaa13d375a8e15c91caa84","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea02df466df60ecd758eb3b4df3f0cadc5c886ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef5439ba5b9ac93349f5df12ef88b42a0ce26340","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/faa070c7ad8ba25dcd0b12d7cdbb419e336f5391","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64470","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:32.390","lastModified":"2026-07-25T10:17:32.390","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: fix use-after-free on marvell probe failure\n\nMake sure to stop any TX URBs submitted during Marvell OOB wakeup\nconfiguration on later probe failures to avoid use-after-free in the\ncompletion callback.\n\nThis issue was reported by Sashiko while reviewing a fix for a wakeup\nsource leak in the btusb probe errors paths."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/bluetooth/btusb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a4ccc9e33d2f01532bcceb621ea06bbf4db6efac","lessThan":"1edd524de5cc8143ece9c42c466346983dc5b5ed","versionType":"git","status":"affected"},{"version":"a4ccc9e33d2f01532bcceb621ea06bbf4db6efac","lessThan":"0ccb1cb0a464dab78284c34196cd3e8e18bab4c4","versionType":"git","status":"affected"},{"version":"a4ccc9e33d2f01532bcceb621ea06bbf4db6efac","lessThan":"631de465aba7f8ae46478bf5f598111412e8eff8","versionType":"git","status":"affected"},{"version":"a4ccc9e33d2f01532bcceb621ea06bbf4db6efac","lessThan":"6e1b10df890f4663cb38af9fc1c93d36747b75af","versionType":"git","status":"affected"},{"version":"a4ccc9e33d2f01532bcceb621ea06bbf4db6efac","lessThan":"92c736866244340497a8a65afe2ac25354c2bf5e","versionType":"git","status":"affected"},{"version":"a4ccc9e33d2f01532bcceb621ea06bbf4db6efac","lessThan":"a7e941a395711791c7e98d9870c6562c2c9e9ef2","versionType":"git","status":"affected"},{"version":"a4ccc9e33d2f01532bcceb621ea06bbf4db6efac","lessThan":"838c917a2f16eefe68def800ebf48a2af591149a","versionType":"git","status":"affected"},{"version":"a4ccc9e33d2f01532bcceb621ea06bbf4db6efac","lessThan":"c5b600a3c05b1a7a110d558df935a8fc8a471c79","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/bluetooth/btusb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.11","status":"affected"},{"version":"0","lessThan":"4.11","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0ccb1cb0a464dab78284c34196cd3e8e18bab4c4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1edd524de5cc8143ece9c42c466346983dc5b5ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/631de465aba7f8ae46478bf5f598111412e8eff8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e1b10df890f4663cb38af9fc1c93d36747b75af","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/838c917a2f16eefe68def800ebf48a2af591149a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/92c736866244340497a8a65afe2ac25354c2bf5e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a7e941a395711791c7e98d9870c6562c2c9e9ef2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c5b600a3c05b1a7a110d558df935a8fc8a471c79","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64471","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:32.510","lastModified":"2026-07-25T10:17:32.510","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: fix use-after-free on registration failure\n\nMake sure to release the sibling interfaces in case controller\nregistration fails to avoid use-after-free and double-free when they are\neventually disconnected.\n\nThis issue was reported by Sashiko while reviewing a fix for a wakeup\nsource leak in the btusb probe errors paths."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/bluetooth/btusb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9bfa35fe422c74882e27cc54450a5f76c96aad68","lessThan":"e09ac7d0c6859a360bf36e7104aef03f88184e0b","versionType":"git","status":"affected"},{"version":"9bfa35fe422c74882e27cc54450a5f76c96aad68","lessThan":"468fcdfaeb937163dd250773a9fed17ab1fa203c","versionType":"git","status":"affected"},{"version":"9bfa35fe422c74882e27cc54450a5f76c96aad68","lessThan":"1ce5012944afaddbda939ec6bae9800fce84abbc","versionType":"git","status":"affected"},{"version":"9bfa35fe422c74882e27cc54450a5f76c96aad68","lessThan":"e6313b800da61a26c2fdd5eba0105e197c0ab3bc","versionType":"git","status":"affected"},{"version":"9bfa35fe422c74882e27cc54450a5f76c96aad68","lessThan":"14e02f1449ba425a44dedbec9a21efafb056e09f","versionType":"git","status":"affected"},{"version":"9bfa35fe422c74882e27cc54450a5f76c96aad68","lessThan":"8db0ce3de78367f61c2970c0f16d9adee8830a23","versionType":"git","status":"affected"},{"version":"9bfa35fe422c74882e27cc54450a5f76c96aad68","lessThan":"da7d7758fe884b256ddc9fef562e5ddef7952383","versionType":"git","status":"affected"},{"version":"9bfa35fe422c74882e27cc54450a5f76c96aad68","lessThan":"eedc6867ebad73edbfaf9a0a65fbef7115cc4753","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/bluetooth/btusb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.27","status":"affected"},{"version":"0","lessThan":"2.6.27","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/14e02f1449ba425a44dedbec9a21efafb056e09f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1ce5012944afaddbda939ec6bae9800fce84abbc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/468fcdfaeb937163dd250773a9fed17ab1fa203c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8db0ce3de78367f61c2970c0f16d9adee8830a23","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/da7d7758fe884b256ddc9fef562e5ddef7952383","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e09ac7d0c6859a360bf36e7104aef03f88184e0b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e6313b800da61a26c2fdd5eba0105e197c0ab3bc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eedc6867ebad73edbfaf9a0a65fbef7115cc4753","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64472","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:32.630","lastModified":"2026-07-25T10:17:32.630","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/mlx5: Fix racy bitfields and tighten struct layout\n\nBitfield operations are not atomic, they use a read-modify-write\npattern, therefore we should be careful not to pack bitfields that\ncan be concurrently updated into the same storage unit.\n\nThis split takes a binary approach: flags that are only modified\npre/post open/close remain bitfields, flags modified from user\naction, including actions that reach across to another device (ex.\nreset) use dedicated storage units.\n\nNote mlx5_vhca_page_tracker.status is relocated to fill the alignment\nhole this split exposes.\n\nBitfield justifications:\n\n  migrate_cap: written only in mlx5vf_cmd_set_migratable() at probe\n  chunk_mode: written only in mlx5vf_cmd_set_migratable() at probe\n  mig_state_cap: written only in mlx5vf_cmd_set_migratable() at probe\n\nDedicated storage units:\n\n  mdev_detach: written in the VF attach/detach event notifier\n               mlx5fv_vf_event() at runtime\n  log_active: written in mlx5vf_start_page_tracker()/\n              mlx5vf_stop_page_tracker() during runtime dirty tracking\n  deferred_reset: written in mlx5vf_state_mutex_unlock()/\n                  mlx5vf_pci_aer_reset_done() during runtime reset handling\n  is_err: set by tracker error handling and dirty-log polling at runtime\n  object_changed: set by tracker event handling and cleared by dirty-log\n                  polling at runtime"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/vfio/pci/mlx5/cmd.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"61a2f1460fd03285ea34c1a235f2f50f71e13a1f","lessThan":"1dd99b8f4e143592e12e5a77e7b538bc698116cb","versionType":"git","status":"affected"},{"version":"61a2f1460fd03285ea34c1a235f2f50f71e13a1f","lessThan":"f1db80a67da928a92ba460ede1be52d8941f46be","versionType":"git","status":"affected"},{"version":"61a2f1460fd03285ea34c1a235f2f50f71e13a1f","lessThan":"399d806f998f7a25405fc1b97227e579aead24af","versionType":"git","status":"affected"},{"version":"61a2f1460fd03285ea34c1a235f2f50f71e13a1f","lessThan":"7ed120b1a007bace57c461805519d70e1af44e59","versionType":"git","status":"affected"},{"version":"61a2f1460fd03285ea34c1a235f2f50f71e13a1f","lessThan":"39d163627b51886492bf31f66cb02c94613d2287","versionType":"git","status":"affected"},{"version":"61a2f1460fd03285ea34c1a235f2f50f71e13a1f","lessThan":"f2365a63b02ddea32e7db78b742c2503ec7b81f1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/vfio/pci/mlx5/cmd.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1dd99b8f4e143592e12e5a77e7b538bc698116cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/399d806f998f7a25405fc1b97227e579aead24af","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/39d163627b51886492bf31f66cb02c94613d2287","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7ed120b1a007bace57c461805519d70e1af44e59","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1db80a67da928a92ba460ede1be52d8941f46be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f2365a63b02ddea32e7db78b742c2503ec7b81f1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64473","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:32.757","lastModified":"2026-07-25T10:17:32.757","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvfio: Remove device debugfs before releasing devres\n\nVFIO device debugfs files created with debugfs_create_devm_seqfile()\nstore a devres allocated debugfs_devm_entry as inode private data.\nvfio_unregister_group_dev() currently calls vfio_device_del() before\nvfio_device_debugfs_exit(), but device_del() releases devres.  This can\nleave debugfs entries visible with stale inode private data while\nunregister waits for userspace references to drain.\n\nRemove the per-device debugfs tree before vfio_device_del().  The debugfs\nview is diagnostic only, so losing it at the start of unregister is\npreferable to preserving entries whose backing storage may already have\nbeen released.\n\nComplete the teardown by clearing the per-device debugfs root after\nremoval.  This matches the global debugfs root cleanup and prevents\nfuture users from mistaking a removed dentry for a live debugfs tree\nduring the remainder of unregister."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/vfio/debugfs.c","drivers/vfio/vfio_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2202844e4468c7539dba0c0b06577c93735af952","lessThan":"6cc60b41d61657dc469893d14e8e55d160056ff1","versionType":"git","status":"affected"},{"version":"2202844e4468c7539dba0c0b06577c93735af952","lessThan":"a53109ffb6b5148e11a27fb7670355b92db12dd3","versionType":"git","status":"affected"},{"version":"2202844e4468c7539dba0c0b06577c93735af952","lessThan":"a5df401dc84f091e20b045560569f0736758fea7","versionType":"git","status":"affected"},{"version":"2202844e4468c7539dba0c0b06577c93735af952","lessThan":"dc7fe87de492ea7f33a72b78d26650b75bf37f4f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/vfio/debugfs.c","drivers/vfio/vfio_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6cc60b41d61657dc469893d14e8e55d160056ff1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a53109ffb6b5148e11a27fb7670355b92db12dd3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a5df401dc84f091e20b045560569f0736758fea7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc7fe87de492ea7f33a72b78d26650b75bf37f4f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64474","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:32.863","lastModified":"2026-07-25T10:17:32.863","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc\n\nvfio_mig_get_next_state() walks vfio_from_fsm_table[] one step at a time,\nlooping to skip optional states the device does not support until\n*next_fsm is supported. A blocked transition is encoded as\nVFIO_DEVICE_STATE_ERROR, which the trailing return reports as -EINVAL.\n\nThe skip loop does not account for the ERROR sentinel.\nstate_flags_table[ERROR] is ~0U and vfio_from_fsm_table[ERROR][*] is\nERROR, so once *next_fsm becomes ERROR the loop condition stays true and\n*next_fsm never changes. The blocked arcs STOP_COPY -> PRE_COPY and\nSTOP_COPY -> PRE_COPY_P2P map to ERROR yet pass the support check on a\nprecopy-capable device, causing the loop to spin forever while holding\nthe driver state mutex. This can result in a soft lockup, and a panic\nwith softlockup_panic set.\n\nTerminate the skip loop on the ERROR sentinel so a blocked transition\nfalls through to the existing return and reports -EINVAL."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/vfio/vfio_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4db52602a6074e9cc523500b8304600ff63e7b85","lessThan":"8e872c07e40d51a66dee7b280a23a460a2e1e3fa","versionType":"git","status":"affected"},{"version":"4db52602a6074e9cc523500b8304600ff63e7b85","lessThan":"ed7d5599e6c398da74845767cd1e6a8370a160fc","versionType":"git","status":"affected"},{"version":"4db52602a6074e9cc523500b8304600ff63e7b85","lessThan":"7f2d6b31089e48db4653df832c9a6afdde9a1c29","versionType":"git","status":"affected"},{"version":"4db52602a6074e9cc523500b8304600ff63e7b85","lessThan":"a3a8afa2f6e7f0dc266d08f02be3f3054241ba47","versionType":"git","status":"affected"},{"version":"4db52602a6074e9cc523500b8304600ff63e7b85","lessThan":"a26b499b757cfc8bbff1088bb1b844639e250893","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/vfio/vfio_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.2","status":"affected"},{"version":"0","lessThan":"6.2","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/7f2d6b31089e48db4653df832c9a6afdde9a1c29","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8e872c07e40d51a66dee7b280a23a460a2e1e3fa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a26b499b757cfc8bbff1088bb1b844639e250893","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3a8afa2f6e7f0dc266d08f02be3f3054241ba47","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed7d5599e6c398da74845767cd1e6a8370a160fc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64475","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:32.980","lastModified":"2026-07-25T10:17:32.980","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/pci: Release the VGA arbiter client on register_device() failure\n\nThe re-order in the Fixes commit below displaced vfio_pci_vga_init() as\nthe last failure point of what is now vfio_pci_core_register_device()\nwithout introducing an unwind for the VGA arbiter registration.\n\nIn current kernels this is mostly benign because vfio_pci_set_decode()\nonly uses pci_dev state, but the original failure path could leave a\ncallback with a freed vdev cookie.  The stale registration also becomes\nunsafe again once the callback follows drvdata to the vfio device.\n\nAdd the required VGA unwind callout."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/vfio/pci/vfio_pci_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"87856f9af04eaacf9848710625a4ffee1d020fa9","lessThan":"0f2a35a0c7ea7da347b814750eaa78adf3582381","versionType":"git","status":"affected"},{"version":"4aeec3984ddc853f7c65903bde472ffdef738bae","lessThan":"8d65decde9afd2bd78bcfffdc0df73b82a0b5509","versionType":"git","status":"affected"},{"version":"4aeec3984ddc853f7c65903bde472ffdef738bae","lessThan":"ef4c38d30b3744e89eb5048218904bb629ea8d47","versionType":"git","status":"affected"},{"version":"4aeec3984ddc853f7c65903bde472ffdef738bae","lessThan":"9e0a3f642e607848669235f5069f35640abbfc88","versionType":"git","status":"affected"},{"version":"4aeec3984ddc853f7c65903bde472ffdef738bae","lessThan":"42d758a09d2c46c42357ecde9a5492f015bde2e5","versionType":"git","status":"affected"},{"version":"4aeec3984ddc853f7c65903bde472ffdef738bae","lessThan":"52adb2dff7ce3d8430e2bdc5988b618a430def85","versionType":"git","status":"affected"},{"version":"4aeec3984ddc853f7c65903bde472ffdef738bae","lessThan":"278a5659c391fe5afe5f9ce1bad1fd24e90144f1","versionType":"git","status":"affected"},{"version":"4aeec3984ddc853f7c65903bde472ffdef738bae","lessThan":"daedde7f024ecf88bc8e832ed40cf2c795f0796a","versionType":"git","status":"affected"},{"version":"d62dccb417cf972c978bf3c68a7d5e846bcf953e","versionType":"git","status":"affected"},{"version":"6694b8daffac5a8661071f085608afc78f7acd08","versionType":"git","status":"affected"},{"version":"5.10.37","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.11.21","lessThan":"5.12","versionType":"semver","status":"affected"},{"version":"5.12.4","lessThan":"5.13","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/vfio/pci/vfio_pci_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0f2a35a0c7ea7da347b814750eaa78adf3582381","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/278a5659c391fe5afe5f9ce1bad1fd24e90144f1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/42d758a09d2c46c42357ecde9a5492f015bde2e5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/52adb2dff7ce3d8430e2bdc5988b618a430def85","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8d65decde9afd2bd78bcfffdc0df73b82a0b5509","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9e0a3f642e607848669235f5069f35640abbfc88","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/daedde7f024ecf88bc8e832ed40cf2c795f0796a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef4c38d30b3744e89eb5048218904bb629ea8d47","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64476","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:33.113","lastModified":"2026-07-25T10:17:33.113","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/pci: Latch disable_idle_d3 per device\n\nWhen disable_idle_d3 was introduced in vfio-pci, it directly manipulated\nthe device power state with pci_set_power_state().  There were no\nrefcounts to maintain or balanced operations, we could unconditionally\nbring the device to D0 and conditionally move it to D3hot.  Therefore\nthe module parameter was made writable.\n\nLater, in commit c61302aa48f7 (\"vfio/pci: Move module parameters to\nvfio_pci.c\"), as part of the vfio-pci-core split, the writable aspect\nof the module parameter was nullified.  The parameter value could still\nbe changed through sysfs, but the vfio-pci driver latched the values\ninto vfio-pci-core globals at module init.  Loading the vfio-pci module,\nor unloading and reloading, with non-default or different values could\nchange the globals relative to existing devices bound to vfio-pci\nvariant drivers.\n\nRuntime PM was introduced in commit 7ab5e10eda02 (\"vfio/pci: Move the\nunused device into low power state with runtime PM\"), which marks the\npoint where power states became refcounted.  PM get and put operations\nneed to be balanced, but the same module operations noted above can\nchange the global variables relative to those devices already bound to\nvfio-pci variant drivers.  This introduces a window where PM operations\ncan now become unbalanced.\n\nTo resolve this with a narrow footprint for stable backports, the\ndisable_idle_d3 flag is latched into the vfio_pci_core_device at the\ntime of initialization, such that the device always operates with a\nconsistent value.\n\nNB. vfio_pci_dev_set_try_reset() now unconditionally raises the\nruntime PM usage count around bus reset to account for disable_idle_d3\nbecoming a per-device rather than global flag.  When this flag is set,\nthe additional get/put pair is harmless and allows continued use of the\nshared vfio_pci_dev_set_pm_runtime_get() helper."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/vfio/pci/vfio_pci_core.c","include/linux/vfio_pci_core.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7ab5e10eda02da1d9562ffde562c51055d368e9c","lessThan":"332d785f9ae426eeeb92527872adf09d84101ba3","versionType":"git","status":"affected"},{"version":"7ab5e10eda02da1d9562ffde562c51055d368e9c","lessThan":"654710ef3135c4546b20a903bc23a51b0c44d6c8","versionType":"git","status":"affected"},{"version":"7ab5e10eda02da1d9562ffde562c51055d368e9c","lessThan":"b98296816d31441b307ef9fa8670dcf5a55e5505","versionType":"git","status":"affected"},{"version":"7ab5e10eda02da1d9562ffde562c51055d368e9c","lessThan":"f6c67cf0051f96ba61d186731d3d9409b9927db2","versionType":"git","status":"affected"},{"version":"7ab5e10eda02da1d9562ffde562c51055d368e9c","lessThan":"062b820290bcb9778e43a73597df76e9bb08acfb","versionType":"git","status":"affected"},{"version":"7ab5e10eda02da1d9562ffde562c51055d368e9c","lessThan":"4575e9aac5336d1365138c0284773bf8da4b1fa3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/vfio/pci/vfio_pci_core.c","include/linux/vfio_pci_core.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/062b820290bcb9778e43a73597df76e9bb08acfb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/332d785f9ae426eeeb92527872adf09d84101ba3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4575e9aac5336d1365138c0284773bf8da4b1fa3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/654710ef3135c4546b20a903bc23a51b0c44d6c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b98296816d31441b307ef9fa8670dcf5a55e5505","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f6c67cf0051f96ba61d186731d3d9409b9927db2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64477","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:33.243","lastModified":"2026-07-25T10:17:33.243","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nx86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled\n\nThe architecture updates the cpu_mask in a domain's header to track which\nonline CPUs are associated with the domain. When this mask becomes empty\nthe architecture initiates offline of the domain that includes calling\non resctrl fs to offline the domain. If it is a monitoring domain in\nwhich LLC occupancy is tracked resctrl fs forces the limbo handler to\nclear all busy RMID state associated with the domain.\n\nThe limbo handler always reads the current event value associated with a\nbusy RMID irrespective of it being checked as part of regular \"is it still\nbusy\" check or whether it will be forced released anyway. When reading an\nRMID on a system with SNC enabled the \"logical RMID\" is converted to the\n\"physical RMID\" and this conversion requires the NUMA node ID of the\nresctrl monitoring domain that is in turn determined by querying the NUMA\nnode ID of any CPU belonging to the monitoring domain.\n\nWhen the monitoring domain is going offline its cpu_mask is empty causing\nthe NUMA node ID query via cpu_to_node() to be done with \"nr_cpu_ids\" as\nargument resulting in an out-of-bounds access.\n\nRefactor the limbo handler to skip reading the RMID when the RMID will\njust be forced to no longer be dirty in the domain anyway. Add a safety\ncheck to the architecture's RMID reader to protect against this scenario."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/x86/kernel/cpu/resctrl/monitor.c","fs/resctrl/monitor.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e13db55b5a0d447dea63cde772c1078405bbbf96","lessThan":"ebc300b7ee0c669fa76a7a8858298ff32e296103","versionType":"git","status":"affected"},{"version":"e13db55b5a0d447dea63cde772c1078405bbbf96","lessThan":"be1567992417dc92133e74126de7a6066c825ac9","versionType":"git","status":"affected"},{"version":"e13db55b5a0d447dea63cde772c1078405bbbf96","lessThan":"58c5ec23b1a238eb75cb0aba6f69d8f9e68ef0b2","versionType":"git","status":"affected"},{"version":"e13db55b5a0d447dea63cde772c1078405bbbf96","lessThan":"fc16126cc11d9f507130bf84ab137ee0938c900e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/x86/kernel/cpu/resctrl/monitor.c","fs/resctrl/monitor.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/58c5ec23b1a238eb75cb0aba6f69d8f9e68ef0b2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be1567992417dc92133e74126de7a6066c825ac9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ebc300b7ee0c669fa76a7a8858298ff32e296103","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc16126cc11d9f507130bf84ab137ee0938c900e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64478","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:33.350","lastModified":"2026-07-25T10:17:33.350","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: avoid kobject path lookup in DualSense match\n\nThe DualSense jack-detection input handler verifies that a matching input\ndevice belongs to the same physical controller by building kobject path\nstrings for both the input device and the USB audio device, then comparing\nthe path prefix.\n\nThis was observed when a weak physical connection caused the controller\nto rapidly disconnect and reconnect. During that repeated hotplug,\nsnd_dualsense_ih_match() can run while the controller's USB device is\nbeing disconnected. kobject_get_path() walks ancestor kobjects and\ndereferences their names; if the USB device kobject name is no longer\nvalid, this can fault in strlen():\n\n  RIP: 0010:strlen+0x10/0x30\n  Call Trace:\n   kobject_get_path+0x34/0x150\n   snd_dualsense_ih_match+0x49/0xd0 [snd_usb_audio]\n   input_register_device+0x566/0x6a0\n   ps_probe+0xb89/0x1590 [hid_playstation]\n\nThe same ownership check can be done without building kobject path\nstrings. The input device is parented below the HID device, USB interface\nand USB device, so walking the input device parent chain and comparing\nagainst the mixer USB device preserves the check without dereferencing\nkobject names during disconnect."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/usb/mixer_quirks.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d0b0264009596c07a77d82808b0dae72bc04ac5c","lessThan":"e4c66a149c408e44e60bfec3fabf08b6b7abbc60","versionType":"git","status":"affected"},{"version":"b4b94f092f193d7a2db8e82af5e51519ae89963c","lessThan":"4566bf8ae9dbfe81bdc2ff1702d59db8a233b06e","versionType":"git","status":"affected"},{"version":"c2d5b0a6c688ffb32c35627e337fbbcc65bc275f","lessThan":"662a1d7b5affc424ea4f4bc20dd99be29e687886","versionType":"git","status":"affected"},{"version":"d04d301614630724feb4048bf17432fc7964fe74","lessThan":"a47ecd904c51ae6a42957feb3cf2f4266adee2e5","versionType":"git","status":"affected"},{"version":"a705899ec6085b12a33aa0fd94a58e82e9e90502","lessThan":"c1da6d3f45036fa63672ee04ad97cb526b40b987","versionType":"git","status":"affected"},{"version":"79d561c4ec0497669f19a9550cfb74812f60938b","lessThan":"a263eb12cbe2e208e6e637df0f9b0be9a484158e","versionType":"git","status":"affected"},{"version":"79d561c4ec0497669f19a9550cfb74812f60938b","lessThan":"4246dd043b7a4f8e3bc1d2896e81d11220610eda","versionType":"git","status":"affected"},{"version":"79d561c4ec0497669f19a9550cfb74812f60938b","lessThan":"7693c0cc415f3a16a7a3355f245474a5e661be4e","versionType":"git","status":"affected"},{"version":"104ad9bae11ee450fb7d0595ff7876cfb6527838","versionType":"git","status":"affected"},{"version":"0105cfc41abeb428d4405951a20e1e239bea5e1d","versionType":"git","status":"affected"},{"version":"5.10.245","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.15.194","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.155","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.109","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.50","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"5.4.300","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"6.16.10","lessThan":"6.17","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/usb/mixer_quirks.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4246dd043b7a4f8e3bc1d2896e81d11220610eda","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4566bf8ae9dbfe81bdc2ff1702d59db8a233b06e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/662a1d7b5affc424ea4f4bc20dd99be29e687886","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7693c0cc415f3a16a7a3355f245474a5e661be4e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a263eb12cbe2e208e6e637df0f9b0be9a484158e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a47ecd904c51ae6a42957feb3cf2f4266adee2e5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c1da6d3f45036fa63672ee04ad97cb526b40b987","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e4c66a149c408e44e60bfec3fabf08b6b7abbc60","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64479","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:33.493","lastModified":"2026-07-25T10:17:33.493","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()\n\nsnd_seq_event_dup() copies an incoming event into a pool cell and, in\nthe UMP-enabled build, clears the trailing cell->ump.raw.extra word that\nthe memcpy() did not cover.  The guard deciding whether to clear it\ncompares the copied size against sizeof(cell->event):\n\n\tmemcpy(&cell->ump, event, size);\n\tif (size < sizeof(cell->event))\n\t\tcell->ump.raw.extra = 0;\n\nFor a legacy (non-UMP) event, size == sizeof(struct snd_seq_event) ==\nsizeof(cell->event), so the condition is false and the extra word keeps\nstale data.  The cell pool is allocated with kvmalloc() (not zeroed) and\ncells are reused via a free list, so that word holds uninitialised heap\nor leftover event data.\n\nWhen such a cell is delivered to a UMP client (client->midi_version > 0)\nthat set SNDRV_SEQ_FILTER_NO_CONVERT -- so the legacy event reaches it\nunconverted -- snd_seq_read() reads it out as the larger struct\nsnd_seq_ump_event and copies the stale word to user space, a 4-byte\nkernel heap infoleak to an unprivileged /dev/snd/seq client.\n\nCompare against sizeof(cell->ump) instead, so the trailing word is zeroed\nfor every event shorter than the UMP cell."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/core/seq/seq_memory.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6389f2c135311c4ce7c08c3b29145c8f95aacf1f","lessThan":"d7649aa11089a93ea2285c210397aa67e5800766","versionType":"git","status":"affected"},{"version":"d7e2ce72833bb23a82b4201fbed7214cc04a4a8c","lessThan":"a224c84e5d3d35708c082c84ad12d81d90762195","versionType":"git","status":"affected"},{"version":"46397622a3fa8372b8fda0f04b33d16923b03b1b","lessThan":"ea672a9f6cc38f06fe69dd2c257ef8a3d4db179a","versionType":"git","status":"affected"},{"version":"46397622a3fa8372b8fda0f04b33d16923b03b1b","lessThan":"fb1aa5082847b98f44f9c6272aee9d0dca9244f0","versionType":"git","status":"affected"},{"version":"46397622a3fa8372b8fda0f04b33d16923b03b1b","lessThan":"651ba82fe2a144bc7356d940bfd235c3810b0549","versionType":"git","status":"affected"},{"version":"46397622a3fa8372b8fda0f04b33d16923b03b1b","lessThan":"6ded42615fa1f4949925afd0a8a9e1ab3bf96202","versionType":"git","status":"affected"},{"version":"46397622a3fa8372b8fda0f04b33d16923b03b1b","lessThan":"435990e25bf1f4af3e6df12a6fbfd1f7ba4a97d4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/core/seq/seq_memory.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.5","status":"affected"},{"version":"0","lessThan":"6.5","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/435990e25bf1f4af3e6df12a6fbfd1f7ba4a97d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/651ba82fe2a144bc7356d940bfd235c3810b0549","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6ded42615fa1f4949925afd0a8a9e1ab3bf96202","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a224c84e5d3d35708c082c84ad12d81d90762195","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d7649aa11089a93ea2285c210397aa67e5800766","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea672a9f6cc38f06fe69dd2c257ef8a3d4db179a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb1aa5082847b98f44f9c6272aee9d0dca9244f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64480","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:33.617","lastModified":"2026-07-25T10:17:33.617","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: ice1712: check snd_ctl_new1() return value\n\nsnd_ctl_new1() can return NULL when memory allocation fails. The\nice1712 driver calls snd_ctl_new1() without checking the return value\nbefore dereferencing the pointer in multiple places (ice1712.c,\nice1724.c, aureon.c), which can lead to NULL pointer dereferences.\n\nAdd NULL checks after snd_ctl_new1() calls and return -ENOMEM if any\nfails."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/pci/ice1712/aureon.c","sound/pci/ice1712/ice1712.c","sound/pci/ice1712/ice1724.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0df0097ea2d52401c31e550389ac758c90e6a1eb","lessThan":"57d59be545b309d4bb54ac472b15d1e67f254d95","versionType":"git","status":"affected"},{"version":"b9a4efd61b6b9f62f83752959e75a5dae20624fa","lessThan":"69bf1dfa3215524c4ae255bb9dce0770875abbeb","versionType":"git","status":"affected"},{"version":"b9a4efd61b6b9f62f83752959e75a5dae20624fa","lessThan":"d34ad480b8896d2b486e2cf29ce1790326cad205","versionType":"git","status":"affected"},{"version":"b9a4efd61b6b9f62f83752959e75a5dae20624fa","lessThan":"71b87108ad93d433cdb20704a8dc8852304cf2c2","versionType":"git","status":"affected"},{"version":"b9a4efd61b6b9f62f83752959e75a5dae20624fa","lessThan":"38a7cc46370a57122fb29c4bfe48a851c0c64459","versionType":"git","status":"affected"},{"version":"b9a4efd61b6b9f62f83752959e75a5dae20624fa","lessThan":"2b929b91b0f3bc6de8a844370049cd99ee8e31ff","versionType":"git","status":"affected"},{"version":"286e17a1c3baeb1b1cd36b63ee16e8a6e63d558e","versionType":"git","status":"affected"},{"version":"6.1.34","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.3.8","lessThan":"6.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/pci/ice1712/aureon.c","sound/pci/ice1712/ice1712.c","sound/pci/ice1712/ice1724.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2b929b91b0f3bc6de8a844370049cd99ee8e31ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/38a7cc46370a57122fb29c4bfe48a851c0c64459","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/57d59be545b309d4bb54ac472b15d1e67f254d95","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/69bf1dfa3215524c4ae255bb9dce0770875abbeb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/71b87108ad93d433cdb20704a8dc8852304cf2c2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d34ad480b8896d2b486e2cf29ce1790326cad205","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64481","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:33.733","lastModified":"2026-07-25T10:17:33.733","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda/cs35l41: Fix firmware load work teardown\n\ncs35l41_hda creates ALSA controls whose private data points at the\ncs35l41_hda object. The firmware load control can also queue\nfw_load_work.\n\nThose controls are not removed on component unbind, and device remove\nonly cancels fw_load_work through cs35l41_remove_dsp(). That helper is\nskipped when halo_initialized is false. With firmware_autostart\ndisabled, a firmware load can be requested before the DSP has been\ninitialized. If the component or device is removed before the queued\nwork runs, the worker can run after teardown and dereference driver\nstate that is no longer valid.\n\nTrack the created controls and remove them on unbind so no new control\ncallback can reach the driver data or queue more work. Then cancel\nfw_load_work to drain any request that was already queued. Also cancel\nthe work unconditionally during device remove before runtime PM teardown."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/hda/codecs/side-codecs/cs35l41_hda.c","sound/hda/codecs/side-codecs/cs35l41_hda.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"47ceabd99a28399f8971f4ca0a37ebc0a21dd2a8","lessThan":"8947215c0136c9d905e4a46d824824f8b48a2e5b","versionType":"git","status":"affected"},{"version":"47ceabd99a28399f8971f4ca0a37ebc0a21dd2a8","lessThan":"ce0a903d0591e3e2c790c5b628802b08d1b287cc","versionType":"git","status":"affected"},{"version":"47ceabd99a28399f8971f4ca0a37ebc0a21dd2a8","lessThan":"d6a40a4d083ef74d00c8f9516cb5ff07ac70720b","versionType":"git","status":"affected"},{"version":"47ceabd99a28399f8971f4ca0a37ebc0a21dd2a8","lessThan":"b65020d5398f499c09498c9786dba6d67ae57664","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/hda/codecs/side-codecs/cs35l41_hda.c","sound/hda/codecs/side-codecs/cs35l41_hda.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/8947215c0136c9d905e4a46d824824f8b48a2e5b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b65020d5398f499c09498c9786dba6d67ae57664","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ce0a903d0591e3e2c790c5b628802b08d1b287cc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d6a40a4d083ef74d00c8f9516cb5ff07ac70720b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64482","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:33.843","lastModified":"2026-07-25T10:17:33.843","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: gus: check snd_ctl_new1() return value\n\nsnd_ctl_new1() can return NULL when memory allocation fails.\nsnd_gf1_pcm_volume_control() does not check the return value before\ndereferencing kctl->id.index, which can lead to a NULL pointer\ndereference.\n\nAdd a NULL check after snd_ctl_new1() and return -ENOMEM if it fails."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/isa/gus/gus_pcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c35034fd6446afaf408d5ab296068e32c775c965","lessThan":"97f6bdf5d5ded2e37f358cacb5a95f1393356604","versionType":"git","status":"affected"},{"version":"c5ae57b1bb99bd6f50b90428fabde397c2aeba0f","lessThan":"eccf8e91266e39f6f15637702a04a1d344833fe2","versionType":"git","status":"affected"},{"version":"c5ae57b1bb99bd6f50b90428fabde397c2aeba0f","lessThan":"fc5d4f27ca1293bc1379ef8fff691c30d9803ca2","versionType":"git","status":"affected"},{"version":"c5ae57b1bb99bd6f50b90428fabde397c2aeba0f","lessThan":"5e74e5e8cb7cc25f7a89f59abaf3489bf0c6f4a0","versionType":"git","status":"affected"},{"version":"c5ae57b1bb99bd6f50b90428fabde397c2aeba0f","lessThan":"465075c6835103821d725c13f8c545898e5f2636","versionType":"git","status":"affected"},{"version":"c5ae57b1bb99bd6f50b90428fabde397c2aeba0f","lessThan":"c7fa99d30c7a166a5e5db5a585ce7501ff68326b","versionType":"git","status":"affected"},{"version":"a1374d2683442633f8ad2169f8f31df45048e008","versionType":"git","status":"affected"},{"version":"6.1.34","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.3.8","lessThan":"6.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/isa/gus/gus_pcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/465075c6835103821d725c13f8c545898e5f2636","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5e74e5e8cb7cc25f7a89f59abaf3489bf0c6f4a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/97f6bdf5d5ded2e37f358cacb5a95f1393356604","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c7fa99d30c7a166a5e5db5a585ce7501ff68326b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eccf8e91266e39f6f15637702a04a1d344833fe2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc5d4f27ca1293bc1379ef8fff691c30d9803ca2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64483","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:33.957","lastModified":"2026-07-25T10:17:33.957","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: firewire: isight: bound the sample count to the packet payload\n\nisight_packet() takes the frame count from the device iso packet and\nchecks it only against the device claimed iso length.\n\n\tcount = be32_to_cpu(payload->sample_count);\n\tif (likely(count <= (length - 16) / 4))\n\t\tisight_samples(isight, payload->samples, count);\n\nlength is the iso header data_length. It can be up to 0xffff. So the\ngate allows a count up to about 16379. isight_samples() then copies\ncount frames out of payload->samples into the PCM DMA buffer.\n\npayload->samples holds only 2 * MAX_FRAMES_PER_PACKET values. The\ndevice multiplexes two samples per frame. A count past\nMAX_FRAMES_PER_PACKET reads past the payload. A count past the buffer\nsize writes past runtime->dma_area. The smallest PCM buffer is larger\nthan MAX_FRAMES_PER_PACKET. Bounding the count to MAX_FRAMES_PER_PACKET\nkeeps both the read and the write in range.\n\nA malicious or faulty Apple iSight on the FireWire bus reaches this\nduring a normal capture.\n\nAdd the MAX_FRAMES_PER_PACKET bound to the gate."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/firewire/isight.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3a691b28a0ca3cf4d9010c6158318159e0275d2c","lessThan":"24423e0a9251d348c3f1fb0bb0e61b879e1e976c","versionType":"git","status":"affected"},{"version":"3a691b28a0ca3cf4d9010c6158318159e0275d2c","lessThan":"ebbffacda6733dcbcef601b5b523460f8d8b671e","versionType":"git","status":"affected"},{"version":"3a691b28a0ca3cf4d9010c6158318159e0275d2c","lessThan":"57e4d9043afc1eaddee8f50d11def6e65415d273","versionType":"git","status":"affected"},{"version":"3a691b28a0ca3cf4d9010c6158318159e0275d2c","lessThan":"3ed2fa1ed8cc65f910b8bbc0be3cc366b30f8478","versionType":"git","status":"affected"},{"version":"3a691b28a0ca3cf4d9010c6158318159e0275d2c","lessThan":"31da82b9676c6b112e7c72c7529e6812b919742a","versionType":"git","status":"affected"},{"version":"3a691b28a0ca3cf4d9010c6158318159e0275d2c","lessThan":"8e48a29813df8dd71503800b7acf69c12c035045","versionType":"git","status":"affected"},{"version":"3a691b28a0ca3cf4d9010c6158318159e0275d2c","lessThan":"31a01b70bb90e3ef3147f308e2ea899e1d2485ca","versionType":"git","status":"affected"},{"version":"3a691b28a0ca3cf4d9010c6158318159e0275d2c","lessThan":"29b9667982e4df2ed7744f86b1144f8bb58eb698","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/firewire/isight.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.0","status":"affected"},{"version":"0","lessThan":"3.0","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/24423e0a9251d348c3f1fb0bb0e61b879e1e976c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/29b9667982e4df2ed7744f86b1144f8bb58eb698","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/31a01b70bb90e3ef3147f308e2ea899e1d2485ca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/31da82b9676c6b112e7c72c7529e6812b919742a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3ed2fa1ed8cc65f910b8bbc0be3cc366b30f8478","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/57e4d9043afc1eaddee8f50d11def6e65415d273","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8e48a29813df8dd71503800b7acf69c12c035045","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ebbffacda6733dcbcef601b5b523460f8d8b671e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64484","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:34.083","lastModified":"2026-07-25T10:17:34.083","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: es1938: check snd_ctl_new1() return value\n\nsnd_ctl_new1() can return NULL when memory allocation fails.\nsnd_es1938_mixer() does not check the return value before dereferencing\nthe pointer, which can lead to a NULL pointer dereference.\n\nAdd a NULL check after snd_ctl_new1() and return -ENOMEM if it fails."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/pci/es1938.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"96cad5bd7d0a176db3fdc06717a41271247336bd","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6c4efebaf73e217efbd08cdbda805758a7db3680","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"41759affbcfe3d51a32900da9547a1ffd744a85f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7531a37720c2545a480fd0fa464978569bf9d6a2","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"af01c48e17a66fa038af210a5c49d6cdefd210bd","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9e53e99b6fa3cd82992d963cbff58dbbd1df8651","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1949163dee39e0e4a1468f37dd7302962f6af45a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1edd1f02dddd20aeb6066ded41017615766ea42f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/pci/es1938.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1949163dee39e0e4a1468f37dd7302962f6af45a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1edd1f02dddd20aeb6066ded41017615766ea42f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/41759affbcfe3d51a32900da9547a1ffd744a85f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c4efebaf73e217efbd08cdbda805758a7db3680","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7531a37720c2545a480fd0fa464978569bf9d6a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/96cad5bd7d0a176db3fdc06717a41271247336bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9e53e99b6fa3cd82992d963cbff58dbbd1df8651","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af01c48e17a66fa038af210a5c49d6cdefd210bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64485","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:34.203","lastModified":"2026-07-25T10:17:34.203","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: compress: Fix task creation error unwind\n\nsnd_compr_task_new() allocates the driver task before validating the\nreturned DMA buffers and reserving file descriptors. When either of\nthose later steps fails, the core frees its task wrapper and DMA-buffer\nreferences without calling the driver's task_free() callback. Any\ndriver resources allocated by task_create() are therefore leaked.\n\nThe dual-fd allocation path also jumps to cleanup without storing the\nnegative get_unused_fd_flags() result in retval. Since retval still\ncontains the successful task_create() return value, TASK_CREATE can\nincorrectly report success although the task was discarded.\n\nPreserve the fd allocation errors and call task_free() when failure\noccurs after a successful task_create() callback."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/core/compress_offload.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"04177158cf98a79744937893b100020d77e6f9ac","lessThan":"b27a75d42044d9d4709095617730b91b1c4af423","versionType":"git","status":"affected"},{"version":"04177158cf98a79744937893b100020d77e6f9ac","lessThan":"426a9947a38d272d0e19c031658da68e31128667","versionType":"git","status":"affected"},{"version":"04177158cf98a79744937893b100020d77e6f9ac","lessThan":"4a60127debb9e370d6c0e22a307326b624a141f3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/core/compress_offload.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/426a9947a38d272d0e19c031658da68e31128667","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4a60127debb9e370d6c0e22a307326b624a141f3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b27a75d42044d9d4709095617730b91b1c4af423","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64486","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:34.310","lastModified":"2026-07-25T10:17:34.310","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: cmipci: check snd_ctl_new1() return value\n\nsnd_ctl_new1() can return NULL when memory allocation fails.\nsnd_cmipci_spdif_controls() does not check the return value before\ndereferencing kctl->id.device, which can lead to a NULL pointer\ndereference.\n\nAdd NULL checks after snd_ctl_new1() calls and return -ENOMEM if any\nfails."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/pci/cmipci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3454490e0396191f8f9c215fccf5deef76abffb5","lessThan":"b44888c33c4f11277d0e5e023338f2740232a4ed","versionType":"git","status":"affected"},{"version":"f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9","lessThan":"8825a06bfa7932a7a74dec01669d405df0b47286","versionType":"git","status":"affected"},{"version":"f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9","lessThan":"4dd5b0b1a52a8d6e59a3f217204817228ce0238b","versionType":"git","status":"affected"},{"version":"f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9","lessThan":"af2b009b773bc42995546507963e5e78970dc3ed","versionType":"git","status":"affected"},{"version":"f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9","lessThan":"67e9ea92cd598cba1783ff701553c776a6cedee9","versionType":"git","status":"affected"},{"version":"f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9","lessThan":"c205bd1b28fb7e5f1061a4e78813fad7d315cb3e","versionType":"git","status":"affected"},{"version":"7bf12707fa3db4c14fbe8ab93efb421d8ca93bf8","versionType":"git","status":"affected"},{"version":"6.1.34","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.3.8","lessThan":"6.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/pci/cmipci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4dd5b0b1a52a8d6e59a3f217204817228ce0238b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/67e9ea92cd598cba1783ff701553c776a6cedee9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8825a06bfa7932a7a74dec01669d405df0b47286","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af2b009b773bc42995546507963e5e78970dc3ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b44888c33c4f11277d0e5e023338f2740232a4ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c205bd1b28fb7e5f1061a4e78813fad7d315cb3e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64487","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:34.423","lastModified":"2026-07-25T10:17:34.423","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser\n\nsnd_usb_caiaq_tks4_dispatch() decodes the Traktor Kontrol S4 input\nstream in fixed 16-byte (TKS4_MSGBLOCK_SIZE) message blocks. On every\niteration it advances buf and subtracts the block size while looping on\n\"while (len)\".\n\nlen is urb->actual_length. That value is supplied by the device and is\nnot guaranteed to be a multiple of 16. When a final short block leaves\nlen between 1 and 15, the loop runs once more, reads up to buf[15], and\nthen does \"len -= TKS4_MSGBLOCK_SIZE\". As len is unsigned this underflows\nto a huge value. The loop then keeps iterating and walking buf far past\nthe end of the 512-byte ep4_in_buf, reading out of bounds until a bogus\nblock id happens to be hit.\n\nIterate only while a full message block is available. This stops the\nunsigned underflow and silently drops any trailing partial block, which\ncarries no complete control value anyway.\n\nThe sibling endpoint-4 parsers are not affected. The Traktor Kontrol X1\nand Maschine arms in snd_usb_caiaq_ep4_reply_dispatch() floor\nurb->actual_length before dispatching."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/usb/caiaq/input.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"15c5ab607045e278ebf4d2ca4aea2250617d50ca","lessThan":"de5f9edc705497b1b2c6b173b22f283486d2fd91","versionType":"git","status":"affected"},{"version":"15c5ab607045e278ebf4d2ca4aea2250617d50ca","lessThan":"70d6d4cfa4ad09688aed2ec8a0cfa72c31f60334","versionType":"git","status":"affected"},{"version":"15c5ab607045e278ebf4d2ca4aea2250617d50ca","lessThan":"884f575cc6acb136eb4a161d925147f85b59c27e","versionType":"git","status":"affected"},{"version":"15c5ab607045e278ebf4d2ca4aea2250617d50ca","lessThan":"05df59b9a61f7ca66548df079d306c41da23845d","versionType":"git","status":"affected"},{"version":"15c5ab607045e278ebf4d2ca4aea2250617d50ca","lessThan":"3cad86197c7bf8b45bb1d8adc1099d0913e80469","versionType":"git","status":"affected"},{"version":"15c5ab607045e278ebf4d2ca4aea2250617d50ca","lessThan":"a5fd3122283bf75c04f6414bf610100beb0565b0","versionType":"git","status":"affected"},{"version":"15c5ab607045e278ebf4d2ca4aea2250617d50ca","lessThan":"0680413f2f10aab43878dd3db711a6a9e45bab7c","versionType":"git","status":"affected"},{"version":"15c5ab607045e278ebf4d2ca4aea2250617d50ca","lessThan":"f7f3f9fd81e7adbaa12c2e62ee07f0e094a543fd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/usb/caiaq/input.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.37","status":"affected"},{"version":"0","lessThan":"2.6.37","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/05df59b9a61f7ca66548df079d306c41da23845d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0680413f2f10aab43878dd3db711a6a9e45bab7c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3cad86197c7bf8b45bb1d8adc1099d0913e80469","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/70d6d4cfa4ad09688aed2ec8a0cfa72c31f60334","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/884f575cc6acb136eb4a161d925147f85b59c27e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a5fd3122283bf75c04f6414bf610100beb0565b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/de5f9edc705497b1b2c6b173b22f283486d2fd91","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7f3f9fd81e7adbaa12c2e62ee07f0e094a543fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64488","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:34.553","lastModified":"2026-07-25T10:17:34.553","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: aoa: check snd_ctl_new1() return value\n\nsnd_ctl_new1() can return NULL when memory allocation fails. In\nlayout.c, the function does not check the return value before\ndereferencing ctl->id.name or passing to aoa_snd_ctl_add(), which can\nlead to a NULL pointer dereference.\n\nAdd NULL checks after snd_ctl_new1() calls and return early if any\nfails."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/aoa/fabrics/layout.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f3d9478b2ce468c3115b02ecae7e975990697f15","lessThan":"b0154ebc6dc552c389a574b1e221d728e10346e7","versionType":"git","status":"affected"},{"version":"f3d9478b2ce468c3115b02ecae7e975990697f15","lessThan":"d62624fe256b2d0d13454c78cbfc70ff5d954dc7","versionType":"git","status":"affected"},{"version":"f3d9478b2ce468c3115b02ecae7e975990697f15","lessThan":"e5e8c4508d95af82f9b4d065f658e5476a8e9bc8","versionType":"git","status":"affected"},{"version":"f3d9478b2ce468c3115b02ecae7e975990697f15","lessThan":"2ee9c46fd2dcd529cef18e37636ee12f5c3dbedd","versionType":"git","status":"affected"},{"version":"f3d9478b2ce468c3115b02ecae7e975990697f15","lessThan":"d73067e2bbf3775a495d9f38e38d0a3cf53ee790","versionType":"git","status":"affected"},{"version":"f3d9478b2ce468c3115b02ecae7e975990697f15","lessThan":"fd786466889e4a6e6de0f4462bd0068edea63960","versionType":"git","status":"affected"},{"version":"f3d9478b2ce468c3115b02ecae7e975990697f15","lessThan":"e47f2a341adbac001b6f5d0211b0cd1c1668637b","versionType":"git","status":"affected"},{"version":"f3d9478b2ce468c3115b02ecae7e975990697f15","lessThan":"8df560fefe6fed6a20b7e06720eeaeccec349ac0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/aoa/fabrics/layout.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.18","status":"affected"},{"version":"0","lessThan":"2.6.18","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2ee9c46fd2dcd529cef18e37636ee12f5c3dbedd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8df560fefe6fed6a20b7e06720eeaeccec349ac0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b0154ebc6dc552c389a574b1e221d728e10346e7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d62624fe256b2d0d13454c78cbfc70ff5d954dc7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d73067e2bbf3775a495d9f38e38d0a3cf53ee790","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e47f2a341adbac001b6f5d0211b0cd1c1668637b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5e8c4508d95af82f9b4d065f658e5476a8e9bc8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fd786466889e4a6e6de0f4462bd0068edea63960","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64489","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:34.687","lastModified":"2026-07-25T10:17:34.687","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: ymfpci: check snd_ctl_new1() return value\n\nsnd_ctl_new1() can return NULL when memory allocation fails.\nsnd_ymfpci_create_spdif_controls() does not check the return value\nbefore dereferencing kctl->id.device, which can lead to a NULL pointer\ndereference.\n\nAdd NULL checks after snd_ctl_new1() calls and return -ENOMEM if any\nfails."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/pci/ymfpci/ymfpci_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1f6c520932bca5be9e8dec137fccb2fc094a80fe","lessThan":"d7c71dfd4b80f0eacac2c157a8a3a4c6e8b2e0d1","versionType":"git","status":"affected"},{"version":"c9b83ae4a1609b1914ba7fc70826a3f3a8b234db","lessThan":"91095474eea29b95c9a8bceb9b501a2702b6c55f","versionType":"git","status":"affected"},{"version":"c9b83ae4a1609b1914ba7fc70826a3f3a8b234db","lessThan":"02f33c2062c75e28abc7ad58ce86451cf3140455","versionType":"git","status":"affected"},{"version":"c9b83ae4a1609b1914ba7fc70826a3f3a8b234db","lessThan":"f6538a318947b627710b08a268bc80a48c23bde7","versionType":"git","status":"affected"},{"version":"c9b83ae4a1609b1914ba7fc70826a3f3a8b234db","lessThan":"18ec7d7785be7a4ee8ea11e355122282caad4267","versionType":"git","status":"affected"},{"version":"c9b83ae4a1609b1914ba7fc70826a3f3a8b234db","lessThan":"e64d170346d00b580c0043de3e5ccb3e331c47d4","versionType":"git","status":"affected"},{"version":"cf671d2462d9af50c328bcc185d2c7b9726f8093","versionType":"git","status":"affected"},{"version":"6.1.34","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.3.8","lessThan":"6.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/pci/ymfpci/ymfpci_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/02f33c2062c75e28abc7ad58ce86451cf3140455","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/18ec7d7785be7a4ee8ea11e355122282caad4267","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/91095474eea29b95c9a8bceb9b501a2702b6c55f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d7c71dfd4b80f0eacac2c157a8a3a4c6e8b2e0d1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e64d170346d00b580c0043de3e5ccb3e331c47d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f6538a318947b627710b08a268bc80a48c23bde7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64490","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:34.807","lastModified":"2026-07-25T10:17:34.807","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: virtio: Validate control metadata from the device\n\nvirtio-snd control handling trusts the device-provided control type and\nvalue count returned by the device.\n\nThat metadata is then used directly to index g_v2a_type_map[] in\nvirtsnd_kctl_info(), and to size loops and memcpy() operations in\nvirtsnd_kctl_get() and virtsnd_kctl_put() against fixed-size\nvirtio_snd_ctl_value and snd_ctl_elem_value arrays.\n\nA buggy or malicious device can therefore trigger out-of-bounds access by\nadvertising an invalid control type or an oversized value count.\n\nValidate control type and count once in virtsnd_kctl_parse_cfg(), before\nquerying enumerated items or exposing the control to ALSA."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/virtio/virtio_kctl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d6568e3de42dd971a1356f7ba581e6600d53f0a0","lessThan":"3243563f99ef5d3949b934bd6390a5679405d0e1","versionType":"git","status":"affected"},{"version":"d6568e3de42dd971a1356f7ba581e6600d53f0a0","lessThan":"5da9742de22db0dbaa8d414214ab5e1bedde00f9","versionType":"git","status":"affected"},{"version":"d6568e3de42dd971a1356f7ba581e6600d53f0a0","lessThan":"21584672fd699abe1768241d6c501b2de6139b6a","versionType":"git","status":"affected"},{"version":"d6568e3de42dd971a1356f7ba581e6600d53f0a0","lessThan":"c77a6cbb36ff8cbc1f084d94f8dcda5250935271","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/virtio/virtio_kctl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/21584672fd699abe1768241d6c501b2de6139b6a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3243563f99ef5d3949b934bd6390a5679405d0e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5da9742de22db0dbaa8d414214ab5e1bedde00f9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c77a6cbb36ff8cbc1f084d94f8dcda5250935271","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64491","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:34.910","lastModified":"2026-07-25T10:17:34.910","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usx2y: us144mkii: fix work UAF on disconnect\n\ntascam_disconnect() cancels capture_work and midi_in_work before\nusb_kill_anchored_urbs() kills the capture/MIDI-in URBs.  Those URBs\nself-resubmit, and their completion handlers reschedule the work.\n\nA URB that completes in the small window between cancel_work_sync() and\nusb_kill_anchored_urbs() therefore re-arms the work after its only\ncancel.  Nothing cancels it again before snd_card_free() frees the\ncard-private tascam structure, so the work handler then runs on freed\nmemory.\n\nKill the anchored URBs before cancelling the work; once the work is\ncancelled no remaining URB can complete to re-arm it."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/usb/usx2y/us144mkii.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c1bb0c13e430623c26543baae5bb9ae21139db87","lessThan":"c071df05bcda0e47aac581d4b564b2bebcb1ff60","versionType":"git","status":"affected"},{"version":"c1bb0c13e430623c26543baae5bb9ae21139db87","lessThan":"27161c68d5e78807c9d897db222a775b298d05fd","versionType":"git","status":"affected"},{"version":"c1bb0c13e430623c26543baae5bb9ae21139db87","lessThan":"147996e7e7c9e8339c0e04f6fa7ccb3e4d448ff7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/usb/usx2y/us144mkii.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/147996e7e7c9e8339c0e04f6fa7ccb3e4d448ff7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/27161c68d5e78807c9d897db222a775b298d05fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c071df05bcda0e47aac581d4b564b2bebcb1ff60","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64492","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:35.017","lastModified":"2026-07-25T10:17:35.017","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: temperature: tmp006: use devm_iio_trigger_register\n\ntmp006_probe() allocates the DRDY trigger with devm_iio_trigger_alloc()\nbut registers it with plain iio_trigger_register(). The driver has no\n.remove() callback, so on module unload the trigger stays in the global\ntrigger list while its memory is freed by devm, leaving a dangling\nentry.\n\nSwitch to devm_iio_trigger_register() so the registration is undone in\nthe same devm scope as the allocation."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/temperature/tmp006.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"91f75ccf9f032e17cde54f0c01eae2da4f067bc5","lessThan":"a4f8491da9563ba6eb77969ac26fc7052114c476","versionType":"git","status":"affected"},{"version":"91f75ccf9f032e17cde54f0c01eae2da4f067bc5","lessThan":"d90f868f56a16e10eedc6552f48d99dff4d275b7","versionType":"git","status":"affected"},{"version":"91f75ccf9f032e17cde54f0c01eae2da4f067bc5","lessThan":"3c5eed894efd93d68d7f6a359a81ddef0e928774","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/temperature/tmp006.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3c5eed894efd93d68d7f6a359a81ddef0e928774","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4f8491da9563ba6eb77969ac26fc7052114c476","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d90f868f56a16e10eedc6552f48d99dff4d275b7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64493","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:35.120","lastModified":"2026-07-25T10:17:35.120","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: pressure: mpl115: fix runtime PM leak on read error\n\nmpl115_read_raw() takes a runtime PM reference with pm_runtime_get_sync()\nbefore reading the processed pressure or raw temperature, but on the read\nerror path it returns without calling pm_runtime_put_autosuspend(). Each\nfailed read therefore leaks a runtime PM reference and prevents the device\nfrom autosuspending.\n\nDrop the reference before checking the return value so both the success\nand error paths are balanced."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/pressure/mpl115.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a","lessThan":"5022f4ed5aae974ec530e3cbf0bd223be13055f7","versionType":"git","status":"affected"},{"version":"0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a","lessThan":"aab0fed636b14a5fd52fcae58b484f1cb96b841d","versionType":"git","status":"affected"},{"version":"0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a","lessThan":"b3f1af4ba8e9cf33aa08c4cdcaa5a17b140521ec","versionType":"git","status":"affected"},{"version":"0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a","lessThan":"46e69d3dd429b33e50e2731913239f6af4ea2705","versionType":"git","status":"affected"},{"version":"0c3a333524a3e5ba4b6c7b2638faef8420cfdb2a","lessThan":"fbe67ff37a6fd855a6c097f84f3738bd13d0a898","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/pressure/mpl115.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.2","status":"affected"},{"version":"0","lessThan":"6.2","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/46e69d3dd429b33e50e2731913239f6af4ea2705","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5022f4ed5aae974ec530e3cbf0bd223be13055f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aab0fed636b14a5fd52fcae58b484f1cb96b841d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b3f1af4ba8e9cf33aa08c4cdcaa5a17b140521ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fbe67ff37a6fd855a6c097f84f3738bd13d0a898","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64494","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:35.230","lastModified":"2026-07-25T10:17:35.230","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: light: gp2ap002: fix runtime PM leak on read error\n\ngp2ap002_read_raw() calls pm_runtime_get_sync() before reading the\nlux value, but if gp2ap002_get_lux() fails, it returns directly. This\nskips the pm_runtime_put_autosuspend() call at the \"out\" label,\npermanently leaking a runtime PM reference and preventing the device\nfrom autosuspending.\n\nReplace the direct return with a \"goto out\" to ensure the reference\nis properly dropped on the error path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/light/gp2ap002.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f6dbf83c17cb223ceabd7c42d441414f3e0e8a86","lessThan":"62e0d74821a02f0e0c5c79b99ae64dc83a9a90f5","versionType":"git","status":"affected"},{"version":"f6dbf83c17cb223ceabd7c42d441414f3e0e8a86","lessThan":"7110201c6b21455240c63388f30113f3baafacfc","versionType":"git","status":"affected"},{"version":"f6dbf83c17cb223ceabd7c42d441414f3e0e8a86","lessThan":"2593f0c6ea37df168975694a3b17e7086f11453e","versionType":"git","status":"affected"},{"version":"f6dbf83c17cb223ceabd7c42d441414f3e0e8a86","lessThan":"f350883989ced96d6da7f582f9a6f9c6ffc94e34","versionType":"git","status":"affected"},{"version":"f6dbf83c17cb223ceabd7c42d441414f3e0e8a86","lessThan":"29137052c4485c74bc2d1b0717f69ca4de14274f","versionType":"git","status":"affected"},{"version":"f6dbf83c17cb223ceabd7c42d441414f3e0e8a86","lessThan":"0c655d067ac69ee24e2e9d706c54179ea58a43db","versionType":"git","status":"affected"},{"version":"f6dbf83c17cb223ceabd7c42d441414f3e0e8a86","lessThan":"2ebaea7f3089decb01a8294d89d7e0cf288146c4","versionType":"git","status":"affected"},{"version":"f6dbf83c17cb223ceabd7c42d441414f3e0e8a86","lessThan":"38b72267b7e22768a1f26d9935de4e1752a1dc85","versionType":"git","status":"affected"},{"version":"f3e84bf3f86bb3b7bd50666bb8ef7a203a656ca3","versionType":"git","status":"affected"},{"version":"5.7.6","lessThan":"5.8","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/light/gp2ap002.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.8","status":"affected"},{"version":"0","lessThan":"5.8","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0c655d067ac69ee24e2e9d706c54179ea58a43db","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2593f0c6ea37df168975694a3b17e7086f11453e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/29137052c4485c74bc2d1b0717f69ca4de14274f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2ebaea7f3089decb01a8294d89d7e0cf288146c4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/38b72267b7e22768a1f26d9935de4e1752a1dc85","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/62e0d74821a02f0e0c5c79b99ae64dc83a9a90f5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7110201c6b21455240c63388f30113f3baafacfc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f350883989ced96d6da7f582f9a6f9c6ffc94e34","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64495","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:35.360","lastModified":"2026-07-25T10:17:35.360","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: gyro: bmg160: bail out when bandwidth/filter is not in table\n\nbmg160_get_filter() walks bmg160_samp_freq_table[] looking for the entry\nmatching the bw_bits value read from the chip:\n\n\tfor (i = 0; i < ARRAY_SIZE(bmg160_samp_freq_table); ++i) {\n\t\tif (bmg160_samp_freq_table[i].bw_bits == bw_bits)\n\t\t\tbreak;\n\t}\n\t*val = bmg160_samp_freq_table[i].filter;\n\nIf no entry matches, i ends up equal to the array size and the next line\nreads one slot past the end. bmg160_set_filter() has the same shape, driven\nby 'val' instead of bw_bits.\n\nsmatch flags both:\n\n  drivers/iio/gyro/bmg160_core.c:204 bmg160_get_filter() error:\n  buffer overflow 'bmg160_samp_freq_table' 7 <= 7\n  drivers/iio/gyro/bmg160_core.c:222 bmg160_set_filter() error:\n  buffer overflow 'bmg160_samp_freq_table' 7 <= 7\n\nReturn -EINVAL when no entry matches.\n\nThe set_filter() path is reachable from userspace via the sysfs\nin_anglvel_filter_low_pass_3db_frequency interface, so userspace can\ntrivially trigger the out-of-bounds read with a value that is not in\nbmg160_samp_freq_table[].filter."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/gyro/bmg160_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc","lessThan":"1dc3a833be11e5d503038e3c701745fd0e03903c","versionType":"git","status":"affected"},{"version":"22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc","lessThan":"77e56ebb1786f4296afd5fa46975a989b285ae65","versionType":"git","status":"affected"},{"version":"22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc","lessThan":"029481cddb98697716f4bf3021d035eaf2ca0e1f","versionType":"git","status":"affected"},{"version":"22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc","lessThan":"8d202515baea4e2e3be448d1590099af28f2346d","versionType":"git","status":"affected"},{"version":"22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc","lessThan":"d85ee50f58dd83fe74f6d0bf8bd345c657b216e8","versionType":"git","status":"affected"},{"version":"22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc","lessThan":"7bbf02b63961fc1768c9c654392c11f2077d4c59","versionType":"git","status":"affected"},{"version":"22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc","lessThan":"6c8675468862161d1c59130266852b66867d3861","versionType":"git","status":"affected"},{"version":"22b46c45fb9be8ec1fcb4d9b74810e6a20ff67cc","lessThan":"8320c77e67382d5d55d77043a5f60a867d408a2b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/gyro/bmg160_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.18","status":"affected"},{"version":"0","lessThan":"3.18","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/029481cddb98697716f4bf3021d035eaf2ca0e1f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1dc3a833be11e5d503038e3c701745fd0e03903c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c8675468862161d1c59130266852b66867d3861","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/77e56ebb1786f4296afd5fa46975a989b285ae65","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7bbf02b63961fc1768c9c654392c11f2077d4c59","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8320c77e67382d5d55d77043a5f60a867d408a2b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8d202515baea4e2e3be448d1590099af28f2346d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d85ee50f58dd83fe74f6d0bf8bd345c657b216e8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64496","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:35.490","lastModified":"2026-07-25T10:17:35.490","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: event: Fix event FIFO reset race\n\n`iio_event_getfd()` creates the event file descriptor with\n`anon_inode_getfd()`, which allocates a new fd, creates the anonymous\nfile and installs it in the process fd table before returning to the\ncaller.\n\nThe IIO code resets the event FIFO after `anon_inode_getfd()` has returned,\nbut before `IIO_GET_EVENT_FD_IOCTL` has copied the fd number to userspace.\nBut since fd tables are shared between threads, another thread can guess\nthe newly allocated fd number and issue a `read()` on it as soon as the fd\nhas been installed.\n\nThis means the `kfifo_to_user()` in `iio_event_chrdev_read()` can run in\nparallel with the `kfifo_reset_out()` in `iio_event_getfd()`.\n\nThe kfifo documentation says that `kfifo_reset_out()` is only safe when it\nis called from the reader thread and there is only one concurrent reader.\nOtherwise it is dangerous and must be handled in the same way as\n`kfifo_reset()`.\n\nIf that happens, `kfifo_to_user()` can advance the FIFO `out` index based\non state from before the reset, after the reset has already moved the `out`\nindex to the current `in` index. That can leave the FIFO with an `out`\nindex past the `in` index. A later `read()` can then see an underflowed\nFIFO length and copy more data than the event FIFO buffer contains. This\ncan result in an out-of-bounds read and leak adjacent kernel memory to\nuserspace.\n\nMove the FIFO reset before `anon_inode_getfd()`. At that point the event fd is\nmarked busy, but the new fd has not been installed yet, so userspace cannot\naccess it while the FIFO is reset."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/industrialio-event.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b91accafbb1031b80d22ad83576877ff2f8b4774","lessThan":"9dc84ba4be5bbeb29ee49efe6cea2cb32c461424","versionType":"git","status":"affected"},{"version":"b91accafbb1031b80d22ad83576877ff2f8b4774","lessThan":"d16a702ca7d29c0b7a9b509339d1b044a1cadb32","versionType":"git","status":"affected"},{"version":"b91accafbb1031b80d22ad83576877ff2f8b4774","lessThan":"a13ef1adbc62085b21b546b07b0be7e2fbf52150","versionType":"git","status":"affected"},{"version":"b91accafbb1031b80d22ad83576877ff2f8b4774","lessThan":"0d4a646d7f87ea3625fafe387043fddc6a2f5e7f","versionType":"git","status":"affected"},{"version":"b91accafbb1031b80d22ad83576877ff2f8b4774","lessThan":"72c6aa8e0d74eab91b8694cde97dec088c248fee","versionType":"git","status":"affected"},{"version":"b91accafbb1031b80d22ad83576877ff2f8b4774","lessThan":"9edefd4c56bee3fe331e0355d1f10a533134999d","versionType":"git","status":"affected"},{"version":"b91accafbb1031b80d22ad83576877ff2f8b4774","lessThan":"f187dc5a4c4846ffa07d9bda6e760837ed005574","versionType":"git","status":"affected"},{"version":"b91accafbb1031b80d22ad83576877ff2f8b4774","lessThan":"af791d295737ea6b6ff2c8d8488462a49c14af01","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/industrialio-event.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.15","status":"affected"},{"version":"0","lessThan":"3.15","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0d4a646d7f87ea3625fafe387043fddc6a2f5e7f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/72c6aa8e0d74eab91b8694cde97dec088c248fee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9dc84ba4be5bbeb29ee49efe6cea2cb32c461424","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9edefd4c56bee3fe331e0355d1f10a533134999d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a13ef1adbc62085b21b546b07b0be7e2fbf52150","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af791d295737ea6b6ff2c8d8488462a49c14af01","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d16a702ca7d29c0b7a9b509339d1b044a1cadb32","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f187dc5a4c4846ffa07d9bda6e760837ed005574","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64497","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:35.623","lastModified":"2026-07-25T10:17:35.623","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: chemical: scd30: Cleanup initializations and fix sign-extension bug\n\nInclude linux/bitfield.h for FIELD_GET().\n\nCreate new macros for bit manipulation in combination with manual bit\nmanipulation being replaced with FIELD_GET().\n\nThe current variable declaration and initializations are barely readable\nand use comma separations across multiple lines. Refactor the\ninitializations so that mantissa and exp have separate declarations and\nsign gets initialized later.\n\nIn addition (and due to the nature of the cleanup), fix a sign-extension\nbug where, float32 would get bitwise anded with ~BIT(31)\n(which is 0xFFFFFFFF7FFFFFFF) which corrupted the exponent."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/chemical/scd30_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"64b3d8b1b0f5c16c19045785e4da8391ae35ec99","lessThan":"0ccff849bde90973e6c13a666f6ceab5c55b30d4","versionType":"git","status":"affected"},{"version":"64b3d8b1b0f5c16c19045785e4da8391ae35ec99","lessThan":"1821bcacd8ac5b214c53be16cbb8172bf193f0b6","versionType":"git","status":"affected"},{"version":"64b3d8b1b0f5c16c19045785e4da8391ae35ec99","lessThan":"40bb0fdb37f441c9c9f52bf58bbd8a0ca3cc9598","versionType":"git","status":"affected"},{"version":"64b3d8b1b0f5c16c19045785e4da8391ae35ec99","lessThan":"b131f0011dfef72350f4e3f11df94dc3e6b46065","versionType":"git","status":"affected"},{"version":"64b3d8b1b0f5c16c19045785e4da8391ae35ec99","lessThan":"8d4a46e971cf846bda98b20d4cabfa21c1276e5f","versionType":"git","status":"affected"},{"version":"64b3d8b1b0f5c16c19045785e4da8391ae35ec99","lessThan":"82accdd57404399eddf3d56fd9beda7c61307388","versionType":"git","status":"affected"},{"version":"64b3d8b1b0f5c16c19045785e4da8391ae35ec99","lessThan":"d49ff54b2784aa56a7c97982de713604de89d23a","versionType":"git","status":"affected"},{"version":"64b3d8b1b0f5c16c19045785e4da8391ae35ec99","lessThan":"60d877910a43c305b5165131b258a17b1d772d57","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/chemical/scd30_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.9","status":"affected"},{"version":"0","lessThan":"5.9","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0ccff849bde90973e6c13a666f6ceab5c55b30d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1821bcacd8ac5b214c53be16cbb8172bf193f0b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/40bb0fdb37f441c9c9f52bf58bbd8a0ca3cc9598","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/60d877910a43c305b5165131b258a17b1d772d57","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/82accdd57404399eddf3d56fd9beda7c61307388","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8d4a46e971cf846bda98b20d4cabfa21c1276e5f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b131f0011dfef72350f4e3f11df94dc3e6b46065","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d49ff54b2784aa56a7c97982de713604de89d23a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64498","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:35.753","lastModified":"2026-07-25T10:17:35.753","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: buffer: hw-consumer: free scan_mask on buffer release\n\nThe scan_mask lifetime changed in commit 9a2e1233d38c (\"iio: buffer:\nhw-consumer: remove redundant scan_mask flexible array\").\n\nBefore that change, the scan mask storage was embedded in struct\nhw_consumer_buffer, so iio_hw_buf_release() could free the whole\nallocation with a single kfree(hw_buf).\n\nThat commit moved the scan mask to a separate bitmap_zalloc() allocation\nstored in buffer.scan_mask, but left iio_hw_buf_release() unchanged.\n\nFree the scan mask in iio_hw_buf_release() before freeing the buffer\nwrapper."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/buffer/industrialio-hw-consumer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9a2e1233d38c460ad07f36901931f3674a32d1ed","lessThan":"fb8e18f8ca724bd4de4643cad5b7c7230b9a5a71","versionType":"git","status":"affected"},{"version":"9a2e1233d38c460ad07f36901931f3674a32d1ed","lessThan":"6325d6e2204327965b849c0a16efb6ac9202e5a8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/buffer/industrialio-hw-consumer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6325d6e2204327965b849c0a16efb6ac9202e5a8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb8e18f8ca724bd4de4643cad5b7c7230b9a5a71","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64499","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:35.860","lastModified":"2026-07-25T10:17:35.860","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ti-ads1119: fix PM reference leak in buffer preenable\n\nads1119_triggered_buffer_preenable() resumes the device with\npm_runtime_resume_and_get() before starting a conversion.\n\nIf i2c_smbus_write_byte() fails, the function returns the error directly\nand leaves the runtime PM usage counter elevated. The matching\npostdisable callback is not called when preenable fails, so the reference\nis leaked and the device may remain runtime-active indefinitely.\n\nStore the I2C transfer result in ret and drop the runtime PM reference on\nfailure before returning the error."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/adc/ti-ads1119.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a9306887eba41c5fe7232727a8147da3d3c4f83c","lessThan":"f40292fb19399a3c3f82de698023ba87c01e66cf","versionType":"git","status":"affected"},{"version":"a9306887eba41c5fe7232727a8147da3d3c4f83c","lessThan":"ffb2195921c3d629194b9807de589578df9f9cb8","versionType":"git","status":"affected"},{"version":"a9306887eba41c5fe7232727a8147da3d3c4f83c","lessThan":"6537f08100189d12bec4975000244e6ac4873c28","versionType":"git","status":"affected"},{"version":"a9306887eba41c5fe7232727a8147da3d3c4f83c","lessThan":"adf4bc07f814da8329278d32600147f5a150938c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/adc/ti-ads1119.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6537f08100189d12bec4975000244e6ac4873c28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/adf4bc07f814da8329278d32600147f5a150938c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f40292fb19399a3c3f82de698023ba87c01e66cf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ffb2195921c3d629194b9807de589578df9f9cb8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64500","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:35.957","lastModified":"2026-07-25T10:17:35.957","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: lpc32xx: Initialize completion before requesting IRQ\n\nIn the report from Jaeyoung Chung:\n\n\"lpc32xx_adc_probe() in drivers/iio/adc/lpc32xx_adc.c registers its\ninterrupt handler with devm_request_irq() before it initializes\nst->completion with init_completion(). If an interrupt arrives after\ndevm_request_irq() and before init_completion(), the handler calls\ncomplete() on an uninitialized completion, causing a kernel panic.\n\nThe probe path, in lpc32xx_adc_probe():\n\n    iodev = devm_iio_device_alloc(&pdev->dev, sizeof(*st)); /* st kzalloc-zeroed */\n    ...\n    retval = devm_request_irq(&pdev->dev, irq, lpc32xx_adc_isr, 0,\n                              LPC32XXAD_NAME, st);           /* register handler */\n    ...\n    init_completion(&st->completion);                       /* initialize completion */\n\nlpc32xx_adc_isr() calls complete():\n\n    complete(&st->completion);\n\nIf the device raises an interrupt before init_completion() runs,\ncomplete() acquires the uninitialized wait.lock and walks the zeroed\ntask_list in swake_up_locked(). The zeroed task_list makes list_empty()\nreturn false, so swake_up_locked() dereferences a NULL list entry,\ntriggering a KASAN wild-memory-access.\"\n\nFix the chance of a spurious IRQ causing an uninitialized pointer\ndereference by moving init_completion() above devm_request_irq()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/adc/lpc32xx_adc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7901b2a1453e48c9defff2c97c67d3089bf4df7a","lessThan":"7090c0d29708ee305022d0ea7b37612b33242fa2","versionType":"git","status":"affected"},{"version":"7901b2a1453e48c9defff2c97c67d3089bf4df7a","lessThan":"0e33587967b356519aa6f220b5b43c6976320397","versionType":"git","status":"affected"},{"version":"7901b2a1453e48c9defff2c97c67d3089bf4df7a","lessThan":"1ddf7b6ffb8ebb22b92a184a9eaa76277ef0c7cd","versionType":"git","status":"affected"},{"version":"7901b2a1453e48c9defff2c97c67d3089bf4df7a","lessThan":"820c4f15353efe9a9429ae86ccceeaf4e0e4e585","versionType":"git","status":"affected"},{"version":"7901b2a1453e48c9defff2c97c67d3089bf4df7a","lessThan":"48eccc6caed4e62c0f199ab3a3772fa969cd3b2d","versionType":"git","status":"affected"},{"version":"7901b2a1453e48c9defff2c97c67d3089bf4df7a","lessThan":"9e2e8b8cdfd37ae7c7a8a5c96c59e98a768731c4","versionType":"git","status":"affected"},{"version":"7901b2a1453e48c9defff2c97c67d3089bf4df7a","lessThan":"2f18c5551aa97ca7f39dbb151c67c9053ccadc17","versionType":"git","status":"affected"},{"version":"7901b2a1453e48c9defff2c97c67d3089bf4df7a","lessThan":"e561b35633f450ee607e87a6401d97f156a0cd54","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/adc/lpc32xx_adc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0e33587967b356519aa6f220b5b43c6976320397","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1ddf7b6ffb8ebb22b92a184a9eaa76277ef0c7cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2f18c5551aa97ca7f39dbb151c67c9053ccadc17","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/48eccc6caed4e62c0f199ab3a3772fa969cd3b2d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7090c0d29708ee305022d0ea7b37612b33242fa2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/820c4f15353efe9a9429ae86ccceeaf4e0e4e585","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9e2e8b8cdfd37ae7c7a8a5c96c59e98a768731c4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e561b35633f450ee607e87a6401d97f156a0cd54","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64501","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:36.090","lastModified":"2026-07-25T10:17:36.090","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ad_sigma_delta: fix CS held asserted and state leaks\n\nIn ad_sigma_delta_single_conversion(), set_mode(AD_SD_MODE_IDLE) and\ndisable_one() were called from the out: block while keep_cs_asserted\nwas still true. This caused any SPI transfer issued by those callbacks\nto carry cs_change=1, leaving CS permanently asserted after the\nconversion. Fix by moving both calls into the out_unlock: block, after\nkeep_cs_asserted is cleared, matching the pattern already used in\nad_sd_calibrate().\n\nIn the error path of ad_sd_buffer_postenable(), if an operation fails\nafter set_mode(AD_SD_MODE_CONTINUOUS) has already succeeded (e.g.\nspi_offload_trigger_enable()), the device is left in continuous\nconversion mode with CS physically asserted. Additionally,\nbus_locked remaining true after spi_bus_unlock() causes subsequent\nSPI operations to call spi_sync_locked() without the bus lock actually\nheld, allowing concurrent SPI access.\n\nFix the error path by clearing keep_cs_asserted first, then calling\nset_mode(AD_SD_MODE_IDLE) to revert the device mode and deassert CS,\nthen clearing bus_locked before releasing the bus.\n\nFor devices that implement neither set_mode nor disable_one (such as\nMAX11205, which has no physical CS pin), no SPI transfer is issued\nduring cleanup and the cs_change flag has no effect on any physical\nline."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/adc/ad_sigma_delta.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"132d44dc6966c1cf841ffe0f6f048165687e870b","lessThan":"c313bb7c38855e94ceef939d152dd75e5a904b5f","versionType":"git","status":"affected"},{"version":"132d44dc6966c1cf841ffe0f6f048165687e870b","lessThan":"f1de829ee87a1198d3465493ce430d36c5fa029c","versionType":"git","status":"affected"},{"version":"132d44dc6966c1cf841ffe0f6f048165687e870b","lessThan":"c72da0688575e5ef39c36bb44fed53aa18f8ae65","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/adc/ad_sigma_delta.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/c313bb7c38855e94ceef939d152dd75e5a904b5f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c72da0688575e5ef39c36bb44fed53aa18f8ae65","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1de829ee87a1198d3465493ce430d36c5fa029c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64502","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:36.200","lastModified":"2026-07-25T10:17:36.200","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ad_sigma_delta: fix clear_pending_event for registerless devices\n\nad_sigma_delta_clear_pending_event() falls through to the status register\nread path for devices with has_registers = false and no rdy_gpiod. For\nsuch devices, ad_sd_read_reg() skips the address byte entirely and clocks\nraw MISO bytes with no address phase — making it byte-for-byte identical\nto reading conversion data. If a pending conversion result is present,\nthis partially consumes it and corrupts the data stream for the subsequent\nad_sd_read_reg() call in ad_sigma_delta_single_conversion().\n\nFurthermore, with num_resetclks = 0 on these devices, data_read_len\nevaluates to 0. If the clocked byte has bit 7 clear, pending_event is set\nand the code attempts memset(data + 2, 0xff, 0 - 1), overflowing to\nSIZE_MAX and corrupting the heap.\n\nFix by returning 0 immediately when neither rdy_gpiod nor has_registers\nis set. This is safe for all current registerless devices: ad7191 and\nad7780 (with powerdown GPIO) are reset between conversions by CS\ndeassertion, so there is no stale result to drain; ad7780 (without\npowerdown GPIO) and max11205 are continuously-converting and cycle ~DRDY\nat the output data rate regardless of whether the previous result was\nread, so the next falling edge fires naturally.\n\nA future registerless device that holds ~DRDY asserted until data is read\nwould be broken by this early return and would require either\nnum_resetclks set or a rdy-gpio.\n\nThe same heap corruption is reachable on any device with rdy_gpiod set\nbut num_resetclks = 0: if the GPIO indicates a pending event, the drain\npath executes memset(data + 2, 0xff, 0 - 1) regardless of has_registers.\nAdd an explicit data_read_len == 0 guard after the pending event check;\nthe stale result is then consumed by the first ad_sd_read_reg() call in\nad_sigma_delta_single_conversion()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/adc/ad_sigma_delta.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"132d44dc6966c1cf841ffe0f6f048165687e870b","lessThan":"3394e0b3328422431cadaf314fa58d3717ed4936","versionType":"git","status":"affected"},{"version":"132d44dc6966c1cf841ffe0f6f048165687e870b","lessThan":"3bceb26dfaf7ba805b459e41c1d0ba916862dade","versionType":"git","status":"affected"},{"version":"132d44dc6966c1cf841ffe0f6f048165687e870b","lessThan":"91bc6767a4f55dc470d8a56b55b9f2ea09094efe","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/adc/ad_sigma_delta.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3394e0b3328422431cadaf314fa58d3717ed4936","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3bceb26dfaf7ba805b459e41c1d0ba916862dade","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/91bc6767a4f55dc470d8a56b55b9f2ea09094efe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64503","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:36.317","lastModified":"2026-07-25T10:17:36.317","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: accel: kxsd9: fix runtime PM imbalance on write_raw() error\n\nkxsd9_write_raw() takes a runtime PM reference with pm_runtime_get_sync()\nbut returns -EINVAL directly when a scale with a non-zero integer part is\nrequested, skipping the matching pm_runtime_put_autosuspend(). This leaks\na runtime PM usage-counter reference on every such write, after which the\ndevice can no longer autosuspend.\n\nSet the error code and fall through to the existing put instead of\nreturning early."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/accel/kxsd9.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9a9a369d6178dd4e263c49085ce1b37e1e8f63a0","lessThan":"a93fd69c1ab0854ac4f5b8439c26dfadb25dfd20","versionType":"git","status":"affected"},{"version":"9a9a369d6178dd4e263c49085ce1b37e1e8f63a0","lessThan":"eeece4a85ece6f3837c75ef26a9b2bf5a1d0fcfc","versionType":"git","status":"affected"},{"version":"9a9a369d6178dd4e263c49085ce1b37e1e8f63a0","lessThan":"191fcfeb729ededd8dd2a999c6bf351ddfa0cec7","versionType":"git","status":"affected"},{"version":"9a9a369d6178dd4e263c49085ce1b37e1e8f63a0","lessThan":"36154171385a8a2444a4b3c6eaa0c5294cb02478","versionType":"git","status":"affected"},{"version":"9a9a369d6178dd4e263c49085ce1b37e1e8f63a0","lessThan":"223703d6e8bed50b6a0b47e160877909518d94b9","versionType":"git","status":"affected"},{"version":"9a9a369d6178dd4e263c49085ce1b37e1e8f63a0","lessThan":"6293211d142605bec435229ef0aa3668b8964164","versionType":"git","status":"affected"},{"version":"9a9a369d6178dd4e263c49085ce1b37e1e8f63a0","lessThan":"13a91e8631cfeb68e5b7fd6687f194f5a86e83fe","versionType":"git","status":"affected"},{"version":"9a9a369d6178dd4e263c49085ce1b37e1e8f63a0","lessThan":"44a5fd874bb6873bdaec59f722c1d57832fbc9df","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/accel/kxsd9.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.9","status":"affected"},{"version":"0","lessThan":"4.9","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/13a91e8631cfeb68e5b7fd6687f194f5a86e83fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/191fcfeb729ededd8dd2a999c6bf351ddfa0cec7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/223703d6e8bed50b6a0b47e160877909518d94b9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/36154171385a8a2444a4b3c6eaa0c5294cb02478","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/44a5fd874bb6873bdaec59f722c1d57832fbc9df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6293211d142605bec435229ef0aa3668b8964164","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a93fd69c1ab0854ac4f5b8439c26dfadb25dfd20","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eeece4a85ece6f3837c75ef26a9b2bf5a1d0fcfc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64504","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:36.443","lastModified":"2026-07-25T10:17:36.443","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niio: accel: bmc150: clamp the device-reported FIFO frame count\n\n__bmc150_accel_fifo_flush() copies the number of samples the device\nreports in its hardware FIFO into an on-stack buffer\n\n\tu16 buffer[BMC150_ACCEL_FIFO_LENGTH * 3];\n\nwhich is sized for at most BMC150_ACCEL_FIFO_LENGTH (32) samples. The\nframe count is read from the FIFO_STATUS register and only masked to its\n7 valid bits:\n\n\tcount = val & 0x7F;\n\nso it can be 0..127. The only other limit applied to it is the optional\ncaller-supplied sample budget:\n\n\tif (samples && count > samples)\n\t\tcount = samples;\n\nwhich does not constrain count on the flush-all path (samples == 0), and\nleaves it well above 32 whenever samples is larger. count samples are\nthen transferred into buffer[]:\n\n\tbmc150_accel_fifo_transfer(data, (u8 *)buffer, count);\n\nbmc150_accel_fifo_transfer() reads count * 6 bytes through regmap, so a\nmalfunctioning, malicious or counterfeit accelerometer (or an attacker\ntampering with the I2C/SPI bus) that reports up to 127 frames writes up\nto 762 bytes into the 192-byte buffer: a stack out-of-bounds write of up\nto 570 bytes that clobbers the stack canary, saved registers and the\nreturn address.\n\nClamp count to BMC150_ACCEL_FIFO_LENGTH, the number of samples buffer[]\nis sized for, before the transfer, mirroring the watermark clamp already\ndone in bmc150_accel_set_watermark(). A well-formed flush reports at most\nBMC150_ACCEL_FIFO_LENGTH frames, so legitimate devices are unaffected."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iio/accel/bmc150-accel-core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3bbec9773389112330954a6a64422eaa78d546c1","lessThan":"b5a9f521e0a49a0266200fd535b32a9668ecb33b","versionType":"git","status":"affected"},{"version":"3bbec9773389112330954a6a64422eaa78d546c1","lessThan":"2fe0531dd73eff1de0f2584cb77716d645e548d5","versionType":"git","status":"affected"},{"version":"3bbec9773389112330954a6a64422eaa78d546c1","lessThan":"d0e6d924a5484e005cae5aff6a0aa07a22f3c9ff","versionType":"git","status":"affected"},{"version":"3bbec9773389112330954a6a64422eaa78d546c1","lessThan":"bfffc98f3de92e0f76be7c7b72e63ac1776a6dbc","versionType":"git","status":"affected"},{"version":"3bbec9773389112330954a6a64422eaa78d546c1","lessThan":"89f4a4ca0ac3a933c750569a771c079a290b0721","versionType":"git","status":"affected"},{"version":"3bbec9773389112330954a6a64422eaa78d546c1","lessThan":"3e766526827acd542bcd36c20c4d5f397e0f6521","versionType":"git","status":"affected"},{"version":"3bbec9773389112330954a6a64422eaa78d546c1","lessThan":"35a3cd8fd65e15029eb90f1e510045b1bb071175","versionType":"git","status":"affected"},{"version":"3bbec9773389112330954a6a64422eaa78d546c1","lessThan":"ce0e1cae26096fe959a0da5563a6d6d5a801d5fb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iio/accel/bmc150-accel-core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.1","status":"affected"},{"version":"0","lessThan":"4.1","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2fe0531dd73eff1de0f2584cb77716d645e548d5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/35a3cd8fd65e15029eb90f1e510045b1bb071175","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3e766526827acd542bcd36c20c4d5f397e0f6521","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/89f4a4ca0ac3a933c750569a771c079a290b0721","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5a9f521e0a49a0266200fd535b32a9668ecb33b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bfffc98f3de92e0f76be7c7b72e63ac1776a6dbc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ce0e1cae26096fe959a0da5563a6d6d5a801d5fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d0e6d924a5484e005cae5aff6a0aa07a22f3c9ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64505","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:36.583","lastModified":"2026-07-25T10:17:36.583","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: function: rndis: add length check for header\n\nAdd a length check for the rndis header in rndis_rm_hdr, to ensure that\nMessageType, MessageLength, DataOffset, and DataLength fields are\npresent before they are accessed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/gadget/function/rndis.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"200dd5092296ad4d5ae47f8445a2fb1edd1da973","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9ffd567d7bf269824dfac06f8ab9a32fef72699b","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b73c0142e3acdc063b50c33afb7be19cdb2cd410","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d6ef5af7d0fe1ac31e5653a77e6d775dd36bc433","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ba2cc601e59fe68716646199a33303493513e2e3","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7515a6d4a9e9e4838b833825882efa00e85f8901","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9facd79028a7807879eb441d12f0e00720980aa3","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"21b5bf155435008e0fb0736795289788e63d426f","versionType":"git","status":"affected"},{"version":"0","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"0","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.96","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.39","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/gadget/function/rndis.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc3","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/200dd5092296ad4d5ae47f8445a2fb1edd1da973","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/21b5bf155435008e0fb0736795289788e63d426f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7515a6d4a9e9e4838b833825882efa00e85f8901","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9facd79028a7807879eb441d12f0e00720980aa3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ffd567d7bf269824dfac06f8ab9a32fef72699b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b73c0142e3acdc063b50c33afb7be19cdb2cd410","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba2cc601e59fe68716646199a33303493513e2e3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d6ef5af7d0fe1ac31e5653a77e6d775dd36bc433","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64506","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:36.710","lastModified":"2026-07-25T10:17:36.710","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: correct drop logic for malformed AMPDU frames\n\nThe previous commit aims to fix issue caused by malformed AMPDU frames.\nBut the drop logic fails to deal with the first AMPDU packet paired with\ncertain range of sequence number, and leads to unexpected packet drop.\nIt is more likely to encounter this failure when there are busy traffic\nduring rekey process and could lead to disconnection from the AP.\nFix this by adding a initial state judgement and only reset status\nduring pairwise rekey."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/realtek/rtw89/core.c","drivers/net/wireless/realtek/rtw89/mac80211.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bda294ed0ed05ada2a832b19a55dd4a6fa72b1a1","lessThan":"994994cfadaf1fd362dea9b8d9d633f85dc1b3c3","versionType":"git","status":"affected"},{"version":"bda294ed0ed05ada2a832b19a55dd4a6fa72b1a1","lessThan":"63ccdfac8677387dfdbd9d4336089e9823280704","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/realtek/rtw89/core.c","drivers/net/wireless/realtek/rtw89/mac80211.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/63ccdfac8677387dfdbd9d4336089e9823280704","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/994994cfadaf1fd362dea9b8d9d633f85dc1b3c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64507","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:36.810","lastModified":"2026-07-25T10:17:36.810","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nx86/bugs: Enable IBPB flush on BPF JIT allocation\n\nEnable hardening against JIT spraying when Spectre-v2 mitigations are in\nuse. Specifically, issue an IBPB flush on BPF JIT memory reuse. Skip\nenabling the IBPB flush if the BPF dispatcher is already using a retpoline\nsequence.\n\nThis hardening applies only when BPF-JIT is in use. Guard the enabling\nunder CONFIG_BPF_JIT so that bugs.c still builds with CONFIG_BPF_JIT=n."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/x86/include/asm/nospec-branch.h","arch/x86/kernel/cpu/bugs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"cb27f3bf915cc0f20fc0c48da9059304e39ebd35","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9354248fc1c33a844ca1872761f6668b393e8c37","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"8a4c8af9ae67eb072d90d1b339f14d27a82bd2a1","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"52440e15d9628f8f239373c0f2e5e8f92feea2df","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a3af84b0fa00ead01fcd0e28b5d773ff25990a0d","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.39","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/x86/include/asm/nospec-branch.h","arch/x86/kernel/cpu/bugs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/52440e15d9628f8f239373c0f2e5e8f92feea2df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8a4c8af9ae67eb072d90d1b339f14d27a82bd2a1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9354248fc1c33a844ca1872761f6668b393e8c37","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3af84b0fa00ead01fcd0e28b5d773ff25990a0d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb27f3bf915cc0f20fc0c48da9059304e39ebd35","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64508","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:36.920","lastModified":"2026-07-25T10:17:36.920","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Support for hardening against JIT spraying\n\nThe BPF JIT allocator packs many small programs into larger executable\nallocations and reuses space within those allocations as programs are\nloaded and freed. When fresh code is written into space that a previous\nprogram occupied, an indirect jump into the new program can reuse a branch\nprediction left behind by the old one.\n\nFlush the indirect branch predictors before reusing JIT memory so that\nindirect jumps into a newly written program don't reuse predictions from an\nold program that occupied the same space.\n\nIntroduce bpf_arch_pred_flush_enabled static key and bpf_arch_pred_flush\nstatic call for flushing the branch predictors on JIT memory reuse.\nArchitectures that need a flush, can update it to a predictor flush\nfunction. By default, its a NOP and does not emit any CALL.\n\nAllocations larger than a pack are not covered by this flush. That is safe\nbecause cBPF programs (the unprivileged attack surface) are bounded well\nbelow a pack size. Issue a warning if this assumption is ever violated\nwhile the flush is active."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/linux/filter.h","kernel/bpf/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6e52c240c43a601b681e3a4e58fc5685114d4726","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"eed774da601268dae674e14d54a15e3624691f52","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"8ff183ee4d8c452960df58175a094828c0513b2e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7a6c171c6a1ac6d1509752dac131d941a3de0b37","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"96cce16e26dd02a8678f1e87f88a4b5cdb63b995","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.39","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.4","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/linux/filter.h","kernel/bpf/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6e52c240c43a601b681e3a4e58fc5685114d4726","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7a6c171c6a1ac6d1509752dac131d941a3de0b37","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8ff183ee4d8c452960df58175a094828c0513b2e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/96cce16e26dd02a8678f1e87f88a4b5cdb63b995","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eed774da601268dae674e14d54a15e3624691f52","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64509","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:37.030","lastModified":"2026-07-25T10:17:37.030","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nrust: block: fix GenDisk cleanup paths\n\nGenDiskBuilder::build() still has fallible work after\n__blk_mq_alloc_disk(), but its error path only recovers the\nforeign queue data. That leaks the temporary gendisk and\nrequest_queue until later teardown. If the caller moved the last\nArc<TagSet<T>> into build(), the leaked queue can retain blk-mq\nstate after the tag set is dropped.\n\nFix the pre-registration failure path by dropping the temporary\ngendisk reference with put_disk() before recovering queue_data,\nso disk_release() can tear down the owned queue.\n\nAlso pair GenDisk::drop() with put_disk() after del_gendisk().\nOnce a Rust GenDisk has been added with device_add_disk(),\ndel_gendisk() only unregisters it; the final gendisk reference\nstill has to be dropped to complete the release path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["rust/kernel/block/mq/gen_disk.rs"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3253aba3408aa4eb2e4e09365eede3e63ef7536b","lessThan":"d1dcaa5229a63a6b6df7e0f673fe576cf3d6e8cb","versionType":"git","status":"affected"},{"version":"3253aba3408aa4eb2e4e09365eede3e63ef7536b","lessThan":"e7636f26f77070a529c26d65afd217514ce85ce4","versionType":"git","status":"affected"},{"version":"3253aba3408aa4eb2e4e09365eede3e63ef7536b","lessThan":"6822a2685b4da9a87efd1fce4b042678a31ff734","versionType":"git","status":"affected"},{"version":"3253aba3408aa4eb2e4e09365eede3e63ef7536b","lessThan":"2957771379fa335103a4b539db57bb2271e12142","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["rust/kernel/block/mq/gen_disk.rs"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2957771379fa335103a4b539db57bb2271e12142","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6822a2685b4da9a87efd1fce4b042678a31ff734","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d1dcaa5229a63a6b6df7e0f673fe576cf3d6e8cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e7636f26f77070a529c26d65afd217514ce85ce4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64510","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:37.137","lastModified":"2026-07-25T10:17:37.137","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: NFIT: core: Fix acpi_nfit_init() error cleanup\n\nIf acpi_nfit_init() fails after adding the acpi_desc object to the\nacpi_descs list, that object is never removed from that list because\nthe acpi_nfit_shutdown() devm action is not added for the NFIT device\nin that case.  Next, the acpi_nfit_init() failure causes\nacpi_nfit_probe() to fail, the acpi_desc object is freed, and a\ndangling pointer is left behind in the acpi_descs.  Any subsequent\nACPI Machine Check Exception will trigger nfit_handle_mce() which\niterates over acpi_descs and so a use-after-free will occur.\n\nMoreover, if acpi_nfit_probe() returns 0 after installing a notify\nhandler for the NFIT device and without allocating the acpi_desc\nobject and setting the NFIT device's driver data pointer, the\nacpi_desc object will be allocated by acpi_nfit_update_notify()\nand acpi_nfit_init() will be called to initialize it.  Regardless\nof whether or not acpi_nfit_init() fails in that case, the\nacpi_nfit_shutdown() devm action is not added for the NFIT device\nand acpi_desc is never removed from the acpi_descs list.  If the\nacpi_desc object is freed subsequently on driver removal, any\nsubsequent ACPI MCE will lead to a use-after-free like in the\nprevious case.\n\nTo address the first issue mentioned above, make acpi_nfit_probe()\ncall acpi_nfit_shutdown() directly on acpi_nfit_init() failures and\nto address the other one, add a remove callback to the driver and\nmake it call acpi_nfit_shutdown().  Also, since it is now possible to\npass NULL to acpi_nfit_shutdown() or the acpi_desc object passed to it\nmay not have been initialized, add checks against NULL for acpi_desc and\nits nvdimm_bus field to that function and make acpi_nfit_unregister()\nclear the latter after unregistering the NVDIMM bus."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/acpi/nfit/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a61fe6f7902ecaa89d5e6c709490fc4324927134","lessThan":"ee82078e776ae31266cc70fdf62ac17c3c6f100a","versionType":"git","status":"affected"},{"version":"a61fe6f7902ecaa89d5e6c709490fc4324927134","lessThan":"6ff054cc02a763914773b026cacb429e5fbf64fa","versionType":"git","status":"affected"},{"version":"a61fe6f7902ecaa89d5e6c709490fc4324927134","lessThan":"b07d22a2d17ad6465c87bd5752bc70e4c16e0ee4","versionType":"git","status":"affected"},{"version":"a61fe6f7902ecaa89d5e6c709490fc4324927134","lessThan":"c127dbd832bd4b9aef8a749d9f491b74042f9b47","versionType":"git","status":"affected"},{"version":"a61fe6f7902ecaa89d5e6c709490fc4324927134","lessThan":"df7c92216a1583a76cb0cbf2f21cd68870609b05","versionType":"git","status":"affected"},{"version":"a61fe6f7902ecaa89d5e6c709490fc4324927134","lessThan":"3b2628f7682aea8d9ce09ad4b9a3bd144b451eaa","versionType":"git","status":"affected"},{"version":"a61fe6f7902ecaa89d5e6c709490fc4324927134","lessThan":"7d69235bdc581a4346e9bcd6a8bea37d3e1abd25","versionType":"git","status":"affected"},{"version":"a61fe6f7902ecaa89d5e6c709490fc4324927134","lessThan":"38bf27511ef41bffebd157ec3eba41fc89ba59cd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/acpi/nfit/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.6","status":"affected"},{"version":"0","lessThan":"4.6","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/38bf27511ef41bffebd157ec3eba41fc89ba59cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3b2628f7682aea8d9ce09ad4b9a3bd144b451eaa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6ff054cc02a763914773b026cacb429e5fbf64fa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d69235bdc581a4346e9bcd6a8bea37d3e1abd25","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b07d22a2d17ad6465c87bd5752bc70e4c16e0ee4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c127dbd832bd4b9aef8a749d9f491b74042f9b47","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/df7c92216a1583a76cb0cbf2f21cd68870609b05","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ee82078e776ae31266cc70fdf62ac17c3c6f100a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64511","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:37.273","lastModified":"2026-07-25T10:17:37.273","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: NFIT: core: Fix possible NULL pointer dereference\n\nAfter commit 9b311b7313d6 (\"ACPI: NFIT: Install Notify() handler before\ngetting NFIT table\"), acpi_nfit_probe() installs an ACPI notify handler\nfor the NFIT device before checking the presence of the NFIT table.  If\nthat table is not there, 0 is returned without allocating the acpi_desc\nobject and setting the driver data pointer of the NFIT device.  If the\nplatform firmware triggers an NFIT_NOTIFY_UC_MEMORY_ERROR notification\non the NFIT device at that point, acpi_nfit_uc_error_notify() will\ndereference a NULL pointer.\n\nPrevent that from occurring by adding an acpi_desc check against NULL\nto acpi_nfit_uc_error_notify()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/acpi/nfit/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9b311b7313d6c104dd4a2d43ab54536dce07f960","lessThan":"a44343fe230aa48c74ef09830f3c5c90848b257e","versionType":"git","status":"affected"},{"version":"9b311b7313d6c104dd4a2d43ab54536dce07f960","lessThan":"3c8f73b0fbdf956c98e2329d5aaea3ad09a9cfb6","versionType":"git","status":"affected"},{"version":"9b311b7313d6c104dd4a2d43ab54536dce07f960","lessThan":"452945662fd8e9862a2d2043239c7ee1815d1ac4","versionType":"git","status":"affected"},{"version":"9b311b7313d6c104dd4a2d43ab54536dce07f960","lessThan":"873576e585da5d0fc5debbab74eed565c0acea99","versionType":"git","status":"affected"},{"version":"9b311b7313d6c104dd4a2d43ab54536dce07f960","lessThan":"027e128abb82788189d6d45b68e3e8e7329b67be","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/acpi/nfit/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/027e128abb82788189d6d45b68e3e8e7329b67be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3c8f73b0fbdf956c98e2329d5aaea3ad09a9cfb6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/452945662fd8e9862a2d2043239c7ee1815d1ac4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/873576e585da5d0fc5debbab74eed565c0acea99","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a44343fe230aa48c74ef09830f3c5c90848b257e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64512","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:37.380","lastModified":"2026-07-25T10:17:37.380","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: CPPC: Suppress UBSAN warning caused by field misuse\n\nThe definition of reg->access_width changes depending on the\nreg->space_id type.  Type ACPI_ADR_SPACE_PLATFORM_COMM uses\naccess_width to indicate the PCC region, which can result in a UBSAN\nif the value is greater than 4.\n\nFor example:\n\n UBSAN: shift-out-of-bounds in drivers/acpi/cppc_acpi.c:1090:9\n shift exponent 32 is too large for 32-bit type 'int'\n CPU: 61 UID: 0 PID: 1220 Comm: (udev-worker) Not tainted 7.0.10-201.fc44.aarch64 #1 PREEMPT(lazy)\n Hardware name: To be filled by O.E.M.\n Call trace:\n  ...(trimming)\n  ubsan_epilogue+0x10/0x48\n  __ubsan_handle_shift_out_of_bounds+0xdc/0x1e0\n  cpc_write+0x4d0/0x670\n  cppc_set_perf+0x18c/0x490\n  cppc_cpufreq_cpu_init+0x1c8/0x380 [cppc_cpufreq]\n  ... (trimming)\n\nLets fix this by validating the region type, as well as whether\naccess_width has a value. Then since we are returning bit_width\ndirectly for ACPI_ADR_SPACE_PLATFORM_COMM, drop the code correcting\nthe size."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/acpi/cppc_acpi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4949affd5288b867cdf115f5b08d6166b2027f87","lessThan":"b54c4632946ae42f2b39ed38abd909bbf78cbcc2","versionType":"git","status":"affected"},{"version":"01fc53be672acae37e611c80cc0b4f3939584de3","lessThan":"e904596ba6dd108534ffa15e3e46b2fe245145e2","versionType":"git","status":"affected"},{"version":"1b890ae474d19800a6be1696df7fb4d9a41676e4","lessThan":"2fb80e962029000959f651665baa4838cc92eb99","versionType":"git","status":"affected"},{"version":"2f4a4d63a193be6fd530d180bb13c3592052904c","lessThan":"37f28bf8f14672dfa395994e41fd778a63f0bf5c","versionType":"git","status":"affected"},{"version":"2f4a4d63a193be6fd530d180bb13c3592052904c","lessThan":"f29dc6132d4968e39d8fa575d1a12e2c718ce57b","versionType":"git","status":"affected"},{"version":"2f4a4d63a193be6fd530d180bb13c3592052904c","lessThan":"dc066bd13c860bb27d6ace511210e18b8064c1d9","versionType":"git","status":"affected"},{"version":"2f4a4d63a193be6fd530d180bb13c3592052904c","lessThan":"1b1acf2dada0cc3931bb2cb9ff8832edfbee46a1","versionType":"git","status":"affected"},{"version":"6cb6b12b78dcd8867a3fdbb1b6d0ed1df2b208d1","versionType":"git","status":"affected"},{"version":"5.15.154","lessThan":"5.15.155","versionType":"semver","status":"affected"},{"version":"6.1.90","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.30","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.8.9","lessThan":"6.9","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/acpi/cppc_acpi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"5.15.155","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1b1acf2dada0cc3931bb2cb9ff8832edfbee46a1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2fb80e962029000959f651665baa4838cc92eb99","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/37f28bf8f14672dfa395994e41fd778a63f0bf5c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b54c4632946ae42f2b39ed38abd909bbf78cbcc2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc066bd13c860bb27d6ace511210e18b8064c1d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e904596ba6dd108534ffa15e3e46b2fe245145e2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f29dc6132d4968e39d8fa575d1a12e2c718ce57b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64513","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:37.510","lastModified":"2026-07-25T10:17:37.510","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Unconditionally recompute CR8 intercept on PPR update\n\nThe TPR_THRESHOLD field in the VMCS is used by VMX to induce VM exits\nwhen the guest's virtual TPR falls under the specified threshold,\nallowing KVM to inject previously masked interrupts.\n\nKVM handles these VM exits in handle_tpr_below_threshold().\nCommit eb90f3417a0c (\"KVM: vmx: speed up TPR below threshold vmexits\")\noptimized this function by calling apic_update_ppr() instead of raising\nKVM_REQ_EVENT. apic_update_ppr() then raises KVM_REQ_EVENT if there is\na pending, deliverable interrupt.\n\nHowever, if there are no new interrupts pending, apic_update_ppr() does\nnot issue the request. Thus, kvm_lapic_update_cr8_intercept() and\nvmx_update_cr8_intercept() are not called before VM entry, which results\nin a high, stale TPR_THRESHOLD. This is problematic due to the following\nsentence in 28.2.1.1 \"VM-Execution Control Fields\" in the SDM:\n\n  The following check is performed if the “use TPR shadow” VM-execution\n  control is 1 and the “virtualize APIC accesses” and “virtual-interrupt\n  delivery” VM-execution controls are both 0: the value of bits 3:0 of\n  the TPR threshold VM-execution control field should not be greater\n  than the value of bits 7:4 of VTPR.\n\nThis error condition is typically not observed when KVM runs on a bare\nmetal system because modern processors support APICv, which enables\nvirtual-interrupt delivery, and which KVM uses when possible. This\ncauses the processor to no longer generate TPR-below-threshold exits\nand to no longer check TPR_THRESHOLD on entry. However, when running\non older platforms, or under nested virtualization on a hypervisor that\ndoes not support virtual-interrupt delivery and enforces this check\n(like Hyper-V) this can cause a VM entry failure with hardware error\n0x7, as seen in [1].\n\nCall kvm_lapic_update_cr8_intercept() if apic_update_ppr() does not\nfind a deliverable interrupt (and thus does not raise KVM_REQ_EVENT).\nRemove calls to kvm_lapic_update_cr8_intercept() on paths that end up in\napic_update_ppr(), as they now become redundant. This ensures that any\npath that updates the guest's PPR also figures out if KVM needs to wait\nfor a TPR change (using TPR_THRESHOLD on VMX or CR8 intercepts on SVM)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/x86/kvm/lapic.c","arch/x86/kvm/x86.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"eb90f3417a0cc4880e979ccc84e41890d410ea5b","lessThan":"ff9c4c6428883182960cfe5c78928f0896d80ebc","versionType":"git","status":"affected"},{"version":"eb90f3417a0cc4880e979ccc84e41890d410ea5b","lessThan":"8c8e8ac22ee17d52f9eb2bc814bca7fab90fb8df","versionType":"git","status":"affected"},{"version":"eb90f3417a0cc4880e979ccc84e41890d410ea5b","lessThan":"bb365a506b1e6fb050c0fceaad354fe395385ef0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/x86/kvm/lapic.c","arch/x86/kvm/x86.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.11","status":"affected"},{"version":"0","lessThan":"4.11","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/8c8e8ac22ee17d52f9eb2bc814bca7fab90fb8df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb365a506b1e6fb050c0fceaad354fe395385ef0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff9c4c6428883182960cfe5c78928f0896d80ebc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64514","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:37.633","lastModified":"2026-07-25T10:17:37.633","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nuserfaultfd: gate must_wait writability check on pte_present()\n\nuserfaultfd_must_wait() and userfaultfd_huge_must_wait() read the PTE\nwithout taking the page table lock and then apply pte_write() /\nhuge_pte_write() to it.  Those accessors decode bits from the present\nencoding only; on a swap or migration entry they read the offset bits that\nhappen to share the same position and return an undefined result.\n\nThe intent of the check is \"is this fault still WP-blocked?\".  A\nnon-marker swap entry means the page is in transit -- the userfault\ncontext the original fault delivered against is no longer the same, and\nthe swap-in or migration completion path will re-deliver a fresh fault if\nuserspace still needs to handle it.  Worst case under the current code the\ngarbage write bit says \"wait\", and the thread stays asleep until a\nUFFDIO_WAKE that may never arrive.\n\nGate the writability check on pte_present() so the lockless re-check only\ninspects present-PTE bits when the entry is actually present.  The\nnon-present, non-marker case returns \"don't wait\" and lets the fault path\nretry."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/userfaultfd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"369cd2121be440543280b91056de187f625d0dbb","lessThan":"a5700a4c1c9099ac2ac73fe8a09cf059972e0d2f","versionType":"git","status":"affected"},{"version":"369cd2121be440543280b91056de187f625d0dbb","lessThan":"d4026417e8184d13850a0bad4d96ceb6ed9f7152","versionType":"git","status":"affected"},{"version":"369cd2121be440543280b91056de187f625d0dbb","lessThan":"29e6f952c5fb7dc1d6b90fe5b7f36063d44ddae0","versionType":"git","status":"affected"},{"version":"369cd2121be440543280b91056de187f625d0dbb","lessThan":"5f4dbdb0a87596214076b20b94f2b71b522170b3","versionType":"git","status":"affected"},{"version":"369cd2121be440543280b91056de187f625d0dbb","lessThan":"a6e9a4939e359599701b1da351e84f72e021443a","versionType":"git","status":"affected"},{"version":"369cd2121be440543280b91056de187f625d0dbb","lessThan":"60d696a037eeeedfb57756dfe7ec08a1587c8631","versionType":"git","status":"affected"},{"version":"369cd2121be440543280b91056de187f625d0dbb","lessThan":"710183888174639a15fcec16cd1af766b8480bb7","versionType":"git","status":"affected"},{"version":"369cd2121be440543280b91056de187f625d0dbb","lessThan":"8e80af52db652fbc41320eee45a4f73bc029faf2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/userfaultfd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.11","status":"affected"},{"version":"0","lessThan":"4.11","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/29e6f952c5fb7dc1d6b90fe5b7f36063d44ddae0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5f4dbdb0a87596214076b20b94f2b71b522170b3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/60d696a037eeeedfb57756dfe7ec08a1587c8631","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/710183888174639a15fcec16cd1af766b8480bb7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8e80af52db652fbc41320eee45a4f73bc029faf2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a5700a4c1c9099ac2ac73fe8a09cf059972e0d2f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a6e9a4939e359599701b1da351e84f72e021443a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d4026417e8184d13850a0bad4d96ceb6ed9f7152","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64515","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:37.763","lastModified":"2026-07-25T10:17:37.763","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix MLE defragmentation\n\nIf either reconf or EPCS multi-link element (MLE) is contained in\na non-transmitted profile, the defragmentation routine is called\nwith a pointer to the defragmented copy, but the original elements.\n\nThis is incorrect for two reasons:\n - if the original defragmentation was needed, it will not find the\n   correct data\n - if the original frame is at a higher address, the parsing will\n   potentially overrun the heap data (though given the layout of\n   the buffers, only into the new defragmentation buffer, and then\n   it has to stop and fail once that's filled with copied data.\n\nFix it by tracking the container along with the pointer and in\ndoing so also unify the two almost identical defragmentation\nroutines."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/mac80211/parse.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4d70e9c5488dd57ff5fcabe4d4ecf3d9dd4555ff","lessThan":"1f573e17bcb7275ddd1c8f47f46ae0faf0e902a4","versionType":"git","status":"affected"},{"version":"4d70e9c5488dd57ff5fcabe4d4ecf3d9dd4555ff","lessThan":"55c479aae99b120489a432db9c717484e523dfd6","versionType":"git","status":"affected"},{"version":"4d70e9c5488dd57ff5fcabe4d4ecf3d9dd4555ff","lessThan":"722b3f86df80644463d29fe5451e30a617f74500","versionType":"git","status":"affected"},{"version":"4d70e9c5488dd57ff5fcabe4d4ecf3d9dd4555ff","lessThan":"a74e893f30db64cdce0fc7a96d3baa417bcd55f5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/mac80211/parse.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1f573e17bcb7275ddd1c8f47f46ae0faf0e902a4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/55c479aae99b120489a432db9c717484e523dfd6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/722b3f86df80644463d29fe5451e30a617f74500","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a74e893f30db64cdce0fc7a96d3baa417bcd55f5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64516","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:37.870","lastModified":"2026-07-25T10:17:37.870","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vce1: Fix VCE 1 firmware size and offsets\n\nThe VCPU BO contains the actual FW at an offset, but\nit was not calculated into the VCPU BO size.\nSubtract this from the FW size to make sure there is\nno out of bounds access.\n\nMake sure the stack and data offsets are aligned to\nthe 32K TLB size.\n\nCheck that the FW microcode actually fits in the\nspace that is reserved for it.\n\n(cherry picked from commit c16fe59f622a080fc457a57b3e8f14c780699449)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/amd/amdgpu/vce_v1_0.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d4a640d4b9f34aa9472c71986ef4b5a42dbe4f0f","lessThan":"ce0de178ef08408f6ba8f2e9a13bf52fbe5852f4","versionType":"git","status":"affected"},{"version":"d4a640d4b9f34aa9472c71986ef4b5a42dbe4f0f","lessThan":"3e5a1d5bb2ff061e64c7992f8e5404dfd4c2d0f3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/amd/amdgpu/vce_v1_0.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3e5a1d5bb2ff061e64c7992f8e5404dfd4c2d0f3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ce0de178ef08408f6ba8f2e9a13bf52fbe5852f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64517","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:37.973","lastModified":"2026-07-25T10:17:37.973","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/gsc: Fix double-free of managed BO in error path\n\nThe error path in xe_gsc_init_post_hwconfig() explicitly frees a BO\nallocated with xe_managed_bo_create_pin_map() via\nxe_bo_unpin_map_no_vm(). Since the managed BO already has a devm\ncleanup action registered, this causes a double-free when devm\nunwinds during probe failure.\n\nRemove the explicit free and let devm handle it, consistent with\nall other xe_managed_bo_create_pin_map() callers.\n\n(cherry picked from commit 71d61e3e299a17139e47f980a4d6f425b2c59bf7)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/xe/xe_gsc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2e5d47fe7839298fa096970e184aac9bf82c3bd3","lessThan":"7cb975fcd4777e7bad688f66aa0c10c16dd8276b","versionType":"git","status":"affected"},{"version":"2e5d47fe7839298fa096970e184aac9bf82c3bd3","lessThan":"2c890e71ae26fa32f5a96c3694b71a2c310940e7","versionType":"git","status":"affected"},{"version":"2e5d47fe7839298fa096970e184aac9bf82c3bd3","lessThan":"889f70de2b51a877339e1979aab95111b41bed75","versionType":"git","status":"affected"},{"version":"2e5d47fe7839298fa096970e184aac9bf82c3bd3","lessThan":"d3ded53fab90996e7d94a39049e11962dd066725","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/xe/xe_gsc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2c890e71ae26fa32f5a96c3694b71a2c310940e7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7cb975fcd4777e7bad688f66aa0c10c16dd8276b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/889f70de2b51a877339e1979aab95111b41bed75","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3ded53fab90996e7d94a39049e11962dd066725","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64518","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:38.080","lastModified":"2026-07-25T10:17:38.080","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: Fix out-of-bounds access for twsk in tcp_ao_established_key().\n\nlockdep_sock_is_held() was added in tcp_ao_established_key()\nby the cited commit.\n\nIt can be called from tcp_v[46]_timewait_ack() with twsk.\n\nSince it does not have sk->sk_lock, the lockdep annotation\nresults in out-of-bound access.\n\n  $ pahole -C tcp_timewait_sock vmlinux | grep size\n  \t/* size: 288, cachelines: 5, members: 8 */\n  $ pahole -C sock vmlinux | grep sk_lock\n  \tsocket_lock_t              sk_lock;              /*   440   192 */\n\nLet's not use lockdep_sock_is_held() for TCP_TIME_WAIT."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/tcp_ao.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"051f49d5176613dea88ecf73a101c3a99f4720e9","lessThan":"87bb3e719042f0030a6dad39118c6a6b2a491ad9","versionType":"git","status":"affected"},{"version":"6b2d11e2d8fc130df4708be0b6b53fd3e6b54cf6","lessThan":"510db031ba6eb40134f84c90ef963ea4b6dfb878","versionType":"git","status":"affected"},{"version":"6b2d11e2d8fc130df4708be0b6b53fd3e6b54cf6","lessThan":"29cf64d128c94cf98d1c69d8b2962d39db5ff4c6","versionType":"git","status":"affected"},{"version":"6b2d11e2d8fc130df4708be0b6b53fd3e6b54cf6","lessThan":"03cb001ef87b3f8d859cf7f96329acf3d6235d29","versionType":"git","status":"affected"},{"version":"6.12.5","lessThan":"6.12.92","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/tcp_ao.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/03cb001ef87b3f8d859cf7f96329acf3d6235d29","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/29cf64d128c94cf98d1c69d8b2962d39db5ff4c6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/510db031ba6eb40134f84c90ef963ea4b6dfb878","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/87bb3e719042f0030a6dad39118c6a6b2a491ad9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64519","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:38.187","lastModified":"2026-07-25T10:17:38.187","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Fix infinite loop in layout state revocation\n\nfind_one_sb_stid() skips stids whose sc_status is non-zero, but the\nSC_TYPE_LAYOUT case in nfsd4_revoke_states() never sets sc_status\nbefore calling nfsd4_close_layout(). The retry loop therefore finds\nthe same layout stid on every iteration, hanging the revoker\nindefinitely."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/nfsd/nfs4state.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1e33e1414bec54a4feafa9e67e2617031be0afe2","lessThan":"d1fc00ec02e9deb3f8d2bd59caf938c554fbc576","versionType":"git","status":"affected"},{"version":"1e33e1414bec54a4feafa9e67e2617031be0afe2","lessThan":"fe59ae27d7346245f5d8d97220f374e63efd28b5","versionType":"git","status":"affected"},{"version":"1e33e1414bec54a4feafa9e67e2617031be0afe2","lessThan":"44e5e4eb3a07bf3e1d931dd9f96f3edcfa376605","versionType":"git","status":"affected"},{"version":"1e33e1414bec54a4feafa9e67e2617031be0afe2","lessThan":"4f8ef58c10bfe5f86a643c7c8331b37e69e3dae1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/nfsd/nfs4state.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/44e5e4eb3a07bf3e1d931dd9f96f3edcfa376605","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4f8ef58c10bfe5f86a643c7c8331b37e69e3dae1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d1fc00ec02e9deb3f8d2bd59caf938c554fbc576","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe59ae27d7346245f5d8d97220f374e63efd28b5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64520","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:38.290","lastModified":"2026-07-25T10:17:38.290","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies\n\nThe register-based PARTITION_INFO_GET path trusted the firmware-provided\nindices when copying partition descriptors into the caller buffer.\nReject inconsistent counts or index progressions so the copy loop cannot\nwrite past the allocated array.\n\n(fixed cur_idx when exactly one descriptor in the first fragment)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/firmware/arm_ffa/driver.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ba85c644ac8dc37d9b01a3332c2f142cb4d46954","lessThan":"f39bc7ebe75e2186b417a024a7f7e2fd4cc7eb95","versionType":"git","status":"affected"},{"version":"ba85c644ac8dc37d9b01a3332c2f142cb4d46954","lessThan":"79d95c02ae0a95e6e80e8e92b7ca74ecee02854f","versionType":"git","status":"affected"},{"version":"ba85c644ac8dc37d9b01a3332c2f142cb4d46954","lessThan":"3974ea1938406f9bfa7c1f48d4e43533f447bb08","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/firmware/arm_ffa/driver.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3974ea1938406f9bfa7c1f48d4e43533f447bb08","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/79d95c02ae0a95e6e80e8e92b7ca74ecee02854f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f39bc7ebe75e2186b417a024a7f7e2fd4cc7eb95","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64521","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:38.393","lastModified":"2026-07-25T10:17:38.393","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: meson: amlogic-a4: fix deadlock issue\n\nAccessing the pinconf-pins sysfs node may deadlock.\n\npinconf_pins_show() holds pctldev->mutex, and the platform driver\ncalls pinctrl_find_gpio_range_from_pin(), which tries to acquire\nthe same mutex again, leading to a deadlock.\n\nUse pinctrl_find_gpio_range_from_pin_nolock() to fix this issue."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/pinctrl/meson/pinctrl-amlogic-a4.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6e9be3abb78c2f6c97a51070004a5165702f0ed9","lessThan":"e917713f013423069782ff554935c7a5d4266783","versionType":"git","status":"affected"},{"version":"6e9be3abb78c2f6c97a51070004a5165702f0ed9","lessThan":"744ac926c0e55267a10b49b5b72582afef4ad49f","versionType":"git","status":"affected"},{"version":"6e9be3abb78c2f6c97a51070004a5165702f0ed9","lessThan":"e72ce029810390eb987a036fb2c8a5da9a23b685","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/pinctrl/meson/pinctrl-amlogic-a4.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/744ac926c0e55267a10b49b5b72582afef4ad49f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e72ce029810390eb987a036fb2c8a5da9a23b685","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e917713f013423069782ff554935c7a5d4266783","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64522","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:38.497","lastModified":"2026-07-25T10:17:38.497","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA\n\nmlx5e_xfrm_add_state() handles acquire-flow temporary SAs by allocating\nsoftware state and skipping hardware offload setup.\n\nThat path jumps to the common success label before taking the eswitch mode\nblock. After tunnel-mode validation was moved earlier, the common success\nlabel unconditionally calls mlx5_eswitch_unblock_mode(). For acquire SAs,\nthis decrements esw->offloads.num_block_mode without a matching increment.\n\nReturn directly after installing the acquire SA offload handle, so only the\npaths that successfully called mlx5_eswitch_block_mode() call the matching\nunblock."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/en_accel/ipsec.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"22239eb258bc1e6ccdb2d3502fce1cc2b2a88386","lessThan":"b5bd4249e430f5963d559708ee96a671716d2400","versionType":"git","status":"affected"},{"version":"22239eb258bc1e6ccdb2d3502fce1cc2b2a88386","lessThan":"ecafd8284e527666e83261e6e57a7c7341d591cb","versionType":"git","status":"affected"},{"version":"22239eb258bc1e6ccdb2d3502fce1cc2b2a88386","lessThan":"abe003b33223ff33552f291644bf35d9c2f992fb","versionType":"git","status":"affected"},{"version":"993c4ba71596c30418ba5a0ddcf4f9c2f431466a","versionType":"git","status":"affected"},{"version":"6.17.4","lessThan":"6.18","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/en_accel/ipsec.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/abe003b33223ff33552f291644bf35d9c2f992fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5bd4249e430f5963d559708ee96a671716d2400","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ecafd8284e527666e83261e6e57a7c7341d591cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64523","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:38.597","lastModified":"2026-07-25T10:17:38.597","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/handshake: Take a long-lived file reference at submit\n\nhandshake_nl_accept_doit() needs the file pointer backing\nreq->hr_sk->sk_socket to survive the window between\nhandshake_req_next() and the subsequent FD_PREPARE() and get_file().\nThe submit-side sock_hold() does not provide that.  sk_refcnt keeps\nstruct sock alive, but struct socket is owned by sock->file: when\nthe consumer fputs the last file reference, sock_release() tears\nthe socket down regardless of any sock_hold.\n\nAdd an hr_file pointer to struct handshake_req and acquire an\nexplicit reference on sock->file during handshake_req_submit().\nhandshake_complete() and handshake_req_cancel() release the\nreference on the completion-bit-winning path.\n\nThe submit error path must also release the file reference, but\nafter rhashtable insertion a concurrent handshake_req_cancel() can\ndiscover the request and race the error path.  Gate the error-path\ncleanup -- sk_destruct restoration, fput, and request destruction\n-- with test_and_set_bit(HANDSHAKE_F_REQ_COMPLETED), the same\nserialization handshake_complete() and handshake_req_cancel()\nalready use.  When cancel has already claimed ownership, the submit\nerror path returns without touching the request; socket teardown\nhandles final destruction.\n\nThe accept-side dereferences are not yet retargeted; that change\ncomes in the next patch."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/handshake/handshake.h","net/handshake/netlink.c","net/handshake/request.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"685b10dd0e32c7782cead16c8cf055c609678583","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"16eaba5aa89c04eea125905bb8f988c1897f4f29","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"09dba37eee70d0596e26645015f1aa95a9848e9d","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.12.93","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.0.12","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/handshake/handshake.h","net/handshake/netlink.c","net/handshake/request.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/09dba37eee70d0596e26645015f1aa95a9848e9d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/16eaba5aa89c04eea125905bb8f988c1897f4f29","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/685b10dd0e32c7782cead16c8cf055c609678583","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64524","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:38.713","lastModified":"2026-07-25T10:17:38.713","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/hyperv: validate resolution_count and fix WIN8 fallback\n\nA SYNTHVID_RESOLUTION_RESPONSE with resolution_count > 64 walks past\nthe supported_resolution[SYNTHVID_MAX_RESOLUTION_COUNT] array in the\nparse loop. Bound resolution_count against the array size, folded\ninto the existing zero-check.\n\nWhen the WIN10 resolution probe fails, the caller in\nhyperv_connect_vsp() left hv->screen_*_max / preferred_* unpopulated,\nwhich sets mode_config.max_width / max_height to 0 and makes\ndrm_internal_framebuffer_create() reject every userspace framebuffer\nwith -EINVAL. The pre-WIN10 branch had the same gap for\npreferred_width / preferred_height. Use a single post-probe fallback\nguarded by screen_width_max == 0 so both paths converge on the WIN8\ndefaults."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/hyperv/hyperv_drm_proto.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"76c56a5affeba1e163b66b9d8cc192e6154466f0","lessThan":"96f7de3172d4aa878b7f87173b2b3507c350fcd6","versionType":"git","status":"affected"},{"version":"76c56a5affeba1e163b66b9d8cc192e6154466f0","lessThan":"bc573752f3dac0d1ab8df7078c1851bc76717653","versionType":"git","status":"affected"},{"version":"76c56a5affeba1e163b66b9d8cc192e6154466f0","lessThan":"1fb565b77b8f44afabb02de6310065f109d89e94","versionType":"git","status":"affected"},{"version":"76c56a5affeba1e163b66b9d8cc192e6154466f0","lessThan":"a321c908f2eeea01539668eb270d074d9b88e490","versionType":"git","status":"affected"},{"version":"76c56a5affeba1e163b66b9d8cc192e6154466f0","lessThan":"9c698b2c43c2667c34f5336bf46ad5786216ac2a","versionType":"git","status":"affected"},{"version":"76c56a5affeba1e163b66b9d8cc192e6154466f0","lessThan":"8a114b25b5521eae451b13bce98ae978624962e5","versionType":"git","status":"affected"},{"version":"76c56a5affeba1e163b66b9d8cc192e6154466f0","lessThan":"13d33b9ef67066c77c84273fac5a1d3fde3533d1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/hyperv/hyperv_drm_proto.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/13d33b9ef67066c77c84273fac5a1d3fde3533d1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1fb565b77b8f44afabb02de6310065f109d89e94","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8a114b25b5521eae451b13bce98ae978624962e5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/96f7de3172d4aa878b7f87173b2b3507c350fcd6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c698b2c43c2667c34f5336bf46ad5786216ac2a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a321c908f2eeea01539668eb270d074d9b88e490","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bc573752f3dac0d1ab8df7078c1851bc76717653","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64525","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:38.830","lastModified":"2026-07-25T10:17:38.830","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit\n\nThe struct pernet_operations docstring in include/net/net_namespace.h\nexplicitly warns against blocking RCU primitives in .exit handlers:\n\n    Exit methods using blocking RCU primitives, such as\n    synchronize_rcu(), should be implemented via exit_batch.\n    [...]\n    Please, avoid synchronize_rcu() at all, where it's possible.\n\n    Note that a combination of pre_exit() and exit() can\n    be used, since a synchronize_rcu() is guaranteed between\n    the calls.\n\nxfrm_policy_fini() violates this: it calls synchronize_rcu() before\nfreeing the policy_bydst hash tables (so no RCU reader is mid-\ntraversal at free time), but runs from xfrm_net_ops.exit -- once per\nnamespace -- so a cleanup_net() of N namespaces pays N full RCU\ngrace periods serially.\n\nUse the documented pre_exit/exit split. Move the policy flush (and\nthe workqueue drains it depends on) into a new .pre_exit handler;\nxfrm_policy_fini() then runs in .exit and frees the hash tables\nafter the synchronize_rcu_expedited() that cleanup_net() guarantees\nbetween the two phases. Providing O(1) RCU grace periods per batch\ninstead of O(N).\n\nObserved on Linux 6.18 with a workload doing unshare(CLONE_NEWNET)\nat ~13/sec sustained: cleanup_net() and the netns_wq rescuer kthread\nboth stuck in xfrm_policy_fini()'s synchronize_rcu(), >300k struct\nnet accumulated in the cleanup queue, Percpu in /proc/meminfo climbed\nto 130+ GB on 256-CPU hosts, and memcg OOMs followed. setup_net and\n__put_net counts were balanced, ruling out a refcount leak."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/xfrm/xfrm_policy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"438b1f668ad58f46ce699bb48e4698a7839e3f9e","lessThan":"bca6386dc08750fc7cdcbc7683473748ba3114b9","versionType":"git","status":"affected"},{"version":"3733fce2871c9bca9dd18a1a23b1432ea215a094","lessThan":"91cc13978ab0bc6f669139f53e7e613a860d10e0","versionType":"git","status":"affected"},{"version":"069daad4f2ae9c5c108131995529d5f02392c446","lessThan":"d14ae8ef88c2c6590e107db61b6adce148cec7b3","versionType":"git","status":"affected"},{"version":"069daad4f2ae9c5c108131995529d5f02392c446","lessThan":"3e52417318473782012b236d0325bf7d2266a597","versionType":"git","status":"affected"},{"version":"b66920a3348c0f63ba18365248fa21fbf0b3a937","versionType":"git","status":"affected"},{"version":"33a3149dd81a1e2f52b80ee1e0fc380b39f3d028","versionType":"git","status":"affected"},{"version":"6.12.83","lessThan":"6.12.93","versionType":"semver","status":"affected"},{"version":"6.18.24","lessThan":"6.18.35","versionType":"semver","status":"affected"},{"version":"6.6.136","lessThan":"6.7","versionType":"semver","status":"affected"},{"version":"6.19.14","lessThan":"6.20","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/xfrm/xfrm_policy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3e52417318473782012b236d0325bf7d2266a597","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/91cc13978ab0bc6f669139f53e7e613a860d10e0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bca6386dc08750fc7cdcbc7683473748ba3114b9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d14ae8ef88c2c6590e107db61b6adce148cec7b3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64526","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:38.950","lastModified":"2026-07-25T10:17:38.950","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: tsconfig: fix missing ethnl_ops_complete()\n\ntsconfig_prepare_data() calls ethnl_ops_begin(), we need to call\nethnl_ops_complete() before returning the error."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ethtool/tsconfig.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6e9e2eed4f39d52edf5fd006409d211facf49f6b","lessThan":"d02342d9bb4f0ab682f1846a4fbc15dd2955f7e6","versionType":"git","status":"affected"},{"version":"6e9e2eed4f39d52edf5fd006409d211facf49f6b","lessThan":"d53fe379d1f9a92e8a1bb2556084c8c177ebf8fd","versionType":"git","status":"affected"},{"version":"6e9e2eed4f39d52edf5fd006409d211facf49f6b","lessThan":"6386bd772de64e6760306eb91c7e86163af6c22f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ethtool/tsconfig.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6386bd772de64e6760306eb91c7e86163af6c22f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d02342d9bb4f0ab682f1846a4fbc15dd2955f7e6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d53fe379d1f9a92e8a1bb2556084c8c177ebf8fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64527","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:39.053","lastModified":"2026-07-25T10:17:39.053","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/hyperv: validate VMBus packet size in receive callback\n\nhyperv_receive_sub() reads msg->vid_hdr.type and dispatches into one\nof four message-type branches without knowing how many bytes the host\nwrote into hv->recv_buf. The completion path then runs\nmemcpy(hv->init_buf, msg, VMBUS_MAX_PACKET_SIZE), so the consumer that\nwakes on wait_for_completion_timeout() can read up to 16 KiB of\nresidue from a prior message as if it were the response payload.\n\nPass bytes_recvd into hyperv_receive_sub() and reject any packet that\ndoes not cover the pipe + synthvid header. A single switch on\nmsg->vid_hdr.type then computes the type-specific payload size: the\nthree completion-driving types (SYNTHVID_VERSION_RESPONSE,\nSYNTHVID_RESOLUTION_RESPONSE, SYNTHVID_VRAM_LOCATION_ACK) fall through\nto a shared exit that requires that size before memcpy/complete, while\nSYNTHVID_FEATURE_CHANGE validates its own payload and returns before\nreading is_dirt_needed. Unknown types are dropped.\n\nSYNTHVID_RESOLUTION_RESPONSE is variable length: the host fills\nresolution_count entries, not the full SYNTHVID_MAX_RESOLUTION_COUNT\narray. Validate the fixed prefix first so resolution_count can be\nread, bound it against the array, then require only the count-sized\narray, so the shorter responses the host actually sends are accepted.\n\nOnly run the sub-handler when vmbus_recvpacket() returned success. The\nmemcpy length is bytes_recvd, which is bounded by VMBUS_MAX_PACKET_SIZE\nonly on a successful receive; on -ENOBUFS vmbus_recvpacket() instead\nreports the required length, which can exceed hv->recv_buf, so copying\nbytes_recvd would read and write past the 16 KiB buffers. Gating on the\nsuccess return keeps the copy bounded. The nonzero-return path is itself\na malformed-message case and is now logged rather than silently skipped;\nchannel recovery is not attempted.\n\nRejected packets are reported via drm_err_ratelimited() rather than\nsilently dropped, matching the CoCo-hardened pattern in\nhv_kvp_onchannelcallback()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/hyperv/hyperv_drm_proto.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"76c56a5affeba1e163b66b9d8cc192e6154466f0","lessThan":"57d5d697642e05d5dd2d40660817765943dd709f","versionType":"git","status":"affected"},{"version":"76c56a5affeba1e163b66b9d8cc192e6154466f0","lessThan":"f5251226551bfec98c4705641b6f94ff1f238d91","versionType":"git","status":"affected"},{"version":"76c56a5affeba1e163b66b9d8cc192e6154466f0","lessThan":"049a6b474823049fe60212f25f26e4b30f44ee8f","versionType":"git","status":"affected"},{"version":"76c56a5affeba1e163b66b9d8cc192e6154466f0","lessThan":"588c84b461393ff1998ac7b97b04f953f642e0df","versionType":"git","status":"affected"},{"version":"76c56a5affeba1e163b66b9d8cc192e6154466f0","lessThan":"164dc7bf17609340233c6bf4f66bb7c7008a0511","versionType":"git","status":"affected"},{"version":"76c56a5affeba1e163b66b9d8cc192e6154466f0","lessThan":"c8974d96b6a5496f33dc69a3ce28a7bf5078def4","versionType":"git","status":"affected"},{"version":"76c56a5affeba1e163b66b9d8cc192e6154466f0","lessThan":"7f87763f47a3c22fb50265a00619ef10f2394b18","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/hyperv/hyperv_drm_proto.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/049a6b474823049fe60212f25f26e4b30f44ee8f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/164dc7bf17609340233c6bf4f66bb7c7008a0511","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/57d5d697642e05d5dd2d40660817765943dd709f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/588c84b461393ff1998ac7b97b04f953f642e0df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f87763f47a3c22fb50265a00619ef10f2394b18","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c8974d96b6a5496f33dc69a3ce28a7bf5078def4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f5251226551bfec98c4705641b6f94ff1f238d91","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64528","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:39.187","lastModified":"2026-07-25T10:17:39.187","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntty: serial: samsung: Remove redundant port lock acquisition in rx helpers\n\nSashiko identified a deadlock when the console flow is engaged [1].\n\nWhen console flow control is enabled (UPF_CONS_FLOW),\ns3c24xx_serial_stop_tx() calls s3c24xx_serial_rx_enable() and\ns3c24xx_serial_start_tx() calls s3c24xx_serial_rx_disable().\n\nThe serial core framework invokes the .stop_tx() and .start_tx()\ncallbacks with the port->lock spinlock already held. Furthermore, all\ninternal driver paths that invoke stop_tx (such as the DMA TX\ncompletion handler s3c24xx_serial_tx_dma_complete() or the PIO TX IRQ\nhandler s3c24xx_serial_tx_irq()) also acquire port->lock prior to\ncalling it. (Note that s3c24xx_serial_start_tx() is only invoked by the\nserial core).\n\nHowever, s3c24xx_serial_rx_enable() and s3c24xx_serial_rx_disable()\nunconditionally attempt to acquire port->lock again using\nuart_port_lock_irqsave(). Since spinlocks are not recursive, this\ncauses a deadlock on the same CPU when console flow control is engaged.\n\nRemove the redundant lock acquisition from both rx helper functions."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/tty/serial/samsung_tty.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b497549a035c2a81b71c7a27f2b00c8a16c09423","lessThan":"ee9eb72be95490602c493db050c73d925c3a4d74","versionType":"git","status":"affected"},{"version":"b497549a035c2a81b71c7a27f2b00c8a16c09423","lessThan":"10014eb7eee351f7b587f8ac85830f0c9343cb9a","versionType":"git","status":"affected"},{"version":"b497549a035c2a81b71c7a27f2b00c8a16c09423","lessThan":"f4c3e63fa8639aedf96fb200d9939945a9eed51e","versionType":"git","status":"affected"},{"version":"b497549a035c2a81b71c7a27f2b00c8a16c09423","lessThan":"a9c22e0f93ba18322a6623ecdda2f0cd858ca350","versionType":"git","status":"affected"},{"version":"b497549a035c2a81b71c7a27f2b00c8a16c09423","lessThan":"14143ec10d69f42806b5d7b046f0fd1b835831ae","versionType":"git","status":"affected"},{"version":"b497549a035c2a81b71c7a27f2b00c8a16c09423","lessThan":"9fd48937046efc9abb89379d63ee9cc5c661d711","versionType":"git","status":"affected"},{"version":"b497549a035c2a81b71c7a27f2b00c8a16c09423","lessThan":"9c92b42207978559e32903c3098aaf5c5b5788b2","versionType":"git","status":"affected"},{"version":"b497549a035c2a81b71c7a27f2b00c8a16c09423","lessThan":"a3bb136bff5e6a5e48cdd813246c9c4686feaaa9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/tty/serial/samsung_tty.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.27","status":"affected"},{"version":"0","lessThan":"2.6.27","versionType":"semver","status":"unaffected"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/10014eb7eee351f7b587f8ac85830f0c9343cb9a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/14143ec10d69f42806b5d7b046f0fd1b835831ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c92b42207978559e32903c3098aaf5c5b5788b2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9fd48937046efc9abb89379d63ee9cc5c661d711","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3bb136bff5e6a5e48cdd813246c9c4686feaaa9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a9c22e0f93ba18322a6623ecdda2f0cd858ca350","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ee9eb72be95490602c493db050c73d925c3a4d74","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f4c3e63fa8639aedf96fb200d9939945a9eed51e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64529","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-25T10:17:39.317","lastModified":"2026-07-25T10:17:39.317","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - remove unused character device and IOCTLs\n\nThe QAT driver exposes a character device (qat_adf_ctl) with IOCTLs\nfor device configuration, start, stop, status query and enumeration.\nThese IOCTLs are not part of any public uAPI header and have no known\nin-tree or out-of-tree users. Device lifecycle is already managed via\nsysfs.\n\nThe ioctl interface also increases the attack surface and is the\nsubject of a number of bug reports.\n\nRemove the character device, the IOCTL definitions, and the related\ndata structures (adf_dev_status_info, adf_user_cfg_key_val,\nadf_user_cfg_section, adf_user_cfg_ctl_data). Drop the now-unused\nadf_cfg_user.h header and strip adf_ctl_drv.c down to the minimal\nmodule_init/module_exit hooks for workqueue, AER, and crypto/compression\nalgorithm registration.\n\nClean up leftover dead code that was only reachable from the removed\nIOCTL paths: adf_cfg_del_all(), adf_devmgr_verify_id(),\nadf_devmgr_get_num_dev(), adf_devmgr_get_dev_by_id(),\nadf_get_vf_real_id() and the unused ADF_CFG macros.\n\nAdditionally, drop the entry associated to QAT IOCTLs in\nioctl-number.rst."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["Documentation/userspace-api/ioctl/ioctl-number.rst","drivers/crypto/intel/qat/qat_common/adf_cfg.c","drivers/crypto/intel/qat/qat_common/adf_cfg.h","drivers/crypto/intel/qat/qat_common/adf_cfg_common.h","drivers/crypto/intel/qat/qat_common/adf_cfg_user.h","drivers/crypto/intel/qat/qat_common/adf_common_drv.h","drivers/crypto/intel/qat/qat_common/adf_ctl_drv.c","drivers/crypto/intel/qat/qat_common/adf_dev_mgr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d8cba25d2c68992a6e7c1d329b690a9ebe01167d","lessThan":"071590a44cbc38483fceb1ab943363ec26868e1b","versionType":"git","status":"affected"},{"version":"d8cba25d2c68992a6e7c1d329b690a9ebe01167d","lessThan":"1de076f43e64bf65fbe7280a269c70e0e60518df","versionType":"git","status":"affected"},{"version":"d8cba25d2c68992a6e7c1d329b690a9ebe01167d","lessThan":"a4999664a5ef77bdb0c6e6b935f581ac8ce6b63a","versionType":"git","status":"affected"},{"version":"d8cba25d2c68992a6e7c1d329b690a9ebe01167d","lessThan":"6848a6e39cac44fdb7cb88f0f777df62172d1551","versionType":"git","status":"affected"},{"version":"d8cba25d2c68992a6e7c1d329b690a9ebe01167d","lessThan":"b1ea97076bd0a5196290deba172034e480646727","versionType":"git","status":"affected"},{"version":"d8cba25d2c68992a6e7c1d329b690a9ebe01167d","lessThan":"b8ebf008696de1ec08c90d51f94d7e40bd448be1","versionType":"git","status":"affected"},{"version":"d8cba25d2c68992a6e7c1d329b690a9ebe01167d","lessThan":"de2cc38489b629927910b1aeff69bba7bd5c6f1b","versionType":"git","status":"affected"},{"version":"d8cba25d2c68992a6e7c1d329b690a9ebe01167d","lessThan":"3ae49dd04dbb11fb73f17f58a982dba128abe83a","versionType":"git","status":"affected"},{"version":"d8cba25d2c68992a6e7c1d329b690a9ebe01167d","lessThan":"d237230728c567297f2f98b425d63156ab2ed17f","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["Documentation/userspace-api/ioctl/ioctl-number.rst","drivers/crypto/intel/qat/qat_common/adf_cfg.c","drivers/crypto/intel/qat/qat_common/adf_cfg.h","drivers/crypto/intel/qat/qat_common/adf_cfg_common.h","drivers/crypto/intel/qat/qat_common/adf_cfg_user.h","drivers/crypto/intel/qat/qat_common/adf_common_drv.h","drivers/crypto/intel/qat/qat_common/adf_ctl_drv.c","drivers/crypto/intel/qat/qat_common/adf_dev_mgr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.17","status":"affected"},{"version":"0","lessThan":"3.17","versionType":"semver","status":"unaffected"},{"version":"5.10.260","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.211","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.177","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.144","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.95","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.37","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.14","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1.2","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/071590a44cbc38483fceb1ab943363ec26868e1b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1de076f43e64bf65fbe7280a269c70e0e60518df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3ae49dd04dbb11fb73f17f58a982dba128abe83a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6848a6e39cac44fdb7cb88f0f777df62172d1551","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4999664a5ef77bdb0c6e6b935f581ac8ce6b63a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b1ea97076bd0a5196290deba172034e480646727","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b8ebf008696de1ec08c90d51f94d7e40bd448be1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d237230728c567297f2f98b425d63156ab2ed17f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/de2cc38489b629927910b1aeff69bba7bd5c6f1b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-66011","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-07-25T11:17:18.347","lastModified":"2026-07-25T11:17:18.347","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"ImageMagick","product":"ImageMagick","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"7.1.2-27","versionType":"semver","status":"affected"},{"version":"7.1.2-27","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","baseScore":3.3,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.8,"impactScore":1.4}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-401"}]}],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cvhv-g4rq-3hmw","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/imagemagick-before-27-memory-leak-via-invalid-cli-options","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-66012","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-07-25T11:17:19.053","lastModified":"2026-07-25T11:17:19.053","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy actions across the entire workspace. When the Publish server is enabled in anonymous mode (Conf.Publish.Enable=true and Conf.Publish.Auth.Enable=false), the Publish reverse proxy attaches an anonymous RoleReader JWT to proxied requests, allowing a remote unauthenticated attacker to reach /mcp. The attacker can read conf/conf.json to extract accessAuthCode, api.token, and cookieKey in plaintext, write arbitrary files in the workspace, and plant a plugin into data/plugins/ that executes with nodeIntegration:true and no contextIsolation on the next desktop launch, leading to administrator takeover."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"siyuan-note","product":"siyuan","defaultStatus":"unaffected","packageURL":"pkg:npm/github.com/siyuan-note/siyuan","versions":[{"version":"0","lessThan":"3.7.2","versionType":"semver","status":"affected"},{"version":"3.7.2","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":6.0}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://github.com/siyuan-note/siyuan/commit/c72ca4cd09019e5f64afdee8f8c6ec5ef34858db","source":"disclosure@vulncheck.com"},{"url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-cvhv-7xhj-xjp8","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/siyuan-before-unauthenticated-administrator-takeover-via-mcp","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-66013","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-07-25T11:17:19.193","lastModified":"2026-07-25T11:17:19.193","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"openremote","product":"openremote","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.26.2","versionType":"semver","status":"affected"},{"version":"1.26.2","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://github.com/openremote/openremote/security/advisories/GHSA-gpfc-h59v-63cv","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/openremote-before-authentication-bypass-via-console-registration","source":"disclosure@vulncheck.com"}]}}]}